Back to All Cheatsheet Libraries cheatsheets

MDM for Education

Apple School Manager, Shared iPad, 1:1 vs cart deployments, and the FERPA/COPPA/CIPA/KCSIE compliance layer schools actually face.

Schools aren't small businesses with worse budgets

The constraints are genuinely different in kind. Your users are children, which changes the legal position entirely. Devices are often shared between several people a day. Deployment happens in a single frantic week each August, then must survive ten months without a technician touching most of it. And the person running it is frequently a teacher with a TLR payment rather than a full-time IT team.

Dimension Corporate Education
UsersAdults with employment contracts and acceptable-use policies.Minors. Consent, safeguarding, and data-protection obligations apply differently and more strictly.
Device ownershipUsually one device per person, long-lived.Often shared carts, trolleys, or shared iPads with several users per device per day.
Deployment rhythmContinuous — a few devices a week as people join.Enormous seasonal spike. Hundreds of devices in days, then near-zero.
Content filteringOptional, policy-driven.Legally required in many jurisdictions, and must follow 1:1 devices home.
Support modelDedicated IT team and helpdesk.Often one part-time technician, or a teacher. Self-healing configuration matters far more.
Budget cycleAnnual opex, relatively flexible.Capital grants and fixed funding windows. Refresh cycles are long and hard to move.
Failure toleranceA broken laptop is one person's bad day.A broken cart is a lesson that can't run, for thirty students, with no fallback.

Apple School Manager is ABM with education features bolted on

Same foundations as the business version — Automated Device Enrollment, Apps and Books, Managed Apple IDs — plus rosters, classes, and Shared iPad. See MDM Fundamentals for the shared concepts; this covers what's education-specific.

Feature What it does Notes
Managed Apple IDsSchool-owned Apple accounts for students and staff, created in bulk.Can federate with Google Workspace or Microsoft Entra ID so students use existing credentials. Age-appropriate restrictions apply automatically.
Roster data / SIS syncImports classes, teachers, and students from your MIS/SIS via SFTP or a supported integration.Drives Classroom and Schoolwork automatically. Far better than maintaining class lists by hand.
Shared iPadMultiple students sign into the same iPad, each with their own data, settings, and Drive-backed documents.Requires Managed Apple IDs and adequate storage — see the 1:1 vs Shared tab for the practical constraints.
Apple ClassroomTeacher app for viewing student screens, launching apps, locking devices, and sharing work.Needs devices on the same network and correctly configured class data. Works over Bluetooth/Wi-Fi proximity.
Apple SchoolworkAssignment distribution and progress tracking tied to app activity.Requires apps that support ClassKit to report progress meaningfully.
Apps and Books (VPP)Bulk app licence purchasing, assignable to devices or users and reclaimable.Many education apps are free but still need licence assignment. Device-assigned licences avoid needing an Apple ID on the iPad at all.
Consideration 1:1 Shared / cart
Cost per studentHighest — one device each.Much lower; one cart serves several classes a day.
Filtering obligationMust follow the device home. Needs on-device filtering, not just network-level.Network filtering usually sufficient since devices stay on site.
Sign-in modelOne account, always signed in. Simple.Shared iPad or Managed Guest Session. More moving parts.
StorageWhole device per student.Shared iPad partitions storage per user — a 64 GB iPad shared by 10 students is genuinely tight. Buy more storage than feels necessary.
Login speedInstant.First login for a new user downloads their data — can take minutes, which wastes lesson time.
Damage & lossHigher — devices travel. Needs an insurance or contribution scheme.Lower, but no individual accountability for damage.
Best forSecondary, sixth form, homework-dependent curricula.Primary, specific subject rooms, occasional-use scenarios.
Making carts actually work
  • Charging is the failure point. A cart where half the devices are flat is a cancelled lesson. Buy carts that genuinely charge every bay and check them on a schedule.
  • Number devices physically and match to the MDM record, so "device 14 is broken" is actionable without hunting serial numbers.
  • Wi-Fi density matters more than raw speed — 30 devices waking simultaneously in one room is a different problem from 30 spread across a building.
  • Keep two or three spare configured devices per cart. A swap takes seconds; a repair takes days.
  • Schedule OS updates for holidays. An update prompting mid-lesson across a cart is disruptive and predictable.

Know which obligation each control satisfies

Filtering, monitoring, and data protection are three separate requirements that people routinely conflate. A filter does not satisfy a monitoring duty, and neither addresses data-protection obligations. This is a technical reference, not legal advice — your DPO or legal counsel owns the compliance position.

Framework Where What it requires (broadly)
FERPAUSProtects education records. Governs who may access student data and under what conditions, including third-party vendors acting as school officials.
COPPAUSApplies to online services collecting data from under-13s. Schools can consent on parents' behalf in limited educational contexts — vendor vetting matters.
CIPAUSTies E-Rate funding to internet filtering and a documented safety policy.
UK GDPR / DPA 2018UKChildren are a vulnerable category. Requires a lawful basis, DPIAs for high-risk processing, and data minimisation.
KCSIEEnglandStatutory safeguarding guidance including expectations for filtering and monitoring, with governor-level oversight.
Age Appropriate Design CodeUKStandards for online services likely to be accessed by children — relevant when selecting edtech.
A practical compliance baseline
  • Filter, and make it follow 1:1 devices home. Network-only filtering doesn't meet the obligation for devices that leave site.
  • Monitor separately. Filtering blocks; monitoring flags concerning behaviour for a human to review. These are different products and different duties.
  • Name who reviews alerts and how fast. An unreviewed monitoring system creates liability rather than reducing it.
  • Vet every app and extension pushed to student devices. Record what data each processes and where it goes.
  • Run a DPIA before deploying anything that processes student data at scale.
  • Write down the leaver policy — how long student accounts and data are retained after they leave, and who deletes them.
  • Restrict staff access to student data by role, and enforce 2FA on every staff and admin account.

Surviving the August deployment window

1

Order early enough that devices arrive in ABM/ASM before the holidays

Devices must be assigned to your MDM in Apple School Manager (or licensed for Chrome) before they can zero-touch enroll. Supply-chain delay in July becomes a crisis in September.

2

Build and test the full enrollment on a handful of devices in June

Do not test the configuration for the first time on 200 devices in the last week of August. Prove the whole flow — enroll, apps, filtering, sign-in — on five devices while there's time to fix it.

3

Sync rosters before configuring Classroom

Class and teacher data from your MIS drives Apple Classroom and Google Classroom. Get the sync working first, or you'll rebuild class lists manually.

4

Stage in batches with physical labelling

Enroll, label, and cart in batches with a checklist. Track which batch each device came from — when something's wrong it's usually wrong for a whole batch.

5

Train the teachers, not just the devices

A perfectly configured cart is useless if staff can't use Classroom or don't know how to report a fault. Budget time for this — it's the step most often skipped and most often regretted.

6

Document the recovery runbook

Write down how to re-enroll a device, reset a student password, and swap a faulty unit — in language a non-technical colleague can follow. You will not always be the person doing it.

Hard-won practical advice

Charging beats configuration

More lessons are lost to flat batteries than to any policy misconfiguration. Audit cart charging termly and replace failing bays promptly.

Buy more storage than you think

Shared iPad partitions storage per user. Base-model devices shared across a class fill up fast, and the failure mode is a student unable to sign in.

Disable Find My on school-owned Apple devices

Activation Lock on a returned student device is the classic education MDM disaster. Block personal Apple ID sign-in by policy and keep devices supervised via ASM.

Schedule updates for holidays

Set update deadlines that land during breaks. An OS update prompting across a cart mid-lesson is entirely avoidable.

Give teachers a self-service route

A catalogue where staff can install approved apps themselves removes a large share of tickets and doesn't require them to wait for a technician.

Track AUE and end-of-support dates

Chromebooks have AUE dates; iPads eventually stop receiving iPadOS updates. Record both in your asset inventory and plan refresh around them rather than discovering them.

Resources