Automated Device Enrollment (DEP) lets Apple Business Manager (ABM) or Apple School Manager (ASM) assign new Macs, iPads, and iPhones to Trio before they even leave the box—true zero-touch provisioning.
Important: you must connect Apple Push Notification Service (APN) first. Follow the steps in Connect Apple Push Notification Service (APN) and verify APN shows Connected before starting DEP.
Prerequisites
Requirement | Details |
Role | Security Admin or Fleet Admin |
APN status | Connected in MDM Setup |
Apple account | ABM or ASM account with Admin or Device Enrollment Manager privileges |
Files | • Public key ( |
Open the DEP Wizard
Go to Fleet → MDM Setup → Apple.
Click Set up Automated Device Enrollment next to Automated Device Enrollment (DEP).
The Connect to Automated Device Enrollment (DEP) wizard opens on Step 1 • Download Token.
Step-by-Step Setup
1. Download Trio’s public key
Click Download Public Key. Save the file (trio-public-key.pem) to your computer; Apple will need it to generate the server token.
2. Create the MDM server and token in ABM/ASM
Sign in to https://business.apple.com or https://school.apple.com with your Apple ID.
In the lower-left corner, click your account name ➜ Preferences ➜ Device Management Settings ➜ Add.
Enter a server name (e.g., Trio MDM Server).
Upload the
trio-public-key.pemfile in Upload Public Key.Click Save. Apple generates an MDM server entry.
Select the server you just created and click Download Token to save the
.p7mfile.
3. Upload the server token to Trio
Back in the Trio wizard, drag-and-drop the
.p7mfile into Upload MDM Server Token (Step 3).Click Connect. Trio validates the token and shows DEP as Connected, along with server name, token expiration, and the number of linked devices.
When the token nears expiration, Trio emails reminders 30, 15, and 7 days out.
What Happens Next?
Devices assigned to Trio MDM Server in ABM/ASM will auto-enroll during setup.
You can bulk move existing devices to Trio by selecting them in ABM/ASM and choosing Edit Device Management.
All linked devices appear in Fleet → Devices with an enrollment method of DEP.
Troubleshooting
Issue | Symptom | Fix |
“Token invalid” on upload | Wizard won’t accept | Make sure you downloaded the token after uploading Trio’s public key and that the file hasn’t been renamed. |
DEP shows Not Connected | Status badge is gray | Re-upload a fresh token; Apple tokens expire yearly or when the server is edited. |
Devices don’t auto-enroll | Mac/iPad skips MDM screen | In ABM/ASM, confirm the device is assigned to Trio MDM Server and has an internet connection on first boot. |
Token expired notification | Email alerts from Trio | Generate a new token in ABM/ASM and upload before the expiration date to avoid interruptions. |





