Requirements
- On the Kobiton Mac, download the latest version of Apple Configurator 2. At the time of this writing, the latest version is 2.11.1 (3K81).
- On the iOS devices:
- Remove iCloud account
- Disable Restriction mode
Apple Configurator 2 Settings
- Open the Apple Configurator 2 application.
- On the menu bar, open the Apple Configurator 2 dropdown menu and select Install Automation Tools.
- On the Install Automation Tools popup, click Install.
- On the Apple Configurator 2 is trying to add a new helper popup, enter your username and password (login info) and click Add Helper.
Import Organization
- On the menu bar, click Apple Configurator 2 title > Preferences and select Organizations.
- On the bottom left, select the + symbol
- On the Create an Organization popup, click Next.
- On the Sign in to Apple School Manager or Apple Business Manager, sign in with your Apple credentials or click Skip to create a new organization.
- On Create an Organization,
- fill in the necessary information (Name is the only required field) and click Next
- Select Generate a new supervision identity and click Done
- Enter the Mac's password and select Update Settings.
- Back in the Organizations tab, click on the ellipses dropdown menu and select Import Organization.
Create and Export Supervision Identity
- On the menu bar, click Apple Configurator 2 title > Preference and select the Organizations tab
- Click on the ellipses dropdown menu
- Select Export Supervision Identity
- To export, fill in the following fields and click Save:
- Save as: Organization.der
- Where: Save these files somewhere easily accessible
-
Format: Unencrypted DER (.crt and .der, for Automator and cfgutil)
- On the Export for cfgutil popup, click Export
Activate Supervised Mode for iOS devices
- Use a USB cable to attach your iOS device to the Mac
- Click on Unsupervised tab, right click on the iOS device and select Prepare
- On the Prepare Devices modal, set the fields as follows:
- Prepare with: Manual Configuration
- Enable Supervise devices and Allow devices to pair with other computers
- Click Next
- On the Enroll in MDM Server modal, select Do not enroll in MDM and click Next
- On the Assign to Organization, select Kobiton Inc. and click Next
- On the Configure iOS Setup Assistant, Setup Assistant: Don’t show any of these steps and click Prepare
- If the confirmation popup is displayed, click Erase
- After the device has completed the preparing process, on the physical device, go through the device setup and sign in with your Apple ID credentials
- On the Apple Configurator 2 app, the device will be moved from the Unsupervised tab to the Supervised tab
Unlock Token Device Settings
- If not already, connect the device via USB to the Mac
- Move or copy & paste Organization.crt and Organization.der (created in Create and Export Supervision Identity section) to:
~/Library/Application\ Support/Kobiton/
- Navigate to:
~/Library/Application\ Support/Kobiton/devices/${device udid}
- In the {device’s UDID} directory, create the following two files and respective information:
-
- passcode:
{
"type":"pin",
"key": "{8-digit passcode}"
} - config:
{
"unlockPasscodeEnabled":
true
}
- passcode:
-
- For the updates to take place, unplug and plug the device back into the Mac
Troubleshooting Notes
- If the Kobiton desktop cannot detect the iOS device, on the physical device:
- Turn the screen on
- Enter the device's passcode
- Click the Trust button
- If the desktop does not recognize the device, restart the desktop app to trigger the device's startup process
- Set devices to Allow access to USB accessories:
- Go to settings > FaceID & passcode
- Under Allow Access When Locked, turn on USB accessories
- Set 8-character passcodes on devices
Known Limitations:
- When restarting the Mac Mini, Apple Desktop, or device, Apple will require a manual code bypass on the physical device.