Forum Discussion
IOS Enrollment Policys - User affinity with modern auth, does not work with Company Portal VPP
Company Portal is installed, but it starts a second enrollment because the VPP assignment lacks ADE configuration. Microsoft documents that Setup Assistant with modern authentication should install Company Portal through the enrollment policy’s Install Company Portal with VPP option; Intune then sends the app and configuration automatically. Edit the policy assigned to the ADE token, keep User affinity and Setup Assistant with modern authentication, select the Company Portal VPP token, and sync the token. Remove the separate assignment and custom Company Portal configuration for this test. Wipe the iPad and enroll it again, because ADE settings apply during activation. After Setup Assistant, sign in to Company Portal once to complete Entra registration and compliance. Do not add separate XML for this documented flow. If the VPP selector is absent from the new policy interface, capture the policy ID and open an Intune support case; that differs from Microsoft’s configuration guidance.
- GT3Jul 29, 2026Copper Contributor
Was able to get a hold of Intune MVP contact and get it working.
Your post is incorrect based on testing and functioning setup now.
The XML is needed for policies to work.
The Microsoft documentation states "profiles" not polices.
its capsensitive which caused an issue on 1 letter.<dict>
<key>IntuneCompanyPortalEnrollmentAfterUDA</key>
<dict>
<key>IntuneDeviceId</key>
<string>{{deviceid}}</string>
<key>UserId</key>
<string>{{userid}}</string>
</dict>
</dict>
documentation reads Terrrible, its probably AI.https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-ios