Skip to content

Commit b327346

Browse files
committed
added direct enrollment
1 parent be30bc0 commit b327346

2 files changed

Lines changed: 53 additions & 7 deletions

File tree

memdocs/intune/fundamentals/deployment-guide-enrollment-ios-ipados.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 01/25/2022
10+
ms.date: 02/24/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: enrollment
@@ -36,7 +36,7 @@ Personal and organization-owned devices can be enrolled in Intune. Once they're
3636
- [Apple Configurator](#apple-configurator-enrollment)
3737
- [BYOD: User and Device enrollment](#byod-user-and-device-enrollment)
3838

39-
This article provides recommendations on the iOS/iPadOS enrollment method to use. It also includes an overview of the administrator and user tasks for each enrollment type. For more specific information, see [Enroll macOS devices](../enrollment/ios-enroll.md).
39+
This article provides recommendations on the iOS/iPadOS enrollment method to use. It also includes an overview of the administrator and user tasks for each enrollment type. For more specific information, see [Enroll iOS/iPadOS devices](../enrollment/ios-enroll.md).
4040

4141
> [!TIP]
4242
> [!INCLUDE [tips-guidance-plan-deploy-guides](../includes/tips-guidance-plan-deploy-guides.md)]
@@ -223,7 +223,7 @@ When you create an enrollment profile in the [Endpoint Manager admin center](htt
223223

224224
## Apple Configurator enrollment
225225

226-
Use on devices owned by your organization, and includes [Direct Enrollment](../enrollment/device-enrollment-direct-enroll-macos.md). This option requires you to physically connect macOS devices to a Mac computer using the USB port.
226+
Use on devices owned by your organization, and includes [Direct Enrollment](../enrollment/apple-configurator-enroll-ios.md#direct-enrollment). This option requires you to physically connect iOS/iPadOS devices to a Mac computer using the USB port.
227227

228228
For more specific information on this enrollment type, see [Apple Configurator enrollment](../enrollment/apple-configurator-enroll-ios.md).
229229

memdocs/intune/fundamentals/deployment-guide-enrollment-macos.md

Lines changed: 50 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 04/22/2021
10+
ms.date: 02/24/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: enrollment
@@ -36,9 +36,7 @@ You have the following options when enrolling macOS devices:
3636

3737
- [BYOD: Device enrollment](#byod-device-enrollment)
3838
- [Automated device enrollment (ADE)](#automated-device-enrollment-ade-supervised)
39-
40-
> [!NOTE]
41-
> Enrollment through Apple Configurator is available for iOS/iPadOS devices. It's not available for macOS devices. When you create a macOS enrollment profile, it appears that Apple Configurator is an option. This behavior is a known issue, and will be fixed in a future release (no ETA). Do not create a macOS enrollment profile with Apple Configurator. It doesn't work.
39+
- [Direct enrollment](#direct-enrollment)
4240

4341
This article:
4442

@@ -195,6 +193,54 @@ For more specific information on the end user steps, see [Enroll your macOS devi
195193

196194
[!INCLUDE [users-dont-like-enroll](../includes/users-dont-like-enroll.md)]
197195

196+
## Direct enrollment
197+
198+
Use on devices owned by your organization that don't need user device affinity.
199+
200+
These devices are organization-owned, and use Apple Configurator. The only purpose is to be a kiosk-style device. They aren't associated with a single or specific user. These devices are commonly used to scan items, print tickets, get digital signatures, manage inventory, and more.
201+
202+
For more specific information on this enrollment type, see [Use Direct Enrollment for macOS devices](../enrollment/device-enrollment-direct-enroll-macos.md).
203+
204+
---
205+
| Feature | Use this enrollment option when |
206+
| --- | --- |
207+
| You need a wired connection, or are having a network issue. | ✔️ |
208+
| Your organization doesn't want administrators to use the ABM or ASM portals, or doesn't want to set up all the requirements. | ✔️ <br/><br/> The idea of *not* using the ABM or ASM portals is to give administrators less control.|
209+
| A country doesn't support Apple Business Manager (ABM) or Apple School Manager (ASM). | ✔️ <br/><br/> If your country supports ABS or ASM, then devices should be enrolled using [Automated Device Enrollment](#automated-device-enrollment-ade-supervised) (in this article). |
210+
| Devices are owned by the organization or school. | ✔️ |
211+
| You have new or existing devices. | ✔️ |
212+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ <br/><br/> If you have a large number of devices, then this method will take some time. |
213+
| Devices are associated with a single user. | ❌ <br/><br/> Not recommended. Devices that need user affinity should be enrolled using [Automated device enrollment (ADE)](#automated-device-enrollment-ade-supervised). |
214+
| Devices are user-less, such as kiosk or dedicated device. | ✔️ |
215+
| Devices are personal or BYOD. | ❌ <br/><br/> Not recommended. BYOD or personal devices should be enrolled using [MAM-WE](deployment-guide-enrollment-mamwe.md) (opens another Microsoft article), or [BYOD: Device enrollment](#byod-device-enrollment) (in this article). |
216+
| Devices are managed by another MDM provider. | ❌ <br/><br/> To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune. Or, you can use MAM-WE to manage specifics apps on the device. Since these devices are organization-owned, we recommend enrolling in Intune. |
217+
| You use the device enrollment manager (DEM) account. | ❌ <br/><br/> The DEM account isn't supported. |
218+
219+
---
220+
221+
### Direct enrollment administrator tasks
222+
223+
This task list provides an overview. For more specific information, see [macOS Direct Enrollment](../enrollment/device-enrollment-direct-enroll-macos.md).
224+
225+
- Be sure your devices are [supported](supported-devices-browsers.md).
226+
- Be sure the [Apple MDM push certificate](../enrollment/apple-mdm-push-certificate-get.md) is added to Endpoint Manager, and is active. This certificate is required to enroll macOS devices. For more information, see [Get an Apple MDM push certificate](../enrollment/apple-mdm-push-certificate-get.md).
227+
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), create an enrollment profile. Select **Enroll without user affinity** (user-less devices or shared devices):
228+
229+
- Users can't use apps that require a user, including the Company Portal app. The Company Portal app isn't used, needed, or supported on enrollments without user affinity. Be sure users don't install the Company Portal app from the Apple app store.
230+
- **Enroll with user affinity** is available in the UI, but it won't work. Don't select this option. If you need user affinity, then use [Automated Device Enrollment](#automated-device-enrollment-ade-supervised) (in this article).
231+
232+
- When the enrollment profile is ready, export the policy, and copy the file to the macOS device. Double-click the file to install the enrollment policy.
233+
234+
For more information on this enrollment option, and its prerequisites, see [macOS Direct Enrollment](../enrollment/device-enrollment-direct-enroll-macos.md).
235+
236+
### Direct enrollment end user tasks
237+
238+
- **Enroll without user affinity**: No actions. Be sure they don't install the Company Portal app from the Apple app store.
239+
240+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-enroll-without-user-affinity.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll macOS devices using Direct enrollment. Select enroll without user affinity.":::
241+
242+
[!INCLUDE [users-dont-like-enroll](../includes/users-dont-like-enroll.md)]
243+
198244
## Next steps
199245

200246
- [MAM-WE](deployment-guide-enrollment-mamwe.md)

0 commit comments

Comments
 (0)