Home > Enterprise Mobility Management > Device Enrollment > Mac Enrollment

Mac Enrollment

Access Rights

By default, Systems Manager will grant administrators the maximum amount of control available when applied to your Apple devices upon enrollment. However, in certain bring-your-own-device (BYOD) environments where the device is personally owned, device owners may not want administrators having this level of control over their personal devices.

 

Systems Manager can be customized to meet the needs of different deployment models by changing the permissions of what can be retrieved from or sent to the device. It is important to note that Access Rights must be set before devices are enrolled; changes made after enrollment will only take effect if a device is re-enrolled.

 

Access rights limitations can be found in Configure > General. See the article here for more info

On-device Enrollment

If you have a Dashboard account set up with an EMM network, you can find instructions under Systems manager > MDM > Add devices, or follow along the steps below.

Note that are two methods for Mac enrollment: Agent or Profile. Either one can be used for enrollment, but since each enables a different subset of features, both should be utilized when possible to access all available MDM features.

Agent Installation

  • Navigate to MDM > Add devices > macOS

  • Click the Download button. An agent, "MerakiPCCAgent.pkg" will download. Note that this installer will enroll devices into the Systems Manager network it was downloaded from.
  • After the download is complete, double-click MerakiPCCAgent.pkg.
  • When the installer begins, click Continue.
  • Read the Software License and click Continue.
  • Click Agree to accept if prompted.
  • Click Install to perform a standard installation.
  • Once the installation has finished, your Mac device will show up under Monitor > Clients in Dashboard as soon as it has an Internet connection.

Profile Installation

  • Navigate to MDM > Add devices > macOS

  • From the device, open m.meraki.com

  • Enter your network ID, where XXX-XXX-XXXX is the network-specific ID.
  • Press Register.
    • If using SM Enrollment Authentication then follow the prompts accordingly. For more information view the Enrollment Authentication article here.
  • In the profile that appears, press Install, then Install again to confirm.

Device Enrollment Program (DEP)   

Through integration between Systems Manager and Apple, you can automatically have devices enroll into Systems Manager and install the management profile both over the air and out of the box. For more information about configuring and using DEP, please view the following page.

Additional Enrollment Methods

SM Sentry Enrollment SSID

You can also use SM Sentry to force iOS, Android, Windows, and Mac devices to enroll in Systems Manager for an efficient mass deployment or BYOD. When enabled on a given SSID for a Cisco Meraki wireless AP, Sentry facilitates the secure and rapid onboarding and deployment of SM to mobile devices. For more information on Systems Manager Sentry enrollment, please visit the following page.

Other Options 

You can also send device enrollment information to your users via email, by navigating to MDM > Add devices > macOS. This method also allows you to pre-configure a tag to be applied upon registration.

You must to post a comment.
Last modified
17:27, 27 Jul 2017

Tags

Classifications

This page has no classifications.

Explore Meraki

You can find out more about Cisco Meraki on our main site, including information on products, contacting sales and finding a vendor.

Explore Meraki

Contact Support

Most questions can be answered by reviewing our documentation, but if you need more help, Cisco Meraki Support is ready to work with you.

Open a Case

Ask the Community

In the Meraki Community, you can keep track of the latest announcements, find answers provided by fellow Meraki users and ask questions of your own.

Visit the Community