Apple MDM Enrollment Methods
Description
|
Enrolling Apple devices involves the installation of an MDM Enrolment Profile.
Installation may be initiated by either the user or the device. This same distinction also applies to the linking of the enrolment. |
Who starts enrollment?
Apple enrollment methods differ in who starts the process and whether management is linked to the device or the user.
Automated Device Enrollment (ADE) is device-driven. During Setup Assistant, an eligible device contacts Apple and receives the FileWave MDM enrollment profile assigned to it.
Account-driven enrollment is user-initiated. The user selects Sign In to Work or School Account in Settings or System Settings. The device then performs service discovery and organization authentication, retrieves the enrollment profile, and requires a Managed Apple Account sign-in to complete enrollment.
User vs Device Enrolment
Automated Device Enrolment links enrolment with the identity of the device; providing the maximum management options available. The extreme opposite is Bring Your Own Device (BYOD) enrolment. This is an example of the user's identity linking enrolment and provides the minimum amount of control.
User enrolment cryptographically separates organisational data from user data and limits many features of MDM. Further details explained in Apple's KB:
Apple: User Enrollment and MDM
Overview
Therefore, the key methods of enrolment can be categorised as:
- profile-based device enrolment
- account-driven device enrolment
- profile-based user enrolment
- account-driven user enrolment
Enrolment Methods
Automated Device Enrolment
On startup, the device reaches out to Apple and, where associated, the Enrolment Profile is delivered to the device and installed. The user is then prompted for authentication (if not configured for no authentication).
OTA Enrolment
This enrolment type potentially has two offerings:
- User authenticates to download the Enrolment Profile and then instals the Profile manually.
- An Enrolment Profile is provided to the user, for example by email, and the user manually instals the Profile.
BYOD
BYOD also could be described with two possible options:
- Enrolment Profile is downloaded and then the user authenticates (deprecated, see below note)
- User authenticates in Settings and then approves the subsequently downloaded Profile.
Deprecation
For current iPhone and iPad BYOD enrollment, use Account-Driven User Enrollment. Apple deprecated profile-based User Enrollment in iOS 17 and iPadOS 17 and no longer supports it in iOS 18 and iPadOS 18.
Account-Driven User Enrolment
Although these are personal devices, this enrolment method requires the user to add credentials into Settings which must be a Managed Apple ID. Federated Authentication links a supported IdP with Apple, matching Managed Apples IDs with IdP usernames and passwords.
FileWave 15.5 and later support Account-Driven User Enrollment for iOS and iPadOS. Follow the linked FileWave workflow for the required Apple and identity configuration.

No comments to display
No comments to display