Apple School manager (ASM) is a portal used to manage students, staff, and devices, and to purchase content. It links with Intune for deployment of apps and enrolment of devices through the Device Enrolment Programme (DEP).
ASM can be accessed using a generic admin account provided by Hwb, which can be looked up in the User Management Portal. For local authorities, this includes the ability to manage devices added to DEP and assign to their Mobile Device Management (MDM) token, as well as purchase or manage apps for schools in their authority. For schools, this includes purchasing and managing apps for the school only.
Only apps and credit belonging to a legacy VPP account can be migrated to Hwb’s Apple School Manager.
To request transfer of apps from a legacy VPP account please contact the Hwb service desk, providing the Apple Id and password of the account.
Once the transfer is complete, apps will be available in a ‘legacy’ location in Apple School Manager. A content manager for the school will need to check the apps and move them to their ‘main’ location to be available for deployment in Intune.
Any credit transferred will remain associated with the legacy VPP account and must be spent using that account. Hwb will advise how much credit, if any, has been transferred and provide the relevant details to log in.
Log into Apple School Manager using the generic ASM account
Go to Apps and Books
Filter Location for the ‘legacy’ location (“[School Number] VPP Legacy Location”)
Select the app to transfer
Click Transfer next to the legacy location
Enter the quantity of licenses to transfer and click Transfer
Log into Apple School Manager using a content manager account for the school
Click Apps and Books
Search for the app you wish to procure
Select the location to assign the app to (for schools, there should only be one location)
Enter the quantity you wish to procure
Click Get
Use a sensible number when entering the quantity of free apps, as using a large number can cause delays when performing other actions in Intune/ASM that verifies licenses. It is recommended to consider how many you need and add a small buffer.
To buy apps you must first place an order with your supplier for credit, which can then be redeemed and used in Apple School Manager.
Purchase order processes can differ for each local authority so please check with your local authority on how to place an order. You will need to provide the supplier with an Apple Id - we recommend using the Hwb provided Content Manager account for the school, but this can be any Apple Id.
Once you have received email confirmation that the credit is in the VPP portal:
Go to the VPP credit portal and click Sign In
Log in with the same Apple Id that you specified when placing the order – if using the Hwb provided Content Manager account you will be redirected to the standard Hwb login screen
Click Orders in the menu on the left to list all orders associated with the Apple Id
Click Download next to the appropriate order
Open the downloaded CSV file and copy the code under the Redemption Code column
Go to Apple School Manager and log in with the Content Manager account for the school
Click on the account name in the bottom left, then Preferences -> Payments and Billing
Click Add under Store Credit
Enter the redemption code copied from the CSV file, and click Redeem
Confirm the store credit amount has increased
Procure the desired app(s) following the same procedure as procuring free apps
Apps belonging to a location whose token has been added to Intune will sync automatically twice a day. However, you can force a sync in Intune:
Browse to the Microsoft Intune admin centre
Sign in with your Hwb Intune admin account
Click on Tenant Admin > Connectors and tokens > Apple VPP Tokens
Search for the relevant token
Click on (…) and then click Sync
MDM tokens can only be updated by local authority (LA) Intune admins. This must be done once a year.
Browse to Apple School Manager
Sign in with the generic ASM admin account
Click on the account in the bottom left hand corner, then click Preferences
Select the appropriate MDM token under Your MDM Servers
Click Download Token
Confirm by clicking Download Server Token
Browse to the Microsoft Intune admin centre
Sign in with your Hwb Intune admin account
Go to Devices > Enroll devices > Apple enrollment > Enrollment program tokens
Search for the appropriate MDM token, if required, and click it
Click Renew token
Click Select a file and choose the new token downloaded from Apple School Manager
Leave the Apple ID as is
Click Next and complete the wizard
Browse to Apple School Manager
Sign in with the generic ASM admin account
Click on the account in the bottom left hand corner, then click Preferences > Payments and Billing
Under Server Tokens, click Download next to each server token to be renewed
Browse to the Microsoft Intune admin centre
Sign in with your Hwb Intune admin account
Click on Tenant Admin > Connectors and tokens > Apple VPP Tokens
Search for the appropriate VPP token, if required, and click it
Click Settings under Basics
Click Select a file and choose the new token downloaded from Apple School Manager
Leave the token name and Apple ID as is
Click Review + save
It is also possible to update VPP tokens in bulk using a PowerShell script, available by request to the Hwb Service Desk.
Managed Apple Ids are accounts that can be used with Apple services and devices. They are available for staff and students and enable the user to log in Apple services with their Hwb username and password. Accounts are created and maintained through the schools’ MIS data.
Managed Apple Ids can be used to sign into iPads with user affinity, such as teacher devices, or shared iPads. Users can have their own separate ‘profile’ and log into apps with their Hwb account without worrying about the next user.
For managed Apple Ids to be provisioned for school they must be opt-in – this can be done by a local authority or school Intune admin through the User Management Portal. Once created, they can be viewed and managed through Apple School Manager.
Individual schools can be opted-in through their dashboard. This can be done by a local authority Intune admin or a school Intune admin:
Log into the User Management Portal with an account that has the Intune Admin role
Select Apple School Manager from the Administrator menu
Check the box to turn on Apple School Manager user provisioning
Confirm the pop-up
Local authority Intune admins can also opt-in all their primary and special schools, middle school, and/or secondary schools in one go:
Log into the User Management Portal with an account that has the Intune Admin role
Select Apple School Manager from the Administrator menu
Check the box for Primary and Special Schools, Middle Schools or Secondary Schools – you can do one, two, or all three at once, or add another selection at a later date.
Click the Update button, and confirm the pop-up
To opt-out of Apple School Manager user provisioning you must log a request with the Hwb Service Desk.
When logging into a shared iPad for the first time, a user be will be prompted to setup a passcode – 4-digits for learners, and 8 or more characters (letters and numbers) for staff. This can then be used to log onto any shared iPad without the need for their Hwb password.
Passcodes can be reset through the Apple School Manager portal. School staff can reset passcodes for learners using their Hwb account. Local authority admins can reset passcodes for school staff and learners using their generic ASM admin account. School staff can also reset learners' passcodes through the Apple Classroom app.
This is a temporary password and will expire in 90 days. The user will be prompted to change their passcode after entering the temporary one.
Log into Apple School Manager
Under Users, search for and click on the target user
Click on Reset Shared iPad Passcode
Enter a new passcode, or let Apple School Manager generate one
Choose to send the temporary passcode to the user as an email, or create a downloadable PDF to see the temporary passcode onscreen
Apple classes can be used in the Apple Classroom or Apple Schoolwork apps on managed devices. Users must have Managed Apple Ids to use these apps.
Teachers can create Apple classes manually from within the apps, or managed classes can be created through the User Management Portal. Hwb managed Apple Classes are maintained using the MIS data, which keeps the class memberships up-to-date whenever a user joins or leaves the school.
To create a managed Apple class:
Log into the User Management Portal with an admin or staff account
In the school dashboard, go to Administration > View Groups
Find the desired group and select it
Click the Add Apple Class button
Click Confirm on the pop-up
For information on using the Apple Classroom and Apple Schoolwork apps, please see the corresponding Apple documentation:
https://support.apple.com/en-gb/guide/classroom/welcome/web
https://support.apple.com/en-gb/guide/schoolwork-teacher/welcome/ios
For further support please contact the Hwb Service Desk.