By Marc Nahum - Sr. Program Manager | Microsoft Intune
Updated 02/27/2023: This article has been updated to include the additional enrollment option using an iPhone for iOS/iPadOS and macOS.
Any enterprise or education institution that owns iOS/iPadOS devices can take advantage of automatic enrollment to Intune, as well as the extra features and controls that Apple’s Automated Device Enrollment (ADE) - previously known as Device Enrollment Program (DEP) – provides.
When ADE was first introduced, only Apple resellers and telecom carriers were able to add devices to Apple Business Manager or Apple School Manager. However, since the release of iOS 11, Apple supports the ability to manually add iOS and iPadOS devices yourself with the Apple Configurator 2.5 (AC2) tool. This means that, regardless of where the device was purchased, you can benefit from using ABM or ASM.
This article helps IT pros and mobile device administrators understand the steps required to manually add iOS and iPadOS devices to Apple Business Manager (ABM) or Apple School Manager (ASM), as well as enrolling them into the Intune service.
Warning: The devices are fully wiped during the enrollment process. Apple treats devices being added to ABM/ASM as proprietary to the account and requires all previous settings to be reset.
There are two options for adding an iOS/iPadOS or Mac device to ABM/ASM—either with an iPhone or with a Mac. Regardless of which method you use, once the new device is added, you must assign the devices to Intune.
The Apple Configurator for iOS is available with iOS/iPadOS 15 and macOS Monterey (macOS 12). This feature allows admin to enroll an iOS device running iOS 16 or later or a Mac with the T2 Security Chip or Apple silicon running macOS Monterey or later to an ABM/ASM with an iPhone, without needing to have a Mac onsite. This is especially helpful in eliminating the need to have resellers add devices to your ABM/ASM account as you are able to do so yourself from an iPhone.
Start the configurator application on the iPhone and log in with your ABM/ASM Apple ID.
By default, the device you import will automatically use the same network as the iPhone you’re using to set it up with is connected to. However, you can also use a configuration profile imported from the settings.
Note: Wireless networks using certificates are not supported. Be sure to use a password-protected network.
To import the new device into your ABM/ASM, you must have it within proximity of the iPhone being used to complete the setup. The iPhone will display setup prompts for the device being added.
Follow the steps outlined in the Apple Configurator User Guide to complete the setup process.
Once the device has been added to your ABM/ASM, assign the device to Intune. See the Assign the device in the Intune admin center section in this document.
Using a Mac to add Apple devices includes several steps.
There are a lot of options in AC2, so we’ll cover only the steps necessary to import the devices to ABM or ASM and assign them to the Intune MDM server. See the Apple Configurator 2 User Guide for more information.
During the onboarding process, the device will need to connect to the internet. Therefore, it’s mandatory to have a Wi-Fi profile, which will allow it to automatically connect. The profile can be as complex as is required, but must not prompt the user for any action, or require a certificate to authenticate.
Screenshot of a Wi-Fi profile and configured settings in Apple Configurator 2.
Note: This step is not mandatory, but it will create a trusted configuration and avoid any doubts that the URL is the proper one.
Screenshot of the Apple Configurator - Default Enrollment Profile in the Microsoft Intune admin center.
Important: The device will be fully wiped during this process.
If this is the first time you’re connecting the device to the Mac, a pop up will appear asking for the Mac to be trusted. Select Trust.
Do not select:
Name: “Microsoft Intune”
URL: The one created in the step, “Generate MDM Server URL for Intune”
Example URL: https://appleconfigurator2.manage.microsoft.com/MDMServiceConfig?id=<Intune_tenant_ID>&AADTenantId=<AAD_tenant_ID>
If you didn’t up the organization name, you’ll need to do that next. That Organization name will be displayed on the device.
The iOS setup assistant steps selected on the next screen are not important as they will be defined in Intune later.
At this point, the device will be erased. When the device restarts, steps in AC2 are complete.
You now need to assign it to Intune in the ABM/ASM console.
You can multi select your devices with the “Shift” key and select “Edit MDM Server”.
Once the device is assigned it will need to be synchronized. This occurs automatically every 12 hours, or you can manually trigger the synchronization in the Microsoft Intune admin center:
Note: You can manually synchronize the devices from ABM/ASM to Intune at a maximum frequency of every 15 minutes.
At this point you should have successfully added your ADE device to Intune.
Let us know if you have any questions by replying to this post or reaching out to @IntuneSuppTeam on Twitter.
Post updates:
02/27/23: This article has been updated to include the additional enrollment option using an iPhone for iOS/iPadOS and macOS.
04/03/23: updated post with an updated post link.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.