question

tarouchabi-7271 avatar image
0 Votes"
tarouchabi-7271 asked Crystal-MSFT commented

About User Enrollment (preview) of Intune.

What is the difference between registration with "User Enrollment" and registration with "intune portal app"?
When do I have to use "User Enrollment"?
Is it mandatory to use AMB to use "User Enrollment"?

mem-intune-enrollment
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

Crystal-MSFT avatar image
0 Votes"
Crystal-MSFT answered Crystal-MSFT commented

@tarouchabi-7271Thanks for posting in our Q&A. From your description, It seems we have some questions about user enrollment for BYOD.

In General, users can enroll their personal devices for Intune management, know as "bring your own device" or BYOD. There are three options for enrolling users:

  • App Protection Policies give you the lightest BYOD experience, providing management at an app level only. However, if you want to also secure the device with a 6-digit complex PIN, you can use these policies along with User Enrollment.

  • Device Enrollment is what you may think of as typical BYOD enrollment. It provides admins with a wide range of management options.

  • User Enrollment is a more streamlined enrollment process that provides admins with a subset of device management options. This feature is currently in preview.

https://docs.microsoft.com/en-us/mem/intune/enrollment/ios-enroll#user-owned-iosipados-and-ipados-devices-byod

User Enrollment is created and designed by Apple to facilitate an enrollment and management scenario for Bring Your Own Devices (BYOD). That enrollment and management scenario requires Managed Apple IDs. Managed Apple IDs are a type of Apple ID that is available for use through Apple Business Manager and Apple School Manager. They are owned and managed by your organization. Those Managed Apple IDs are used to create an additional user identity on the device and can live perfectly alongside personal Apple IDs.

We can check if we have managed apple ID for our organization. If yes, we can try user enrollment with the steps as below:
https://www.petervanderwoude.nl/post/getting-started-with-user-enrollment-for-ios-ipados-devices/
Note: non-Microsoft link, just for the reference

However, if there’s no managed apple ID, we can consider the device enrollment method for BYOD instead.

Hope it can help


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


· 4
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks alot.
How is it different from registering with an Enrollment Program token (registering via Apple Business Manager)?

0 Votes 0 ·

@tarouchabi-7271, Thanks for the reply. Add Enrollment Program token is one step in ADE enrollment. In General, ADE is for the iOS/iPadOS devices through Apple's Automated Device Enrollment (ADE). Automated Device Enrollment lets you enroll large numbers of devices without ever touching them. Devices like iPhones, iPads, and MacBooks can be shipped directly to users. When a user turns on the device, Setup Assistant, which includes the typical out-of-box-experience for Apple products, runs with preconfigured settings and the device enrolls into management. We can see more details in the following link:
https://docs.microsoft.com/en-us/mem/intune/enrollment/device-enrollment-program-enroll-ios

Hope it can help

0 Votes 0 ·

Thank you very much. I understood. Thanks alot.

0 Votes 0 ·
Show more comments