Skip to main content

Settings - MDM Setup (Apple)

Learn how to setup MDM for Apple devices.

Updated over 3 months ago

The MDM Setup section in the Trio Business panel is where IT administrators configure and maintain the critical Apple and Google integrations required for effective device management. This includes linking the environment with Apple Push Notification services (APNs), Device Enrollment Program (DEP), and Volume Purchase Program (VPP) tokens.

These integrations are essential for automating enrollment, managing apps, enforcing profiles, and securing Apple devices across the organization.


Apple Setup Overview

Under the Apple tab, Trio displays three main components required for full functionality with Apple devices:

1. APNs Certificate

The Apple Push Notification service (APNs) certificate is mandatory for managing any iOS, iPadOS, or macOS device. It enables Trio to securely send MDM commands such as:

  • Remote wipe or lock

  • Profile installation or removal

  • Device enrollment notifications

  • Real-time compliance enforcement

Details shown:

  • Apple ID used for certificate creation

  • Expiration Date of the certificate

  • Days Remaining until renewal is needed

  • Status (Connected/Not Connected)

IT admins should monitor the expiration and renew the certificate in time to avoid disruption in management.


2. DEP Token

The Device Enrollment Program (DEP) token allows Trio to automate the out-of-box enrollment of Apple devices. Once a device is activated, it is automatically enrolled into Trio without any manual configuration, enabling:

  • Zero-touch provisioning

  • Supervised mode setup

  • Enforcement of enrollment and restrictions

Shown Info:

  • Company Name linked with Apple Business Manager

  • Business Apple ID

  • Expiration Date and renewal status

  • Connect/Renew options

🔄 DEP simplifies bulk deployments, especially in enterprise or education settings.


3. VPP Token

The Volume Purchase Program (VPP) token allows IT admins to assign and manage apps in bulk—without using personal Apple IDs. Apps purchased through Apple Business Manager can be:

  • Deployed silently to devices

  • Reclaimed and reassigned without repurchase

  • Synced with the organization’s app library

Displayed Information:

  • Company Name associated with the token

  • Business Apple ID (if applicable)

  • Expiration Date and progress bar

  • Options to Add Apps, Renew, or Disconnect

🛠 VPP integration supports large-scale application rollouts while keeping license ownership with the company.


Ongoing Maintenance and Security

To ensure continuous device control, Trio displays real-time connection statuses, color-coded countdowns to expiration, and direct access to Renew and Disconnect options for each certificate or token.

Admins should routinely check this page to:

  • Renew expiring certificates or tokens in time

  • Replace outdated Apple IDs or credentials

  • Verify connectivity after configuration changes

  • Add new apps via the VPP interface


Best Practices

  • Always renew APNs, DEP, and VPP tokens before expiration to avoid losing management capabilities

  • Use dedicated Apple IDs for each integration to maintain long-term visibility

  • Document your Apple Business Manager setup and user access permissions


The MDM Setup page in Trio is the gateway to robust Apple ecosystem management. Keeping this section up to date ensures secure, efficient, and scalable mobile device operations across your enterprise.

Did this answer your question?