Set up automated device enrollment (ADE) for iOS/iPadOS
发布时间:2026-09-08 | 浏览:1
Access to this page requires authorization. You can try signing in or changing directories .
Access to this page requires authorization. You can try changing directories .
Applies to iOS/iPadOS
This article describes how to create an enrollment policy for iOS/iPadOS automated device enrollment (ADE) in Microsoft Intune. For an overview of ADE and prerequisite setup, see Overview of Apple Automated Device Enrollment .
Device platform requirements
New or wiped iOS/iPadOS devices purchased from Apple Business or Apple School Manager.
Tenant configuration requirements
Access to Apple Business portal or Apple School Manager portal .
An active Apple token (.p7m file). For steps, see Set up an ADE token .
An Apple MDM push certificate in Intune .
Automated device enrollment applies device configurations that a device user may not be able to remove. Wipe all devices prior to enrollment to return them to an out-of-box state.
Related configurations
If your organization uses Apple access management, you can optionally configure Apple access management settings in Apple Business or Apple School Manager to control which organization-owned iOS/iPadOS devices users can sign in to with Apple accounts and which apps and services are available. These settings are configured in Apple and enforced by Microsoft Intune after enrollment. They aren’t required to complete ADE setup. For more information, see Configure service access for Apple accounts .
Deploy the Company Portal app
When using automated device enrollment (ADE), deploy the Intune Company Portal app through Intune — not through the App Store. Deploying through Intune is the only way to:
Ensure all ADE devices, including already-enrolled ones, receive the app.
Enable automatic app updates for the Company Portal on ADE devices.
Don't use the App Store version of the Company Portal app. It isn't compatible with automated device enrollment and doesn't provide the automatic updates and availability that deployment does.
Deploy Company Portal as a VPP app
Deploy the app as a required VPP app with device licensing . For information about how to sync, assign, and manage a VPP app, see Assign a volume-purchased app .
To enable automatic app updates for Company Portal, go to your app token settings in the admin center and change Automatic app updates to Yes . See Upload an Apple VPP or Apple Business location token for the steps to access your token settings. If you don't enable automatic updates, the device user must manually check for them.
Stage a device (transition from userless to user affinity)
Device staging is used to transition a device without user affinity to a device with user affinity. To stage a device, set up VPP deployment as described earlier. Then configure and deploy an app configuration policy . Make sure the policy only targets those ADE devices without user affinity.
During initial enrollment, Intune automatically pushes app configuration policy settings for devices enrolled with Setup Assistant with modern authentication. This happens when the enrollment policy setting Install Company Portal is set to Yes . Don't deploy this configuration manually to users — it causes a conflict with the configuration sent during initial enrollment. If both are deployed, Intune incorrectly prompts device users to sign in to the Company Portal and download a management policy they've already installed.
Create an Apple enrollment policy
Create an enrollment policy for automated device enrollment. A device enrollment policy defines the settings applied to a group of devices during enrollment. There's a limit of 1,000 enrollment policies per enrollment token.
Devices will be blocked from enrolling if there aren't enough Company Portal licenses for a VPP token or if the token expires. Intune alerts you when a token is about to expire or licenses are running low.
This article reflects the updated policy creation experience ( Enrollment program tokens > Enrollment policies ) for devices going through automated device enrollment. The older experience ( Enrollment program tokens > Profiles ) differs and will eventually be retired. The older experience won't receive new features, so be sure to create new policies under Enrollment policies . For more information, see New iOS/iPadOS, visionOS, tvOS and macOS ADE enrollment policies experience .
In Microsoft Intune admin center , go to Devices .
In Microsoft Intune admin center , go to Devices .
Expand Device onboarding , and then select Enrollment .
Expand Device onboarding , and then select Enrollment .
Select the Apple mobile tab.
Select the Apple mobile tab.
Choose Enrollment program tokens .
Choose Enrollment program tokens .
Choose a token, and then select Enrollment policies .
Choose a token, and then select Enrollment policies .
Select Create policy > iOS/iPadOS .
Select Create policy > iOS/iPadOS .
For Basics , give the policy a Name and Description for administrative purposes. Users don't see these details.
For Basics , give the policy a Name and Description for administrative purposes. Users don't see these details.
Select Next . Important You must assign an enrollment policy to your devices before the devices become active. We recommend that you set a default enrollment policy as soon as possible so that as devices sync from Apple Business or Apple School Manager, and then turn on, they can enroll correctly through automated device enrollment. If a device you synced from Apple isn't assigned an enrollment policy and someone turns it on to set it up, enrollment fails. Important If you make changes to an existing enrollment policy, the new settings won't take effect on assigned devices until devices are reset back to factory settings and reactivated. The device name template setting is the only setting you can change that doesn't require a factory reset to take effect. Changes to the naming template take effect at the next check-in.
You must assign an enrollment policy to your devices before the devices become active. We recommend that you set a default enrollment policy as soon as possible so that as devices sync from Apple Business or Apple School Manager, and then turn on, they can enroll correctly through automated device enrollment. If a device you synced from Apple isn't assigned an enrollment policy and someone turns it on to set it up, enrollment fails.
If you make changes to an existing enrollment policy, the new settings won't take effect on assigned devices until devices are reset back to factory settings and reactivated. The device name template setting is the only setting you can change that doesn't require a factory reset to take effect. Changes to the naming template take effect at the next check-in.
On the Device group tab, optionally select a Microsoft Entra security group to use for enrollment time grouping. The group maps directly to this enrollment policy, and you can edit it after policy creation. Only static Microsoft Entra security groups are available for selection. To configure this setting, you must have the enrollment time device membership assignment permission in a custom RBAC role (under Enrollment programs ). For more information about how enrollment time grouping works, see Enrollment time grouping in Microsoft Intune .
On the Device group tab, optionally select a Microsoft Entra security group to use for enrollment time grouping. The group maps directly to this enrollment policy, and you can edit it after policy creation.
Only static Microsoft Entra security groups are available for selection. To configure this setting, you must have the enrollment time device membership assignment permission in a custom RBAC role (under Enrollment programs ).
For more information about how enrollment time grouping works, see Enrollment time grouping in Microsoft Intune .
On the Configuration settings tab, configure User Affinity . User affinity determines whether devices enroll with or without an assigned user. Your options: Enroll with User Affinity : Select this option for devices that belong to users who want to use the Company Portal for services like installing apps. Enrolling with user affinity is also referred to as enrolling with a user . Enroll without User Affinity : Select this option for devices that aren't affiliated with a single user. Use this option for devices that don't access local user data. This option is typically used for kiosk, point of sale (POS), or shared-utility devices. Enrolling without user affinity is also referred to as enrolling userless . In some situations, you might want to associate a primary user with devices enrolled without user affinity. To do this task, you can send the IntuneUDAUserlessDevice key to the Company Portal app in an app configuration policy for managed devices. The first user that signs in to the Company Portal app is established as the primary user. If the first user signs out and a second user signs in, the first user remains the primary user of the device. For more information, see Configure the Company Portal app to support iOS and iPadOS ADE devices . Enroll with Microsoft Entra ID shared mode : Select this option to enroll devices that will be in shared mode.
On the Configuration settings tab, configure User Affinity . User affinity determines whether devices enroll with or without an assigned user. Your options:
Enroll with User Affinity : Select this option for devices that belong to users who want to use the Company Portal for services like installing apps. Enrolling with user affinity is also referred to as enrolling with a user .
Enroll with User Affinity : Select this option for devices that belong to users who want to use the Company Portal for services like installing apps. Enrolling with user affinity is also referred to as enrolling with a user .
Enroll without User Affinity : Select this option for devices that aren't affiliated with a single user. Use this option for devices that don't access local user data. This option is typically used for kiosk, point of sale (POS), or shared-utility devices. Enrolling without user affinity is also referred to as enrolling userless . In some situations, you might want to associate a primary user with devices enrolled without user affinity. To do this task, you can send the IntuneUDAUserlessDevice key to the Company Portal app in an app configuration policy for managed devices. The first user that signs in to the Company Portal app is established as the primary user. If the first user signs out and a second user signs in, the first user remains the primary user of the device. For more information, see Configure the Company Portal app to support iOS and iPadOS ADE devices .
Enroll without User Affinity : Select this option for devices that aren't affiliated with a single user. Use this option for devices that don't access local user data. This option is typically used for kiosk, point of sale (POS), or shared-utility devices. Enrolling without user affinity is also referred to as enrolling userless .
In some situations, you might want to associate a primary user with devices enrolled without user affinity. To do this task, you can send the IntuneUDAUserlessDevice key to the Company Portal app in an app configuration policy for managed devices. The first user that signs in to the Company Portal app is established as the primary user. If the first user signs out and a second user signs in, the first user remains the primary user of the device. For more information, see Configure the Company Portal app to support iOS and iPadOS ADE devices .
Enroll with Microsoft Entra ID shared mode : Select this option to enroll devices that will be in shared mode.
Enroll with Microsoft Entra ID shared mode : Select this option to enroll devices that will be in shared mode.
If you selected Enroll with User Affinity for the User Affinity field, you have the option to choose the authentication method employees must use. For more information about each authentication method, see Authentication methods for automated device enrollment . Your options: Company Portal Setup Assistant with modern authentication Important We recommend using Setup Assistant with modern authentication for your Apple devices for ADE (automated device enrollment) scenarios with user device affinity. While use of the legacy authentication remains available, we don't recommend its use.
If you selected Enroll with User Affinity for the User Affinity field, you have the option to choose the authentication method employees must use. For more information about each authentication method, see Authentication methods for automated device enrollment .
Setup Assistant with modern authentication
We recommend using Setup Assistant with modern authentication for your Apple devices for ADE (automated device enrollment) scenarios with user device affinity. While use of the legacy authentication remains available, we don't recommend its use.
If you selected Setup Assistant (legacy) for the authentication method but you also want to use Conditional Access or deploy company apps on the devices, you need to install Company Portal on the devices and sign in to complete the Microsoft Entra registration. To do so, select Yes for Install Company Portal . If you want users to receive Company Portal without having to authenticate into the App Store, in Install Company Portal with VPP , select a VPP token. Make sure the token doesn't expire and that you have enough device licenses for the Company Portal app to deploy correctly.
If you selected Setup Assistant (legacy) for the authentication method but you also want to use Conditional Access or deploy company apps on the devices, you need to install Company Portal on the devices and sign in to complete the Microsoft Entra registration. To do so, select Yes for Install Company Portal . If you want users to receive Company Portal without having to authenticate into the App Store, in Install Company Portal with VPP , select a VPP token. Make sure the token doesn't expire and that you have enough device licenses for the Company Portal app to deploy correctly.
If you select a token for Install Company Portal with VPP , you can lock the device in Single App Mode (specifically, the Company Portal app) right after the Setup Assistant completes. Select Yes for Run Company Portal in Single App Mode until authentication to set this option. To use the device, the user must first authenticate by signing in to the Company Portal. Note Multifactor authentication isn't supported on a single device locked in Single App Mode. This limitation exists because the device can't switch to a different app to complete the second factor of authentication. If you want multifactor authentication on a Single App Mode device, the second factor must be on a different device. This feature is supported only for iOS/iPadOS 11.3.1 and later.
If you select a token for Install Company Portal with VPP , you can lock the device in Single App Mode (specifically, the Company Portal app) right after the Setup Assistant completes. Select Yes for Run Company Portal in Single App Mode until authentication to set this option. To use the device, the user must first authenticate by signing in to the Company Portal.
Multifactor authentication isn't supported on a single device locked in Single App Mode. This limitation exists because the device can't switch to a different app to complete the second factor of authentication. If you want multifactor authentication on a Single App Mode device, the second factor must be on a different device.
This feature is supported only for iOS/iPadOS 11.3.1 and later.
If you want devices using this policy to be supervised, select Yes in the Supervised list. Supervised devices give you more management options and disabled Activation Lock by default. We recommend that you use ADE as the mechanism for enabling supervised mode, especially if you're deploying large numbers of iOS/iPadOS devices. Apple Shared iPad for Business devices must be supervised. Users are notified that their devices are supervised in the Settings app. In the app at the top of their screen, a static message tells them This iPhone is supervised and managed by <your organization> . Note If a device is enrolled without supervision, you need to use Apple Configurator if you want to set it to supervised. To reset the device in this way, you need to connect it to a Mac with a USB cable. For more information, see Apple Configurator Help .
If you want devices using this policy to be supervised, select Yes in the Supervised list.
Supervised devices give you more management options and disabled Activation Lock by default. We recommend that you use ADE as the mechanism for enabling supervised mode, especially if you're deploying large numbers of iOS/iPadOS devices. Apple Shared iPad for Business devices must be supervised.
Users are notified that their devices are supervised in the Settings app. In the app at the top of their screen, a static message tells them This iPhone is supervised and managed by <your organization> .
If a device is enrolled without supervision, you need to use Apple Configurator if you want to set it to supervised. To reset the device in this way, you need to connect it to a Mac with a USB cable. For more information, see Apple Configurator Help .
For Locked enrollment , select Yes or No . Locked enrollment disables iOS/iPadOS settings that allow the management profile to be removed. If you enable locked enrollment, the button in the Settings app that lets users remove a management profile will be hidden and users won't be able to unenroll their device. If you're setting up devices in Microsoft Entra ID shared mode, select Yes . Locked enrollment works a little differently, at first, on devices not originally purchased through Apple Business but later added to be a part of automated device enrollment: users on these devices can see the remove management button in the Settings app for the first 30 days after activating their device. After that provisional period, this option is hidden. For more information, see Prepare devices manually (opens Apple Configurator Help docs). Important This setting is different from the remove and reset options in the Company Portal app. Regardless of how you configure locked enrollment, the Remove Device or Factory Reset options in the Company Portal app remain unavailable on devices enrolled through automated device enrollment. Users won't be able to remove the device on the Company Portal website either. For more information about the self-service actions available on enrolled devices, see Self-service actions .
For Locked enrollment , select Yes or No . Locked enrollment disables iOS/iPadOS settings that allow the management profile to be removed. If you enable locked enrollment, the button in the Settings app that lets users remove a management profile will be hidden and users won't be able to unenroll their device. If you're setting up devices in Microsoft Entra ID shared mode, select Yes .
Locked enrollment works a little differently, at first, on devices not originally purchased through Apple Business but later added to be a part of automated device enrollment: users on these devices can see the remove management button in the Settings app for the first 30 days after activating their device. After that provisional period, this option is hidden. For more information, see Prepare devices manually (opens Apple Configurator Help docs).
This setting is different from the remove and reset options in the Company Portal app. Regardless of how you configure locked enrollment, the Remove Device or Factory Reset options in the Company Portal app remain unavailable on devices enrolled through automated device enrollment. Users won't be able to remove the device on the Company Portal website either. For more information about the self-service actions available on enrolled devices, see Self-service actions .
If you selected Enroll without User Affinity and Supervised in the previous steps, you need to decide whether to configure the devices to be Apple Shared iPad for Business devices . Select Yes for Shared iPad to enable multiple users to sign in to a single device. Users authenticate by using their Managed Apple IDs and federated authentication accounts or by using a temporary session (like the Guest account). This option requires iOS/iPadOS 13.4 or later. With Shared iPad, all Setup Assistant panes after activation are automatically skipped. Note A device wipe will be required if an iOS/iPadOS enrollment policy with Shared iPad enabled is sent to an unsupported device. Unsupported devices include any iPhone models, and iPads running iPadOS/iOS 13.3 and earlier. Supported devices include iPads running iPadOS 13.3 and later. To set up Apple Shared iPad for Business, configure these settings: In the User Affinity list, select Enroll without User Affinity . In the Supervised list, select Yes . In the Shared iPad list, select Yes . If you're setting up Apple Shared iPad for Business devices, also configure: Maximum cached users : Enter the number of users that you expect to use the shared iPad. You can cache up to 24 users on a 32-GB or 64-GB device. If you choose a low number, it might take a while for your users' data to appear on their devices after they sign in. If you choose a high number, your users could run out of disk space. Maximum seconds after screen lock before password is required : Enter the amount of time in seconds. Accepted values include: 0, 60, 300, 900, 3600, and 14400. If the screen lock exceeds this amount of time, a device password will be required to unlock the device. Available for devices in Shared iPad mode running iPadOS 13.0 and later. Maximum seconds of inactivity until user session logs out : The minimum allowed value for this setting is 30. If there isn't any activity after the defined period, the user session ends and signs the user out. If you leave the entry blank or set it to zero (0), the session will never end due to inactivity. Available for devices in Shared iPad mode running iPadOS 14.5 and later. Require Shared iPad temporary session only : Configures the device so that users only see the guest version of the sign-in experience and must sign in as guests. They can't sign in with a Managed Apple ID. Available for devices in Shared iPad mode running iPadOS 14.5 and later. When set to Yes , this setting cancels out the following shared iPad settings, because they aren't applicable in temporary sessions: Maximum cached users Maximum seconds after screen lock before password is required Maximum seconds of inactivity until user session logs out Maximum seconds of inactivity until temporary session logs out : The minimum allowed value for this setting is 30. If there isn't any activity after the defined period, the temporary session ends and signs the user out. If you leave the entry blank or set it to zero (0), the session will never end due to inactivity. Available for devices in Shared iPad mode running iPadOS 14.5 and later. This setting is available when Require Shared iPad temporary session only is set to Yes . Note If temporary sessions are enabled, all of the user's data is deleted when they sign out of the session. This means that all targeted policies and apps will come down to the user when they sign-in, and they'll be erased when the user sign outs. To alter a Shared iPads configuration to not have temporary sessions, the device will need to be fully reset and a new enrollment policy with the updated configurations will need to be sent down to the iPad.
If you selected Enroll without User Affinity and Supervised in the previous steps, you need to decide whether to configure the devices to be Apple Shared iPad for Business devices . Select Yes for Shared iPad to enable multiple users to sign in to a single device. Users authenticate by using their Managed Apple IDs and federated authentication accounts or by using a temporary session (like the Guest account). This option requires iOS/iPadOS 13.4 or later. With Shared iPad, all Setup Assistant panes after activation are automatically skipped.
A device wipe will be required if an iOS/iPadOS enrollment policy with Shared iPad enabled is sent to an unsupported device. Unsupported devices include any iPhone models, and iPads running iPadOS/iOS 13.3 and earlier. Supported devices include iPads running iPadOS 13.3 and later.
To set up Apple Shared iPad for Business, configure these settings: In the User Affinity list, select Enroll without User Affinity . In the Supervised list, select Yes . In the Shared iPad list, select Yes .
In the User Affinity list, select Enroll without User Affinity .
In the Supervised list, select Yes .
In the Shared iPad list, select Yes .
If you're setting up Apple Shared iPad for Business devices, also configure:
Maximum cached users : Enter the number of users that you expect to use the shared iPad. You can cache up to 24 users on a 32-GB or 64-GB device. If you choose a low number, it might take a while for your users' data to appear on their devices after they sign in. If you choose a high number, your users could run out of disk space.
Maximum cached users : Enter the number of users that you expect to use the shared iPad. You can cache up to 24 users on a 32-GB or 64-GB device. If you choose a low number, it might take a while for your users' data to appear on their devices after they sign in. If you choose a high number, your users could run out of disk space.
Maximum seconds after screen lock before password is required : Enter the amount of time in seconds. Accepted values include: 0, 60, 300, 900, 3600, and 14400. If the screen lock exceeds this amount of time, a device password will be required to unlock the device. Available for devices in Shared iPad mode running iPadOS 13.0 and later.
Maximum seconds after screen lock before password is required : Enter the amount of time in seconds. Accepted values include: 0, 60, 300, 900, 3600, and 14400. If the screen lock exceeds this amount of time, a device password will be required to unlock the device. Available for devices in Shared iPad mode running iPadOS 13.0 and later.
Maximum seconds of inactivity until user session logs out : The minimum allowed value for this setting is 30. If there isn't any activity after the defined period, the user session ends and signs the user out. If you leave the entry blank or set it to zero (0), the session will never end due to inactivity. Available for devices in Shared iPad mode running iPadOS 14.5 and later.
Maximum seconds of inactivity until user session logs out : The minimum allowed value for this setting is 30. If there isn't any activity after the defined period, the user session ends and signs the user out. If you leave the entry blank or set it to zero (0), the session will never end due to inactivity. Available for devices in Shared iPad mode running iPadOS 14.5 and later.
Require Shared iPad temporary session only : Configures the device so that users only see the guest version of the sign-in experience and must sign in as guests. They can't sign in with a Managed Apple ID. Available for devices in Shared iPad mode running iPadOS 14.5 and later. When set to Yes , this setting cancels out the following shared iPad settings, because they aren't applicable in temporary sessions: Maximum cached users Maximum seconds after screen lock before password is required Maximum seconds of inactivity until user session logs out
Require Shared iPad temporary session only : Configures the device so that users only see the guest version of the sign-in experience and must sign in as guests. They can't sign in with a Managed Apple ID. Available for devices in Shared iPad mode running iPadOS 14.5 and later.
When set to Yes , this setting cancels out the following shared iPad settings, because they aren't applicable in temporary sessions:
Maximum cached users
Maximum seconds after screen lock before password is required
Maximum seconds of inactivity until user session logs out
Maximum seconds of inactivity until temporary session logs out : The minimum allowed value for this setting is 30. If there isn't any activity after the defined period, the temporary session ends and signs the user out. If you leave the entry blank or set it to zero (0), the session will never end due to inactivity. Available for devices in Shared iPad mode running iPadOS 14.5 and later. This setting is available when Require Shared iPad temporary session only is set to Yes .
Maximum seconds of inactivity until temporary session logs out : The minimum allowed value for this setting is 30. If there isn't any activity after the defined period, the temporary session ends and signs the user out. If you leave the entry blank or set it to zero (0), the session will never end due to inactivity. Available for devices in Shared iPad mode running iPadOS 14.5 and later.
This setting is available when Require Shared iPad temporary session only is set to Yes .
If temporary sessions are enabled, all of the user's data is deleted when they sign out of the session. This means that all targeted policies and apps will come down to the user when they sign-in, and they'll be erased when the user sign outs.
To alter a Shared iPads configuration to not have temporary sessions, the device will need to be fully reset and a new enrollment policy with the updated configurations will need to be sent down to the iPad.
For Await final configuration , your options are: Yes : Enable a locked experience at the end of Setup Assistant to ensure your most critical device configuration policies are installed on the device. Just before the home screen loads, Setup Assistant pauses and lets Intune check in with the device. The end-user experience locks while users await final configurations. The amount of time that users are held on the Awaiting final configuration screen varies, and depends on the total number of policies and apps you apply to the device. The more policies and apps assigned to the device, the longer the waiting time. Setup Assistant and Microsoft Intune don't enforce a minimum or maximum time limit during this portion of setup. During product validation, most devices we tested were released and able to access the home screen within 15 minutes. If you enable this feature and are using someone outside of Microsoft to help you provision devices, tell them about the potential for increased provisioning time. Note Only device configuration policies start installing during the awaiting final configuration screen, and applications aren't included in this. The locked experience works on devices targeted with new and existing enrollment policies. Supported devices include: iOS/iPadOS 13 and later devices enrolling with Setup Assistant with modern authentication iOS/iPadOS 13 and later devices enrolling without user affinity iOS/iPadOS 13 and later devices enrolling with Microsoft Entra ID shared mode This setting is applied once during the out-of-box automated device enrollment experience in Setup Assistant. The device user doesn't experience it again unless they re-enroll their device. Yes is the default setting for new enrollment policies. No : The device is released to the home screen when Setup Assistant ends, regardless of policy installation status. Device users might be able to access the home screen or change device settings before all policies are installed. No is the default setting for existing enrollment policies The await configuration setting is unavailable in policies with this combination of configurations: User affinity: Enroll without user affinity (Step 6 in this section) Shared iPad: Yes (Step 12 in this section)
For Await final configuration , your options are:
Yes : Enable a locked experience at the end of Setup Assistant to ensure your most critical device configuration policies are installed on the device. Just before the home screen loads, Setup Assistant pauses and lets Intune check in with the device. The end-user experience locks while users await final configurations. The amount of time that users are held on the Awaiting final configuration screen varies, and depends on the total number of policies and apps you apply to the device. The more policies and apps assigned to the device, the longer the waiting time. Setup Assistant and Microsoft Intune don't enforce a minimum or maximum time limit during this portion of setup. During product validation, most devices we tested were released and able to access the home screen within 15 minutes. If you enable this feature and are using someone outside of Microsoft to help you provision devices, tell them about the potential for increased provisioning time. Note Only device configuration policies start installing during the awaiting final configuration screen, and applications aren't included in this. The locked experience works on devices targeted with new and existing enrollment policies. Supported devices include: iOS/iPadOS 13 and later devices enrolling with Setup Assistant with modern authentication iOS/iPadOS 13 and later devices enrolling without user affinity iOS/iPadOS 13 and later devices enrolling with Microsoft Entra ID shared mode This setting is applied once during the out-of-box automated device enrollment experience in Setup Assistant. The device user doesn't experience it again unless they re-enroll their device. Yes is the default setting for new enrollment policies.
Yes : Enable a locked experience at the end of Setup Assistant to ensure your most critical device configuration policies are installed on the device. Just before the home screen loads, Setup Assistant pauses and lets Intune check in with the device. The end-user experience locks while users await final configurations.
The amount of time that users are held on the Awaiting final configuration screen varies, and depends on the total number of policies and apps you apply to the device. The more policies and apps assigned to the device, the longer the waiting time. Setup Assistant and Microsoft Intune don't enforce a minimum or maximum time limit during this portion of setup. During product validation, most devices we tested were released and able to access the home screen within 15 minutes. If you enable this feature and are using someone outside of Microsoft to help you provision devices, tell them about the potential for increased provisioning time.
Only device configuration policies start installing during the awaiting final configuration screen, and applications aren't included in this.
The locked experience works on devices targeted with new and existing enrollment policies. Supported devices include:
iOS/iPadOS 13 and later devices enrolling with Setup Assistant with modern authentication
iOS/iPadOS 13 and later devices enrolling without user affinity
iOS/iPadOS 13 and later devices enrolling with Microsoft Entra ID shared mode
This setting is applied once during the out-of-box automated device enrollment experience in Setup Assistant. The device user doesn't experience it again unless they re-enroll their device. Yes is the default setting for new enrollment policies.
No : The device is released to the home screen when Setup Assistant ends, regardless of policy installation status. Device users might be able to access the home screen or change device settings before all policies are installed. No is the default setting for existing enrollment policies
No : The device is released to the home screen when Setup Assistant ends, regardless of policy installation status. Device users might be able to access the home screen or change device settings before all policies are installed. No is the default setting for existing enrollment policies
The await configuration setting is unavailable in policies with this combination of configurations:
User affinity: Enroll without user affinity (Step 6 in this section)
Shared iPad: Yes (Step 12 in this section)
Optionally, create a device name template to quickly identify devices assigned this policy in the admin center. Intune uses your template to create and format device names. The names are given to devices when they enroll and upon each successive check-in. To create a template:
Optionally, create a device name template to quickly identify devices assigned this policy in the admin center. Intune uses your template to create and format device names. The names are given to devices when they enroll and upon each successive check-in. To create a template:
Under Apply device name template , select Yes .
Under Apply device name template , select Yes .
In the Device Name Template box, enter the template you want to use to construct device names. The template can include the device type and serial number. It can't contain more than 63 characters, including the variables. Example: {{DEVICETYPE}}-{{SERIAL}}
In the Device Name Template box, enter the template you want to use to construct device names. The template can include the device type and serial number. It can't contain more than 63 characters, including the variables. Example: {{DEVICETYPE}}-{{SERIAL}}
You can activate a cellular data plan. This setting applies to devices running iOS/iPadOS 13.0 and later. Configuring this option sends a command to activate cellular data plans for your eSim-enabled cellular devices. Your carrier must provision activations for your devices before you can activate data plans using this command. To activate a cellular data plan, select Yes , and then enter your carrier's activation server URL.
You can activate a cellular data plan. This setting applies to devices running iOS/iPadOS 13.0 and later. Configuring this option sends a command to activate cellular data plans for your eSim-enabled cellular devices. Your carrier must provision activations for your devices before you can activate data plans using this command. To activate a cellular data plan, select Yes , and then enter your carrier's activation server URL.
Under Setup Assistant , configure the following policy settings: Department setting Description Department Appears when users tap About Configuration during activation. Department Phone Appears when users tap the Need Help button during activation. You can hide Setup Assistant screens on the device during user setup. For a description of all screens, see Setup Assistant screen reference (in this article). If you select Hide , the screen isn't shown during setup. After setting up the device, the user can still go to the Settings menu to set up the feature. If you select Show , the screen is shown during setup, but only if there are steps to complete after the restore or after the software update. Users can sometimes skip the screen without taking action. They can then later go to the device's Settings menu to set up the feature. With Shared iPad, all Setup Assistant panes after activation are automatically skipped regardless of the configuration.
Under Setup Assistant , configure the following policy settings:
You can hide Setup Assistant screens on the device during user setup. For a description of all screens, see Setup Assistant screen reference (in this article).
If you select Hide , the screen isn't shown during setup. After setting up the device, the user can still go to the Settings menu to set up the feature.
If you select Show , the screen is shown during setup, but only if there are steps to complete after the restore or after the software update. Users can sometimes skip the screen without taking action. They can then later go to the device's Settings menu to set up the feature.
With Shared iPad, all Setup Assistant panes after activation are automatically skipped regardless of the configuration.
To save the policy, select Create .
To save the policy, select Create .
Dynamic groups in Microsoft Entra ID
You can use the enrollment Name field to create a dynamic group in Microsoft Entra ID. For more information, see Microsoft Entra dynamic groups .
You can use the policy name to define the enrollmentProfileName parameter to assign devices with this enrollment policy.
Before device setup, and to ensure quick delivery to devices with user affinity, make sure the enrolling user is a member of a Microsoft Entra user group.
If you assign dynamic groups to enrollment policies, there might be a delay in delivering applications and policies to devices after the enrollment.
Setup Assistant screen reference
The following table describes the Setup Assistant screens shown during automated device enrollment for iOS/iPadOS. You can show or hide these screens on supported devices during enrollment. For more information about how each Setup Assistant screen affects the user experience, see these Apple resources:
Apple Platform Deployment guide: Manage Setup Assistant for Apple devices
Apple Developer documentation: SkipKeys
Assign an enrollment policy to devices
Before devices can be enrolled, you need to assign an enrollment policy to them.
You can also assign serial numbers to policies in the Apple Serial Numbers pane.
In Microsoft Intune admin center , go to Devices .
Expand Device onboarding , and then select Enrollment .
Select the Apple mobile tab.
Choose Enrollment program tokens .
Select an enrollment token.
Select Devices .
Select all devices you want to assign, and then select Assign policy .
Under Assign policy , choose the automated device enrollment policy you created for the devices, and then select Assign .
Assign a default policy
You can pick a default policy to be applied to all devices that enroll with a specific token.
In the admin center, return to Enrollment program tokens .
Select an enrollment token.
Select Set Default Policy .
Select a policy in the list, and then select Save . From here, Intune applies the policy to all devices that enroll with the selected enrollment token.
Ensure that Device Type Restrictions under Enrollment Restrictions doesn't have the default All Users policy set to block the iOS/iPadOS platform. This setting causes automated enrollment to fail and your device shows as Invalid Profile, regardless of user attestation. To permit enrollment only by company-managed devices, block only personally owned devices, which permits corporate devices to enroll. Microsoft defines a corporate device as a device that's enrolled through a Device Enrollment Program or a device that's manually entered under Corporate device identifiers .
These Setup Assistant screens don't work correctly on devices running iOS/iPadOS 14.5 and later:
Passcode Touch ID and Face ID
Touch ID and Face ID
Hide both screens on devices running iOS/iPadOS 14.5 and later. If you want to require passcodes on those devices, create a device configuration policy or a compliance policy with passcode requirements. After the user enrolls and receives the policy, the passcode requirement takes effect.
To sync devices, assign enrollment policies, and distribute devices to users, see Manage ADE devices .
To renew or delete your enrollment program token, see Set up an ADE token .
For troubleshooting, see Troubleshoot iOS/iPadOS device enrollment problems .
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?
Additional resources
Last updated on 2026-05-18