You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/deployment-guide-enrollment-ios-ipados.md
+33-12Lines changed: 33 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: MandiOhlinger
8
8
ms.author: mandia
9
9
manager: dougeby
10
-
ms.date: 10/11/2021
10
+
ms.date: 01/25/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: enrollment
@@ -167,13 +167,17 @@ When you create an enrollment profile in the [Endpoint Manager admin center](htt
167
167
168
168
-**Enroll with user affinity + Company Portal app**:
169
169
170
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity and use the Company Portal app for authentication.":::
171
+
170
172
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`). Once entered, the Company Portal app is automatically installed from your enrollment profile. It can take some time for the Company Portal app to auto-install.
171
173
2. Users open the Company Portal app, and sign in with their organization credentials (`[email protected]`). When they sign-in, the enrollment starts. When enrollment completes, users can install and use apps used by your organization, including LOB apps.
172
174
173
175
Users may have to enter more information. For more specific end user steps, see [Enroll your organization-provided iOS device](../user-help/enroll-your-device-dep-ios.md).
174
176
175
177
-**Enroll with user affinity + Setup Assistant (legacy) + Company Portal app**:
176
178
179
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-setup-assistant-legacy-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity, use the Setup Assistant for authentication, and install the Company Portal app.":::
180
+
177
181
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`).
178
182
2. The Setup Assistant prompts the user for information.
179
183
3. The Company Portal app automatically opens, and should lock the device in a kiosk-style mode. It can take some time for the Company Portal app to open. Users sign in with their organization credentials (`[email protected]`), and the device is enrolled in Intune.
@@ -182,30 +186,39 @@ When you create an enrollment profile in the [Endpoint Manager admin center](htt
182
186
183
187
-**Enroll with user affinity + Setup Assistant (legacy) - Company Portal app**:
184
188
189
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-setup-assistant-legacy-no-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity, use the Setup Assistant for authentication, and don't install the Company Portal app.":::
190
+
185
191
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`).
186
192
2. The Setup Assistant prompts the user for information, and enrolls the device in Intune. The device isn't registered in Azure AD.
187
193
188
-
-**Enroll with user affinity + Setup Assistant with modern authentication + Company Portal app**:
194
+
-**Enroll with user affinity + Setup Assistant with modern authentication**:
195
+
196
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-setup-assistant-modern-authentication.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity, and use the Setup Assistant for authentication. The Company Portal app automatically installs.":::
When users enter their Azure AD credentials, the enrollment starts.
193
201
194
-
2. Setup Assistant prompts the user for additional information. When the home screen appears, setup is complete, the device is fully enrolled, and user device affinity is established. Users can use their devices and see your apps and policies on their devices. At this point, however, the device is not yet fully registered with Azure AD.
195
-
3. The Company Portal app automatically installs. Users open Company Portal and sign in with their work or school account (`[email protected]`) again.
196
-
4. Users complete registration in Company Portal, which fully registers the device with Azure AD. Users then gain access to corporate resources protected by conditional access policies.
202
+
2. Setup Assistant prompts the user for additional information. When the home screen appears, setup is complete. The device is fully enrolled, and user device affinity is established. Users can use their devices and see your apps and policies on their devices.
197
203
198
-
-**Enroll with user affinity + Setup Assistant with modern authentication - Company Portal app**:
204
+
At this point, the device isn't fully registered with Azure AD.
199
205
200
-
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]`or `user@gmail.com`) and their organization Azure AD credentials.
206
+
3. If you **Install Company Portal app with VPP** (recommended), then the Company Portal app automatically installs. Users open the Company Portal app, and sign in with their work or school account (`user@contoso.com`) again. They complete Azure AD registration in the Company Portal app, which fully registers the device with Azure AD. Users then gain access to corporate resources protected by conditional access policies.
201
207
202
-
When users enter their Azure AD credentials, the enrollment starts.
208
+
4. If you don't **Install Company Portal app with VPP**, and want to use the Company Portal app, then:
209
+
210
+
1. Users sign in to the Apple app store with their Apple ID (`[email protected]` or `[email protected]`). When they sign in, the Company Portal app automatically installs.
211
+
212
+
This extra sign-in step slows the enrollment, especially if users don't sign in immediately.
203
213
204
-
2. The Setup Assistant prompts the user for additional information. When it completes, users can use the device. When the home screen shows, the enrollment is complete. Users will see your apps and policies on the device.
205
-
3. The Company Portal app automatically installs. Users don't need to open the Company Portal app, or sign in to the app. If they don't sign in, then the device isn't registered with Azure AD, and isn't shown in a user's device list in Azure AD. Any resources depending on conditional access aren't available.
214
+
If they don't sign in to the app store, then the Company Portal app doesn't install. If the app isn't installed, then users can't register the device in Azure AD. Since the device hasn't completed registration, the device shows as non-compliant in Azure AD. Any resources depending on conditional access aren't available.
215
+
216
+
2. Users open the Company Portal app, and sign in with their work or school account (`[email protected]`) again. They complete Azure AD registration in the Company Portal app, which fully registers the device with Azure AD. At the next check-in, users gain access to corporate resources protected by conditional access policies.
206
217
207
218
-**Enroll without user affinity**: No actions. Be sure they don't install the Company Portal app from the Apple app store.
208
219
220
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-enroll-without-user-affinity.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll without user affinity.":::
@@ -219,7 +232,7 @@ For more specific information on this enrollment type, see [Apple Configurator e
219
232
| --- | --- |
220
233
| You need a wired connection, or are having a network issue. | ✔️ |
221
234
| Your organization doesn't want administrators to use the ABM or ASM portals, or doesn't want to set up all the requirements. | ✔️ <br/><br/> The idea of *not* using the ABM or ASM portals is to give administrators less control.|
222
-
| A country doesn't support Apple Business Manager (ABM) or Apple School Manager (ASM). | ✔️ <br/><br/> If your country supports ABS or ASM, then devices should be enrolled using Automatic Device Enrollment. |
235
+
| A country doesn't support Apple Business Manager (ABM) or Apple School Manager (ASM). | ✔️ <br/><br/> If your country supports ABS or ASM, then devices should be enrolled using [Automated Device Enrollment](#automated-device-enrollment-ade-supervised) (in this article). |
223
236
| Devices are owned by the organization or school. | ✔️ |
224
237
| You have new or existing devices. | ✔️ |
225
238
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ <br/><br/> If you have a large number of devices, then this method will take some time. |
@@ -297,25 +310,33 @@ The tasks depend on the option you configured in the enrollment profile.
297
310
298
311
-**Enroll with user affinity + Company Portal app**:
299
312
313
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-user-affinity-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll with user affinity and use the Company Portal app for authentication.":::
314
+
300
315
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`). Once entered, the Company Portal app is automatically installed from the app store. It can take some time for the Company Portal app to auto-install.
301
316
2. Open the Company Portal app, and sign in with their organization credentials (`[email protected]`). When users sign-in, the enrollment starts. When enrollment completes, users can install and use apps used by your organization, including LOB apps.
302
317
303
318
Users may have to enter more information. For more specific steps, see [Enroll your organization-provided iOS device](../user-help/enroll-your-device-dep-ios.md).
304
319
305
320
-**Enroll with user affinity + Setup Assistant + Company Portal app**:
306
321
322
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-user-affinity-setup-assistant-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll with user affinity, use Setup Assistant for authentication, and install the Company Portal app.":::
323
+
307
324
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their organization credentials (`[email protected]`). This step enrolls the device in Intune.
3. The Company Portal app automatically installs from the app store. Users open the Company Portal app, and sign in with their organization credentials (`[email protected]`). This step registers the device in Azure AD. Users can install and use apps used by your organization, including LOB apps.
310
327
311
328
-**Enroll with user affinity + Setup Assistant - Company Portal app**:
312
329
330
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-user-affinity-setup-assistant-no-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll with user affinity, use Setup Assistant for authentication, and don't install the Company Portal app.":::
331
+
313
332
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their organization credentials (`[email protected]`). This step enrolls the device in Intune.
314
333
2. The Setup Assistant prompts the user for information, including the Apple ID (`[email protected]` or `[email protected]`). This step pushes the Intune management profile to the device.
315
334
3. Users install the management profile. The profile checks-in with the Intune service, and enrolls the device. The device isn't registered in Azure AD.
316
335
317
336
-**Enroll without user affinity**: You're using Direct enrollment. No actions. Be sure they don't install the Company Portal app from the Apple app store.
318
337
338
+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-enroll-without-user-affinity.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll without user affinity.":::
@@ -364,7 +385,7 @@ This task list provides an overview. For more specific information, see [Set up
364
385
> [!NOTE]
365
386
> BYOD can become organization-owned devices. To make these devices corporate, see [Identify devices as corporate-owned](../enrollment/corporate-identifiers-add.md).
366
387
367
-
User enrollment is considered friendlier to end users, but may not provide the feature set and security features administrators need. In some scenarios, user enrollment may not be the best option. Consider the following scenarios:
388
+
User enrollment is considered friendlier to end users. But, it may not provide the feature set and security features administrators need. In some scenarios, user enrollment may not be the best option. Consider the following scenarios:
368
389
369
390
- User enrollment creates a work partition on the devices. The features and security you configure in the user enrollment profile only exist in the work partition. They don't exist in the user partition. Users can't factory reset the work partition. Administrators can. Users can factory reset the personal partition. Administrators can't.
0 commit comments