iPad to ABM via Configurator 2 - New Supervision Identity won't break existing connections, will it?

VintageMacGuy
Contributor II

I have a few devices that didn't get added to Apple Business Manager (ABM) for whatever reason. I am going to try to add it myself by following the steps here:
https://blog.kandji.io/add-devices-to-apple-business-manager-using-apple-configurator-2

But I want a sanity check that under Section 2 - Add Devices to Apple Business Manager, step 8 - generate a new Supervision Identity - if I do this, I won't break any already enrolled devices (Mac or iPad). There are some firm warnings under the help section about testing well and using the same Supervision Identity for all the devices.

That makes me think there is a chance that creating a new Supervision Identity will break the existing devices that are already enrolled in ABM and cause them to become unmanaged and have to wipe and reinstall hundreds of Macs and iPads. You know - that nightmare scenario every Mac Admin has. Because I don't want that.

How do I add this little guy without breaking the fleet?

5 REPLIES 5

Phantom5
Contributor II

You definitely don't need any supervision identities to enroll devices in Apple Business Manager. The only time you'd need a supervision identity is while using Apple Configurator to enroll your devices into your MDM.

Thanks for the reply, however, I think the question you were answering was "Do I need a supervision identity to add a device to ABM?".

But the question I was asking is "Will creating a new supervision identity break the old supervision identity on existing devices?".

jamtay
New Contributor II

Just wondering if you managed to find out about this? The instructions surrounding this are a bit confusing....

No - nothing. And I agree - there is little documentation about it and what I did find alluded to bad things happening - which doesn't really make sense if you are just trying to add a device into ABM.

Phantom5
Contributor II

The answer is "No". A supervision identity is only there to tell your MDM to trust Apple Configurator when enrolling devices. Also Supervision identities have no use when enrolling devices in AXM. A new supervision identity won't break anything, as your enrolled devices are already trusting your MDM server, so no problem there.

  • If you are using Apple Configurator to enroll your devices in AXM only, then you don't need to set up a supervision identity.
  • If you are using Apple Configurator to enroll your devices in AXM, and/or you want to enroll those devices in your MDM at the same time (same workflow), then you do need to create a supervision identity either in Configurator or the MDM server and use it to create a trust between configurator and the MDM server.