question

JoshuaWalsh-6281 avatar image
0 Votes"
JoshuaWalsh-6281 asked JoshuaWalsh-6281 commented

Getting iOS User Enrollment to work

Hi all,

I'm trying to get iOS User Enrollment to work with Intune. I have done the following:

  • Created a Group for my pilot users

  • Added an Apple MDM Push certificate

  • Signed up for Apple Business Manager

  • Connected ABM to Azure AD for Federated Authentication

  • Created an Enrollment Type Profile in Intune that only allows User Enrollment, and assigned this profile to the pilot group. (It's the only iOS Enrollment Type Profile, so it's definitely got priority)

I have tested the enrollment process with two users on two devices. Here are the results:

Device #1:

Device has been in use by user for over a year. Installed Company Portal app. Signed in to MS account via Company Portal app. Agreed to download configuration profile. Activated configuration profile in Settings app. Asked to sign in to Managed Apple ID. Email field is greyed out and can't be changed, user must sign in with the same email address as their MS account. User enters same password as MS account. User informed that their credentials are incorrect.

Device #2:

Device has been factory reset due to exited employee. Set up as new device. Created new Apple ID. Installed Company Portal app. Signed in to MS account via Company Portal app. Agreed to download configuration profile. Activated configuration profile in Settings app. Agreed that company will have control over device. Device enrolled successfully.

But it appears to be Device Enrollment, not User Enrollment. The user was not asked to sign in to a Managed Apple ID. Tested by using "Wipe" function in Intune. Device fully factory reset, including personal data.

Does anyone have any suggestions of what I could be doing wrong?

Thanks!

mem-intune-generalmem-intune-enrollment
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Have you seen the limitation of User Enrollment? That might affect the experience of User Enrollment. For example, User Enrollment only supports a unique enrollment ID for each device enrolled, but this ID doesn't persist after unenrollment.

https://docs.microsoft.com/en-us/mem/intune/enrollment/ios-user-enrollment-supported-actions


0 Votes 0 ·

Thanks for the reply, I didn't get an email about it so I didn't see it until now.

I don't think any of those limitations are affecting me. The issue I have is that User Enrollment doesn't work at all, Device Enrollment is always used, despite my Enrollment Type Profile. Those limitations all apply once a device has been User Enrolled, but I can't even get to that point.

0 Votes 0 ·

0 Answers