Blog Post

Intune Customer Success
5 MIN READ

Setup Assistant with modern authentication for ADE - Intune Public Preview

Intune_Support_Team's avatar
Intune_Support_Team
Silver Contributor
Apr 20, 2021

Updated 8/27/21: We're excited to take the preview tag off and share that Setup Assistant with modern authentication for ADE (iOS/iPadOS 13+ and macOS 10.15+) is now generally available! See Automatically enroll iOS/iPadOS devices by using Apple's Automated Device Enrollment on how to use this authentication method on iOS/iPadOS devices, and Automatically enroll macOS devices with the Apple Business Manager or Apple School Manager for macOS devices.

 

We’re excited to announce support for a new authentication method for Apple's Automated Device Enrollment (ADE) which is Setup Assistant with modern authentication. This new authentication method is available for iOS/iPadOS devices running 13.0 and later and for macOS devices running 10.15 and later, in public preview in Microsoft Endpoint Manager.

 

For automated device enrollment scenarios where the authentication method is Setup Assistant with modern authentication, you can create a filter rule based on the enrollment profile name (enrollmentProfileName). See: Using filters with Setup Assistant with modern auth for ADE for corporate iOS/iPadOS/macOS devices to learn more.

 

Overview

When creating an ADE enrollment profile, you can choose a new authentication method: Setup Assistant with modern authentication. This authentication method for ADE allows your organization to require authentication with Azure Active Directory (Azure AD) in an out-of-box experience (OOBE) during enrollment with Setup Assistant, prior to users accessing the home screen. You have the option to also require multi-factor authentication (MFA) depending on the settings in your Conditional Access policy.

 

Users are required to authenticate with their Azure AD credentials twice: once during enrollment with Setup Assistant, and then again when they sign in to the Company Portal. After initial authentication with Azure AD during Setup Assistant, the home screen appears, and users can freely use the device for resources not protected by Conditional Access. User affinity is established when a user arrives at the home screen after the setup screens. However, the device will not show in a user's device list in the Azure AD portal until the user signs in to Company Portal. The additional sign in to the Company Portal app fully completes a device’s Azure AD registration and gives the user access to corporate resources protected by Conditional Access. This method provides all the security of authenticating with the Company Portal but doesn’t make users wait until the Company Portal installs on the device before they can start using it.

 

The correct Company Portal version will automatically be delivered as a required app to the device for iOS/iPadOS. We recommend choosing a Volume Purchase Program (for the enrollment profile. Otherwise, it will be delivered when the user sets up their Apple ID during the Setup Assistant screens. To learn how to get the Company Portal on macOS devices, see Add the Company Portal for macOS app.

 

Company Portal Redirection

A new improvement we’ve made to our onboarding experience helps guide users to complete that second Azure AD authentication by automatically redirecting to the iOS/iPadOS Company Portal when the user attempts to access corporate data.


If users open any managed iOS/iPadOS applications that are protected by Conditional Access and they haven't completed the additional Azure AD sign in to the iOS/iPadOS Company Portal, they will be redirected to the Company Portal from those other apps as part of this new change. This way, users are guided to complete that last step before they can access resources protected by Conditional Access.


Here is what it will look like if a user tries to open an app protected by Conditional Access before authenticating in the Company Portal:

 

Conditional Access block screen.

 

System prompt that opens the iOS/iPadOS Intune Company Portal.

 

Configuration in Microsoft Endpoint Manager admin center

The Intune documentation explains how to configure the Setup Assistant with Modern Authentication for iOS/iPadOS device enrollment and macOS device enrollment. In the Microsoft Endpoint Manager admin center, you can a user for multi-factor authentication. For instructions, see Require multi-factor authentication for Intune device enrollments. The following screenshot provides an example of the prompt locations:

 

MFA prompt locations for Microsoft Intune and Microsoft Intune Enrolment.

 

Enrolling devices with user device affinity but without Azure AD registration

For both iOS/iPadOS and macOS, user device affinity (also known as primary user) in Intune is established when a user lands on the home screen after the Setup Assistant screens. However, the device is not fully registered with Azure AD until the additional sign in to Company Portal, as mentioned above. This is also when device compliance is assessed, and the device shows as compliant in the Microsoft Endpoint Manager admin center. However, if you would like to keep devices fully enrolled with Intune but without Azure AD registration, this is also supported.

After the user completes the initial Azure AD sign in during Setup Assistant, if there are no resources protected by Conditional Access and if Azure AD registration is not required, then this authentication method can be used to fully enroll the device. If you choose this ADE flow, which does not require users to sign in to the Company Portal post enrollment, you will see the following device behavior:

  • The device will not show up in a user’s device list in the Azure AD portal (since there is no device identity association within Azure AD).

  • The device will not show up as compliant in the Microsoft Endpoint Manager admin center.

 

Keep in my mind

  • When enrolling an iOS/iPadOS device with Setup Assistant with Modern Authentication, app configuration policies are automatically applied to the iOS/iPadOS device. Don’t send a separate app configuration policy to the Company Portal for those iOS/iPadOS devices or it will result in an error.

  • If you choose Setup assistant with Modern Authentication as the authentication method for a device that is not running the correct software version, users will fall back to the legacy Setup Assistant ADE flow.

  • For iOS/iPadOS, we recommend selecting to install the Company Portal app from a VPP token in the enrollment profile. When VPP is used, the application can be downloaded and installed without user interaction. When VPP isn't used, an Apple ID is required to install the application. If the user doesn't sign in to an Apple ID during Setup Assistant, they will be prompted to sign in when Intune attempts to install the Company Portal.

 

Let us know if you have any questions by commenting on this post or reaching out to @IntuneSuppTeam on Twitter.

 

Post updates:
8/20/21 - added post on using filters with Setup Assistant with modern auth for ADE for corporate iOS/iPadOS/macOS devices.

8/26/21 - we're excited to take the preview tag off and share that Setup Assistant with modern authentication for ADE (iOS/iPadOS 13+ and macOS 10.15+) is now generally available! 

Updated Dec 19, 2023
Version 14.0

45 Comments

  • Dheeraj Oswal's avatar
    Dheeraj Oswal
    Copper Contributor

    Intune_Support_Team  Thankyou for sharing the feature update. Definitely this is exciting and adds a lot of benefits. 

     

    Would like to share the observations that, once the device lands home screen and Company portal is installed the device checks in automatically and device records is created on MEM console and the device is marked complaint without having to manually login to Company portal .

    Note- the articles described that CP login is required once the device lands home screen to access CA protected apps. 

     

  • Hi kpax-io and e-aldo, thank you for your feedback! It's helpful for us while this feature is in public preview and we work through issues that are found. We will take this issue back to the team to investigate. At the point of signing into the Company Portal, the device is already enrolled and there should not be an additional management profile coming down. While we don't have a specific fix right now, please make sure you are not sending down any app config policies targeted at the iOS/iPadOS Company Portal app if enrolling your device with setup assistant with modern authentication for iOS/iPadOS. For iOS/iPadOS, the correct app config is already being applied automatically behind the scenes in the enrollment profile, so no app config is needed for the iOS/iPadOS Company Portal. Sending down an additional app config in this case may result in an error. We’ll keep this post updated as we learn more. Thanks!

  • kpax-io's avatar
    kpax-io
    Copper Contributor

    I have made some progress.

     

    Under DEP Profile, tenant admin > customization, I changed this setting 'Device enrollment' to 'Available, no prompts' from 'Available, with Prompts'. Additionally, I removed my own account as an enrollment manager.

     

    With these two steps removed the additional profile download is no longer occurring. In "Comp Portal" under 'Devices' it displays says "Register this device" for my iPad, but otherwise compliant with policies and the iPad is shown in the endpoint manager and I am able to use functions from there on the device.

     

    Let us know if any of this is expected,

     

    Thanks,

  • e-aldo's avatar
    e-aldo
    Iron Contributor

    Hi all,
    I also experienced the same issue and this exprience is similar like when you set-up an enrollment profile without user affinity then try to enroll the device linked to this profile.


    I'll describe here the user experience to help everyone understand well.

     

    // User experience

    Language > Country/Region > Network > Device activation + Getting settings > Remote Management > Gettings settings from "Company Name" > Passcode > ...

    Note: Gettings settings from "Company Name" means that the device get ADE settings from Intune so the first Management profile is dowloaded and applied here.

     

    After the company portal is installed and the user start the device enrollment, another Management profile is also downloaded and this one cannot be installed due to conflict.

     

    I hope all those scenarios will find solutions.

    cc: Intune_Support_Team 

     

    Regards,

    AEL

  • kpax-io's avatar
    kpax-io
    Copper Contributor

    I am trying this out on an iPad, the modern auth is working in the setup assistant and the device gets a management profile applied in this process/

     

    However, from the launcher using 'comp portal' shows the device as not enrolled and tries to download a new management profile from the workflow, the profile downloads and fails to install and the device doesn't end up compliant as a result.

     

    Not sure if it is intentional to have the device try to get a new management profile after it already has one applied from the setup assistant.