Home

IOS Device Management via Intune - DEP + Apple Managed ID vs Company Portal deployment?

%3CLINGO-SUB%20id%3D%22lingo-sub-206764%22%20slang%3D%22en-US%22%3EIOS%20Device%20Management%20via%20Intune%20-%20DEP%20%2B%20Apple%20Managed%20ID%20vs%20Company%20Portal%20deployment%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-206764%22%20slang%3D%22en-US%22%3E%3CP%3EAlmost%202%20years%20ago%20I%20posted%20a%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fsocial.technet.microsoft.com%2FForums%2Fen-US%2Fb49069d3-7d05-4a73-b452-df10aee7f71c%2Fintune-ios-management-thoughts-questions-oobe-and-managed-apple-id%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ethread%20about%20dealing%20with%20Apple%20Managed%20ID%20on%20DEP%20controlled%20devices%20via%20Intune%3C%2FA%3E.%20There%20weren't%20any%20really%20good%20answers%20to%20those%20questions%20then.%20I%20am%20re-visiting%20it%20now%20and%20it%20seems%20it%20still%20is%20a%20problem.%20Apple%20recommends%20Managed%20IDs%20for%20schools%20via%20their%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fschool.apple.com%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Eschool.apple.com%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Esite.%20These%20accounts%20have%20some%20really%20nice%20features%20for%20students%20and%20teachers%20like%20200%20GB%20of%20iCloud%20for%20free%20and%20managed%20app%20purchasing.%20The%20managed%20app%20purchasing%20relies%20upon%20a%20MDM%20to%20manage%20it.%20Intune%20is%20a%20MDM%20that%20supports%20IOS%20devices%2C%20however%20very%20poorly.%20One%20of%20the%20(intended)%20drawbacks%20of%20managed%20ids%20is%20that%20they%20don't%20have%20permissions%20to%20install%20apps%20via%20the%20store%2C%20rather%20the%20MDM%20is%20supposed%20to%20push%20to%20device.%20The%20problem%20is%20Intune%20relies%20upon%20the%20Company%20Portal%20app%20for%20enrollment%20in%20MDM.%20If%20you%20are%20using%20a%20managed%20ID%20you%20can't%20install%20the%20app.%20You%20get%20stuck%20in%20a%20loop%20and%20have%20a%20useless%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20found%20that%20if%20I%20choose%20to%20authenticate%20with%20Apple%20Setup%20Assistant%20rather%20than%20Company%20Portal%20it%20appears%20to%20do%20some%20device%20level%20install%20rather%20than%20user%20since%20the%20apps%20get%20installed.%20However%20if%20you%20do%20this%20you%20can't%20use%20a%20MFA%20account%20since%20it%20isn't%20supported.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAm%20I%20missing%20something%20or%20is%20this%20still%20the%20best%20Intune%20has%20to%20offer%20for%20IOS%20device%20management%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-206764%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-207122%22%20slang%3D%22en-US%22%3ERe%3A%20IOS%20Device%20Management%20via%20Intune%20-%20DEP%20%2B%20Apple%20Managed%20ID%20vs%20Company%20Portal%20deployment%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-207122%22%20slang%3D%22en-US%22%3E%3CP%3EFor%20device%20licensing%20you%20still%20need%20to%20login%20and%20enroll%20device.%20The%20only%20two%20ways%20I%20know%20to%20do%20this%20is%20during%20setup%20of%20IOS%20device%20via%20remote%20management%20(this%20method%20doesn't%20support%20MFA%20accounts)%20or%20via%20the%20Company%20Portal%20app.%20One%20will%20work%20with%20Managed%20ID%20but%20not%20MFA%20accounts%2C%20the%20other%20will%20work%20with%20MFA%20but%20not%20managed%20ID.%20No%20way%20to%20have%20both.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-206904%22%20slang%3D%22en-US%22%3ERe%3A%20IOS%20Device%20Management%20via%20Intune%20-%20DEP%20%2B%20Apple%20Managed%20ID%20vs%20Company%20Portal%20deployment%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-206904%22%20slang%3D%22en-US%22%3EHey%2C%3CBR%20%2F%3E%3CBR%20%2F%3ENot%20sure%20about%20Apple%20Managed%20ID%2C%20but%20to%20install%20apps%20by%20Intune%20you%20can%20use%20user%20license%20or%20device%20license.%20In%20last%20case%20user%20won't%20be%20asked%20for%20Apple%20ID%20or%20anything.%3CBR%20%2F%3ETo%20enable%20that%20you%20need%20to%20use%20VPP%20and%20set%20device%20license%20type%20in%20deployment.%3C%2FLINGO-BODY%3E
Brian Hoyt
Contributor

Almost 2 years ago I posted a thread about dealing with Apple Managed ID on DEP controlled devices via Intune. There weren't any really good answers to those questions then. I am re-visiting it now and it seems it still is a problem. Apple recommends Managed IDs for schools via their school.apple.com site. These accounts have some really nice features for students and teachers like 200 GB of iCloud for free and managed app purchasing. The managed app purchasing relies upon a MDM to manage it. Intune is a MDM that supports IOS devices, however very poorly. One of the (intended) drawbacks of managed ids is that they don't have permissions to install apps via the store, rather the MDM is supposed to push to device. The problem is Intune relies upon the Company Portal app for enrollment in MDM. If you are using a managed ID you can't install the app. You get stuck in a loop and have a useless device.

 

I have found that if I choose to authenticate with Apple Setup Assistant rather than Company Portal it appears to do some device level install rather than user since the apps get installed. However if you do this you can't use a MFA account since it isn't supported.

 

Am I missing something or is this still the best Intune has to offer for IOS device management?

2 Replies
Hey,

Not sure about Apple Managed ID, but to install apps by Intune you can use user license or device license. In last case user won't be asked for Apple ID or anything.
To enable that you need to use VPP and set device license type in deployment.

For device licensing you still need to login and enroll device. The only two ways I know to do this is during setup of IOS device via remote management (this method doesn't support MFA accounts) or via the Company Portal app. One will work with Managed ID but not MFA accounts, the other will work with MFA but not managed ID. No way to have both.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
38 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies