Category filter
Apple User Enrollment for iOS devices
User Enrollment for iOS devices is an enrollment method designed for Bring Your Own Device (BYOD) deployments where the user, instead of the organization, owns the device. It primarily focuses on enhancing user privacy and enterprise security.
User Enrollment requires a Managed Apple ID to establish a user identity on the device. Managed Apple IDs are created by an organization and provide end-users access to specific Apple services. This Managed Apple ID can co-exist with the personal Apple ID of the user without interacting with one another.
Once the User Enrollment profile is set up, a separate Apple File System (APFS) volume containing the managed apps and data will be automatically created and encrypted on the device. Such containerization allows organizations to manage corporate data without interfering with end users’ personal data. However, unlike Automated Device Enrollment, where the MDM has complete control over the device, User Enrollment supports only a limited set of payloads and restrictions on the device. For instance, critical MDM commands such as, enable/disable lost mode, allow/clear activation lock, etc., cannot be executed. Additionally, device-specific information such as serial number, UDID, IMEI, MEID, etc., cannot be retrieved from the MDM console.
Setting up User Enrollment in the Hexnode UEM portal
- Log in to your Hexnode portal.
- Go to Enroll > Platform – Specific > iOS > Email or SMS.
- Choose the authentication mode as Authenticated Enrollment.
- Select the Ownership of the device as Personal.
- Choose the Apple Enrollment Type as User Enrollment from the below options:
- Device Enrollment
- User Enrollment
- Click on Next.
- Configure the necessary details for sending enrollment requests and hit Send.
Enrollment requests comprising the enrollment URL, username, and password will be sent to the users via email or SMS.
On the device,
If Ownership is selected as Personal and Apple Enrollment Type is selected as User Enrollment from the portal,
- Open the Safari browser and enter the enrollment URL specified in the enrollment request.
For example, https://portalname.hexnodemdm.com/enroll/.
- On the enrollment screen, enable the checkbox to agree with the terms and conditions. Click Enroll.
- Enter your “Managed Apple ID” and click on Download Profile.
If Ownership is selected as Let the user choose from the portal,
- Open the Safari browser and enter the enrollment URL specified in the enrollment request.
For example, https://portalname.hexnodemdm.com/enroll/.
- On the enrollment screen, enable the checkbox to agree with the terms and conditions. Click Enroll.
- Enter your username and password and select I own this device. Click on Authenticate. Alternatively, selecting My organization owns this device will enroll the device using Device enrollment.
- Next, select how you want the devices to be managed by Hexnode UEM:
- Manage entire device – To manage the device completely without limitations on MDM capabilities.
- Manage only work-related data and apps – To manage corporate data by creating a separate volume on the device with limited MDM capabilities.
- Select Manage only work-related data and apps and enter your “Managed Apple ID”.
- Click on Download Profile.
Finally, after the enrollment profile is downloaded, navigate to Settings > Enrol in Hexnode and click on Enrol My iPhone. Here, you need to enter the password of your Managed Apple ID. Once the enrollment is successful, you can see the downloaded Hexnode MDM profile in General > VPN & Device Management.
MDM functionalities in User enrolled devices
Compared to other enrollment types, User Enrollment severely limits the permissions that an MDM has when administering a device. Unlike device enrollment, device details such as Serial Number, UDID, IMEI and MEID cannot be retrieved in this case.
Here is a comprehensive list of available Hexnode UEM functionalities on devices enrolled using User Enrollment.
- Remote Actions
- Scan Device
- Scan Device Location
- Lock Device
- Edit Device Attributes
- Install Application
- Uninstall Application
- Disenroll device
- Broadcast Message
- Associate Policy
- Add Devices To Groups
- Set Friendly Name
- Export Device Details
- Delete Device
- Passcode
Despite what passcode requirements are specified, there are certain exceptions in the passcode policy on the devices enrolled using user enrollment:
- No simple value allowed.
- Minimum passcode length is 6.
- Restrictions
- Allow Device Functionality
- Siri
- Allow Siri while device is locked
- Screen capture
- Allow Application Settings
- Sync managed data with iCloud
- Backup enterprise-deployed iBooks
- Fraud warning
- Allow Security and Privacy Settings
- Today View on lock screen
- Control Center on lock screen
- Lock screen notifications
- Force encrypted backup
- Send diagnostic data to Apple
- Allow Device Functionality
- App Management
Deploy and manage Enterprise and VPP apps using the Mandatory Apps policy or Install Application action from the Hexnode UEM console. You can also add Web Clips to the Home Screen on iPhone and iPad devices.
User Enrollment requires an Apple VPP token associated with your Hexnode portal to install managed apps from the App Store on devices.
Once the device is disenrolled from Hexnode, all the managed apps and data will be removed, and the device will return to its original state before enrollment.
- Network
- Security
- Accounts
- Expense Management
- Configurations