Intune + Apple School Manager — How to Manage All Your Devices
The teacher opens the laptop and it's ready to use. All apps installed, all policies in place. Here's how modern device management works for schools.
What is MDM — and why do schools need it?
MDM (Mobile Device Management) is a system for centrally managing, configuring, and securing all digital devices in an organization — computers, tablets, and phones. Instead of IT staff manually configuring each device, everything is handled automatically via the cloud.
For schools with hundreds of devices, manual management is unsustainable. Imagine a new teacher starting — without MDM, someone has to physically configure the laptop, install apps, set security policies, and register the device. With MDM, all of this happens automatically the first time the device is powered on.
MDM is also a requirement for Sweden's digital national exams, where devices must be pre-registered and Safe Exam Browser (SEB) distributed centrally.
Microsoft Intune — for Windows and Android
Microsoft Intune is Microsoft's cloud-based MDM solution and is included in Microsoft 365 Education licenses. It primarily manages Windows computers and Android devices, but can also handle macOS and iOS.
Windows Autopilot
Autopilot is Intune's zero-touch deployment for Windows. When a new computer is ordered, the vendor registers the device's hardware ID directly with Intune. The first time the user starts the computer and connects to the internet, configuration, apps, and policies are downloaded automatically. No IT staff needs to touch the device. The computer can be shipped directly to the teacher's home or to the school — it configures itself.
Policies and Configuration
Through Intune, you can manage everything centrally: disk encryption requirements (BitLocker), firewall rules, WiFi profiles, VPN settings, Windows Update schedules, and which apps are installed. Different groups (teachers, students, administration) can have different policies. Everything is managed through a web interface — the Microsoft Intune admin center.
App Distribution
Intune can automatically install apps — both from the Microsoft Store and custom installation packages (MSI, MSIX, Win32). Safe Exam Browser, the Office suite, Google Chrome, Zoom, and other tools can be distributed to the right groups without the user having to do anything.
Apple School Manager — for iPad and Mac
Apple School Manager (ASM) is Apple's equivalent for schools. It manages iPads, iPhones, and Mac computers. ASM works best as a registration portal — it connects devices to your MDM solution (such as Intune) via Automated Device Enrollment (formerly DEP).
Zero-Touch for Apple Devices
Just like Autopilot for Windows, Apple devices are registered at the point of purchase. When an iPad or MacBook is powered on for the first time, it automatically connects to ASM and downloads its configuration. Apps are installed, restrictions are set, and the device is ready to use — without IT ever touching it.
Managed Apple IDs and Shared iPad
ASM creates Managed Apple IDs automatically based on the school's user data (synchronized from Microsoft Entra ID/Azure AD). The Shared iPad feature lets multiple students share the same iPad — each student logs in and gets their own environment with their apps and files.
App Distribution via VPP
Through the Volume Purchase Program (VPP), now integrated into ASM as "Apps and Books", the school can purchase and distribute apps centrally. Apps are assigned to devices, not Apple IDs — making it easy to move licenses between devices as needed. SEB for iPad is easily distributed through this channel.
How Intune and ASM Work Together
The best scenario for most schools is to use Intune as the central MDM solution and connect ASM to Intune. This way, all devices — Windows, Android, iPad, Mac — are managed from a single interface. Apple devices are registered in ASM, which forwards them to Intune for policy management.
The flow looks like this:
- Purchase — devices are ordered through an Apple Authorized Reseller (or directly from Apple) and automatically registered in ASM
- Connection — ASM forwards the devices to Intune via Automated Device Enrollment
- Configuration — Intune applies policies, installs apps, and sets security requirements
- Delivery — the device is shipped to the school or directly to the user
- Activation — the user powers on the device, logs in, and everything is ready
Security and Compliance
MDM is not just about convenience — it's a core security function. With Intune, you can:
- Remote wipe a lost or stolen device — all school data is erased, personal data can be preserved
- Require encryption — BitLocker on Windows, FileVault on Mac, automatically enabled
- Block non-compliant devices — a device that doesn't meet security requirements is denied access to school resources
- Report — see the status of all devices, which ones are missing updates, and which are no longer checking in
Digital National Exams and SEB
Sweden's digital national exams require that Safe Exam Browser (SEB) is distributed to all exam devices. With Intune and ASM, SEB can be installed and configured centrally — on Windows, macOS, and iPad — without IT staff visiting every classroom. The SEB configuration file can be distributed as a profile, and the school can verify that all devices have the correct version installed before exam day.
How We Help
At Strandholm Consulting, we help schools implement and operate Intune and Apple School Manager. We handle the entire chain:
- Planning — we map your device environment and design policies
- Setup — we configure Intune, Autopilot, and the ASM connection
- Enrollment — we enroll existing and new devices
- App distribution — we package and distribute apps including SEB
- Training — we train your IT staff on day-to-day operations
- Ongoing support — we monitor and troubleshoot devices proactively
Want to simplify your device management?
Book a free walkthrough. We'll show you how Intune and ASM work in practice — tailored to your school.
Book a walkthrough