Hi @sybylla,
This happens because Google no longer permits Google sign-in inside certain native web views. During Apple Automated Device Enrollment on iPhone, the enrollment screen is launched by the operating system before a full browser session is available. Google identifies this native iPhone web view as a disallowed user agent and blocks the sign-in attempt with 403: disallowed_useragent.
For iPhones, Google authentication cannot be completed during the ADE setup flow in this context. The practical approach is to enroll iPhones without Google authentication and then associate users after enrollment.
If you are using automated ABM assignment and do not want to disable Google authentication for all Apple devices, use a separate ADE/MDM server configuration for iPhones:
- In Apple Business, create a new MDM server for iPhones.
- Configure Default Device Assignment to the created MDM server, so iPhones are assigned to this new MDM server.
- Integrate that new MDM server as a separate ADE account in Hexnode.
- In Hexnode, create or use an ADE enrollment profile with Authentication set to No Authentication.
- Set that No Authentication profile as the default configuration profile for the new iPhone-specific ADE account.
This lets iPhones enroll successfully without Google sign-in, while Macs and iPads can remain assigned to the existing ADE account that uses Google authentication.
Regards,
Sienna Carter
Hexnode UEM