Skip to content

Commit e12765e

Browse files
author
Thomas Raya
authored
Merge pull request #6589 from MandiOhlinger/ado13055801
ADO 13055801: Adding images to end user tasks
2 parents f050349 + 2f36ab5 commit e12765e

10 files changed

Lines changed: 33 additions & 12 deletions

memdocs/intune/fundamentals/deployment-guide-enrollment-ios-ipados.md

Lines changed: 33 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 10/11/2021
10+
ms.date: 01/25/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: enrollment
@@ -167,13 +167,17 @@ When you create an enrollment profile in the [Endpoint Manager admin center](htt
167167

168168
- **Enroll with user affinity + Company Portal app**:
169169

170+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity and use the Company Portal app for authentication.":::
171+
170172
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`). Once entered, the Company Portal app is automatically installed from your enrollment profile. It can take some time for the Company Portal app to auto-install.
171173
2. Users open the Company Portal app, and sign in with their organization credentials (`[email protected]`). When they sign-in, the enrollment starts. When enrollment completes, users can install and use apps used by your organization, including LOB apps.
172174

173175
Users may have to enter more information. For more specific end user steps, see [Enroll your organization-provided iOS device](../user-help/enroll-your-device-dep-ios.md).
174176

175177
- **Enroll with user affinity + Setup Assistant (legacy) + Company Portal app**:
176178

179+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-setup-assistant-legacy-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity, use the Setup Assistant for authentication, and install the Company Portal app.":::
180+
177181
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`).
178182
2. The Setup Assistant prompts the user for information.
179183
3. The Company Portal app automatically opens, and should lock the device in a kiosk-style mode. It can take some time for the Company Portal app to open. Users sign in with their organization credentials (`[email protected]`), and the device is enrolled in Intune.
@@ -182,30 +186,39 @@ When you create an enrollment profile in the [Endpoint Manager admin center](htt
182186

183187
- **Enroll with user affinity + Setup Assistant (legacy) - Company Portal app**:
184188

189+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-setup-assistant-legacy-no-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity, use the Setup Assistant for authentication, and don't install the Company Portal app.":::
190+
185191
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`).
186192
2. The Setup Assistant prompts the user for information, and enrolls the device in Intune. The device isn't registered in Azure AD.
187193

188-
- **Enroll with user affinity + Setup Assistant with modern authentication + Company Portal app**:
194+
- **Enroll with user affinity + Setup Assistant with modern authentication**:
195+
196+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-user-affinity-setup-assistant-modern-authentication.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll with user affinity, and use the Setup Assistant for authentication. The Company Portal app automatically installs.":::
189197

190198
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`) and their organization Azure AD credentials (`[email protected]`).
191199

192200
When users enter their Azure AD credentials, the enrollment starts.
193201

194-
2. Setup Assistant prompts the user for additional information. When the home screen appears, setup is complete, the device is fully enrolled, and user device affinity is established. Users can use their devices and see your apps and policies on their devices. At this point, however, the device is not yet fully registered with Azure AD.
195-
3. The Company Portal app automatically installs. Users open Company Portal and sign in with their work or school account (`[email protected]`) again.
196-
4. Users complete registration in Company Portal, which fully registers the device with Azure AD. Users then gain access to corporate resources protected by conditional access policies.
202+
2. Setup Assistant prompts the user for additional information. When the home screen appears, setup is complete. The device is fully enrolled, and user device affinity is established. Users can use their devices and see your apps and policies on their devices.
197203

198-
- **Enroll with user affinity + Setup Assistant with modern authentication - Company Portal app**:
204+
At this point, the device isn't fully registered with Azure AD.
199205

200-
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `user@gmail.com`) and their organization Azure AD credentials.
206+
3. If you **Install Company Portal app with VPP** (recommended), then the Company Portal app automatically installs. Users open the Company Portal app, and sign in with their work or school account (`user@contoso.com`) again. They complete Azure AD registration in the Company Portal app, which fully registers the device with Azure AD. Users then gain access to corporate resources protected by conditional access policies.
201207

202-
When users enter their Azure AD credentials, the enrollment starts.
208+
4. If you don't **Install Company Portal app with VPP**, and want to use the Company Portal app, then:
209+
210+
1. Users sign in to the Apple app store with their Apple ID (`[email protected]` or `[email protected]`). When they sign in, the Company Portal app automatically installs.
211+
212+
This extra sign-in step slows the enrollment, especially if users don't sign in immediately.
203213

204-
2. The Setup Assistant prompts the user for additional information. When it completes, users can use the device. When the home screen shows, the enrollment is complete. Users will see your apps and policies on the device.
205-
3. The Company Portal app automatically installs. Users don't need to open the Company Portal app, or sign in to the app. If they don't sign in, then the device isn't registered with Azure AD, and isn't shown in a user's device list in Azure AD. Any resources depending on conditional access aren't available.
214+
If they don't sign in to the app store, then the Company Portal app doesn't install. If the app isn't installed, then users can't register the device in Azure AD. Since the device hasn't completed registration, the device shows as non-compliant in Azure AD. Any resources depending on conditional access aren't available.
215+
216+
2. Users open the Company Portal app, and sign in with their work or school account (`[email protected]`) again. They complete Azure AD registration in the Company Portal app, which fully registers the device with Azure AD. At the next check-in, users gain access to corporate resources protected by conditional access policies.
206217

207218
- **Enroll without user affinity**: No actions. Be sure they don't install the Company Portal app from the Apple app store.
208219

220+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/ade-enroll-without-user-affinity.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using automated device enrollment (ADE). Select enroll without user affinity.":::
221+
209222
[!INCLUDE [users-dont-like-enroll](../includes/users-dont-like-enroll.md)]
210223

211224
## Apple Configurator enrollment
@@ -219,7 +232,7 @@ For more specific information on this enrollment type, see [Apple Configurator e
219232
| --- | --- |
220233
| You need a wired connection, or are having a network issue. | ✔️ |
221234
| Your organization doesn't want administrators to use the ABM or ASM portals, or doesn't want to set up all the requirements. | ✔️ <br/><br/> The idea of *not* using the ABM or ASM portals is to give administrators less control.|
222-
| A country doesn't support Apple Business Manager (ABM) or Apple School Manager (ASM). | ✔️ <br/><br/> If your country supports ABS or ASM, then devices should be enrolled using Automatic Device Enrollment. |
235+
| A country doesn't support Apple Business Manager (ABM) or Apple School Manager (ASM). | ✔️ <br/><br/> If your country supports ABS or ASM, then devices should be enrolled using [Automated Device Enrollment](#automated-device-enrollment-ade-supervised) (in this article). |
223236
| Devices are owned by the organization or school. | ✔️ |
224237
| You have new or existing devices. | ✔️ |
225238
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ <br/><br/> If you have a large number of devices, then this method will take some time. |
@@ -297,25 +310,33 @@ The tasks depend on the option you configured in the enrollment profile.
297310

298311
- **Enroll with user affinity + Company Portal app**:
299312

313+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-user-affinity-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll with user affinity and use the Company Portal app for authentication.":::
314+
300315
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their Apple ID (`[email protected]` or `[email protected]`). Once entered, the Company Portal app is automatically installed from the app store. It can take some time for the Company Portal app to auto-install.
301316
2. Open the Company Portal app, and sign in with their organization credentials (`[email protected]`). When users sign-in, the enrollment starts. When enrollment completes, users can install and use apps used by your organization, including LOB apps.
302317

303318
Users may have to enter more information. For more specific steps, see [Enroll your organization-provided iOS device](../user-help/enroll-your-device-dep-ios.md).
304319

305320
- **Enroll with user affinity + Setup Assistant + Company Portal app**:
306321

322+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-user-affinity-setup-assistant-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll with user affinity, use Setup Assistant for authentication, and install the Company Portal app.":::
323+
307324
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their organization credentials (`[email protected]`). This step enrolls the device in Intune.
308325
2. The Setup Assistant prompts the user for information, including the Apple ID (`[email protected]` or `[email protected]`).
309326
3. The Company Portal app automatically installs from the app store. Users open the Company Portal app, and sign in with their organization credentials (`[email protected]`). This step registers the device in Azure AD. Users can install and use apps used by your organization, including LOB apps.
310327

311328
- **Enroll with user affinity + Setup Assistant - Company Portal app**:
312329

330+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-user-affinity-setup-assistant-no-company-portal-app.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll with user affinity, use Setup Assistant for authentication, and don't install the Company Portal app.":::
331+
313332
1. When the device is turned on, the Apple Setup Assistant runs. Users enter their organization credentials (`[email protected]`). This step enrolls the device in Intune.
314333
2. The Setup Assistant prompts the user for information, including the Apple ID (`[email protected]` or `[email protected]`). This step pushes the Intune management profile to the device.
315334
3. Users install the management profile. The profile checks-in with the Intune service, and enrolls the device. The device isn't registered in Azure AD.
316335

317336
- **Enroll without user affinity**: You're using Direct enrollment. No actions. Be sure they don't install the Company Portal app from the Apple app store.
318337

338+
:::image type="content" source="./media/deployment-guide-enrollment-ios-ipados/configurator-enroll-without-user-affinity.png" alt-text="In the Endpoint Manager admin center and Microsoft Intune, enroll iOS/iPadOS devices using Apple Configurator. Select enroll without user affinity.":::
339+
319340
[!INCLUDE [users-dont-like-enroll](../includes/users-dont-like-enroll.md)]
320341

321342
## BYOD: User and Device enrollment
@@ -364,7 +385,7 @@ This task list provides an overview. For more specific information, see [Set up
364385
> [!NOTE]
365386
> BYOD can become organization-owned devices. To make these devices corporate, see [Identify devices as corporate-owned](../enrollment/corporate-identifiers-add.md).
366387
367-
User enrollment is considered friendlier to end users, but may not provide the feature set and security features administrators need. In some scenarios, user enrollment may not be the best option. Consider the following scenarios:
388+
User enrollment is considered friendlier to end users. But, it may not provide the feature set and security features administrators need. In some scenarios, user enrollment may not be the best option. Consider the following scenarios:
368389

369390
- User enrollment creates a work partition on the devices. The features and security you configure in the user enrollment profile only exist in the work partition. They don't exist in the user partition. Users can't factory reset the work partition. Administrators can. Users can factory reset the personal partition. Administrators can't.
370391

6.3 KB
Loading
12.1 KB
Loading
Loading
Loading
Loading
5.92 KB
Loading
13.4 KB
Loading
Loading
Loading

0 commit comments

Comments
 (0)