Blog Post

Intune Customer Success
4 MIN READ

Understanding Apple enrollment methods in Microsoft Intune

Intune_Support_Team's avatar
Intune_Support_Team
Silver Contributor
Jul 18, 2025

By: Rishita Sarin – Product Manager | Microsoft Intune

 

Microsoft Intune, together with Microsoft Entra ID, facilitates a secure, streamlined process for registering and enrolling devices to access your organization’s resources. Once users and devices are registered within your Microsoft Entra ID (also called a tenant), then you can utilize Intune for its endpoint management capabilities. The process that enables device management for a device is called device enrollment.

 

During enrollment, Intune installs a mobile device management (MDM) certificate on the enrolling device. The MDM certificate communicates with the Intune service, and enables Intune to start enforcing your organization's policies, like:

  • Enrollment policies that limit the number or type of devices someone can enroll.
  • Compliance policies that help users and devices meet your organization’s requirements.
  • Configuration profiles that configure work-appropriate features and settings on devices.

 

This blog aims to provide an overview of Microsoft Intune’s enrollment methods for Apple devices to help you make informed decisions about device management.

 

Enrollment methods

Personal owned devices (BYOD)

To get started with enrolling personally owned devices navigate to the Intune admin center, Devices > Enrollment > Apple > Enrollment types > Create.

 

 

Apple’s name since 2019

Intune’s name

When to use it

Profile-based Device Enrollment (Previously known as User Enrollment)

 

Device enrollment with Company Portal

  • Secures entire personal device.
  • Supports app takeover.

Web enrollment

  • Secures entire personal device.
  • Supports app takeover.
  • We recommend enabling web-based enrollment for devices running iOS/iPadOS 15 and later because it doesn't require employees and students to install the Company Portal app. Post-enrollment functionality remains the same as with app-based enrollment.

Profile-based User Enrollment

(Support ended in 2024)

User enrollment with Company Portal

(Support ended in 2024)

Do not use this

(Support ended in 2024)

Account-driven User Enrollment

Account-driven user enrollment

  • Secures only work-related apps on a personal device.
  • No support for app takeover.

Account-driven Device Enrollment

Not supported

Not supported

N/A

Determine based on user choice

Gives users the option to select if they want to secure their entire device or only work-related apps.

 

Corporate owned devices

Devices Enrollment Apple Enrollment program tokens > select a token > Enrollment policies > Create

 

 

Apple’s name since 2019

Intune’s name

When to use it

Automated Device Enrollment (ADE) (Previously known as Device Enrollment Program (DEP))

Automated Device Enrollment (ADE) for iOS/iPadOS

Automated Device Enrollment (ADE) for macOS

  • Secures entire corporate device.

  • Enroll with User Affinity: Select this option for devices that belong to users who want to use the Company Portal for services like installing apps.

  • Enroll without User Affinity: Select this option for devices that aren't affiliated with a single user. Use this option for devices that don't access local user data. This option is typically used for kiosk, point of sale (POS), or shared-utility devices.

  • Enroll with Microsoft Entra ID shared mode (only iOS/iPadOS): Select this option to enroll devices that will be in shared mode.

 

💡 Tip: If you’re enrolling Apple devices for frontline worker scenarios, make sure to check out this detailed guide: Get started with iOS/iPadOS frontline worker devices.

 

Improvements

Based on customer feedback, Intune introduced a faster and more intuitive version of device enrollment with the Intune Company Portal called web enrollment in 2023. Web enrollment retains all the benefits of device enrollment with added benefits of reduced latency and without requiring installation of the Company Portal app. We strongly encourage you to take advantage of web enrollment for a faster and more efficient enrollment process for your users.

 

Additionally, turning on just-in-time (JIT) registration and compliance remediation (automatically set up as part of JIT registration setup) for all iOS/iPadOS enrollments can significantly improve the registration and compliance remediation experience. By bringing the enrollment experience to where the user is, we help them get productive faster and ensure a smoother transition.

 

This applies to both iOS/iPadOS bring-your-own-device (BYOD) web enrollment and corporate Automated Device Enrollment (ADE), specifically for Setup Assistant with modern authentication within ADE. For more information on JIT registration and compliance remediation, check out this blog post: Use JIT registration and JIT compliance remediation for all your iOS/iPadOS enrollments.

 

As a result of recent enhancements to our enrollment workflows, the Company Portal app is no longer required for some enrollment methods. However, we recognize the use cases for the Company Portal go beyond enrollment, and we’ll continue to support and invest in improvements for the app.

 

One example of upcoming improvements to the Company Portal is the addition of the user-less app catalog. This enhancement opens the doors for future frontline worker (FLW) scenarios, allowing for more flexible and efficient device management without the need for user-specific configurations. Stay tuned to What’s new in Intune for the release and more!

 

If you have any questions or want to share how you’re using Apple enrollment across your organization in Intune, leave a comment below or reach out to us on X @IntuneSuppTeam or @MSIntune. You can also connect with us on LinkedIn: aka.ms/IntuneLinked.

Updated Jul 21, 2025
Version 2.0

6 Comments

  • mdmworkprofile's avatar
    mdmworkprofile
    Copper Contributor

    We are particularly interested in the concept of a "User-less App Catalog" for Kiosk devices, which would allow Frontline Workers to directly download the required apps. Currently, we need to create separate App Groups and assignments for each department’s requirements. With User-less App Catalog approach, users could easily access and install the necessary apps without additional configuration overhead.

  • Serendipity96's avatar
    Serendipity96
    Copper Contributor

    Can we PLEASE make it possible to assign multiple devices at once to a single profile? It is absolutely painstaking to have to assign each device one by one to an enrollment profile.

    • Intune_Support_Team's avatar
      Intune_Support_Team
      Silver Contributor

      Hi Serendipity96​ 

       

      Great suggestion, and we understand the frustration.

       

      Microsoft Intune is introducing a new ADE Enrollment Policy Experience (ECv2) UI for iOS/iPadOS. This revamped experience will allow you to:

      - Select multiple devices at once

      - Assign them to a single enrollment policy using multi-select UI

      This future update will significantly reduce the time and effort required to manage device enrollment. It is expected to be released in Q4 CY25 and, you can read more about it here: New iOS/iPadOS ADE enrollment policies experience | Microsoft Community Hub

       

      In the meantime, making use of the default profile feature may help to assign to all new devices syncing over from Apple Business Manager (ABM) or Apple School Manager (ASM) via ADE, whilst keeping an eye out for the new multi-device enrollment UI for an even smoother workflow coming soon.

       

      Thanks! 

      Intune Support Team

      • Serendipity96's avatar
        Serendipity96
        Copper Contributor

        That's great, and a welcome change. We already have default profiles set - but that's the point of frustration. Not everything needs to be set to the default profile. If I have devices I want to set up as shared devices, and it's a batch of 15, then I have to set them one by one to that profile. That's where the frustration comes from. This is time consuming as a whole.