# How to enroll Apple TVs

Apple TVs are becoming a significant entity in enterprises. It is one of the most promising streaming and signage tool used today in enterprise infrastructures. Hexnode supports the management of Apple TVs with a set of easy enrollment methods. They can be enrolled in Hexnode via different methods:

1. [Apple Configurator Enrollment](#apple-configurator-enrollment)
2. [Apple Business Enrollment](#abm-enrollment)
3. [Apple Business Enrollment via Apple Configurator](#abm-enrollment-via-apple-configurator)

 Note: 
Before enrolling an Apple TV, make sure to
[ configure the APNs certificate](https://www.hexnode.com/mobile-device-management/help/apns-settings/) on your Hexnode portal.

 

Apple Configurator Enrollment
-----------------------------

Apple Configurator is a macOS tool that can be used to supervise and enroll Apple devices in mobile device management solutions. Apple Configurator is also used for creating configuration profile and deploy applications for enterprise and educational institutions. The enrollment can be completed through a wired setup or wirelessly over-the-air.

 Pre-requisites:- An Apple TV with tvOS 10.2 or higher.
- A macOS device with Apple Configurator 2.5 or later.
- Make sure the Mac and Apple TV are connected to the same Wi-Fi or ethernet connection.

 

Follow the steps below to enroll Apple TV to Hexnode using Apple Configurator:

Step 1: Assigning a default user

1. On the Hexnode portal, go-to **Enroll > Platform – Specific > tvOS > Apple Configurator**.
2. Choose the required domain and assign a user from **Select User** option and click **Save**.

 Note: You can change the assigned user from  **Manage > Device > Actions > Change Owner** after completing the device enrollment.

 

 

Step 2: Creating a Wi-Fi profile in Apple Configurator

1. Open Apple Configurator on the host Mac. On the **menu** bar, click on **File** → **New Profile** → **Wi-Fi**, select **Configure**.
2. Enter the SSID, security type, password, and any other relevant settings required to connect to your Wi-Fi network.
3. Click **Save** from the **File** menu.

 

 

Step 3: Creating a Blueprint in Apple Configurator

1. Open Apple Configurator 2.0 on your host Mac machine.
2. Go to **Blueprints** and click on **Edit Blueprints**.
3. Click on **New** from the bottom left and enter a name for the blueprint.
4. Double click on the blueprint, this will take you to the **Info** page. Change the blueprint **Target** to **Apple TV**.
5. Go back to the **All Blueprints** page and select the blueprint.
6. Click on the **Add** button (located on top of the Configurator) and choose **Profiles** and select the Wi-Fi profile. Alternately right-click on the blueprint and click on **Add** and choose **Profile** to add the previously created Wi-Fi profile.
7. Select the blueprint and click on the **Prepare** button on top of the Configurator. Or else, right click on the blueprint and select **Prepare**.
8. Choose **Prepare with: Manual configuration**. Enable the options **Supervise devices** and **Allow devices to pair with other computers** and click **Next**. If *Allow devices to pair with other computers* is not selected, the device cannot be detected by Mac or a PC when connected via USB.
9. Now you should choose the enrollment server to remotely manage the device. Select a server that you have already created for your Hexnode portal. However, if you haven’t already created a server, click on **New Server** from the drop-down and click **Next**.
10. If you are creating a new server, 
    1. Specify a name for the server and enter the URL, which can be found at **Enroll > Platform – Specific > tvOS > Apple Configurator** on your Hexnode MDM console and click **Next**.
    2. The trust anchor certificates for the MDM server will be automatically added, click on **Next**.
11. Now choose the organization used to supervise the devices. To create a new organization, select the **New Organization** from the drop-down menu, and click **Next**. Note that this step will be hidden if no organization is already registered in the Apple Configurator.
12. **Skip** the Sign in to **Apple School Manager or Apple Business Manager** page.
13. Enter the information of your organization and then select **Next**. The information includes **Name, Phone, Email** and **Address**.
14. Select **Generate a new supervision identity** and click **Next**.
15. From the **Setup Assistant** screen, select any of the three options from the drop-down: **Show all steps**, **Show only some steps**, and **Do not show any of these steps**. If *Show only some steps* is selected, choose the steps to be shown during the device activation from the same page. Click **Prepare**.

 

 

Step 4: Applying Blueprint to the Apple TV 

Connect the Apple TV to the Mac running Apple Configurator using a USB cable.

**OR**

Connect the Mac running Apple Configurator and the Apple TV by pairing them over a network.

 Note: 
The Mac and Apple TV should be connected to the same Wi-Fi network.

 
To pair them over a network,

1. On your Apple TV, go to **Settings > Remotes and Devices > Remote App and Devices**.
2. On your Mac, open Apple Configurator 2.
3. Click on **Apple Configurator 2** in the **menu** bar and choose the **Paired Devices**.
4. From the search results, click **Pair** next to your Apple TV.
5. Enter the 6-digit pin that appears on the screen of your Apple TV.
6. On the **All Devices** page in the Apple Configurator, select your paired Apple TV. ![enroll apple tvs in hexnode mdm](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Apple-tv-config.png)
7. Right-click on the device, select **Apply**, then choose the required Blueprint and click **Apply**. This will raise a prompt to **Erase** the device. Proceed with erasing and follow the on-screen instructions on your Apple TV after reset to complete the enrollment.

You can find the installed profile in Apple TV from **Settings > General > Device Management**.

 

 

Apple Business enrollment
-------------------------

Apple Business was introduced by Apple to help Business and Educational organizations remotely deploy Apple devices. Using Apple Business, a brand-new Apple device can be enrolled in Hexnode without a technician ever touching it. After the devices have been enrolled in Hexnode, you can apply ADE policies via the Hexnode portal.

 Pre-requisites:- tvOS 10.2 or later
- The organization should be enrolled in [Apple Business](https://business.apple.com/). Also, make sure to [link Hexnode with Apple Business](https://www.hexnode.com/mobile-device-management/help/enrollment-of-apple-devices-through-dep/#configuring-dep-with-hexnode) using a secure token.
- The device must have been ordered after March 1, 2011, whether it was purchased directly from Apple or a participating Apple Authorized Reseller or carrier.
- If the device was purchased directly from Apple, the Apple Customer Number that is assigned to your organization is required to connect eligible orders and devices to Apple Business.
- If the device was purchased directly from a participating Apple Authorized Reseller or carrier, the device must be linked to that reseller’s ADE ResellerID. The actual date of eligibility is determined by the participating Apple Authorized Reseller or carrier sales’ history.

 

Here is how to assign Apple TVs to the Hexnode server via Apple Business:

1. Log in to your [Apple Business](https://business.apple.com) account.
2. Complete the two-step verification.
3. Click **Devices**. Search and select the required devices from the list. You can filter devices based on their device management, enforcement deadline, source, order numbers, device types, storage size etc. Then, click on **Assign Device Management** to assign the device management server.
4. Next, select the required **device management server** (Hexnode) from the dropdown, and click **Continue.**
[![Add Hexnode as device management server in Apple Business.](https://www.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Add-device-management-server-in-Apple-Business.png)](https://www.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Add-device-management-server-in-Apple-Business.png "Add device management server in Apple Business")

6. Confirm your action to complete the assignment.

[Create a configuration profile](https://www.hexnode.com/mobile-device-management/help/dep-management/#dep-configuration-profiles) with required configurations in Hexnode and attach it with the devices for streamlined enrollment. The device is now ready for deployment. If you have a new device, activate ADE by connecting it to the internet and applying **Remote Management** configurations. If you have an already activated device, reset the device to its factory settings to initiate the device enrollment procedure. After resetting, connect the device to a Wi-Fi network and apply **Remote Management**.

Apple Business Enrollment via Apple Configurator
------------------------------------------------

Apple devices purchased before March 1, 2011 and other non-Authorized resellers or non-Apple purchased devices cannot be directly enrolled via Apple Business enrollment. Such devices can be enrolled in ADE with the help of Apple Configurator. Also, Apple TV’s that were previously **Released** from ADE can also be added back using this enrollment method.

### Step A: Create a Wi-Fi profile in Apple Configurator

1. Open Apple Configurator on the host Mac. On the **menu** bar, click on **File → New Profile → Wi-Fi**, select **Configure**.
2. Enter the SSID, security type, password, and any other relevant settings required to connect to your Wi-Fi network.
3. Click **Save** from the **File** menu.

 

 

### Step B: Prepare a Blueprint and attach the Wi-Fi profile

1. Open Apple Configurator 2.0 on your host Mac machine.
2. Go to **Blueprints** and click on **Edit Blueprints**.
3. Click on **New** from the bottom left and enter a name for the blueprint.
4. Double click on the blueprint, this will take you to the **Info** page. Change the blueprint **Target** to **Apple TV**. Click on **Back**.
5. Select the blueprint and click on the Add button (located on top of Apple Configurator). Choose **Profiles** and select the created Wi-Fi profile. Alternately right-click on the blueprint and click on **Add** and choose **Profile** to add the Wi-Fi profile.
6. Then select the blueprint and click on the **Prepare** button on top of the Apple Configurator. Or, right click on the blueprint and select **Prepare**.
7. Choose **Prepare with: Manual configuration**. Enable the options **Add to Apple School Manager or Apple Business Manager**, **Activate and complete enrollment**, **Supervise devices** and **Allow devices to pair with other computers** and click **Next**. If *Allow devices to pair with other computers* is not selected, the device cannot be detected by Mac or a PC when connected via USB.
8. Now choose the enrollment server to remotely manage the device. Select **New Server** from the drop-down and click **Next**.
9. Specify a name for the server and enter the URL, which can be found at **Enroll > Platform – Specific > tvOS > Apple Configurator** and click on **Next**.
10. The trust anchor certificates for the MDM server will be automatically added, click on **Next**.
11. Now choose the organization used to supervise the devices. To create a new organization, select the **New Organization** from the drop-down menu, and click **Next**. Note that, this step will be hidden if no organization is already registered in the Apple Configurator.
12. Sign in to your Apple Business Manager account. Note that this account should have administrative permissions to manage devices.
13. Select **Generate a new supervision identity** and click **Next**.
14. From the **Setup Assistant** screen, select any of the three options from the drop-down: **Show all steps**, **Show only some steps**, and **Do not show any of these steps**. If Show only some steps is selected, choose the steps to be shown from the same page. Click Next.
15. Then select the previously prepared Wi-Fi profile and click **Next**.
16. Click on **Prepare**.

 

 

### Step C: Pair the devices and associate the Blueprint

Connect the host Mac and the Apple TV either wirelessly or via a USB cable. To pair Apple devices over a network, refer **Step 4: Applying Blueprint to the Apple TV** in the **Apple Configurator Enrollment**.

Now, apply Blueprint to devices. To do so, select the device and click on **Blueprints**, select the required Blueprint, and click on **Apply**.

If the device is supervised, the Wi-Fi profile will automatically install on the device and you will be prompted to initiate the erase action on Apple Configurator. However, if the device is not-supervised, you will be notified that the Wi-Fi profile installation cannot be completed without manual intervention. Install the profile by physically accessing the device and manually reset the device to its factory settings.

 

 

 

### Step D: Sync the Apple Business Manager account with Hexnode

Once the device is reset, leave it on the Hello screen. Then sync your Apple Business Manager account with Hexnode. For that, first create a DEP Account in Hexnode.

1. In the Hexnode UEM portal, go to **Enroll > All Enrollments > No-Touch > Apple Business/School Manager** to obtain the MDM DEP certificate.
2. Click on **Next**.
3. Provide an **Account name** and download the certificate file **Hexnode_Apple_DEP_cert.pem**.
4. Sign in to your [Apple Business Manager](https://business.apple.com) account.
5. Click your name at the bottom of the sidebar. Then, go to **Preferences** > **Your MDM Servers**, and click on **Add**.
6. Name the MDM server and upload the public key (the ADE certificate previously obtained) and click **Save**.
7. Click on **Download Token > Download Server Token**.
8. Go back to your Hexnode UEM console and upload the ADE server token in the field **Upload DEP server token file**.
9. Check the box **Add as Pre-approved device** if you want to [pre-approve](https://www.hexnode.com/mobile-device-management/help/pre-enrollment-of-devices-hexnode-mdm/#pre-approved-dep-enrollment) the ADE devices that you are planning to enroll using Hexnode.
10. Choose a **Default Configuration Profile**. By default, the **Default DEP profile** will be selected. If you want to attach a different configuration profile with the ADE Account, choose it from the drop-down.
11. Select the **User authentication** mechanism that should be implemented when enrolling devices. 
    1. **Use Global Authentication settings:** The authentication mode as selected under **Admin** > **Enrollment** > **Authentication Modes** is considered.
    2. **No Authentication:** If this option is selected, the device enrollment can be completed without any user authentication. The user to which the device should be assigned must be specified. 
        - **Domain**: Select the domain in which the user resides. It can be Hexnode’s local directory or any integrated directory domains.
        - **Default user**: Choose the user in the selected domain to which all the ADE devices should be assigned to.
12. Click on **Next** to move on to the next steps.

 

 

### Step E: Assign the devices to the Hexnode server in Apple Business

On applying the configurations via the Blueprint, the device will get listed under **Devices** tab in Apple Business. Select the devices and assign it to the MDM server.

Devices can be assigned individually or in bulk. To select devices in bulk, use the available filter criteria to group the required devices together. However, if you want to enroll multiple devices without filtering then just select the required devices manually.

1. On your Apple Business account, go to **Devices**.
2. Search and select the required devices from the list. You can filter devices based on their device management, enforcement deadline, source, order numbers, device types, storage size etc. Then, click on **Assign Device Management** to assign the device management server.
3. Next, select the required **device management server** (Hexnode) from the dropdown, and click **Continue.**
4. Click on **Continue** and then confirm your action.
5. Now, go to your Hexnode UEM admin console and click on **Sync with ADE** under **Enroll > All Enrollments > No-Touch > Apple Business/School Manager > ADE Devices**.

 

 

### Step F: Activate the device and get it enrolled in Apple Business

Now, start activating the erased device or the new device to which the Blueprint was attached. The device will get automatically associated with the Wi-Fi network configured under the Wi-Fi profile. Enable Remote Management for the device and follow the on-screen instructions to complete the device enrollment.

 

 

 

### 30-day provisional period

Apple devices enrolled in Apple Business via Apple Configurator will not work like an actual ADE enrolled device during the initial 30-days after deployment. That is, even if you have configured to block the manual MDM administration removal in the associated ADE profile, the user can choose to remove the MDM management from **Settings > General > profiles**. However, after the initial 30-days of enrollment, the user will be blocked from bypassing the MDM management.