Goal
Get Apple Business Manager (ABM) live for the organization, then move the iPad fleet from ad hoc distribution to Custom Apps and enable zero-touch re-provisioning (ADE). This replaces the interim setup built in #509.
Why
-
Ad hoc-signed apps require Developer Mode on every device (iPadOS 16+), enabled by hand per iPad. Custom Apps builds do not. Discovered 2026-08-19 on the first fleet install.
-
Ad hoc distribution (current, working) pins device UDIDs in provisioning profiles: every new fleet iPad means new profiles + secret updates + a release tag, and profiles expire yearly. Custom Apps via ABM removes all of that.
-
Without ADE, a wiped or replacement iPad needs hands: USB to cederikmini, cfgutil, Setup Assistant taps. With ADE, a wipe re-provisions the device by itself: no Wi-Fi tap, no T&C tap, straight into SimpleMDM.
Steps
- D-U-N-S number: check whether the legal entity has one (lookup at developer.apple.com/enroll/duns-lookup). If not, request it (free, days).
- Enroll in ABM: business.apple.com/enroll with the D-U-N-S number and cederik@experiencenet.com (or a role account). Apple verifies with a phone call to the legal entity. Takes days.
- Connect SimpleMDM to ABM: SimpleMDM admin has an ABM/DEP wizard (server token exchange). Account "Hydra experiencenet", credentials in Claude memory / with Cederik.
- Apps and Books (VPP): enable in ABM, link the location token to SimpleMDM.
- Custom Apps: in App Store Connect, set HydraHeadiPad (app id 6769830962) distribution to Custom App, visible to our ABM organization. Then replace the ad hoc export step in hydraheadipad release.yml with a Custom App update flow, and delete the ADHOC_* secrets.
- Device assignment: the 3 fleet iPads (serials CD41QG5C44, CPQD0CW7CG, FQ70X0JHF6) were NOT bought through Apple/reseller channels tied to us, so they enter ABM either via the original reseller re-assigning the serials (ask the previous provider who sold them) or via Apple Configurator for iPhone during a re-provision (requires wiping each device once, physical access, 30-day provisional window).
- ADE profile: once serials are in ABM, assign them to the SimpleMDM MDM server and set the ADE profile (supervised, skip all panes, auto-advance). Test by remote-wiping one device and watching it come back enrolled with zero touches.
References
- Runbook and takeover history: github.com/cederikdotcom/hydramdm, docs/runbooks/runbook.md
- Interim setup and device inventory: issue #509
- SimpleMDM API gotcha: v2 UI Groups = assignment_groups; hydra-ipad-heads = 2425035