Prerequisites
- A SimpleMDM custom attribute that holds each device user’s email address. SimpleMDM has no built-in email variable, so the profile substitutes a custom attribute you name. For a trustworthy mapping, populate it from your identity provider during SAML-authenticated (Automated) enrollment. Manually or API-populated attributes work but are best-effort and can be blank or spoofed.
- A device group to use as the pilot target.
Steps
1
Confirm the email attribute
In SimpleMDM, open Settings › Custom Attributes and note the exact name of the attribute that holds the user email, for example
email. Cimento does not create it.2
Create an API key
Open Settings › API and create a key for Cimento with exactly the permissions in the table below. Set every other resource to none.
3
Enter the values in Cimento
Under Admin → Integrations → AI agents → SimpleMDM, enter the attribute name exactly as it appears in SimpleMDM, then paste the API key. The key is stored encrypted per tenant and never shown again. If the attribute name does not match, SimpleMDM substitutes nothing and devices report unattributed.
4
Verify
Cimento makes read-only calls to confirm the key works and to list your device groups.
5
Deploy
Choose a device group. Cimento uploads the signed
.pkg as an app and the .mobileconfig as a custom configuration profile with attribute support enabled, pairs both with the group through an assignment group, and pushes the install. Nothing is pushed until you click Deploy. The page then tracks install status per device.Permissions to set and why
Set to write
Set to read
Needed only to disconnect
If a permission is missing, Cimento names the specific one to grant, so you can start with this set.