Blog Post

Intune Customer Success
5 MIN READ

Upcoming changes to iOS/iPadOS Company Portal app deployment for Setup Assistant with modern auth

Intune_Support_Team's avatar
Intune_Support_Team
Silver Contributor
Sep 14, 2022

Updated January 17, 2023: The change has been delayed. We will update this post when it's time to replan for this future change.

 

Updated December 19 2023: We’ve been hard at work to improve the ADE experience through the release of Setup Assistant with modern authentication, Just in Time (JIT) registration and compliance remediation, and the "Await until configuration" setting. Learn more in our blog here: aka.ms/Intune/Improved-ADE.

 

Based on customer feedback and the upcoming Just in Time (JIT) Registration feature, we're planning to remove automatic deployment of the iOS/iPadOS Company Portal app as a required app for Automated Device Enrollment (ADE) Setup Assistant with modern authentication enrollment profiles in a future Intune service release.

 

With JIT Registration, the Company Portal app will no longer be required for Azure Active Directory (Azure AD) registration or compliance. The new feature allows admins to tailor the Company Portal app with the desired customizations to fit their organization’s needs.

 

This change will occur in two phases. The first phase will remove the automatic deployment from new profiles and introduce a new configuration option for existing enrollment profiles to stop automatic deployment. The second phase will remove automatic deployment from existing enrollment profiles. We'll keep you updated on the expected timeline and any additional information for the change in this post.

 

Existing ADE profiles with Setup Assistant with modern authentication

To prepare for this change, we will be adding a new option for all existing ADE Setup Assistant with modern authentication enrollment profiles that will allow you to stop the automatic deployment of the iOS/iPadOS Company Portal as a required app from the enrollment profile. The new option will be available in the “Install Company Portal with VPP” drop-down menu. Stay tuned to In development and What’s new in Intune for the release.

 

If you have existing ADE profiles with Setup Assistant with modern authentication, once it's available, enable the new drop-down configuration to stop the automatic deployment of the Company Portal app. After updating the configuration of the setting, use an app configuration policy and app targeting to push the Company Portal app as an available or required Volume Purchase Program (VPP) app (this is optional because of JIT Registration, which will be released at that time). VPP is not required but is recommended. A few months after the new drop-down is released, we will be removing the automatic deployment of the Company Portal app from the modern authentication enrollment profile regardless of the VPP setting configuration.

 

After updating your existing profile, complete the following steps:

  1. Create an app configuration policy, specifically sending the app configuration XML file called “Use the Company Portal on an Automated Device Enrollment (ADE) device enrolled with user affinity” see Add app configuration policies for managed iOS/iPadOS devices for instructions.
  2. Deploy the Company Portal app to the device, there are two options for this:
    1. (Recommended) Set up VPP for iOS/iPadOS and assign the Company Portal app as required. For instructions see How to manage iOS and macOS apps purchased through Apple Business Manager with Microsoft Intune. You're highly encouraged to set “Automatic app updates” to Yes.
    2. Add the Company Portal to Intune, see Add apps to Microsoft Intune and then assign the app as required by following these instructions: Assign apps to groups with Microsoft Intune.

The correct app configuration policy must be assigned to the devices regardless of whether VPP is configured for the Company Portal. The Company Portal is required on the device.

 

Note: Later, we'll remove the automatic deployment of the Company Portal app from the modern authentication enrollment profile regardless of the “Install Company Portal with VPP” setting configuration. However, you'll continue to see the setting in the enrollment profile. No changes are needed if you’ve already taken the steps above.

 

New ADE profiles with Setup Assistant with modern authentication

Once automatic deployment of the Company Portal app has been removed, you'll no longer see the “Install Company Portal with VPP” setting when creating new ADE profiles. You'll need to use an app configuration policy and app targeting to deliver the Company Portal app. Here’s what to do:

  1. Create an app configuration policy, specifically sending the app configuration XML file called “Use the Company Portal on an Automated Device Enrollment (ADE) device enrolled with user affinity” see Add app configuration policies for managed iOS/iPadOS devices for instructions.
  2. Deploy the Company Portal app to the device as a required app, there are two options for this:
    1. (Recommended) Set up VPP for iOS/iPadOS and assign the Company Portal app. For instructions see How to manage iOS and macOS apps purchased through Apple Business Manager with Microsoft Intune. You're highly encouraged to set “Automatic app updates” to Yes.
    2. Add the Company Portal to Intune, see Add apps to Microsoft Intune and then assign the app as required by following these instructions: Assign apps to groups with Microsoft Intune.

The correct app configuration policy must be assigned to the devices regardless of VPP being configured for the Company Portal or not.

 

Key takeaways

  • This change only affects the Setup Assistant with modern authentication for iOS/iPadOS.
  • At the time of this change, if you choose to utilize JIT Registration:
    • We will not be blocking the Company Portal app deployment for Setup Assistant with modern authentication but, rather, making it optional.
    • Company Portal will not be required for Azure AD registration or compliance.
  • There are no changes to multi-factor authentication (MFA). If MFA is configured and required by the organization, a second device is still required for authentication.
  • The Company Portal app on existing enrolled devices will not be affected by the enrollment profile changes until the devices are re-enrolled.

 

We’ll continue to update this post with additional details, as needed, including when the new drop-down option becomes available and expected timelines for this change. More documentation will be available once the new option has been released. If you have any questions, please comment below or reach out to us on Twitter @IntuneSuppTeam.

 

Post updates:

10/10/22: Updated the content above to provide additional clarity.

10/31/22: Updated to clarify the timeline of Q1 CY2023 (was Q1 2023).

01/17/23: Change has been delayed. We will update this post when it's time to replan for this future change.

12/19/23: Added blog: aka.ms/Intune/Improved-ADE.

Updated Dec 20, 2023
Version 11.0

35 Comments

  • Hi Ginsmon_Joseph_IAEADarren O'Leary, and Peter_Holdridge, thank you for your feedback, it's very appreciated! 

    • The Company Portal authentication method is not affected with the changes outlined in this post, only Setup Assistant with modern authentication for iOS/iPadOS. However, I highly encourage you to move your iOS/iPadOS ADE enrollment profiles and devices over to Setup Assistant with modern authentication as soon as possible because we will be deprecating the Company Portal authentication method in the future. There will be a new blog post about this later on with more details. Setup Assistant with modern authentication is the main ADE authentication method for enrollment and we are continuously investing in improving the flow. 
    • While the Company Portal app is currently required for Azure AD registration and device compliance for Setup Assistant with modern auth, that will not always be the case when Just in Time Registration for Setup Assistant with modern auth (iOS/iPadOS) releases in public preview. With Just in Time Registration, the Company Portal will no longer be required for Azure AD registration or compliance checks, and this will all be handled behind the scenes with Apple's SSO extension and will be done with an authentication in a configured Office app. More details are coming on this soon in a blog post. 
    • Everyone will be required to stop the automatic deployment of the Company Portal app and app config policy from the Setup Assistant with modern authentication enrollment profile. We made this decision based on issues with the automatic deployment, which include the inability for auto-updates to work on the Company Portal, incorrect configuration of duplicating the app config policy, and back up and restore issues. Once JIT Registration releases in public preview, the Company Portal will be fully optional and you will be able to send it manually as an available or required app with the attached app config policy if your organization chooses to do so. That way, auto-updating of the Company Portal will work and there won't be any app config policy duplication that results in incorrect management profile downloads. Due to these issues that customers have been facing, Intune making the Company Portal piece optional allows for granular customization. Soon, admins will be able to configure and target the Company Portal exactly how they want, and this will get rid of any current issues. 

    Just to clarify, we are not removing the Company Portal aspect of Setup Assistant with modern authentication, we are making sure admins can configure and target the app exactly how they want while making it optional in the near future. 

     

    thank you!

  • Will everyone be required to make this change or will there be two options? We prefer to use the automated ADE deployment method as it currently stand. Less admin overhead.

  • What is the rationale for this change please? As the Company Portal App is required for Device Compliance, why give admins the option of not deploying it automatically?

  • Thats interesting.

    But does it affect the profiles with authentication method as Company portal app and not setup assistant with modern authentication?