Subject matter expertise · 2026-05-11 · trunk
The Apple overview adds enrollment decision guidance, distinguishes ownership and management models, links a capability matrix, and expands declarative/reactive context.
Counts describe source structure, including commands in substeps. More elements do not by themselves prove better usability.
Before · parent revision
Adding Apple Devices

Overview
Use the Apple platform to enroll and manage Apple devices running iOS (8.0 or later), macOS (10.12 or later), or tvOS (10.2 or later).
This section has the following topics:
- Using the Apple Push Notification Service
- Adding iOS Devices
- Adding macOS Devices
- Adding tvOS Devices
- Manually Renewing MDM Profiles for Apple Devices
- Using Apple Automated Device Enrollment
Apple devices do not require a SOTI MobiControl device agent for enrollment. However, you can install a SOTI MobiControl device agent on iOS devices after enrollment. To do so, create an app policy (see Using App Policies) that has the SOTI MobiControl device agent and target the enrolled device.
Use Lightweight Directory Access Protocol (LDAP) or IdP (backed by LDAP) to enroll your devices. After configuring the LDAP (see Managing Directory Service Connections) or IdP connection (see Managing Identity Provider Connections), enroll devices in specific device groups based on their LDAP or IdP groups. You can also use the LDAP or IdP groups for device authentication.
Automated Device Enrollment
Automated Device Enrollment (ADE) enables zero-touch, large-scale deployment of Apple devices. Use it for devices purchased directly from Apple, an Apple Authorized Reseller, or a carrier. After ordering the devices from a preferred channel, configure all the management settings in SOTI MobiControl. Settings should include preventing users from unenrolling their devices. Ship the devices directly to the user’s home. After unboxing and activating the device, it automatically enrolls in SOTI MobiControl. All the management settings and apps are ready for the user. You can further simplify the setup process for users by removing specific steps in Setup Assistant to get users up and running.
See the Apple Business Manager User Guide for more information on ADE.
For more information on using ADE with SOTI MobiControl, see Using Apple Automated Device Enrollment.
Declarative Devices
Normally SOTI MobiControl manages all Apple devices using a Reactive profile. However, compatible Apple devices have access to Declarative Device Management (see Declarative versus Reactive Profiles).
Reused content from Declarative versus Reactive Profiles is not expanded in this historical preview.
See Declarative versus Reactive Profiles for details.Se
After · committed revision
Adding Apple Devices

Overview
Use SOTI MobiControl to enroll and manage Apple devices running iOS (8.0 or later), macOS (10.12 or later), or tvOS (10.2 or later).
SOTI MobiControl supports more than one Apple enrollment model. Use the following decision flow to choose the right one.
For a side-by-side comparison of ownership models, supervision, device agent use, and standard App Store source deployment, see Apple Enrollment Capability Matrix.
- For iOS and iPadOS: Decide based on whether the device is employee-owned or
organization-owned.
- If the device is employee-owned and you need privacy-preserving management of only work data, use user-based enrollment. For supported iOS and iPadOS deployments, this uses Account-driven User Enrollment (ADUE).
- If the device is organization-owned, use device-based enrollment.
- Use Automated Device Enrollment (ADE) when you need full supervision, the highest level of management control, or zero-touch provisioning. This flow uses Apple Business Manager and Setup Assistant.
- Use Account-driven Device Enrollment (ADDE) when you need device-based enrollment but do not need supervision. This flow provides more controls than Account-driven User Enrollment and does not require Setup Assistant automation.
- Use the profile-driven SOTI Enrollment Service flow when you need profile-based Device Enrollment without supervision and the workflow depends on an enrollment URL and profile installation.
- For macOS: Decide whether the device is employee-owned or company-owned.
- Use macOS account-driven enrollment when the device can use a lighter MDM-only management model. This flow does not provide supervision and does not support device-agent deployment. Users enroll from macOS' device settings.
- Use ADE when you need the higher-control company-owned enrollment model, supervision for eligible deployments, or support for compatible downstream agent-based management. This flow uses Apple Business Manager and Setup Assistant.
- For tvOS: Use Automated Device Enrollment (ADE) only. Apple TV devices in SOTI MobiControl use the organization-owned ADE flow through Apple Business Manager and Setup Assistant. Account-driven and profile-driven Apple enrollment flows do not apply to tvOS.
After you choose the platform and enrollment model, continue with the matching platform overview topic: Adding iOS Devices for iOS and iPadOS, Adding macOS Devices for macOS, or Adding tvOS Devices for tvOS.
This section has the following topics:
- Using the Apple Push Notification Service
- Apple Enrollment Capability Matrix
- Adding iOS Devices
- Adding macOS Devices
- Adding tvOS Devices
- Manually Renewing MDM Profiles for Apple Devices
- Using Apple Automated Device Enrollment
Apple devices do not require a SOTI MobiControl device agent for enrollment. However, you can install a SOTI MobiControl device agent on iOS devices after enrollment. To do so, create an app policy (see Using App Policies) that has the SOTI MobiControl device agent and target the enrolled device.
Use Lightweight Directory Access Protocol (LDAP) or IdP (backed by LDAP) to enroll your devices. After configuring the LDAP (see Managing Directory Service Connections) or IdP connection (see Managing Identity Provider Connections), enroll devices in specific device groups based on their LDAP or IdP groups. You can also use the LDAP or IdP groups for device authentication.
Automated Device Enrollment
Automated Device Enrollment (ADE) enables zero-touch, large-scale deployment of Apple devices.
Use ADE for company-owned devices, especially when devices are purchased directly from Apple, an Apple Authorized Reseller, or a participating carrier. It is the right choice when your deployment needs Setup Assistant automation, zero-touch provisioning, full supervision, or the highest level of management control.
With ADE, you first configure the management settings in SOTI MobiControl and assign the devices to the MDM server in Apple Business Manager. After the devices are shipped to users, they can un-box and activate them so that enrollment starts automatically during setup.
Use ADE instead of lighter sign-in based flows when you need the strongest organization-owned enrollment model. For tvOS, ADE is the only supported Apple enrollment flow in SOTI MobiControl. If you need employee-owned or lighter-managed alternatives instead, see user-based enrollment for iOS and iPadOS, device-based enrollment for iOS and iPadOS, or Adding macOS Devices.
For more information on using ADE with SOTI MobiControl, see Using Apple Automated Device Enrollment. For iOS account-driven and profile-driven alternatives, see Adding iOS Devices. For macOS account-driven enrollment, see Adding macOS Devices. For tvOS, see Adding tvOS Devices. See the Apple Business Manager User Guide for Apple's official documentation.
Declarative Devices
SOTI MobiControl supports both of Apple's management models for compatible Apple devices. Reactive management uses the traditional MDM command and check-in workflow. Declarative Device Management (DDM) extends that workflow by letting the device apply declared state locally and report status changes proactively.
In SOTI MobiControl, declarative management is available in specific Apple workflows such as declarative profiles, declarative app policies, Apple firmware management policies, and DDM activation controls. Other Apple workflows continue to use the reactive model.
For a structured overview of how these models differ and where SOTI MobiControl uses each one, see Declarative and Reactive Management for Apple Devices.
Highlighted changes
Green marks additions; red marks removals. Historical review comments are shown in amber. Colour is also supported by placement and strike-through.
Adding Apple Devices

Overview
Use the Apple platform to enroll and manage Apple devices running iOS (8.0 or later), macOS (10.12 or later), or tvOS (10.2 or later).
This section has the following topics:
- Using the Apple Push Notification Service
- Adding iOS Devices
- Adding macOS Devices
- Adding tvOS Devices
- Manually Renewing MDM Profiles for Apple Devices
- Using Apple Automated Device Enrollment
Apple devices do not require a SOTI MobiControl device agent for enrollment. However, you can install a SOTI MobiControl device agent on iOS devices after enrollment. To do so, create an app policy (see Using App Policies) that has the SOTI MobiControl device agent and target the enrolled device.
Use Lightweight Directory Access Protocol (LDAP) or IdP (backed by LDAP) to enroll your devices. After configuring the LDAP (see Managing Directory Service Connections) or IdP connection (see Managing Identity Provider Connections), enroll devices in specific device groups based on their LDAP or IdP groups. You can also use the LDAP or IdP groups for device authentication.
Automated Device Enrollment
Automated Device Enrollment (ADE) enables zero-touch, large-scale deployment of Apple devices. Use it for devices purchased directly from Apple, an Apple Authorized Reseller, or a carrier. After ordering the devices from a preferred channel, configure all the management settings in SOTI MobiControl. Settings should include preventing users from unenrolling their devices. Ship the devices directly to the user’s home. After unboxing and activating the device, it automatically enrolls in SOTI MobiControl. All the management settings and apps are ready for the user. You can further simplify the setup process for users by removing specific steps in Setup Assistant to get users up and running.
See the Apple Business Manager User Guide for more information on ADE.
For more information on using ADE with SOTI MobiControl, see Using Apple Automated Device Enrollment.
Declarative Devices
Normally SOTI MobiControl manages all Apple devices using a Reactive profile. However, compatible Apple devices have access to Declarative Device Management (see Declarative versus Reactive Profiles).
Reused content from Declarative versus Reactive Profiles is not expanded in this historical preview.
See Declarative versus Reactive Profiles for details.Se
Overview
Use SOTI MobiControl to enroll and manage Apple devices running iOS (8.0 or later), macOS (10.12 or later), or tvOS (10.2 or later).
SOTI MobiControl supports more than one Apple enrollment model. Use the following decision flow to choose the right one.
For a side-by-side comparison of ownership models, supervision, device agent use, and standard App Store source deployment, see Apple Enrollment Capability Matrix.
- For iOS and iPadOS: Decide based on whether the device is employee-owned or
organization-owned.
- If the device is employee-owned and you need privacy-preserving management of only work data, use user-based enrollment. For supported iOS and iPadOS deployments, this uses Account-driven User Enrollment (ADUE).
- If the device is organization-owned, use device-based enrollment.
- Use Automated Device Enrollment (ADE) when you need full supervision, the highest level of management control, or zero-touch provisioning. This flow uses Apple Business Manager and Setup Assistant.
- Use Account-driven Device Enrollment (ADDE) when you need device-based enrollment but do not need supervision. This flow provides more controls than Account-driven User Enrollment and does not require Setup Assistant automation.
- Use the profile-driven SOTI Enrollment Service flow when you need profile-based Device Enrollment without supervision and the workflow depends on an enrollment URL and profile installation.
- For macOS: Decide whether the device is employee-owned or company-owned.
- Use macOS account-driven enrollment when the device can use a lighter MDM-only management model. This flow does not provide supervision and does not support device-agent deployment. Users enroll from macOS' device settings.
- Use ADE when you need the higher-control company-owned enrollment model, supervision for eligible deployments, or support for compatible downstream agent-based management. This flow uses Apple Business Manager and Setup Assistant.
- For tvOS: Use Automated Device Enrollment (ADE) only. Apple TV devices in SOTI MobiControl use the organization-owned ADE flow through Apple Business Manager and Setup Assistant. Account-driven and profile-driven Apple enrollment flows do not apply to tvOS.
After you choose the platform and enrollment model, continue with the matching platform overview topic: Adding iOS Devices for iOS and iPadOS, Adding macOS Devices for macOS, or Adding tvOS Devices for tvOS.
This section has the following topics:
- Using the Apple Push Notification Service
- Apple Enrollment Capability Matrix
- Adding iOS Devices
- Adding macOS Devices
- Adding tvOS Devices
- Manually Renewing MDM Profiles for Apple Devices
- Using Apple Automated Device Enrollment
Apple devices do not require a SOTI MobiControl device agent for enrollment. However, you can install a SOTI MobiControl device agent on iOS devices after enrollment. To do so, create an app policy (see Using App Policies) that has the SOTI MobiControl device agent and target the enrolled device.
Use Lightweight Directory Access Protocol (LDAP) or IdP (backed by LDAP) to enroll your devices. After configuring the LDAP (see Managing Directory Service Connections) or IdP connection (see Managing Identity Provider Connections), enroll devices in specific device groups based on their LDAP or IdP groups. You can also use the LDAP or IdP groups for device authentication.
Automated Device Enrollment
Automated Device Enrollment (ADE) enables zero-touch, large-scale deployment of Apple devices.
Use ADE for company-owned devices, especially when devices are purchased directly from Apple, an Apple Authorized Reseller, or a participating carrier. It is the right choice when your deployment needs Setup Assistant automation, zero-touch provisioning, full supervision, or the highest level of management control.
With ADE, you first configure the management settings in SOTI MobiControl and assign the devices to the MDM server in Apple Business Manager. After the devices are shipped to users, they can un-box and activate them so that enrollment starts automatically during setup.
Use ADE instead of lighter sign-in based flows when you need the strongest organization-owned enrollment model. For tvOS, ADE is the only supported Apple enrollment flow in SOTI MobiControl. If you need employee-owned or lighter-managed alternatives instead, see user-based enrollment for iOS and iPadOS, device-based enrollment for iOS and iPadOS, or Adding macOS Devices.
For more information on using ADE with SOTI MobiControl, see Using Apple Automated Device Enrollment. For iOS account-driven and profile-driven alternatives, see Adding iOS Devices. For macOS account-driven enrollment, see Adding macOS Devices. For tvOS, see Adding tvOS Devices. See the Apple Business Manager User Guide for Apple's official documentation.
Declarative Devices
SOTI MobiControl supports both of Apple's management models for compatible Apple devices. Reactive management uses the traditional MDM command and check-in workflow. Declarative Device Management (DDM) extends that workflow by letting the device apply declared state locally and report status changes proactively.
In SOTI MobiControl, declarative management is available in specific Apple workflows such as declarative profiles, declarative app policies, Apple firmware management policies, and DDM activation controls. Other Apple workflows continue to use the reactive model.
For a structured overview of how these models differ and where SOTI MobiControl uses each one, see Declarative and Reactive Management for Apple Devices.
WYSIWYG-style approximation using the SOTI diff renderer. This is not an Oxygen/DITA-OT build or a live help page. Keyrefs, conrefs, conditional content and related-link navigation may require the original publishing environment. Screenshots are extracted from the matching revision.