Skip to main content

iOS BYOD User Enrollment Overview

What

FileWave User Enrollment lets an organization manage work apps and settings on a personally owned iPhone or iPad without taking full control of the device. FileWave 14 introduced the profile-based BYOD (bring-your-own-device) workflow shown below.

For current BYOD enrollment, use Account-Driven User Enrollment. Apple no longer supports profile-based User Enrollment starting with iOS 18 and iPadOS 18. The account-driven method is available in FileWave 15.5 and later and starts in Settings, not on the legacy web page below. Follow the linked guide to configure FileWave, the organization's enrollment-discovery URL, and Managed Apple Accounts before asking users to enroll.

When/Why

Use User Enrollment for personally owned devices that need organization-managed apps, accounts, or access settings. It limits management; it does not mean the organization can only distribute apps. See Manage BYOD with Apple User Enrollment for the available controls and privacy limits.

Legacy profile-based User Enrollment

The following procedure, screenshots, and video describe the older profile-based method, not enrollment on iOS 18 or iPadOS 18 and later. In the legacy interface, enable User Enrollment on the Mobile tab in preferences as shown below:

GaGowZyVosOOdnaC-embedded-image-yj5xldb0.png

Once enabled, a new tab will be added to the "Enroll iOS Device..." Assistant:

MkgZMhVp7SHODrkA-embedded-image-xwn96lu6.png

And, once user enrollment is enabled, you can go to https://my.server.address:20443/ios/byod to see the user enrollment page:

Nl5KS8EcGK6hoY6M-embedded-image-ci6ebasr.png

For this legacy profile-based method, users start from the web page above rather than Automated Device Enrollment (ADE). User Enrollment requires a Managed Apple Account (formerly Managed Apple ID) from Apple School Manager or Apple Business Manager. The account-driven method linked above uses Settings instead.

See below video of a BYOD device enrollment:

The legacy BYOD enrollment procedure does not require wiping the device first. However, trying to enroll with a Managed Apple Account that is already signed in to iCloud on the device results in an error in this legacy workflow.