Microsoft Technical Takeoff: Windows and Microsoft Intune
Oct 24 2022 07:00 AM - Oct 27 2022 12:00 PM (PDT)
Upcoming changes to iOS/iPadOS Company Portal app deployment for Setup Assistant with modern auth
Published Sep 14 2022 03:35 PM 8,116 Views

Based on customer feedback, we're planning to remove automatic deployment of the iOS/iPadOS Company Portal app as a required app for Automated Device Enrollment (ADE) Setup Assistant with modern authentication enrollment profiles. This will occur in two phases. The first phase will remove the automatic deployment from new profiles and introduce a new configuration option for existing profiles to stop the automatic deployment. The second phase will remove automatic deployment from existing profiles. We'll keep you updated on the expected timeline and any additional information for the change in this post.

 

Existing ADE profiles with Setup Assistant with modern authentication

To prepare for this change, we will be adding a new option for all existing ADE Setup Assistant with modern authentication enrollment profiles that will allow you to stop the automatic deployment of the iOS/iPadOS Company Portal as a required app from the enrollment profile. The new option will be available in the “Install Company Portal with VPP” drop-down menu. Stay tuned to In development and What’s new in Intune for the release.

 

If you have existing ADE profiles with Setup Assistant with modern authentication, enable the new drop-down configuration to stop the automatic deployment of the Company Portal app once it’s available. After updating the configuration of the setting, use an app configuration policy and app targeting to push the Company Portal app as an available or required Volume Purchase Program (VPP) app. VPP is not required but is recommended. A few months after the new drop-down is released, we will be removing the automatic deployment of the Company Portal app from the modern authentication enrollment profile regardless of the VPP setting configuration.

 

After updating your existing profile, complete the following steps:

  1. Create an app configuration policy, specifically sending the app configuration XML file called “Use the Company Portal on an Automated Device Enrollment (ADE) device enrolled with user affinity” see Add app configuration policies for managed iOS/iPadOS devices for instructions.
  2. Deploy the Company Portal app to the device, there are two options for this
    1. (Recommended) Set up VPP for iOS/iPadOS and assign the Company Portal app as required. For instructions see How to manage iOS and macOS apps purchased through Apple Business Manager with Microsoft Intune. You're highly encouraged to set “Automatic app updates” to Yes.
    2. Add the Company Portal to Intune, see Add apps to Microsoft Intune and then assign the app as required by following these instructions: Assign apps to groups with Microsoft Intune.

The correct app configuration policy must be assigned to the devices regardless of whether VPP is configured for the Company Portal. The Company Portal is required on the device.

 

Note: Later, we'll remove the automatic deployment of the Company Portal app from the modern authentication enrollment profile regardless of the “Install Company Portal with VPP” setting configuration. However, you'll continue to see the setting in the enrollment profile. No changes are needed if you’ve already taken the steps above.

 

New ADE profiles with Setup Assistant with modern authentication

Once automatic deployment of the Company Portal app has been removed, you'll no longer see the “Install Company Portal with VPP” setting when creating new ADE profiles. You'll need to use an app configuration policy and app targeting to deliver the Company Portal app. Here’s what to do:

  1. Create an app configuration policy, specifically sending the app configuration XML file called “Use the Company Portal on an Automated Device Enrollment (ADE) device enrolled with user affinity” see Add app configuration policies for managed iOS/iPadOS devices for instructions.
  2. Deploy the Company Portal app to the device as a required app, there are two options for this:
    1. (Recommended) Set up VPP for iOS/iPadOS and assign the Company Portal app. For instructions see How to manage iOS and macOS apps purchased through Apple Business Manager with Microsoft Intune. You're highly encouraged to set “Automatic app updates” to Yes.
    2. Add the Company Portal to Intune, see Add apps to Microsoft Intune and then assign the app as required by following these instructions: Assign apps to groups with Microsoft Intune.

The correct app configuration policy must be assigned to the devices regardless of VPP being configured for the Company Portal or not.

 

We’ll continue to update this post with additional details, as needed, including when the new drop-down option becomes available and expected timelines for this change. More documentation will be available once the new option has been released. If you have any questions, please comment below or reach out to us on Twitter @IntuneSuppTeam.

16 Comments
Version history
Last update:
‎Sep 14 2022 03:35 PM
Updated by: