← All articles

iOS Management Setup in CapaOne Mobile Manager

A step-by-step guide to setting up iOS device management in CapaOne Mobile Manager, covering Apple Push Certificates, ABM integration, VPP, and device enrollment.

CapaOne Mobile Manager enables organizations to manage iPhones and iPads in both corporate and BYOD settings. This guide covers iOS device management implementation from initial setup through app distribution.

Learning Objectives

Upon completion, users can enroll devices, automatically configure corporate-owned DEP devices, and securely distribute applications and configurations.

Required Prerequisites

  • CapaOne account with Mobile Manager License
  • Dedicated Apple ID (not tied to personal accounts)
  • Access to Apple Business Manager or Apple School Manager
  • Internet connectivity for devices and management console

Configuration Process

Apple Push Certificate Setup

Apple Push Notification Service enables Mobile Manager communication with iOS devices. The process involves downloading a push request from CapaOne, creating a certificate through Apple’s Push Certificates Portal, and uploading the resulting .pem file back to CapaOne. Certificates require annual renewal using the same Apple ID.

Apple Business Manager Integration

Device Enrollment Program (DEP) functionality allows automatic device enrollment during initial setup. This involves downloading a public key from CapaOne, registering the MDM server in ABM, and uploading the generated server token.

Volume Purchase Program

VPP tokens enable silent app distribution without requiring individual Apple IDs. Implementation includes downloading the .vpptoken from ABM’s Payment and Billing section and uploading it to CapaOne.

Groups, Configurations and Applications

The platform allows creation of separate groups for supervised and unsupervised devices, with matching configurations and VPP-licensed applications assigned accordingly.

Enrollment Methods

Unsupervised Profile (BYOD)

Users access an enrollment URL or QR code to download and install profiles via device settings.

Supervised Profile (Corporate)

Devices assigned in ABM automatically enroll during setup with zero manual intervention, applying group assignments and configurations upon reconnection after resets.

Maintenance Recommendations

  • Renew Apple Push Certificate annually
  • Refresh ABM/DEP and VPP tokens yearly
  • Maintain separate BYOD and corporate profiles
  • Use DEP for all corporate device purchases
  • Conduct regular compliance reviews
  • Remove unused devices or licenses

Ready to see how CapaOne handles iOS management? Request a demo.

Rikke Borup

Written by

Rikke Borup

CMO, CapaSystems

Rikke is Chief Marketing Officer at CapaSystems, where she has led marketing and communications since 2009. With more than 17 years of experience in the IT sector — including cybersecurity, endpoint management software and IT services — she brings long-standing, practical insight into the challenges facing modern enterprise IT environments.

Trained as a journalist, Rikke specialises in translating complex technical concepts into clear, easy-to-understand communications for IT decision-makers.

Book a Demo →