User Enrollment
2 TopicsIntune - Issues with Account-Driven User Enrollment Issues on iOS 18.5
Hello everyone, Since the release of iOS 18, Apple has deprecated profile-based user enrollment via the Company Portal app, requiring the use of Account-Driven User Enrollment. While this change enhances user experience, I'm encountering challenges in implementing it. Steps Taken: Apple Business Manager (ABM) Account: Created and linked the ABM account to Intune using the token. Corporate devices are successfully appearing in Intune. MDM Server Configuration: Set Intune as the default MDM server for all devices in ABM. Domain Federation: Established Entra ID federation in ABM to synchronize all users. Intune Enrollment Profile: Created an 'Enrollment Type Profile' of type 'Account-Driven User Enrollment.' MDM Push Certificate: Configured and validated the MDM Push certificate. Issue Encountered: According to https://support.apple.com/guide/deployment/account-driven-enrollment-methods-dep4d9e9cd26/web, starting with iOS 18.2, hosting a service discovery file on a web server is no longer mandatory. The device should automatically contact the ABM organization associated with the Managed Apple ID if no web server is found. On an iOS 18.5 device, I navigate to: Settings > General > VPN & Device Management > Sign in to Work or School Account After entering my Microsoft email address (which matches my Managed Apple ID due to federation), I consistently receive the error: "Your Apple ID does not support the expected services on this device." In ABM, under "Access Management" > "Apple Services," all services are activated. Could I be missing a crucial step in the configuration? Any guidance or insights would be greatly appreciated. Thank you in advance for your help. Best regards,751Views1like7CommentsVPP Licensing Issues
Hi there, i'm currently getting frustrated on the following problem: At first the outline: We want users to choose: Do you want to use a personal device? If so you can enroll in MDM with type "User Enrollment". If the user "qualifies" to receive a corporate iOS device, we're using Automated Device Enrollment via ABM No on to the issue: App Assignment for the App MS Teams Required: All devices, with an include filter (All ADE Devices), Device based licensing Idea: this should only happen when using corporate devices Available: All Users, with an exclude filter (All ADE devices), User based licensing Idea: All devices which are not corporate should apply this one. App Assignment for the App MS Whiteboard No Required Assignment Available: All Users, with an exclude filter (All ADE devices), User based licensing Idea: All devices which are not corporate should apply this one. Azure AD Security Group with all Users using corporate ios devices, Device based licensing Idea: All devices which ARE corporate should apply this one. What is the result? The Whiteboard App is working perfectly: When using an ADE device, the device bases license is used. (therefore a silent installation happens, after the user choose "Install app" from Company Portal.) When using an User Enrolled device, the user based license is used. Great! As soon as an App has additionally a required assignment, the whole thing brokes up: When the user on the user enrolled devices tries to install the app from company portal, nothing happens. Intune shows the total misleading error: "Device VPP licensing is only applicable for iOS 9.0+ devices. (0x87D13B69)" The device is way above 9.0 AND the device shouldn't use device licensing. (Of course User Enrollment doesn't support device licensing) I'm totally aware of the fact, that we have to use "user based licensing" for User Enrolled devices AND we have to use Device Based licensing when using ADE and want to install silently or the user don´'t has an apple-id. How can we achive this scenario? We totally don't want to have to choose between either ADE or User Enrollment. Any help, as always is highly appreciated. 🙂 Cheers, Patrick!Solved17KViews1like21Comments