# Apple User Enrollment for iOS devices

**Apple User Enrollment** is a specialized enrollment method designed specifically for **Bring Your Own Device (BYOD)** deployments. It strikes a critical balance between enterprise security and user privacy, making it the ideal choice for organizations where employees use their personal devices for work.

Unlike traditional enrollment methods that grant a Mobile Device Management (MDM) server broad control over the entire hardware, User Enrollment creates a distinct separation between personal and corporate data.

### How it Works: Data Separation and Identity

- **Managed Apple Account:** The core of User Enrollment is the **Managed Apple Account** created and owned by the organization via Apple Business, this identity co-exists with the user’s personal Apple Account without ever merging or interacting.
- **Cryptographic Partitioning:** Once the enrollment profile is installed, the device creates separate encryption keys to protect organizational data. This managed data is stored in a separate volume on the device.
- **Secure Disenrollment:** If a device is disenrolled, these specific encryption keys are destroyed, instantly wiping all corporate data and apps while leaving the user’s personal photos, messages, and apps completely untouched.

1. Technical Prerequisites
--------------------------

Before initiating enrollment, the following configurations must be active:

- **APNs Certificate:** [Configured](https://www.hexnode.com/mobile-device-management/help/apns-settings/) in the Hexnode UEM portal.
- **Apple Business:** Organization must be enrolled in Apple Business.
- **Managed Apple Account:** Created in Apple Business for all end-users.
- **Device Specs:** Unsupervised devices running iOS 13.0+ or iPadOS 13.1+.
- **Safari Settings:** Safari must be in **Mobile View**. If in Desktop Site View, the system will default to “Device Enrollment” instead of “User Enrollment.”

2. Hexnode Portal Configuration
-------------------------------

1. **Navigation:** Go to **Enroll > Platform – Specific > iOS > Email or SMS**.
2. **Authentication:** Set Mode to **Authenticated Enrollment**.
3. **Ownership:** Set Ownership to **Personal**.
4. **Enrollment Type:** Select **User Enrollment** (Avoid selecting “Device Enrollment”).
5. **Dispatch:** Configure request details and click **Send**.

3. On-Device Enrollment Process (User Actions)
----------------------------------------------

### Case A: Ownership is set to “Personal”

1. Open **Safari** and enter the Enrollment URL (e.g., https://portalname.hexnodemdm.com/enroll/).
2. Agree to the Terms and Conditions and click **Enroll**.
3. Enter the **Managed Apple Account** and click **Download Profile**.

### Case B: Ownership is set to “Let the user choose”

1. Follow steps 1-2 above.
2. Enter Username/Password and select **I own this device** (Selecting “My organization owns this device” triggers standard Device Enrollment).
3. Choose **Manage only work-related data and apps**.
4. Enter the **Managed Apple Account** and click **Download Profile**.

### Finalizing Installation (All Cases)

1. Open **Settings** and tap **Enrol in Hexnode UEM**.
2. Tap **Enrol My iPhone**.
3. Enter the password for the **Managed Apple Account**.
4. Verify success: Go to **Settings > General > VPN & Device Managemen**t to view the “Hexnode UEM” profile.

[![With User Enrollment on iOS devices, users can view the amount of iCloud storage space provided by their organization](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2024/07/Organization-provided-iCloud-storage-displayed-in-User-Enrollment-on-iOS-devices.png "Organization-provided iCloud storage displayed in User Enrollment on iOS devices")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2024/07/Organization-provided-iCloud-storage-displayed-in-User-Enrollment-on-iOS-devices.png)

4. Post-Enrollment: App Management (VPP)
----------------------------------------

To enable advanced management via the Hexnode UEM agent:

1. Link a [VPP account](https://www.hexnode.com/mobile-device-management/help/how-to-deploy-apple-vpp-apps-with-hexnode-mdm/) to the Hexnode portal.
2. [Purchase licenses in Apple Business](https://www.hexnode.com/mobile-device-management/help/how-to-install-ios-apps-without-itunes-account/) and deploy the app to devices.
3. Automatic Deployment: If the Managed Apple Account exists in the VPP account, deployment initiates automatically.
4. Manual Deployment: Admins can use the [Install Application](https://www.hexnode.com/mobile-device-management/help/apple-uem-app-distribution/#) action or [Required Apps](https://www.hexnode.com/mobile-device-management/help/apple-uem-app-distribution/#) policy.
5. User Consent: Users must click **Install** on the device prompt to complete the process.

### Managed Apple Account Authentication and Data Separation: 

When a user is signed in with both a personal Apple Account and a Managed Apple Account, “Sign in with Apple” will default to using the Managed Apple Account for managed apps and the personal Apple Account for unmanaged apps. During the sign-in process via Safari or SafariWebView within a managed app, the user can opt to enter their Managed Apple Account to associate the sign-in with their work account. Furthermore, users will be able to access personal iCloud Drive files separately from their organization’s iCloud Drive files within the Files app.

[![With User Enrollment on iOS devices, iCloud Drive will appear separately for personal and organizational data in the Files app](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2024/07/Two-separate-iCloud-Drives-in-User-Enrollment-on-iOS-devices.png "Two separate iCloud Drives in User Enrollment on iOS devices")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2024/07/Two-separate-iCloud-Drives-in-User-Enrollment-on-iOS-devices.png)

5. MDM Functionality & Privacy Boundaries
---------------------------------------------

### Data Separation Features

- **Managed Apple Account:** Defaults for managed apps; Personal Apple Account remains for unmanaged apps.
- **iCloud Drive:** Separate personal and organizational volumes appear in the Files app.
- **Security:** Separate encryption keys protect managed data; these are destroyed upon disenrollment.

### MDM Limitations (Privacy Protections)

Unlike Automated Device Enrollment, User Enrollment **cannot** access:

- Serial Number, UDID, IMEI, or MEID.
- Remote actions like **Clear Activation Lock** or **Enable Lost Mode**.

6. Supported Functionalities in User Enrollment
-----------------------------------------------

CategorySupported Actions & Payloads**Remote Actions**[Scan Device](https://www.hexnode.com/mobile-device-management/help/scan-devices-remotely-using-hexnode-mdm/), [Scan Device Location](https://www.hexnode.com/mobile-device-management/help/how-to-scan-device-location-using-hexnode-mdm/), [Lock Device](https://www.hexnode.com/mobile-device-management/help/lock-a-device-using-hexnode-mdm/), [Edit Device Attributes](https://www.hexnode.com/mobile-device-management/help/how-to-remotely-modify-device-attributes/), [Install](https://www.hexnode.com/mobile-device-management/help/apple-mdm-app-distribution/#install-apps-from-actions)/[Uninstall App](https://www.hexnode.com/mobile-device-management/help/remove-ios-apps-from-devices-using-hexnode-mdm/#remove-apps-from-devices-via-uninstall-application-action), [Disenroll Device](https://www.hexnode.com/mobile-device-management/help/disenroll-and-delete-device-from-hexnode-mdm/), [Broadcast Message](https://www.hexnode.com/mobile-device-management/help/broadcast-messages-to-a-device-enrolled-in-hexnode-mdm/), Associate Policy, Add Devices to Group, [Set Friendly Name](https://www.hexnode.com/mobile-device-management/help/rename-a-device-or-set-friendly-name-using-hexnode-mdm/), [Export Device Details](https://www.hexnode.com/mobile-device-management/help/how-to-export-device-details-using-hexnode-mdm/), [Delete Device](https://www.hexnode.com/mobile-device-management/help/disenroll-and-delete-device-from-hexnode-mdm/#delete-a-pre-approved-device).**[Passcode](https://www.hexnode.com/mobile-device-management/help/password-policy-for-ios/)**Minimum length: 6. No simple values allowed. (Complex characters *cannot* be mandated).**[Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-ios-mdm-restrictions-using-hexnode-mdm/)**Siri (while locked), Screen capture, Sync managed data with iCloud, Fraud warning, Lock screen notifications, Today View on lock screen, Control Center on lock screen, Force encrypted backup, Send diagnostic data to Apple.**App Management**[Enterprise](https://www.hexnode.com/mobile-device-management/help/distribute-ios-enterprise-app/)/[VPP apps](https://www.hexnode.com/mobile-device-management/help/how-to-deploy-apple-vpp-apps-with-hexnode-mdm/) via Required Apps or Install Action. [Web Clips](https://www.hexnode.com/mobile-device-management/help/add-web-clips-to-ios-with-hexnode-mdm/).**Network**[Wi-Fi](https://www.hexnode.com/mobile-device-management/help/set-up-wifi-for-ios-with-hexnode-mdm/), [VPN](https://www.hexnode.com/mobile-device-management/help/ios-vpn-settings/), [Per-App VPN](https://www.hexnode.com/mobile-device-management/help/how-to-configure-per-app-vpn-in-ios-devices-using-hexnode-mdm/).**Security/Accounts**[Certificates](https://www.hexnode.com/mobile-device-management/help/add-certificates-for-ios-devices-with-hexnode-mdm/), [SCEP](https://www.hexnode.com/mobile-device-management/help/how-to-configure-scep-for-ios-devices-with-hexnode-mdm/), [Business Container](https://www.hexnode.com/mobile-device-management/help/how-to-setup-business-container-for-ios-devices-using-hexnode-mdm/), [Email](https://www.hexnode.com/mobile-device-management/help/email-configuration-for-ios/), [ExchangeActiveSync](https://www.hexnode.com/mobile-device-management/help/configure-exchange-activesync-on-ios-with-hexnode-mdm/), [CardDAV](https://www.hexnode.com/mobile-device-management/help/carddav-settings-for-ios/), [Calendar](https://www.hexnode.com/mobile-device-management/help/subscribed-calendar-configuration/), [CalDAV](https://www.hexnode.com/mobile-device-management/help/caldav-settings-for-ios/), [Google Accounts](https://www.hexnode.com/mobile-device-management/help/setup-google-account-on-ios-devices-using-hexnode-mdm/), [LDAP](https://www.hexnode.com/mobile-device-management/help/ldap-settings-for-ios/).**Configurations**[Deploy Custom Configurations](https://www.hexnode.com/mobile-device-management/help/how-to-deploy-custom-configuration-profiles-to-ios-devices/), [Fonts](https://www.hexnode.com/mobile-device-management/help/add-new-font-to-ios-devices-with-hexnode-mdm/), [AirPrint](https://www.hexnode.com/mobile-device-management/help/configure-airprint-on-ios-devices-using-hexnode-mdm/), [AirPlay](https://www.hexnode.com/mobile-device-management/help/connect-ios-to-airplay-with-hexnode-mdm/).**Expense Management**[Network Data Usage Management.](https://www.hexnode.com/mobile-device-management/help/how-to-manage-network-data-usage-on-ios-devices/)Troubleshooting
---------------

1. **Error: “Profile Download Failed” or Wrong Profile Type**
    - **Symptoms:** The device downloads a “Device Enrollment” profile instead of a “User Enrollment” profile, or the download fails entirely.
    - **Cause:** **Safari Desktop View.** On iPads specifically, Safari often defaults to “Request Desktop Website.” User Enrollment profiles only trigger when Safari is in Mobile View.
    - **The Fix:**
        1. In Safari, tap the **‘AA’** or the **Page Settings** icon in the address bar.
        2. Select **Request Mobile Website**.
        3. Restart the enrollment process.
2. **Error: “Managed Apple Account Authentication Failed”**
    - **Symptoms:** The user cannot sign in during the “Enroll in Hexnode UEM” step in the Settings app.
    - **Causes:** The Managed Apple Account has not been created in **Apple Business**. 
        - The user is trying to use their **Personal Apple Account** instead of the corporate one.
        - The Managed Apple Account password has expired or needs a first-time reset.
    - **The Fix:**
        1. Verify the account exists in Apple Business under Users.
        2. Ensure the user is entering the exact Managed Apple Account provided by the admin.
        3. Reset the password in Apple Business if the user is locked out.
3. **Error: “Unable to Install Apps” (VPP Issues)** 
    - **Symptoms:** Enrollment is successful, but the Hexnode UEM agent or required apps fail to install.
    - **Cause:** User Enrollment requires **VPP (Volume Purchase Program)** for app deployment. It does not support standard App Store app installation via the UEM.
    - **The Fix:**
        1. Ensure content token is active in **Apple Business** > **[Organization name]** > **Settings** > [Payments & Billing](https://business.apple.com/main/preferences/paymentsandbilling/appsandbooks) > **Apps & Books** > **Content Tokens.**
        2. Navigate to **Apps & Services > Apps & Books > View Store** to find and purchase the license.
        3. Confirm that licenses for the Hexnode UEM app have been “purchased” (even if free) in Apple Business.
        4. Check that the **Managed Apple Account** is associated with the VPP account.