Set up account driven Apple User Enrollment - Microsoft Intune (2023)

  • Article

Important

This feature is in public preview. For more information, see Public preview in Microsoft Intune.

Set up account driven Apple User Enrollment for personal devices enrolling in Microsoft Intune. Account driven user enrollment provides a faster and more user-friendly enrollment experience than user enrollment with Company Portal. The device user initiates enrollment by signing into their work account in the Settings app. After the user approves device management, the enrollment profile silently installs and Intune policies are applied. Intune uses just-in-time registration and the Microsoft Authenticator app for authentication to reduce the number of times users have to sign in during enrollment and when accessing work apps.

This article describes how to set up account driven Apple User Enrollment in Microsoft Intune. You will:

  • Set up just-in-time registration.
  • Assign Microsoft Authenticator as a required app.
  • Create an enrollment profile.

Prerequisites

Microsoft Intune supports account driven Apple User Enrollment on devices running iOS/iPadOS version 15 or later. If you assign an account driven user enrollment profile to device users running iOS/iPadOS 14.9 or earlier, Microsoft Intune will automatically enroll them via user enrollment with Company Portal.

Before beginning setup, complete the following tasks:

(Video) Microsoft Intune MDM Training | iOS User Enrollment

You also need to set up service discovery so that Apple can reach the Intune service and retrieve enrollment information. To do this, set up and publish an HTTP well-known resource file on the same domain that employees sign into. Apple retrieves the file via an HTTP GET request to “https://contoso.com/.well-known/com.apple.remotemanagement”, with your organization's domain in place of contoso.com. Publish the file on a domain that can handle HTTP GET requests.

Create the file in JSON format, with the content type set to application/json. We've provided the following JSON samples that you can copy and paste into your file. Use the one that aligns with your environment. Replace the YourAADTenantID variable in the base URL with your organization's Azure AD tenant ID.

Microsoft Intune environments:

{"Servers":[{"Version":"mdm-byod", "BaseURL":"https://manage.microsoft.com/EnrollmentServer/PostReportDeviceInfoForUEV2?aadTenantId=YourAADTenantID"}]}

Microsoft Intune for US Government environments:

{"Servers":[{"Version":"mdm-byod", "BaseURL":"https://manage.microsoft.us/EnrollmentServer/PostReportDeviceInfoForUEV2?aadTenantId=YourAADTenantID"}]}

Microsoft Intune operated by 21 Vianet in China environments:

{"Servers":[{"Version":"mdm-byod", "BaseURL":"https://manage.microsoft.cn/EnrollmentServer/PostReportDeviceInfoForUEV2?aadTenantId=YourAADTenantID"}]}

The rest of the JSON sample is populated with all of the information you need, including:

  • Version: The server version is mdm-byod.
  • BaseURL: This URL is the location where the Intune service resides.

Best practices

We recommend extra configurations to help improve the enrollment experience for device users. This section provides more information about each recommendation.

Deploy Company Portal web app

Deploy the web app version of the Intune Company Portal website so that users have quick access to device status, device actions, and compliance information. The web app appears on the home screen and functions as a link to the Company Portal website. Without the web app, devices users can still access the Company Portal website but have to open the browser and type the address into the search field. For more information about how to add a web app, see Add web apps to Microsoft Intune.

Enable federated authentication

Apple User Enrollment requires you to create and provide managed Apple IDs to enrolling users. If you enable federated authentication, which consists of linking Apple Business Manager with Azure AD, you don't have to create and provide unique Apple IDs to each user. Instead, a device user can sign in to their apps with the same credentials they use for their work account. For more information, see Intro to federated authentication with Apple Business Manager in the Apple Business Manager User Guide.

(Video) User Enrollment - IOS BYOD in Intune

Step 1: Set up just-in-time registration and assign Microsoft Authenticator

Important

This feature is in public preview. For more information, see Public preview in Microsoft Intune.

During account driven user enrollment, Microsoft Authenticator acts as the authentication authority for apps. Complete these steps in the Microsoft Intune admin center to configure just-in-time registration and assign Microsoft Authenticator as a required app.

  1. Sign in to the Microsoft Intune admin center.

  2. Create an iOS/iPadOS device configuration policy under Device features > Category > Single sign-on app extension.

  3. For SSO app extension type, select Microsoft Azure AD.

  4. Add the app bundle IDs for any non-Microsoft apps using single sign-on (SSO). The SSO extension automatically applies to all Microsoft apps, so to avoid authentication problems, don't add Microsoft apps to your policy.

    Don't add the Microsoft Authenticator app to the SSO extension either. That process is done later in an app policy.

    (Video) S03E09 - Enrolling iOS Devices To Intune (I.T)

  5. Under Additional configuration, add the required key-value pair. Remove trailing spaces before and after the value and key. Otherwise just-in-time registration won't work.

    • Key: device_registration
    • Type: String
    • Value: {{DEVICEREGISTRATION}}
  6. (Recommended) Add the key-value pair that enables SSO in the Safari browser for all apps in the policy. Remove trailing spaces before and after the value and key. Otherwise just-in-time registration won't work.

    • Key: browser_sso_interaction_enabled
    • Type: Integer
    • Value: 1
  7. Select Next.

  8. For Assignments, assign the profile to all users, or select specific groups.

  9. Select Next.

  10. On the Review + create page, review your choices, and then select Create to finish creating the profile.

  11. Go to Apps > All apps and assign Microsoft Authenticator to groups as a required app. User enrollment supports user-licensed, volume-purchased apps. For more information, see Assign a volume-purchased app.

Step 2: Create enrollment profile

Create an enrollment profile for devices enrolling via account driven user enrollment. The enrollment profile triggers the device user's enrollment experience, and enables them to initiate enrollment from the Settings app.

  1. In the Microsoft Intune admin center, go to Devices > iOS/iPadOS > iOS/iPadOS enrollment.
  2. Select Enrollment types.
  3. Select Create profile > iOS/iPadOS.
  4. On the Basics page, enter a name and description for the profile so that you can distinguish it from other profiles in the admin center. Device users don't see these details.
  5. Select Next.
  6. On the Settings page, for Enrollment type, select Account driven user enrollment.
  7. Select Next.
  8. On the Assignments page, assign the profile to all users, or select specific groups. Device groups aren't supported in user enrollment scenarios because user enrollment requires user identities.
  9. Select Next.
  10. On the Review + create page, review your choices, and then select Create to finish creating the profile.

Step 3: Prepare employees for enrollment

To initiate device enrollment on a personal device, the device owner must go to the Settings app and sign in with their work or school account. If they attempt to sign into an app with their work or school account, the app alerts them to the enrollment requirement and tells them how to proceed.

(Video) Enrolling Ios Devices To Microsoft Intune Administration Console

This section describes the enrollment steps for device users. We recommend using this information in your organization's device onboarding documentation or for troubleshooting and support.

  1. Open the Settings app on your device.
  2. Select General.
  3. Select VPN & Device Management.
  4. Sign in with your work or school account, or with the Apple ID provided to you by your organization.
  5. Select Sign In to iCloud.
  6. Enter the password for the username that's shown on screen. Then select Continue.
  7. Select Allow Remote Management.
  8. Wait a few minutes while your device is configured and the management profile is installed.
  9. To confirm your device is ready to use for work, go to VPN & Device Management. Confirm that your work account is listed under MANAGED ACCOUNT.
  10. Microsoft Authenticator is required to access work apps. Wait a few minutes after enrollment for Authenticator to install on your device. An error message appears if you try to sign in to a work app without Authenticator.
  11. You might receive more prompts asking for your approval to install work apps. Select Install to approve installation.

Profile priority

Intune applies enrollment profiles in the order you prioritize them. To change the order in which they're applied:

  1. Go back to Enrollment types to view your profiles.
  2. Drag and drop the profiles in the list to reorder their priority.

If a conflict occurs because a user is assigned more than one profile, Intune applies the profile with the higher priority.

Removing device from management

The volume and cryptographic keys created to manage the work data on the device are erased when the device unenrolls from Intune.

Next steps

  • For an overview of supported Apple User Enrollment features and management actions in Microsoft Intune, see Overview of Apple User Enrollment in Microsoft Intune.

  • For more details about Apple User Enrollment features and functionality, see User Enrollment and MDM on the Apple support website.

  • For troubleshooting, see Troubleshooting iOS/iPadOS device enrollment errors in Microsoft Intune.

  • For supported settings in Intune device configurations profiles, see:

    • iOS and iPadOS device restrictions
    • iOS and iPadOS device features
    • Set up per-app Virtual Private Network (VPN)

FAQs

What is required for Apple devices to be enrolled in Intune? ›

Requires access to a Mac computer with a USB port. Be sure your devices are supported. Be sure the Apple MDM push certificate is added to Intune, and is active. This certificate is required to enroll iOS/iPadOS devices.

How do I set up iOS enrollment in Intune? ›

Enroll iOS/iPadOS Devices in Intune
  1. Install the company portal app from the App store.
  2. Once installed, open the company portal app and click on Sign in.
  3. Enter the user's email address, and Enter the password. Click on Begin.
Mar 9, 2023

How do I trigger Intune enrollment? ›

Enable Windows automatic enrollment
  1. Sign in to the Azure portal, and select Azure Active Directory > Mobility (MDM and MAM) > Microsoft Intune.
  2. Configure MDM User scope. Specify which users' devices should be managed by Microsoft Intune. ...
  3. Use the default values for the following URLs: MDM Terms of use URL. ...
  4. Select Save.
Mar 26, 2023

How do I add ABM to Intune? ›

The token you download in this step will enable the connection between Microsoft Intune and Apple Business Manager in a later step.
  1. Sign in to the Microsoft Intune admin center.
  2. Go to Devices > iOS/iPadOS > iOS/iPadOS enrollment.
  3. Select Enrollment program tokens.
  4. Select Add.
Mar 26, 2023

How do I set up Apple device enrollment program? ›

DEP is available to qualifying businesses that purchase iPad, iPhone, Mac, or Apple TV directly from Apple or participating Apple Authorized Resellers or carriers.
  1. Step 1: Create an agent account. ...
  2. Step 2: Enable two-step verification. ...
  3. Step 3: Complete the enrollment process. ...
  4. Step 4: Agree to the terms and conditions.

Do you need an Intune license to enroll a device? ›

Whether you manually add users or synchronize from your on-premises Active Directory, you must first assign each user an Intune Plan 1 license before users can enroll their devices in Intune.

How long does Intune enrollment take? ›

How long does the Intune Enrollment process take? We ask for your time and patience as the enrollment process can take up to 30 minutes.

How many types of enrollment are there in Intune? ›

There are two types of device enrollment restrictions you can configure in Microsoft Intune: Device platform restrictions: Restrict devices based on device platform, version, manufacturer, or ownership type. Device limit restrictions: Restrict the number of devices a user can enroll in Intune.

How does Intune enrollment work? ›

During enrollment, Intune installs an MDM certificate on the enrolling device. The MDM certificate communicates with the Intune service, and enables Intune to start enforcing your organization's policies, such as: Enrollment policies that limit the number or type of devices someone can enroll.

How do I manually enroll a device in Intune? ›

3. Enrolling a device in Microsoft Intune
  1. Right-click on Windows > Settings > Accounts.
  2. Access Work or School Account and then click Connect.
  3. Click on Join this device to Azure AD Directory and add DEM user credentials and click on Next and Sign In.
  4. Click on Join and then click on Done.
Oct 31, 2022

How do I know if my user is enrolled in Intune? ›

In the admin center, go to Devices > All devices. Select an enrolled iOS/iPadOS, macOS, or Windows device. Under Monitor, select Enrollment. Review the report data.

What is the limit of user enrollment in Intune? ›

You can register up to five devices.

Can you use ABM without MDM? ›

So, when it comes down to it, yes, you can use a MDM tool without ABM, but you will be missing out on a ton of useful features. This is also a two-way street: you can have ABM without MDM, but then Apple Business Manager will only function as a serial number database.

How do I set up an ABM? ›

How to implement account-based marketing
  1. Step 1: Identify your high-value target accounts. ...
  2. Step 2: Conduct research on those accounts. ...
  3. Step 3: Develop customized marketing campaigns. ...
  4. Step 4: Run your customized marketing campaigns. ...
  5. Step 5: Measure your customized marketing campaigns.

What is Apple device enrollment program? ›

The DEP provides a fast, streamlined way to deploy institution-owned iOS devices and Mac computers purchased directly from Apple, or from participating Apple Authorised Resellers or carriers.

What is Apple user enrollment? ›

User Enrolment is integrated with Managed Apple IDs to establish a user identity on the device. The user must successfully authenticate for enrolment to be completed. The Managed Apple ID can be used alongside the personal Apple ID that the user has already signed in with; the two don't interact with each other.

How long does Apple enrollment take? ›

After you submit your registration, it will tell you that your enrollment is being processed. Apple will call the contact you provided above to verify the information. Once Apple is done, the Account Holder will receive an email that the enrollment is complete. This usually takes 5-7 business days.

How long does Apple Developer account enrollment process take? ›

Apple says it can take up to 24-48 hours to confirm and setup a new Apple developer account. However, some people have had the process take minutes. One SURE way to make it take longer is to use a different credit card to pay for the Apple Developer account enrollment than is already associated with that Apple ID.

What is difference between Intune and Intune device license? ›

Device licenses are for devices that can be managed by Intune but will never be logged into by a Intune or Azure AD user. Examples of these devices are: "kiosks, dedicated devices, phone-room devices, IoT, and other single-use devices that don't require user-based security and management features."

How many licenses do I need for Intune? ›

There is no device license for Microsoft Intune. Instead, devices are linked to user accounts, and every user can link up to five devices on their account.

What subscription is needed for Intune? ›

To use Intune, you need a Microsoft 365 subscription. Intune is compatible with the following licensing plans: Microsoft 365 E5.

What are the limitations of device enrollment manager Intune? ›

There's a limit of 150 DEM accounts in Microsoft Intune.

What are the benefits of Intune enrollment? ›

With Intune, you can protect data on managed devices (enrolled in Intune) and protect data on unmanaged devices (not enrolled in Intune). Intune can isolate organization data from personal data. The idea is to protect your company information by controlling the way users access and share information.

What happens if you install the company portal app and enroll your device in Intune? ›

By enrolling your device in Intune, you get secure access to work or school apps on your mobile device, and access to apps in Intune Company Portal.

Is Intune a full MDM? ›

Microsoft Intune is a cloud-based mobile device management (MDM) service that helps you manage and secure mobile devices used by your employees. With Intune, you can manage apps, devices, and data for your employees. You can also set up security policies to help protect your company's data.

What is the difference between Intune and Active Directory? ›

AADDS and Intune are completely unrelated. AADDS, like on-prem AD, is a directory service like provides identity and authentication services. GPOs exist as well but I'd never call GPOs true management or administration of devices. Intune is a management system to configure and control the state of a device.

What is the minimum iOS version for Intune enrollment? ›

Apple. Intune requires iOS 14. x or later for device enrollment scenarios and app configuration delivered through Managed devices app configuration policies. For Intune app protection policies and app configuration delivered through Managed apps App configuration policies, Intune requires iOS 14.

What is the difference between MDM and MAM? ›

MDM controls apps by controlling the device. MAM controls apps with specific features, such as a vendor-supplied app catalog, which customers typically can modify. MAM and MDM both provide app wrapping and app containerization features.

How do I force a device to connect to Intune? ›

Sync a device
  1. Sign in to the Microsoft Intune admin center.
  2. Select Devices > All devices.
  3. In the list of devices you manage, select a device to open its Overview pane, and then select Sync.
  4. To confirm, select Yes.
May 26, 2023

How to prevent users from enrolling personal devices in Intune? ›

Create a device platform restriction
  1. Sign in to the Microsoft Intune admin center.
  2. Go to Devices > Enroll devices > Enrollment device platform restrictions.
  3. Select the tab along the top of the page that corresponds with the platform you're configuring. ...
  4. Select Create restriction.
Feb 21, 2023

What does this user account is not authorized to use Microsoft Intune? ›

User Name Not Recognized

This user account is not authorized to use Microsoft Intune. Contact your system administrator if you think you have received this message in error." indicates that the user who is trying to enroll the device does not have a valid Intune license.

How do I know if my device is enrolled in MDM? ›

From the screen I can't say but just go to settings and then profile. If there is device management option then we can say it's enrolled in MDM.

Can you have multiple Intune profiles? ›

Microsoft Intune: Multiple managed accounts are the new roadmap feature. This allows people to use a single device with multiple company accounts to access company information through specific Intune managed applications.

What is the difference between Apple Business Manager and an MDM? ›

Apple Business Manager is a simple, web-based portal for IT administrators that works with your third-party mobile device management (MDM) solution so that you can easily buy content in volume, whether your organization uses iPhone, iPad, or Mac.

What is the difference between ABM and MDM? ›

MDM solutions provide businesses with enhanced security, and the ability to remotely manage and oversee all their hardware, as well as boosting remote staff's productivity. ABM stands for Apple Business Manager. In essence, this replaces Apple's previous Device Enrolment Program.

Do you need an MDM for Apple DEP? ›

That means devices enrolled in DEP do not require manual configuration, and users never have to click on MDM links to enroll the device. It prevents users from opting out of MDM or removing IT management settings from their device. To use DEP, the company must first be enrolled in the Apple Deployment Program (ADP).

Why is ABM not easy? ›

One of the struggles is having difficulty in time management. There is a lot of activities, tasks, and assignments that the professors will give. You need to know what you should do first and also when you are going to study. Procrastinating is not advisable to do.

How much does ABM cost? ›

Forrester found in 2019 that the “average ABM budget was around $350,000 (excluding headcount costs). For pilot programs, the budget is understandably lower — averaging about $200,000 — while more mature programs that have proven value have a budget around $600,000.

What is user enrollment and managed Apple IDs? ›

User Enrollment is integrated with Managed Apple IDs to establish a user identity on the device. The user must successfully authenticate for enrollment to be completed. The Managed Apple ID can be used alongside the personal Apple ID that the user has already signed in with; the two don't interact with each other.

How does device enrollment program work? ›

During device enrollment:
  1. Your device enrolls in Microsoft Intune, a mobile device management provider, and registers with your organization. This step ensures that you're authorized to access your organization's email, apps, and Wi-Fi.
  2. Your organization's device management policies are applied to your device.
Feb 20, 2023

What is MDM enrollment? ›

Device Enrollment allows organizations to have users manually enroll devices into a mobile device management (MDM) solution and then manage many different aspects of device use, including the ability to erase the device.

What is a requirement for all devices using Microsoft Intune? ›

Intune requires Android 8. x or higher for device enrollment scenarios and app configuration delivered through Managed devices app configuration policies.

When managing devices in Apple Business Manager How can enrolled devices be searched? ›

Assign, reassign, or unassign devices
  1. In Apple Business Manager , sign in with a user that has the role of Administrator or Device Enrollment Manager.
  2. Select Devices in the sidebar, search for a device in the search field, then select the device from the list.
Apr 27, 2022

Can Macs be enrolled in Intune? ›

Intune supports the use of bootstrap tokens on enrolled Macs running macOS 10.15 or later.

Does Intune work with Apple devices? ›

Intune supports mobile device management (MDM) of iPads and iPhones to give users secure access to work email, data, and apps. This guide provides iOS-specific guidance to help you set up enrollment and deploy apps and policies to users and devices.

How many devices can a user enroll in Intune? ›

Intune device limit restrictions

You can allow a user to enroll up to 15 devices. To set a device limit restriction, sign in to Microsoft Intune admin center. Then go to Devices > Enrollment restrictions. For more information, see Create a device limit restriction.

What happens if a device is not compliant in Intune? ›

The result of this default is when Intune detects a device isn't compliant, Intune immediately marks the device as noncompliant. After a device is marked as noncompliance, Azure Active Directory (AD) Conditional Access can block the device.

Who can enroll up to 1,000 devices with Intune? ›

The DEM account can enroll up to 1,000 mobile devices. Use this account to enroll and configure the devices before giving them to users. The DEM account is an Intune permission that's applied to an Azure AD user account.

Where is the best way to get Apple Business Manager support during enrolment? ›

Check your email for a message from Apple Business Manager with the subject line “Your enrolment is in review”. During the review process, your verification contact is contacted by phone and asked to confirm information about you and your organisation before your enrolment is approved.

How do I manually enroll devices in Apple Business Manager? ›

Manually add an iPhone, iPad, or Apple TV
  1. Click Prepare in the toolbar.
  2. Choose Actions > Prepare.
  3. Control-click the selected devices or Blueprints, then choose Prepare. The Prepare Assistant appears.
Apr 27, 2022

Do you need an MDM to use Apple Business Manager? ›

A Mobile Device Management solution, or MDM, provides businesses with greater control over corporate devices. Technically, you do not require an MDM solution simply to enrol with Apple Business Manager (ABM). However, these systems are designed to be used in conjunction with one another.

Can you deploy apps to an iOS device that is not enrolled in Microsoft Intune? ›

Currently, you can assign iOS/iPadOS and Android apps (line-of-business and store-purchased apps) to devices that aren't enrolled with Intune. To receive app updates on devices that aren't enrolled with Intune, device users must go to their organization's Company Portal and manually install app updates.

What happens when a device is enrolled in Intune? ›

During device enrollment: Your device enrolls in Microsoft Intune, a mobile device management provider, and registers with your organization. This step ensures that you're authorized to access your organization's email, apps, and Wi-Fi. Your organization's device management policies are applied to your device.

How do I know if my computer is enrolled in Intune? ›

How to Confirm a Device Is Enrolled in Intune
  1. Click Start on your Windows device.
  2. Click on Settings.
  3. Click Accounts.
  4. Click Access work or school.
  5. Click Connected to MESA AD domain then click Info. Note: If the Info button does not appear on your device, your device has not been successfully enrolled.
Mar 2, 2021

What is Apple's equivalent to Intune? ›

It's worth noting that Jamf exclusively manages Apple devices while Microsoft Intune manages Windows systems and Android and Apple devices.

How often do iOS devices sync with Intune? ›

About every 8 hours

How do I add Apple apps to Intune? ›

Sign in to the Microsoft Intune admin center. Select Apps > All apps > Add. In the Select app type pane, under the available Store app types, select iOS store app. Click Select.

Videos

1. Enabling Microsoft Intune for Apple iOS/iPad and MacOS Devices
(Intune Expert)
2. Microsoft Azure AD Federation with Apple Business Manager
(T-Minus365)
3. How To Automatically Enroll iOS Devices in Microsoft Intune
(Model Technology Solutions)
4. Microsoft Intune Training part 10 - How to Enroll Personal Owned device | User Enrollment in Intune
(KELVGLOBAL ICT)
5. Account-driven User Enrollment iOS 15
(Chimpa UEM)
6. Enroll your macOS device in Microsoft Intune
(Microsoft 365)

References

Top Articles
Latest Posts
Article information

Author: Lakeisha Bayer VM

Last Updated: 03/09/2023

Views: 6817

Rating: 4.9 / 5 (49 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Lakeisha Bayer VM

Birthday: 1997-10-17

Address: Suite 835 34136 Adrian Mountains, Floydton, UT 81036

Phone: +3571527672278

Job: Manufacturing Agent

Hobby: Skimboarding, Photography, Roller skating, Knife making, Paintball, Embroidery, Gunsmithing

Introduction: My name is Lakeisha Bayer VM, I am a brainy, kind, enchanting, healthy, lovely, clean, witty person who loves writing and wants to share my knowledge and understanding with you.