You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/deployment-guide-enrollment-ios-ipados.md
+26-6Lines changed: 26 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: MandiOhlinger
8
8
ms.author: mandia
9
9
manager: dougeby
10
-
ms.date: 10/11/2021
10
+
ms.date: 01/20/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: enrollment
@@ -167,13 +167,17 @@ When you create an enrollment profile in the [Endpoint Manager admin center](htt
167
167
168
168
-**Enroll with user affinity + Company Portal app**:
169
169
170
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity and use the Company Portal app for authentication.":::
171
+
170
172
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`). Once entered, the Company Portal app is automatically installed from your enrollment profile. It can take some time for the Company Portal app to auto-install.
171
173
2. Users open the Company Portal app, and sign in with their organization credentials (`[email protected]`). When they sign-in, the enrollment starts. When enrollment completes, users can install and use apps used by your organization, including LOB apps.
172
174
173
175
Users may have to enter more information. For more specific end user steps, see [Enroll your organization-provided iOS device](../user-help/enroll-your-device-dep-ios.md).
174
176
175
177
-**Enroll with user affinity + Setup Assistant (legacy) + Company Portal app**:
176
178
179
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-setup-assistant-legacy-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity, use the Setup Assistant for authentication, and install the Company Portal app.":::
180
+
177
181
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`).
178
182
2. The Setup Assistant prompts the user for information.
179
183
3. The Company Portal app automatically opens, and should lock the device in a kiosk-style mode. It can take some time for the Company Portal app to open. Users sign in with their organization credentials (`[email protected]`), and the device is enrolled in Intune.
@@ -182,30 +186,38 @@ When you create an enrollment profile in the [Endpoint Manager admin center](htt
182
186
183
187
-**Enroll with user affinity + Setup Assistant (legacy) - Company Portal app**:
184
188
189
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-setup-assistant-legacy-no-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity, use the Setup Assistant for authentication, and don't install the Company Portal app.":::
190
+
185
191
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`).
186
192
2. The Setup Assistant prompts the user for information, and enrolls the device in Intune. The device isn't registered in Azure AD.
187
193
188
194
-**Enroll with user affinity + Setup Assistant with modern authentication + Company Portal app**:
189
195
196
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-setup-assistant-modern-authentication.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity, and use the Setup Assistant for authentication. The Company Portal app automatically installs.":::
When users enter their Azure AD credentials, the enrollment starts.
193
201
194
-
2.Setup Assistant prompts the user for additional information. When the home screen appears, setup is complete, the device is fully enrolled, and user device affinity is established. Users can use their devices and see your apps and policies on their devices. At this point, however, the device is not yet fully registered with Azure AD.
195
-
3. The Company Portal app automatically installs. Users open Company Portal and sign in with their work or school account (`[email protected]`) again.
202
+
2. Setup Assistant prompts the user for additional information. When the home screen appears, setup is complete. The device is fully enrolled, and user device affinity is established. Users can use their devices and see your apps and policies on their devices. At this point, however, the device isn't fully registered with Azure AD.
203
+
3. The Company Portal app automatically installs. Users open the Company Portal app, and sign in with their work or school account (`[email protected]`) again.
196
204
4. Users complete registration in Company Portal, which fully registers the device with Azure AD. Users then gain access to corporate resources protected by conditional access policies.
197
205
198
206
-**Enroll with user affinity + Setup Assistant with modern authentication - Company Portal app**:
199
207
208
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-setup-assistant-modern-authentication.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity and use the Setup Assistant for authentication. The Company Portal app automatically installs.":::
209
+
200
210
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`) and their organization Azure AD credentials.
201
211
202
212
When users enter their Azure AD credentials, the enrollment starts.
203
213
204
214
2. The Setup Assistant prompts the user for additional information. When it completes, users can use the device. When the home screen shows, the enrollment is complete. Users will see your apps and policies on the device.
205
-
3. The Company Portal app automatically installs. Users don't need to open the Company Portal app, or sign in to the app. If they don't sign in, then the device isn't registered with Azure AD, and isn't shown in a user's device list in Azure AD. Any resources depending on conditional access aren't available.
215
+
3. The Company Portal app automatically installs. Users don't need to open the Company Portal app, or sign in to the app. If they don't sign in, then the device isn't registered with Azure AD. The device isn't shown in a user's device list in Azure AD. Any resources depending on conditional access aren't available.
206
216
207
217
-**Enroll without user affinity**: No actions. Be sure they don't install the Company Portal app from the Apple app store.
208
218
219
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-enroll-without-user-affinity.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll without user affinity.":::
@@ -219,7 +231,7 @@ For more specific information on this enrollment type, see [Apple Configurator e
219
231
| --- | --- |
220
232
| You need a wired connection, or are having a network issue. | ✔️ |
221
233
| Your organization doesn't want administrators to use the ABM or ASM portals, or doesn't want to set up all the requirements. | ✔️ <br/><br/> The idea of *not* using the ABM or ASM portals is to give administrators less control.|
222
-
| A country doesn't support Apple Business Manager (ABM) or Apple School Manager (ASM). | ✔️ <br/><br/> If your country supports ABS or ASM, then devices should be enrolled using Automatic Device Enrollment. |
234
+
| A country doesn't support Apple Business Manager (ABM) or Apple School Manager (ASM). | ✔️ <br/><br/> If your country supports ABS or ASM, then devices should be enrolled using [Automated Device Enrollment](#automated-device-enrollment-ade-supervised) (in this article). |
223
235
| Devices are owned by the organization or school. | ✔️ |
224
236
| You have new or existing devices. | ✔️ |
225
237
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ <br/><br/> If you have a large number of devices, then this method will take some time. |
@@ -297,25 +309,33 @@ The tasks depend on the option you configured in the enrollment profile.
297
309
298
310
-**Enroll with user affinity + Company Portal app**:
299
311
312
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-user-affinity-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll with user affinity and use the Company Portal app for authentication.":::
313
+
300
314
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`). Once entered, the Company Portal app is automatically installed from the app store. It can take some time for the Company Portal app to auto-install.
301
315
2. Open the Company Portal app, and sign in with their organization credentials (`[email protected]`). When users sign-in, the enrollment starts. When enrollment completes, users can install and use apps used by your organization, including LOB apps.
302
316
303
317
Users may have to enter more information. For more specific steps, see [Enroll your organization-provided iOS device](../user-help/enroll-your-device-dep-ios.md).
304
318
305
319
-**Enroll with user affinity + Setup Assistant + Company Portal app**:
306
320
321
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-user-affinity-setup-assistant-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll with user affinity, use Setup Assistant for authentication, and install the Company Portal app.":::
322
+
307
323
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their organization credentials (`[email protected]`). This step enrolls the device in Intune.
3. The Company Portal app automatically installs from the app store. Users open the Company Portal app, and sign in with their organization credentials (`[email protected]`). This step registers the device in Azure AD. Users can install and use apps used by your organization, including LOB apps.
310
326
311
327
-**Enroll with user affinity + Setup Assistant - Company Portal app**:
312
328
329
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-user-affinity-setup-assistant-no-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll with user affinity, use Setup Assistant for authentication, and don't install the Company Portal app.":::
330
+
313
331
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their organization credentials (`[email protected]`). This step enrolls the device in Intune.
314
332
2. The Setup Assistant prompts the user for information, including the Apple ID (`[email protected]` or `[email protected]`). This step pushes the Intune management profile to the device.
315
333
3. Users install the management profile. The profile checks-in with the Intune service, and enrolls the device. The device isn't registered in Azure AD.
316
334
317
335
-**Enroll without user affinity**: You're using Direct enrollment. No actions. Be sure they don't install the Company Portal app from the Apple app store.
318
336
337
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-enroll-without-user-affinity.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll without user affinity.":::
@@ -364,7 +384,7 @@ This task list provides an overview. For more specific information, see [Set up
364
384
> [!NOTE]
365
385
> BYOD can become organization-owned devices. To make these devices corporate, see [Identify devices as corporate-owned](../enrollment/corporate-identifiers-add.md).
366
386
367
-
User enrollment is considered friendlier to end users, but may not provide the feature set and security features administrators need. In some scenarios, user enrollment may not be the best option. Consider the following scenarios:
387
+
User enrollment is considered friendlier to end users. But, it may not provide the feature set and security features administrators need. In some scenarios, user enrollment may not be the best option. Consider the following scenarios:
368
388
369
389
- User enrollment creates a work partition on the devices. The features and security you configure in the user enrollment profile only exist in the work partition. They don't exist in the user partition. Users can't factory reset the work partition. Administrators can. Users can factory reset the personal partition. Administrators can't.
0 commit comments