Skip to main content

Apple MDM Enrollment Methods

Description

Enrolling Apple devices involves the installation of an MDM Enrolment Profile.   

  

Installation may be initiated by either the user or the device.   This same distinction also applies to the linking of the enrolment.

image.png

InitiatingWho Enrolmentstarts enrollment?

ThisApple refersenrollment methods differ in who starts the process and whether management is linked to the drivingdevice forceor ofthe enrolment.user.

Consider Automated Device EnrolmentEnrollment (ADE), deliveringis device-driven. During Setup Assistant, an eligible device contacts Apple and receives the ProfileFileWave beforeMDM authenticationenrollment (ifprofile configured).assigned Thisto isit.

Account-driven enrollment starts after the user authenticates with an exampleeligible ofManaged profile-basedApple enrolment.

Account-driven enrolment relies on the authentication of a user in advance.Account.

User vs Device Enrolment

Automated Device Enrolment links enrolment with the identity of the device; providing the maximum management options available.   The extreme opposite is Bring Your Own Device (BYOD) enrolment.   This is an example of the user's identity linking enrolment and provides the minimum amount of control.

User enrolment cryptographically separates organisational data from user data and limits many features of MDM.   Further details explained in Apple's KB:

Apple: User EnrolmentEnrollment and MDM

Overview

Therefore, the key methods of enrolment can be categorised as:

  • profile-based device enrolment
  • account-driven device enrolment
  • profile-based user enrolment
  • account-driven user enrolment

Enrolment Methods

Automated Device Enrolment

On startup, the device reaches out to Apple and, where associated, the Enrolment Profile is delivered to the device and installed.   The user is then prompted for authentication (if not configured for no authentication).

OTA Enrolment

This enrolment type potentially has two offerings:

  • User authenticates to download the Enrolment Profile and then instals the Profile manually.
  • An Enrolment Profile is provided to the user, for example by email, and the user manually instals the Profile.

BYOD

BYOD also could be described with two possible options:

  • Enrolment Profile is downloaded and then the user authenticates (deprecated, see below note)
  • User authenticates in Settings and then approves the subsequently downloaded Profile.

Deprecation

AlthoughFor definitionscurrent exist for all enrolment methods above, as of iOS18iPhone and macOS15iPad BYOD enrollment, use Account-Driven User Enrollment. Apple willdeprecated profile-based User Enrollment in iOS 17 and iPadOS 17 and no longer supportsupports profile-basedit userin enrolment.iOS  18 Thisand impactsiPadOS the first described BYOD enrolment method, meaning BYOD with personal devices must action account-driven user enrolment.18.

Account-Driven User Enrolment

Although these are personal devices, this enrolment method requires the user to add credentials into Settings which must be a Managed Apple ID.   Federated Authentication links a supported IdP with Apple, matching Managed Apples IDs with IdP usernames and passwords.

Federated Authentication

InitialFileWave 15.5 and later support forAccount-Driven Account-drivenUser user enrolment is currently targetedEnrollment for iOS and iPadOS. Follow the linked FileWave 15.5.workflow  Confirmationfor ofthe inclusionrequired shouldApple beand availableidentity closer to release.configuration.