Home
%3CP%3E%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%20start%3D%223%22%3E%0A%3CLI%3EDeploy%20Company%20Portal%20to%20devices%20with%20the%20app%20configuration%20policy%20targeted%20to%20desired%20groups.%3C%2FLI%3E%0A%3CLI%3ETell%20end%20users%20to%20sign%20into%20the%20Company%20Portal%20app%20when%20it%20is%20automatically%20installed.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99ll%20keep%20this%20post%20updated%20with%20documentation%20links%20when%20we%20roll%20out%20this%20new%20workflow.%20You%E2%80%99ll%20also%20see%20announcements%20in%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fintune%252Fwhats-new%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176284124%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3Du2xW17or98sGwRXFrpejkylpOwIN8U7W0pnmKkwcfIc%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWhat%E2%80%99s%20New%20in%20Intune%3C%2FA%3E%2C%20the%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fsccm%252Fmdm%252Funderstand%252Fwhats-new-in-hybrid-mobile-device-management%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176294129%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3DKLVB21c4YhpPPEjkjdzlQTQg6ncv4OA%252F7eTQnPFN3S8%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehybrid%20What%E2%80%99s%20New%3C%2FA%3E%20page%20and%20in%20the%20Office%20Message%20Center.%20Let%20us%20know%20if%20you%20have%20any%20questions!%3C%2FP%3E%3CLINGO-SUB%20id%3D%22lingo-sub-357326%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-357326%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F279785%22%20target%3D%22_blank%22%3E%400rku5%3C%2FA%3E%20the%20answer%20to%20question%20%231%20is%20no%2C%20it%20will%20not%20impact%20that%20flow.%20For%20%232%2C%20no%20customization%20required.%20Just%20copy%2Fpaste%20the%20script%20as%20is!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-352431%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-352431%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20currently%20experiencing%20issues%20with%20the%20Profile%20installation%20by%20the%20enrollment.%20I%20troubleshooted%20with%20all%20the%20recommendations%20from%20Microsoft%20but%20so%20far%20it%20doesn't%20work...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20some%20users%20with%20iPhone's%20which%20were%20already%20registered%2C%20after%20the%2012.1.4%20iOS%20update%20lost%20their%20Intune%20Credentials-Connection%20to%20the%20Server%20automatically...%20Can%20you%20please%20help%3F%20Since%20I%20opened%20last%20week%20a%20ticket%20with%20Support%20but%20they%20don't%20answer...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-332176%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-332176%22%20slang%3D%22en-US%22%3E%3CP%3E%3CU%3EQuestion%20%231%3A%3C%2FU%3E%3C%2FP%3E%3CP%3EIntune%20with%20Apple%20DEP%3A%20We%20use%20the%20Company%20Portal%20for%20authentication%2C%20what%20is%20a%20pushed%20to%20the%20devices%20using%20Apple%20VPP.%3C%2FP%3E%3CP%3EThe%20Company%20Portal%20is%20also%20set%20as%20required%20app%2C%20so%20the%20phones%20are%20%22blocked%22%20until%20it%20has%20been%20pushed%20to%20the%20device%20and%20the%20user%20has%20logged%20in.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20wonder%20if%20this%20change%20will%20impact%20us%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20majority%20of%20our%20user%20base%20has%20MFA%20enabled%20and%20setup.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CU%3EQuestion%20%232%3A%3C%2FU%3E%3C%2FP%3E%3CP%3EIs%20this%20a%20general%20script%20or%20does%20it%20need%20to%20be%20customized%20for%20each%20individual%20user%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Edict%26gt%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EIntuneCompanyPortalEnrollmentAfterUDA%3C%2FKEY%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CDICT%3E%3C%2FDICT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EIntuneDeviceId%3C%2FKEY%3E%20-%26gt%3B%20Do%20I%20manually%20need%20to%20key%20in%20the%20device%20ID%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CSTRING%3E%7B%7Bdeviceid%7D%7D%3C%2FSTRING%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EUserId%3C%2FKEY%3E%26nbsp%3B%3CSPAN%3E-%26gt%3B%20Do%20I%20manually%20need%20to%20key%20in%20the%20user%20ID%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CSTRING%3E%7B%7Buserid%7D%7D%3C%2FSTRING%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CP%3E%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20isn't%20the%20case%2C%20because%20we%20have%20over%205000%20users...%3C%2FP%3E%3CLINGO-SUB%20id%3D%22lingo-sub-331363%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-331363%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20the%20update.%20%26nbsp%3BWe%20use%20the%20setup%20assistant%20today%20to%20enroll%20users%2C%20but%20we%20also%20deploy%20the%20company%20portal%20app%20at%20the%20same%20time%20and%20ask%20them%20to%20complete%20the%20enrollment%20in%20the%20Company%20Portal%20app%20for%20CA%20policies.%20%26nbsp%3BWhat%20I%E2%80%99m%20not%20understanding%20is%20the%20point%20of%20the%20XML%20file.%20%26nbsp%3BWould%20we%20need%20to%20do%20this%20to%20all%20our%20existing%20devices%20that%20already%20have%20the%20Company%20Portal%20app%20installed%20if%20these%20used%20the%20OS%20Setup%20Assistant%20for%20the%20initial%20login%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CP%3E%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%20start%3D%223%22%3E%0A%3CLI%3EDeploy%20Company%20Portal%20to%20devices%20with%20the%20app%20configuration%20policy%20targeted%20to%20desired%20groups.%3C%2FLI%3E%0A%3CLI%3ETell%20end%20users%20to%20sign%20into%20the%20Company%20Portal%20app%20when%20it%20is%20automatically%20installed.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99ll%20keep%20this%20post%20updated%20with%20documentation%20links%20when%20we%20roll%20out%20this%20new%20workflow.%20You%E2%80%99ll%20also%20see%20announcements%20in%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fintune%252Fwhats-new%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176284124%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3Du2xW17or98sGwRXFrpejkylpOwIN8U7W0pnmKkwcfIc%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWhat%E2%80%99s%20New%20in%20Intune%3C%2FA%3E%2C%20the%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fsccm%252Fmdm%252Funderstand%252Fwhats-new-in-hybrid-mobile-device-management%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176294129%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3DKLVB21c4YhpPPEjkjdzlQTQg6ncv4OA%252F7eTQnPFN3S8%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehybrid%20What%E2%80%99s%20New%3C%2FA%3E%20page%20and%20in%20the%20Office%20Message%20Center.%20Let%20us%20know%20if%20you%20have%20any%20questions!%3C%2FP%3E%3CP%3E%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%20start%3D%223%22%3E%0A%3CLI%3EDeploy%20Company%20Portal%20to%20devices%20with%20the%20app%20configuration%20policy%20targeted%20to%20desired%20groups.%3C%2FLI%3E%0A%3CLI%3ETell%20end%20users%20to%20sign%20into%20the%20Company%20Portal%20app%20when%20it%20is%20automatically%20installed.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99ll%20keep%20this%20post%20updated%20with%20documentation%20links%20when%20we%20roll%20out%20this%20new%20workflow.%20You%E2%80%99ll%20also%20see%20announcements%20in%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fintune%252Fwhats-new%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176284124%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3Du2xW17or98sGwRXFrpejkylpOwIN8U7W0pnmKkwcfIc%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWhat%E2%80%99s%20New%20in%20Intune%3C%2FA%3E%2C%20the%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fsccm%252Fmdm%252Funderstand%252Fwhats-new-in-hybrid-mobile-device-management%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176294129%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3DKLVB21c4YhpPPEjkjdzlQTQg6ncv4OA%252F7eTQnPFN3S8%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehybrid%20What%E2%80%99s%20New%3C%2FA%3E%20page%20and%20in%20the%20Office%20Message%20Center.%20Let%20us%20know%20if%20you%20have%20any%20questions!%3C%2FP%3E%3CP%3E%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%20start%3D%223%22%3E%0A%3CLI%3EDeploy%20Company%20Portal%20to%20devices%20with%20the%20app%20configuration%20policy%20targeted%20to%20desired%20groups.%3C%2FLI%3E%0A%3CLI%3ETell%20end%20users%20to%20sign%20into%20the%20Company%20Portal%20app%20when%20it%20is%20automatically%20installed.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99ll%20keep%20this%20post%20updated%20with%20documentation%20links%20when%20we%20roll%20out%20this%20new%20workflow.%20You%E2%80%99ll%20also%20see%20announcements%20in%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fintune%252Fwhats-new%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176284124%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3Du2xW17or98sGwRXFrpejkylpOwIN8U7W0pnmKkwcfIc%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWhat%E2%80%99s%20New%20in%20Intune%3C%2FA%3E%2C%20the%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fsccm%252Fmdm%252Funderstand%252Fwhats-new-in-hybrid-mobile-device-management%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176294129%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3DKLVB21c4YhpPPEjkjdzlQTQg6ncv4OA%252F7eTQnPFN3S8%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehybrid%20What%E2%80%99s%20New%3C%2FA%3E%20page%20and%20in%20the%20Office%20Message%20Center.%20Let%20us%20know%20if%20you%20have%20any%20questions!%3C%2FP%3E%3CP%3E%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%20start%3D%223%22%3E%0A%3CLI%3EDeploy%20Company%20Portal%20to%20devices%20with%20the%20app%20configuration%20policy%20targeted%20to%20desired%20groups.%3C%2FLI%3E%0A%3CLI%3ETell%20end%20users%20to%20sign%20into%20the%20Company%20Portal%20app%20when%20it%20is%20automatically%20installed.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99ll%20keep%20this%20post%20updated%20with%20documentation%20links%20when%20we%20roll%20out%20this%20new%20workflow.%20You%E2%80%99ll%20also%20see%20announcements%20in%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fintune%252Fwhats-new%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176284124%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3Du2xW17or98sGwRXFrpejkylpOwIN8U7W0pnmKkwcfIc%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWhat%E2%80%99s%20New%20in%20Intune%3C%2FA%3E%2C%20the%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fsccm%252Fmdm%252Funderstand%252Fwhats-new-in-hybrid-mobile-device-management%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176294129%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3DKLVB21c4YhpPPEjkjdzlQTQg6ncv4OA%252F7eTQnPFN3S8%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehybrid%20What%E2%80%99s%20New%3C%2FA%3E%20page%20and%20in%20the%20Office%20Message%20Center.%20Let%20us%20know%20if%20you%20have%20any%20questions!%3C%2FP%3E%3CP%3E%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%20start%3D%223%22%3E%0A%3CLI%3EDeploy%20Company%20Portal%20to%20devices%20with%20the%20app%20configuration%20policy%20targeted%20to%20desired%20groups.%3C%2FLI%3E%0A%3CLI%3ETell%20end%20users%20to%20sign%20into%20the%20Company%20Portal%20app%20when%20it%20is%20automatically%20installed.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99ll%20keep%20this%20post%20updated%20with%20documentation%20links%20when%20we%20roll%20out%20this%20new%20workflow.%20You%E2%80%99ll%20also%20see%20announcements%20in%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fintune%252Fwhats-new%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176284124%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3Du2xW17or98sGwRXFrpejkylpOwIN8U7W0pnmKkwcfIc%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWhat%E2%80%99s%20New%20in%20Intune%3C%2FA%3E%2C%20the%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fsccm%252Fmdm%252Funderstand%252Fwhats-new-in-hybrid-mobile-device-management%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176294129%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3DKLVB21c4YhpPPEjkjdzlQTQg6ncv4OA%252F7eTQnPFN3S8%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehybrid%20What%E2%80%99s%20New%3C%2FA%3E%20page%20and%20in%20the%20Office%20Message%20Center.%20Let%20us%20know%20if%20you%20have%20any%20questions!%3C%2FP%3E%3CP%3E%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%20start%3D%223%22%3E%0A%3CLI%3EDeploy%20Company%20Portal%20to%20devices%20with%20the%20app%20configuration%20policy%20targeted%20to%20desired%20groups.%3C%2FLI%3E%0A%3CLI%3ETell%20end%20users%20to%20sign%20into%20the%20Company%20Portal%20app%20when%20it%20is%20automatically%20installed.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99ll%20keep%20this%20post%20updated%20with%20documentation%20links%20when%20we%20roll%20out%20this%20new%20workflow.%20You%E2%80%99ll%20also%20see%20announcements%20in%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fintune%252Fwhats-new%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176284124%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3Du2xW17or98sGwRXFrpejkylpOwIN8U7W0pnmKkwcfIc%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWhat%E2%80%99s%20New%20in%20Intune%3C%2FA%3E%2C%20the%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fsccm%252Fmdm%252Funderstand%252Fwhats-new-in-hybrid-mobile-device-management%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176294129%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3DKLVB21c4YhpPPEjkjdzlQTQg6ncv4OA%252F7eTQnPFN3S8%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehybrid%20What%E2%80%99s%20New%3C%2FA%3E%20page%20and%20in%20the%20Office%20Message%20Center.%20Let%20us%20know%20if%20you%20have%20any%20questions!%3C%2FP%3E%3CLINGO-SUB%20id%3D%22lingo-sub-329448%22%20slang%3D%22en-US%22%3EEnrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-329448%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3EUpdate%205%2F17%3A%20This%20change%20has%20now%20been%20rolled%20out%20in%20the%20May%20update%20to%20Intune.%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99re%20implementing%20an%20improved%20workflow%20to%20enroll%20corporate%20iOS%20devices%20with%20user%20affinity%20into%20Intune%2C%20specifically%20when%20these%20devices%20use%20Setup%20Assistant%20for%20authentication.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWith%20this%20change%2C%20we%20aim%20to%20improve%20enrollment%20experience%20and%20give%20end%20users%20a%20shortened%20work%20flow.%20We%E2%80%99ll%20have%20detailed%20documentation%20when%20this%20rolls%20out%2C%20but%20we%20thought%20we%E2%80%99d%20share%20what%E2%80%99s%20coming%20so%20you%20can%20familiarize%20yourself%20with%20the%20experience%20and%20set%20up%20policies%20in%20your%20console%20if%20needed.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%3CU%3EExperience%20for%20enrolling%20new%20devices%3C%2FU%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EWhen%20we%20roll%20this%20change%20out%2C%20if%20you%20enroll%20new%20devices%20authenticating%20with%20Setup%20Assistant%2C%20you%20can%20choose%20whether%20or%20not%20to%20deploy%20the%20Intune%20Company%20Portal%20app%20automatically%20in%20Intune%20not%20Azure%20(not%20available%20in%20hybrid%20MDM).%20We%E2%80%99re%20also%20doing%20away%20with%20%E2%80%9CIdentify%20your%20device%E2%80%9D%20screen%20and%20the%20%E2%80%9CConfirm%20your%20device%E2%80%9D%20screen%2C%20where%20end%20users%20enter%20the%20last%204%20digits%20of%20the%20device%E2%80%99s%20serial%20number%20in%20the%20Company%20Portal%20app.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%3CU%3EExperience%20for%20existing%20enrolled%20devices%20%3C%2FU%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EAfter%20this%20change%20is%20rolled%20out%2C%20if%20you%20want%20to%20enable%20Conditional%20Access%20for%20devices%20already%20enrolled%20via%20Setup%20Assistant%2C%20you%E2%80%99ll%20have%20to%20push%20the%20Company%20Portal%20down%20to%20those%20devices.%20Here%E2%80%99s%20how%20you%20would%20do%20that%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EIn%20the%20%3CSTRONG%3EIntune%20on%20Azure%3C%2FSTRONG%3E%20portal%2C%3CUL%3E%0A%3CLI%3EAdd%20the%20Intune%20Company%20Portal%20if%20necessary%2C%20by%20going%20to%20Intune%20%26gt%3B%20Client%20Apps%20%26gt%3B%20Apps%20%26gt%3B%20Add%3C%2FLI%3E%0A%3CLI%3EGo%20to%20Client%20apps%20%26gt%3B%20App%20configuration%20policies%2C%20to%20create%20an%20app%20configuration%20policy%20for%20the%20Company%20Portal%20app.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3EIf%20you%20use%20%3CSTRONG%3Ehybrid%20Mobile%20Device%20Management%3C%2FSTRONG%3E%20(Hybrid%20MDM)%2C%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ECreate%20a%20new%20app%20policy%20in%20the%20Configuration%20Manager%20console%20for%20the%20Company%20Portal%20app.%3C%2FLI%3E%0A%3CLI%3EGo%20to%20Software%20Library%20%26gt%3B%20Application%20Management%20%26gt%3B%20App%20Configuration%20Policies.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3COL%20start%3D%222%22%3E%0A%3CLI%3ECreate%20an%20app%20configuration%20policy%20with%20the%20xml%20below.%20More%20information%20on%20how%20to%20create%20an%20app%20configuration%20policy%20and%20enter%20xml%20data%20can%20be%20found%20at%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fintune%252Fapp-configuration-policies-use-ios%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176274119%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3D8d9LLasG8E%252FZit94QMLavXEcrWHTcvMuGmAn4DYTQrk%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EAdd%20app%20configuration%20policies%20for%20managed%20iOS%20devices%20%3C%2FA%3Eor%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsccm%2Fmdm%2Fdeploy-use%2Fconfigure-ios-apps-with-app-configuration-policies%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EApply%20settings%20to%20iOS%20apps%20with%20app%20configuration%20policies%20in%20System%20Center%20Configuration%20Manager%3C%2FA%3E%20for%20hybrid%20MDM.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%3CDICT%3E%3C%2FDICT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EIntuneCompanyPortalEnrollmentAfterUDA%3C%2FKEY%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CDICT%3E%3C%2FDICT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EIntuneDeviceId%3C%2FKEY%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CSTRING%3E%7B%7Bdeviceid%7D%7D%3C%2FSTRING%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EUserId%3C%2FKEY%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CSTRING%3E%7B%7Buserid%7D%7D%3C%2FSTRING%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CP%3E%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%20start%3D%223%22%3E%0A%3CLI%3EDeploy%20Company%20Portal%20to%20devices%20with%20the%20app%20configuration%20policy%20targeted%20to%20desired%20groups.%3C%2FLI%3E%0A%3CLI%3ETell%20end%20users%20to%20sign%20into%20the%20Company%20Portal%20app%20when%20it%20is%20automatically%20installed.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99ll%20keep%20this%20post%20updated%20with%20documentation%20links%20when%20we%20roll%20out%20this%20new%20workflow.%20You%E2%80%99ll%20also%20see%20announcements%20in%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fintune%252Fwhats-new%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176284124%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3Du2xW17or98sGwRXFrpejkylpOwIN8U7W0pnmKkwcfIc%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWhat%E2%80%99s%20New%20in%20Intune%3C%2FA%3E%2C%20the%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fsccm%252Fmdm%252Funderstand%252Fwhats-new-in-hybrid-mobile-device-management%26amp%3Bdata%3D04%257C01%257CHimali.Pethe%2540microsoft.com%257C4a7c46e49fe4417875cb08d68713f75a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C636844917176294129%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C-1%26amp%3Bsdata%3DKLVB21c4YhpPPEjkjdzlQTQg6ncv4OA%252F7eTQnPFN3S8%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehybrid%20What%E2%80%99s%20New%3C%2FA%3E%20page%20and%20in%20the%20Office%20Message%20Center.%20Let%20us%20know%20if%20you%20have%20any%20questions!%3C%2FP%3E%3CLINGO-LABS%20id%3D%22lingo-labs-329448%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%20Customer%20Success%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EiOS%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-614901%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-614901%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226779%22%20target%3D%22_blank%22%3E%40Intune%20Support%20Team%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%C2%B4ve%20trouble%20with%20some%20of%20my%20Intune%20Managed%20iOS%20devices.%3C%2FP%3E%3CP%3Eex.%20when%20I%20open%20the%20Microsoft365%20Admin%20app%20I%20get%20%22register%20now%22%20after%20password.%3C%2FP%3E%3CP%3EI%20already%20pushed%20the%20Company%20Portal%20App%20with%20%22Client%20Apps%20-%26gt%3B%20Apps%20-%26gt%3B%20Company%20Portal%20-%26gt%3B%20required%22%20(for%20testing%20just%20for%20my%20account)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20I%20try%20to%20make%20an%20App%20configuration%20policy%20I%20get%20an%20error%20after%20pasting%20the%20xml%20%22Key%20value%20is%20missing%20or%20does%C2%B4t%20match%20data%20type%20tag.%20See%20Intune%20docs%20for%20supported%20data%20types%22.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20suggestions%3F%3C%2FP%3E%3CP%3ERegards%2C%20Philip%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-637971%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-637971%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewe%20have%20the%20same%20problem%20as%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F344867%22%20target%3D%22_blank%22%3E%40Philip_Moritz85%3C%2FA%3E%26nbsp%3B%3A%20%22%3CSPAN%3EWhen%20I%20try%20to%20make%20an%20App%20configuration%20policy%20I%20get%20an%20error%20after%20pasting%20the%20xml%20%22Key%20value%20is%20missing%20or%20does%C2%B4t%20match%20data%20type%20tag.%20See%20Intune%20docs%20for%20supported%20data%20types%22.%22%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20would%20appreciate%20any%20suggestions%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ERegards%2C%20Benedikt%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-638051%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-638051%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226779%22%20target%3D%22_blank%22%3E%40Intune%20Support%20Team%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eone%20of%20our%20customers%20with%20around%203%2C500%20devices%20is%20facing%20this%20issue.%20They%20are%20using%20Apple%20DEP%2C%20Setup%20Assistant%20and%20Conditional%20Access%2C%20so%20we%20configured%20the%20Company%20Portal%20to%20be%20pushed%20in%20DEP%20enrollment%20profile%20and%20tried%20to%20configure%20a%20App%20Configuration%20Policy%20for%20the%20Company%20Portal%20as%20well.%20But%20as%20soon%20as%20we%20paste%20your%20XML%2C%20we%20got%20the%20same%20error%20message%20like%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F344867%22%20target%3D%22_blank%22%3E%40Philip_Moritz85%3C%2FA%3E%26nbsp%3Band%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F347442%22%20target%3D%22_blank%22%3E%40bemo1089%3C%2FA%3E%26nbsp%3B.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20Regards%2C%3C%2FP%3E%3CP%3ENico%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-644408%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-644408%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F344867%22%20target%3D%22_blank%22%3E%40Philip_Moritz85%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F347442%22%20target%3D%22_blank%22%3E%40bemo1089%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F292005%22%20target%3D%22_blank%22%3E%40DaNiggo%3C%2FA%3E%26nbsp%3Bcan%20you%20check%20again%3F%20There%20was%20an%20error%20accepting%20the%20xml%20in%20the%20Intune%20backend%20but%20it's%20now%20been%20fixed.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-649249%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-649249%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226779%22%20target%3D%22_blank%22%3E%40Intune%20Support%20Team%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3EIt%20seems%20to%20work%20-%20the%20xml%20code%20got%20accepted%20now.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20and%20BR%3C%2FP%3E%3CP%3EBenedikt%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-651475%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-651475%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226779%22%20target%3D%22_blank%22%3E%40Intune%20Support%20Team%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20the%20XML%20is%20accepted.%3C%2FP%3E%3CP%3EBut%20there%20is%20an%20Error%20on%20this%20Web%20page%3A%3C%2FP%3E%3CP%3EWhen%20i%20open%20this%20site%20with%20Chrome%20or%20Edge%20Browser%20to%20get%20the%20XML%20i%20get%20this%20one%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CDICT%3E%3C%2FDICT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EIntuneCompanyPortalEnrollmentAfterUDA%3C%2FKEY%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CDICT%3E%3C%2FDICT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EIntuneDeviceId%3C%2FKEY%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CSTRING%3E%3C%2FSTRING%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EUserId%3C%2FKEY%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CSTRING%3E%3C%2FSTRING%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CP%3E%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20i%20use%20Edge%20(DEV%20with%20chromium)%20or%20FireFox%20i%20get%20this%20one%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CDICT%3E%3C%2FDICT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EIntuneCompanyPortalEnrollmentAfterUDA%3C%2FKEY%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CDICT%3E%3C%2FDICT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EIntuneDeviceId%3C%2FKEY%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CSTRONG%3E%3CSTRING%3E%7B%7Bdeviceid%7D%7D%3C%2FSTRING%3E%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CKEY%3EUserId%3C%2FKEY%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3CSTRONG%3E%20%3CSTRING%3E%7B%7Buserid%7D%7D%3C%2FSTRING%3E%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20think%20the%20second%20is%20the%20correct%20one.%3C%2FP%3E%3CP%3ENo%20Adblocker%20active.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%20Philip%3C%2FP%3E%3CLINGO-SUB%20id%3D%22lingo-sub-651502%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-651502%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226779%22%20target%3D%22_blank%22%3E%40Intune%20Support%20Team%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F344867%22%20target%3D%22_blank%22%3E%40Philip_Moritz85%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Einteresting%20-%20I%20haven't%20even%20noticed%20that%20jet%20and%20I%20also%20don't%20see%20the%20difference%20on%20your%20post%20(Using%20Edge%20Dev)%20-%20I%20had%20to%20open%20the%20page%20with%20the%20Internet%20explorer%2011%20to%20see%20the%20difference.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20took%20screenshots%20so%20the%20difference%20should%20be%20visible%20-%20would%20be%20interesting%20to%20know%20which%20version%20we%20should%20use.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOpened%20with%20Edge%20Dev%3A%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-left%22%20style%3D%22width%3A%20484px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F116220i64ACB494721807E4%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22EdgeDev.jpg%22%20title%3D%22EdgeDev.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOpened%20with%20IE%2011%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-left%22%20style%3D%22width%3A%20492px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F116221iA381897B7197EA6F%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22IE11.jpg%22%20title%3D%22IE11.jpg%22%20%2F%3E%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%20and%20BR%3C%2FP%3E%3CP%3EBenedikt%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-652335%22%20slang%3D%22en-US%22%3ERe%3A%20Enrolling%20corporate%20iOS%20devices%20authenticating%20with%20Setup%20Assistant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-652335%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F347442%22%20target%3D%22_blank%22%3E%40bemo1089%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226779%22%20target%3D%22_blank%22%3E%40Intune%20Support%20Team%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20saw%20that%20the%20values%20also%20missing%20in%20my%20post%20above.%3C%2FP%3E%3CP%3Ehere%20is%20a%20screenshot%20from%20my%20post%20when%20i%20click%20%22edit%20comment%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20635px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F116261i797FD6B72A05A445%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%222019-05-28%2016_40_53-Clipboard.png%22%20title%3D%222019-05-28%2016_40_53-Clipboard.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3EPhilip%3C%2FP%3E%3C%2FLINGO-BODY%3E

Update 5/17: This change has now been rolled out in the May update to Intune.

 

We’re implementing an improved workflow to enroll corporate iOS devices with user affinity into Intune, specifically when these devices use Setup Assistant for authentication.

 

With this change, we aim to improve enrollment experience and give end users a shortened work flow. We’ll have detailed documentation when this rolls out, but we thought we’d share what’s coming so you can familiarize yourself with the experience and set up policies in your console if needed.

 

Experience for enrolling new devices

When we roll this change out, if you enroll new devices authenticating with Setup Assistant, you can choose whether or not to deploy the Intune Company Portal app automatically in Intune not Azure (not available in hybrid MDM). We’re also doing away with “Identify your device” screen and the “Confirm your device” screen, where end users enter the last 4 digits of the device’s serial number in the Company Portal app. 

 

Experience for existing enrolled devices

After this change is rolled out, if you want to enable Conditional Access for devices already enrolled via Setup Assistant, you’ll have to push the Company Portal down to those devices. Here’s how you would do that:

 

  1. In the Intune on Azure portal,
    • Add the Intune Company Portal if necessary, by going to Intune > Client Apps > Apps > Add
    • Go to Client apps > App configuration policies, to create an app configuration policy for the Company Portal app.

If you use hybrid Mobile Device Management (Hybrid MDM),

  • Create a new app policy in the Configuration Manager console for the Company Portal app.
  • Go to Software Library > Application Management > App Configuration Policies.
  1. Create an app configuration policy with the xml below. More information on how to create an app configuration policy and enter xml data can be found at Add app configuration policies for managed iOS devices or Apply settings to iOS apps with app configuration policies in System Center Configuration Manager for hybrid MDM.

<dict>

    <key>IntuneCompanyPortalEnrollmentAfterUDA</key>

    <dict>

        <key>IntuneDeviceId</key>

        <string>{{deviceid}}</string>

        <key>UserId</key>

        <string>{{userid}}</string>

    </dict>

</dict>

 

  1. Deploy Company Portal to devices with the app configuration policy targeted to desired groups.
  2. Tell end users to sign into the Company Portal app when it is automatically installed.

 

We’ll keep this post updated with documentation links when we roll out this new workflow. You’ll also see announcements in What’s New in Intune, the hybrid What’s New page and in the Office Message Center. Let us know if you have any questions!

12 Comments
Frequent Visitor

Thanks for the update.  We use the setup assistant today to enroll users, but we also deploy the company portal app at the same time and ask them to complete the enrollment in the Company Portal app for CA policies.  What I’m not understanding is the point of the XML file.  Would we need to do this to all our existing devices that already have the Company Portal app installed if these used the OS Setup Assistant for the initial login?

Occasional Visitor

Question #1:

Intune with Apple DEP: We use the Company Portal for authentication, what is a pushed to the devices using Apple VPP.

The Company Portal is also set as required app, so the phones are "blocked" until it has been pushed to the device and the user has logged in.

 

I wonder if this change will impact us?

 

The majority of our user base has MFA enabled and setup.

 

Question #2:

Is this a general script or does it need to be customized for each individual user?

 

dict>

    <key>IntuneCompanyPortalEnrollmentAfterUDA</key>

    <dict>

        <key>IntuneDeviceId</key> -> Do I manually need to key in the device ID?

        <string>{{deviceid}}</string>

        <key>UserId</key> -> Do I manually need to key in the user ID?

        <string>{{userid}}</string>

    </dict>

</dict>

 

Hope this isn't the case, because we have over 5000 users...

Occasional Visitor

Hi,

 

I am currently experiencing issues with the Profile installation by the enrollment. I troubleshooted with all the recommendations from Microsoft but so far it doesn't work...

 

Also some users with iPhone's which were already registered, after the 12.1.4 iOS update lost their Intune Credentials-Connection to the Server automatically... Can you please help? Since I opened last week a ticket with Support but they don't answer...

@0rku5 the answer to question #1 is no, it will not impact that flow. For #2, no customization required. Just copy/paste the script as is!

Senior Member

@Intune Support Team 

I´ve trouble with some of my Intune Managed iOS devices.

ex. when I open the Microsoft365 Admin app I get "register now" after password.

I already pushed the Company Portal App with "Client Apps -> Apps -> Company Portal -> required" (for testing just for my account)

 

When I try to make an App configuration policy I get an error after pasting the xml "Key value is missing or does´t match data type tag. See Intune docs for supported data types".

 

Any help suggestions?

Regards, Philip

Frequent Visitor

Hi,

 

we have the same problem as @Philip_Moritz85 : "When I try to make an App configuration policy I get an error after pasting the xml "Key value is missing or does´t match data type tag. See Intune docs for supported data types"."

 

I would appreciate any suggestions

Regards, Benedikt

Regular Visitor

Hi @Intune Support Team 

 

one of our customers with around 3,500 devices is facing this issue. They are using Apple DEP, Setup Assistant and Conditional Access, so we configured the Company Portal to be pushed in DEP enrollment profile and tried to configure a App Configuration Policy for the Company Portal as well. But as soon as we paste your XML, we got the same error message like @Philip_Moritz85 and @bemo1089 . 

 

Best Regards,

Nico

@Philip_Moritz85 @bemo1089 @DaNiggo can you check again? There was an error accepting the xml in the Intune backend but it's now been fixed.

Frequent Visitor

@Intune Support Team 
It seems to work - the xml code got accepted now.

 

Thanks and BR

Benedikt

Senior Member

@Intune Support Team 

Now the XML is accepted.

But there is an Error on this Web page:

When i open this site with Chrome or Edge Browser to get the XML i get this one:

 

<dict>

    <key>IntuneCompanyPortalEnrollmentAfterUDA</key>

    <dict>

        <key>IntuneDeviceId</key>

        <string></string>

        <key>UserId</key>

        <string></string>

    </dict>

</dict>

 

When i use Edge (DEV with chromium) or FireFox i get this one:

 

<dict>

    <key>IntuneCompanyPortalEnrollmentAfterUDA</key>

    <dict>

        <key>IntuneDeviceId</key>

        <string>{{deviceid}}</string>

        <key>UserId</key>

        <string>{{userid}}</string>

    </dict>

</dict>

 

I think the second is the correct one.

No Adblocker active.

 

Regards, Philip

Frequent Visitor

@Intune Support Team @Philip_Moritz85 

 

interesting - I haven't even noticed that jet and I also don't see the difference on your post (Using Edge Dev) - I had to open the page with the Internet explorer 11 to see the difference.

I took screenshots so the difference should be visible - would be interesting to know which version we should use.

 

Opened with Edge Dev:                                                                                 

EdgeDev.jpg

 

 

 

 

 

 

 

 

 

 

 

 

Opened with IE 11

IE11.jpg










Thanks and BR

Benedikt

Senior Member

@bemo1089 @Intune Support Team 

Just saw that the values also missing in my post above.

here is a screenshot from my post when i click "edit comment"

 

2019-05-28 16_40_53-Clipboard.png

 

Regards,

Philip