Device Enrolment and MDM (2024)

Apple Platform Deployment

Device Enrolment and MDM (1)

Device Enrolment allows organisations to have users manually enrol devices into a mobile device management (MDM) solution and then manage many different aspects of device use, including the ability to erase the device. On Mac computers using macOS 11 or later, Device Enrolment also enforces supervision on the Mac.

When a user removes an enrolment profile, all configuration profiles, their settings and Managed Apps based on that enrolment profile are removed with it.

Device Enrolment has a larger set of payloads that can be applied to the device. For the complete list, see Device Enrolment MDM payload list.

Account-driven Device Enrolment

In iOS 17, iPadOS 17, macOS 14 and visionOS 1.1, or later, organisations can use an account-driven Device Enrolment process, built into Settings and System Settings to make it easier for users to enrol devices.

To do this, the user navigates to Settings > General > VPN & Device Management or to System Settings > Privacy & Security > Profiles and then selects the Sign In to Work or School Account button.

As the user enters their Managed Apple ID, service discovery identifies the MDM solution’s enrolment URL. The user then enters their organisation user name and password. After the authentication succeeds, the enrolment profile is sent to the device. A session token is also issued to the device to allow ongoing authorisation. The device then begins the MDM enrolment process and prompts the user to sign in with their Managed Apple ID. On iPhone, iPad and Apple Vision Pro, the authentication process can be streamlined by using enrolment single sign-on to reduce repeated authentication prompts. After a user is signed in, the new managed account is displayed prominently within Settings and System Settings.

As with User Enrolment, organisational data is cryptographically separated from personal data (see How Apple separates user data from organisation data). Due to this separation, some changes are required to the way apps and backups are handled. For example:

  • Apps installed before MDM enrolment can’t be converted to become Managed Apps.

  • Managed Apps are always removed during unenrolment.

  • Restoring from a backup doesn’t restore MDM enrolment.

  • Users who sign in with their personal Apple ID can’t accept an invitation for Managed App distribution.

Because the discovery process uses the same com.apple.remotemanagement discovery file as User Enrolment, organisations can choose — based on the device model and Managed Apple ID of the user — which account-driven enrolment type (User Enrolment or Device Enrolment) should be used.

How Apple separates user data from organisation data

The table below shows how Apple separates user data from the organisation’s data with Device Enrolment.

Data

Can MDM see it?

Supported operating systems

Capacity and space available

Yes

iOS

iPadOS

macOS

visionOS 1.1

Device name

Yes

iOS

iPadOS

macOS

tvOS

visionOS 1.1

Installed apps

Yes

iOS

iPadOS

macOS

tvOS

visionOS 1.1

Model name and number

Yes

iOS

iPadOS

macOS

tvOS

visionOS 1.1

Operating system version number

Yes

iOS

iPadOS

macOS

tvOS

visionOS 1.1

Phone number

Yes

iOS

Serial number

Yes

iOS

iPadOS

macOS

tvOS

visionOS 1.1

Device location

No

iOS (Supervised)

iPadOS (Supervised)

FaceTime or phone call logs

No

iOS

iPadOS

macOS

visionOS 1.1

Frequency of app use

No

iOS

iPadOS

macOS

tvOS

visionOS 1.1

iMessage or SMS messages

No

iOS

iPadOS

macOS

visionOS 1.1

Personal calendars, contacts, mail, notes, reminders

No

iOS

iPadOS

macOS

visionOS 1.1

Safari browser history

No

iOS

iPadOS

macOS

visionOS 1.1

Helpful?

Thanks for your feedback.

Device Enrolment and MDM (2024)
Top Articles
Your 4 most important habits - Chris Bailey
Identifying skills and upskilling | National Careers Service
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Selly Medaline
Latest Posts
Article information

Author: Lidia Grady

Last Updated:

Views: 5634

Rating: 4.4 / 5 (65 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Lidia Grady

Birthday: 1992-01-22

Address: Suite 493 356 Dale Fall, New Wanda, RI 52485

Phone: +29914464387516

Job: Customer Engineer

Hobby: Cryptography, Writing, Dowsing, Stand-up comedy, Calligraphy, Web surfing, Ghost hunting

Introduction: My name is Lidia Grady, I am a thankful, fine, glamorous, lucky, lively, pleasant, shiny person who loves writing and wants to share my knowledge and understanding with you.