Apple MDM Enrollment Methods

Description

Enrolling Apple devices involves the installation of an MDM Enrolment Profile.  

 

Installation may be initiated by either the user or the device.  This same distinction also applies to the linking of the enrolment.

image.png

Who starts enrollment?

Apple enrollment methods differ in who starts the process and whether management is linked to the device or the user.

Automated Device Enrollment (ADE) is device-driven. During Setup Assistant, an eligible device contacts Apple and receives the FileWave MDM enrollment profile assigned to it.

Account-driven enrollment is user-initiated. The user selects Sign In to Work or School Account in Settings or System Settings. The device then performs service discovery and organization authentication, retrieves the enrollment profile, and requires a Managed Apple Account sign-in to complete enrollment.

User vs Device Enrolment

Automated Device Enrolment links enrolment with the identity of the device; providing the maximum management options available.  The extreme opposite is Bring Your Own Device (BYOD) enrolment.  This is an example of the user's identity linking enrolment and provides the minimum amount of control.

User enrolment cryptographically separates organisational data from user data and limits many features of MDM.  Further details explained in Apple's KB:

Apple: User Enrollment and MDM

Overview

Therefore, the key methods of enrolment can be categorised as:

Enrolment Methods

Automated Device Enrolment

On startup, the device reaches out to Apple and, where associated, the Enrolment Profile is delivered to the device and installed.  The user is then prompted for authentication (if not configured for no authentication).

OTA Enrolment

This enrolment type potentially has two offerings:

BYOD

BYOD also could be described with two possible options:

Deprecation

For current iPhone and iPad BYOD enrollment, use Account-Driven User Enrollment. Apple deprecated profile-based User Enrollment in iOS 17 and iPadOS 17 and no longer supports it in iOS 18 and iPadOS 18.

Account-Driven User Enrolment

Although these are personal devices, this enrolment method requires the user to add credentials into Settings which must be a Managed Apple ID.  Federated Authentication links a supported IdP with Apple, matching Managed Apples IDs with IdP usernames and passwords.

Federated Authentication

FileWave 15.5 and later support Account-Driven User Enrollment for iOS and iPadOS. Follow the linked FileWave workflow for the required Apple and identity configuration.


Revision #12
Created 2024-09-13 07:15:16 UTC by Sean Holden
Updated 2026-07-21 14:13:30 UTC by Josh Levitsky