Switching your mobile device management solution is thought to be a challenging process. But you can simplify the process with proper preparations and planning. This guide will assist you in migrating your Mac devices from another MDM solution to Hexnode.
These steps will guide you through the process of migration:
- Remove assets from current MDM and back up required data.
- Create DEP and VPP accounts (if your organization doesn’t have one).
- Migrate certificates and tokens to Hexnode MDM.
- Sync users from directory services to Hexnode MDM.
- Disenroll devices from current MDM.
- Enroll devices into Hexnode MDM.
Step-1: Remove assets from current MDM and back up required data
When migrating devices, you might have to wipe all the content from the devices. Prior to doing so, decide what all data needs to be kept. Back up the required data to your preferred cloud storage service. Export device and user details from the current MDM to use them for the enrollment process. Delete the DEP and VPP accounts configured in the current MDM.
Step-2: Create DEP and VPP accounts
Go to https://business.apple.com/ and sign up for an Apple Business Manager account if your organization doesn’t have one. Device Enrollment Program (DEP) and Volume Purchase Program (VPP) are seamlessly integrated into Apple Business Manager.
Step-3: Migrate certificates and tokens to Hexnode MDM
– Create a new Apple Push Notification service certificate and add it to your Hexnode MDM portal. APNs certificate is required for Apple devices to communicate with MDM. So, this is a mandatory step.
- Download the self-signed certificate from the Hexnode MDM portal.
- Go to Apple Push Certificates Portal, upload the self-signed certificate and download the APNs certificate generated by Apple.
- Upload the APNs certificate back to the Hexnode MDM portal.
If your organization is already using DEP and VPP with the current MDM, you can continue using the services with Hexnode MDM. Move DEP and VPP tokens to Hexnode MDM. Your DEP token is a record of your organization’s devices and your VPP token keeps track of all app purchases.
DEP server token
In your DEP portal, create a new MDM server for Hexnode and move all the devices from the previous MDM server to the newly created Hexnode MDM server.
- Create a new MDM server in Apple Business Manager using the public key downloaded from your Hexnode MDM portal.
- Get the server token and upload it to your Hexnode portal to link Hexnode and DEP.
- Create a DEP profile in Hexnode which need to be applied during the DEP configuration.
- Assign your DEP devices to the Hexnode MDM server.
Revoke all app licenses and remove any of the previous VPP tokens from the current MDM. Link your VPP account with Hexnode MDM
- Download a new VPP token.
- Configure VPP in Hexnode by uploading this token.
Step-4: Sync users from directory services to Hexnode MDM
You can sync the users from various directory services such as Active Directory (AD), Azure AD and G Suite to the MDM console.
Unbind your current MDM vendor from the directory services and configure Hexnode MDM with them.
- Active Directory
- Configure Active Directory settings under Admin tab to get the users synced from the AD account to the Hexnode portal.
- Azure AD
- Configure Azure AD under Admin tab to get the users synced from the Azure AD account to the Hexnode portal.
- G Suite
- Configure G Suite under Admin tab to get the users and user groups synced from the G Suite account to the Hexnode portal.
Step-5: Disenroll devices from current MDM
Disenroll all your devices from the current MDM.
- Perform disenroll action using the current MDM.
- Manually remove enrollment profiles from your devices. This can’t be done if the MDM enrollment profile is made non-removable.
Step-6: Enroll devices into Hexnode MDM
Your devices can be enrolled in Hexnode using different methods. Choose the method that suites your organization’s requirements.
Automatic enrollment via Apple DEP
Use DEP enrollment for eligible devices. If you haven’t assigned devices to the Hexnode MDM server you have created, assign them by providing the serial number, order number or uploading a CSV file containing the serial numbers of all devices. Devices will automatically enroll upon their initial set up.
Bulk enrollment with CSV import
Use the device and user details downloaded in Step-1 to enroll devices in bulk.
- Bulk user import – Upload the user details as a CSV file and send enrollment requests to the users in bulk.
- Pre-approved enrollment – Bulk import a list of devices based on their serial numbers via a CSV file. You can proactively assign device management policies to these devices and the policies automatically take effect upon enrollment.
Allow users to authenticate with their AD credentials or usernames and passwords set in the portal.
Allow users to enroll without authentication using only the enrollment URL.
Admin can send enrollment requests with the server address, username and password to the users via email/SMS, and they can enroll using them.