Event details
Apple products are a big part of your endpoint management story! Get updates on managing your Apple devices including the latest in device enrollment. We’ll cover topics from app deployment to securing your devices to configuring iOS for special use cases, and what the latest iOS 16 release means for you!
Join us for a special Ask Microsoft Anything (AMA) live stream on managing iOS and macOS devices with Microsoft Endpoint Manager.
This is a great opportunity to learn from Microsoft experts. Add this event to your calendar, RSVP to receive notifications, then join us here for the live stream on the Tech Community on Thursday, July 21.
|
Submit your questions anytime during the hour or post them early in the Comments below. |
76 Comments
- engelcgBrass ContributorFor multiple macOS versio on the same device: for example when testing is necessary on multiple OS version, but the user has only one device assigned, but MDM is preferred on each OS. One more question: with defined compliance policies in place is there a plan to allow devices registered with DEM account (e.g.: shared computers) to allow users to sign in with their own account for e.g.: Office applications?
- dsmodusBrass ContributorWhen a DEP device is wiped from Intune and removed from ABM, will be removed the Apple ID and the device will not be locked on the specific Apple ID or Apple support can solve only?
- Rachelle_Blanchard
Microsoft
Admin response: This question was answered live. Please refer to the recording for more details.
- dsrichmondCopper Contributor
After finishing a setup of an iOS device via Setup Assistant with Modern Authentication, the user will be able to interact with o365 apps in MAM mode UNLESS they manually open Company Portal and finish device enrollment/registration there. How can we ensure users are forced by a policy to ALWAYS finish the setup in Company Portal? Single-app mode is unacceptable here as that deprecated method fails often.
This is holding up our deployment of Setup Assistant with Modern Auth!
- Andy_Cerat
Microsoft
Hello David, Do you have Conditional Access policies applied to require device enrollment? Those policies would block the user from accessing the O365 app and redirect them to the Company Portal app. Our Just In Time Registration (coming soon) will take it one step further and remove the company portal completely from the flow. - Rachelle_Blanchard
Microsoft
Admin response: This question was answered live. Please refer to the recording for more details.
- dsrichmondCopper Contributor@Anya just mentioned a private preview for JIT registration - how can we get hooked into this? Please let me know, this is 100% vital for us!
- dsrichmondCopper ContributorNo, I do mean they are ABLE to use o365 apps but as if they are on a personal device because it is not fully registered. It sounds like just-in-time registration is what we need here, which is awesome news!
- Heather_Poulsen
Community Manager
We're halfway through today's Managing iOS and macOS devices AMA. Keep your questions—and suggestions on future feature prioritization—coming. Thanks!
- engelcgBrass ContributorIs there a plan to enable enrolment of multiple macOS running on the same device? Currently it's not possible as only the last registered one remain in Endpoint manager.
- Heather_Poulsen
Community Manager
The team would love to hear more! Please share details here or reach out via private message here in the Tech Community to AnyaNovicheva about your use case and needs.
- Rachelle_Blanchard
Microsoft
Admin response: This question was answered live. Please refer to the recording for more details.
- TMHCC-HPaulCopper Contributor
Our company organization is just now implementing macOS devices but had iOS mobile devices prior. How do you tackle managing the life cycles of Apple IDs?
- dsrichmondCopper ContributorManaged apple IDs via federation are an option. If you have an enterprise contact at Apple, talk to them - their sales reps will happily get you hooked into a discussion about ABM and how to get that set up.
- Rachelle_Blanchard
Microsoft
Admin response: This question was answered live. Please refer to the recording for more details.
- RobdeRoosIron ContributorDo you use ABM and have you looked at Federation?
- TMHCC-HPaulCopper ContributorWe have implemented both, one of our organization concerns is Apple IDs that was previously enrolled on a iOS mobile device we no longer have access to. Case in point, our email naming convention is "First Letter of the First Name" and the "Full Last Name" (ex. jsmith@companyname.com) but if that Apple ID needs to be recycle with a new employee Apple ID with the same naming convention, we are force to add a number to the email address when registering an Apple ID and therefore is force to add that same email address as a aliases on the back-end to that particular company account. Also take into consideration, that we are just now implementing Jamf and ABM but prior to that, we was manually advises users to use their company email address to register with their Apple IDs. So as a growing organization, we see that kind of getting out of hand and inquiring the best practices on managing Apple IDs.
- Travis_McHughCopper ContributorCan you provide details on Security and Benchmarking/Compliance? Will it leverage Intune for compliance? Will you be able to set security benchmarks in the product?
- Max_Stein
Microsoft
Hi Travis, thanks for the question! Just to clarify, are you referring to deploying Apple security specific policies for managed devices, or more information about Data Protection with Microsoft Intune?
- engelcgBrass ContributorWe saw issues with mobile accounts where passwords are not synced with filevault and keychain if the password wasn't changed via the user profile on macos. Will these get fixed in the announced SSO login?
- Andy_Cerat
Microsoft
We hope so, but are going to need to get some hands on validation to confirm. We hope to understand and share more in the coming months.
- Olaf_ThyssenBrass ContributorIs it or is it not supported to restore an iOS backup from previous ADE/DEP device to new ADE/DEP device during enrollment? We have allowed it in the assistant but the management profile in the backup sometime (or often) causing problems to complete enrollment and supporting supervised mode
- dsrichmondCopper ContributorThis used to fail 100% of the time for us and so we have blocked restore on corporate devices for years. In the last few months (perhaps corresponding with an iOS update, it's not clear) the issue is no longer observed. The root cause - the device attempting to restore managed configuration profile from another device which resulted in a deviceid conflict - seems to no longer happen here. Which errors have you been experiencing?
- Rachelle_Blanchard
Microsoft
Admin response: This question was answered live. Please refer to the recording for more details.
- Travis_McHughCopper ContributorCan you provide details on how Macs/iOS devices are onboarded? does the product integrate well with DEPNotify or have an integrated solution similar to Kandji?
- Max_Stein
Microsoft
Hi, Travis!
Here are a couple of docs that might help: