Skip to main content

Connect Automated Device Enrollment (DEP)

Connect Apple Automated Device Enrollment: Download public key, create the server token, upload .p7m, and enable zero-touch provisioning.

Automated Device Enrollment (DEP) lets Apple Business Manager (ABM) or Apple School Manager (ASM) assign new Macs, iPads, and iPhones to Trio before they even leave the box—true zero-touch provisioning.
Important: you must connect Apple Push Notification Service (APN) first. Follow the steps in Connect Apple Push Notification Service (APN) and verify APN shows Connected before starting DEP.


Prerequisites

Requirement

Details

Role

Security Admin or Fleet Admin

APN status

Connected in MDM Setup

Apple account

ABM or ASM account with Admin or Device Enrollment Manager privileges

Files

Public key (.pem) downloaded from Trio• Server token (.p7m) downloaded from ABM/ASM


Open the DEP Wizard

  1. Go to Fleet → MDM Setup → Apple.

  2. Click Set up Automated Device Enrollment next to Automated Device Enrollment (DEP).

  3. The Connect to Automated Device Enrollment (DEP) wizard opens on Step 1 • Download Token.


Step-by-Step Setup

1. Download Trio’s public key

Click Download Public Key. Save the file (trio-public-key.pem) to your computer; Apple will need it to generate the server token.

2. Create the MDM server and token in ABM/ASM

  1. Sign in to https://business.apple.com or https://school.apple.com with your Apple ID.

  2. In the lower-left corner, click your account name ➜ Preferences ➜ Device Management Settings ➜ Add.

  3. Enter a server name (e.g., Trio MDM Server).

  4. Upload the trio-public-key.pem file in Upload Public Key.

  5. Click Save. Apple generates an MDM server entry.

  6. Select the server you just created and click Download Token to save the .p7m file.

3. Upload the server token to Trio

  1. Back in the Trio wizard, drag-and-drop the .p7m file into Upload MDM Server Token (Step 3).

  2. Click Connect. Trio validates the token and shows DEP as Connected, along with server name, token expiration, and the number of linked devices.

When the token nears expiration, Trio emails reminders 30, 15, and 7 days out.


What Happens Next?

  • Devices assigned to Trio MDM Server in ABM/ASM will auto-enroll during setup.

  • You can bulk move existing devices to Trio by selecting them in ABM/ASM and choosing Edit Device Management.

  • All linked devices appear in Fleet → Devices with an enrollment method of DEP.


Troubleshooting

Issue

Symptom

Fix

“Token invalid” on upload

Wizard won’t accept .p7m

Make sure you downloaded the token after uploading Trio’s public key and that the file hasn’t been renamed.

DEP shows Not Connected

Status badge is gray

Re-upload a fresh token; Apple tokens expire yearly or when the server is edited.

Devices don’t auto-enroll

Mac/iPad skips MDM screen

In ABM/ASM, confirm the device is assigned to Trio MDM Server and has an internet connection on first boot.

Token expired notification

Email alerts from Trio

Generate a new token in ABM/ASM and upload before the expiration date to avoid interruptions.

Did this answer your question?