HydraIssues

Apple Business Manager: enroll org, ADE zero-touch, Custom Apps to replace ad hoc lane
open feature Project: hydramdm Reporter: cederik 19 Aug 2026 20:55

Description

Goal

Get Apple Business Manager (ABM) live for the organization, then move the iPad fleet from ad hoc distribution to Custom Apps and enable zero-touch re-provisioning (ADE). This replaces the interim setup built in #509.

Why

  • Ad hoc-signed apps require Developer Mode on every device (iPadOS 16+), enabled by hand per iPad. Custom Apps builds do not. Discovered 2026-08-19 on the first fleet install.

  • Ad hoc distribution (current, working) pins device UDIDs in provisioning profiles: every new fleet iPad means new profiles + secret updates + a release tag, and profiles expire yearly. Custom Apps via ABM removes all of that.

  • Without ADE, a wiped or replacement iPad needs hands: USB to cederikmini, cfgutil, Setup Assistant taps. With ADE, a wipe re-provisions the device by itself: no Wi-Fi tap, no T&C tap, straight into SimpleMDM.

Steps

  1. D-U-N-S number: check whether the legal entity has one (lookup at developer.apple.com/enroll/duns-lookup). If not, request it (free, days).
  2. Enroll in ABM: business.apple.com/enroll with the D-U-N-S number and cederik@experiencenet.com (or a role account). Apple verifies with a phone call to the legal entity. Takes days.
  3. Connect SimpleMDM to ABM: SimpleMDM admin has an ABM/DEP wizard (server token exchange). Account "Hydra experiencenet", credentials in Claude memory / with Cederik.
  4. Apps and Books (VPP): enable in ABM, link the location token to SimpleMDM.
  5. Custom Apps: in App Store Connect, set HydraHeadiPad (app id 6769830962) distribution to Custom App, visible to our ABM organization. Then replace the ad hoc export step in hydraheadipad release.yml with a Custom App update flow, and delete the ADHOC_* secrets.
  6. Device assignment: the 3 fleet iPads (serials CD41QG5C44, CPQD0CW7CG, FQ70X0JHF6) were NOT bought through Apple/reseller channels tied to us, so they enter ABM either via the original reseller re-assigning the serials (ask the previous provider who sold them) or via Apple Configurator for iPhone during a re-provision (requires wiping each device once, physical access, 30-day provisional window).
  7. ADE profile: once serials are in ABM, assign them to the SimpleMDM MDM server and set the ADE profile (supervised, skip all panes, auto-advance). Test by remote-wiping one device and watching it come back enrolled with zero touches.

References

  • Runbook and takeover history: github.com/cederikdotcom/hydramdm, docs/runbooks/runbook.md
  • Interim setup and device inventory: issue #509
  • SimpleMDM API gotcha: v2 UI Groups = assignment_groups; hydra-ipad-heads = 2425035