Last spring, we announced public preview of Setup Assistant with Modern Authentication for iOS/iPadOS 13+ and macOS 10.15+ for Automated Device Enrollment (ADE), and in August, we made this enrollment flow generally available. This authentication method for ADE allows your organization to require authentication with Azure Active Directory (Azure AD) in an out-of-box experience (OOBE) during enrollment with Setup Assistant, prior to users accessing the home screen. You have the option to also require multi-factor authentication (MFA) depending on the settings in your Conditional Access policy. On or shortly after December 10, 2021, we will be ending support for the older enrollment method that allows you to https://docs.microsoft.com/mem/intune/enrollment/device-enrollment-program-enroll-ios#create-an-apple-enrollment-profile.
How this will affect your organization:
You likely have already moved to use Setup Assistant with modern authentication, however, if you have not, you’ll want to move to this new authentication prior to the December date. This does not affect existing enrolled devices. Within the https://endpoint.microsoft.com/, you’ll want to either create a new ADE enrollment profile, or edit your existing enrollment profile to use the “Setup assistant with modern authentication.” The setting Run Company Portal in Single App Mode until authentication (Devices > iOS/iPadOS > Enrollment Program Tokens > select/create Profile > Management Settings) will no longer be available after this change.
User experience: This new enrollment flow does change the enrollment screen order to put authentication prior to accessing the home screen. If you have user guides that share screen shots, you’ll want to update those so the guides match the new experience.
What you need to do to prepare:
Review the updated documentation and several best practices blogs prior to moving. If you do not adopt the new enrollment profile prior to December 10, new devices will be unable to enroll until you do one of the following:
- (Recommended) Select Setup assistant with modern authentication.
- Use ADE user affinity enrollment with the Company Portal without configuring the Run Company Portal in Single App Mode until authentication setting.
Note: While you can still use ADE user affinity enrollment with the Company Portal for the authentication method, we do not recommend this since the user will need to manually run the Company Portal and complete the enrollment and Azure AD registration steps.
For More Information
- https://aka.ms/MEM-ADEModernAuth-Blog
- https://aka.ms/ade-modern-auth-filters-blog
- https://docs.microsoft.com/mem/intune/enrollment/device-enrollment-program-enroll-ios#create-an-apple-enrollment-profile
https://docs.microsoft.com/mem/intune/enrollment/device-enrollment-program-enroll-ios
https://admin.microsoft.com/AdminPortal/home#/MessageCenter/:/messages/MC284343?MCLinkSource=MajorUpdate