Forum Discussion

Hollis255's avatar
Hollis255
Copper Contributor
Oct 16, 2020

Intune Enrollment and App mgt for company iOS devices even if user is not in Active Directory

We are migrating from one MDM, which was device based, to Endpoint/Intune. Everything seems to be going okay for all users who have an Azure AD account, but we have many users who are not in AD. Is there a way to manage the devices AND push apps out to the iPhones / iPads by Serial number ONLY? So the user never actually needs to sign in?

 

Also, in our previous MDM, we pushed apps using tags and were able to differentiate between iPhones (only got two required apps) and iPads (two required and eight default apps) to automatically push when the device enrolled. Everything I'm seeing just says iOS/iPad and we'd like different things to happen for iPhones than for iPads.

 

Thank you, in advance.

~ H

  • r0bu's avatar
    r0bu
    Brass Contributor
    Hi, you can absolutely mange device without user affinity. How are you currently enrolling device? I would suggest using Apple Business (or School) manager, combined with ADE(DEP) and device assigned VPP apps.

    Depending on your Azure AD licensing level, you can also configure dynamic groups for devices so all iPads fall onto one group and all iPhones fall into another.

    Let me know if this sounds like something that would be of interest and we can chat further
    • Hollis255's avatar
      Hollis255
      Copper Contributor

      Thank you, r0bu, for the reply. We are using ABM + ADE + device assigned VPP (well, we are using VPP...and I choose 'license type = device' when I add groups to them in Intune). Setting up AD groups specifically for iPad and iPhone was a thought I had, as well, but wasn't sure if that was the only way to go.

       

      I've tried to set up 'dynamic' security groups for the purpose of pushing apps to devices for users who are unable to use the portal due to not having an AD account, but wasn't able to get it going. I am unable to figure out how to put devices into the group.

Resources