Apple - Device Enrolment
Enrollment guide: Microsoft Intune enrollment | Microsoft Learn
Device enrolment can be done in a variety of ways depending on the device’s operating system and ownership.
There are two main types of device ownership supported by Hwb that can be set during enrolment:
- With user affinity - This is suitable for one-to-one devices that are primarily used by a single user.
For iPads and Macs, ‘owned’ devices are locked to that user via their Managed Apple Id. They are automatically logged into Apple products and services on that device. - With-out user affinity - This suitable for classroom or ICT suite usage where the device is not solely used by the same user.
For iPads, the behaviour will depend on whether the device is setup as a ‘user-less’ device or shared iPad. The Company Portal app cannot be used to install apps.
Enrolling an iPad as a 'shared iPad' enables a log on screen so users can sign in and have their own separate profile on the device. This is handy for access to Hwb services without having to sign out of them after use, users simply just log off the iPad ready for the next person.
For devices enrolled with 'User affinity' or 'Without User Affinity + Shared iPads' a managed Apple Id is required. Please see Managed Apple Ids for more information.
Consider using 'Without User Affinity + Shared iPad' with the guest account if you don’t want to use managed Apple Ids. The guest account clears data after signing out and is safer than all users sharing the same profile with a non-shared iPad.
iPadOS and MacOS - Automatic Device Enrolment
iPad and MacOS devices are added to Apple School Manager via Apple’s Automatic Device Enrolment (ADE). This is commonly done by an approved reseller at the time of purchase. Alternatively, the Apple Configurator app can be used to add iPadOS and MacOS to Apple School Manager.
After a device has been registered in ADE, it must be assigned to an MDM server in Apple School Manager and sync'd to be made available in the Intune portal. It can then be assigned an enrolment profile configured with one of the above types, and enrolled over-the-air. If the device needs to be wiped at a later date, it can easily be done remotely and re-enrolled over-the-air using the existing assigned profile.
Once enrolled, the device will be visible in the relevant device provisioning group, depending on the name of the enrolment profile used. The device will need to be added to any additional groups to receive additional configuration policies and apps – see Move or add a device to another group.
The Hwb account used to sign-in to the Apple Configurator app must have the Device Enrollment Manager role in Apple School Manager. This is only available to local authority administrators.
The Devices section of Apple School Manager is not scoped. All devices registered in ASM on the Hwb tenant will be visible by all admins, not just your own. Please be very careful that you are acting on the correct devices when making changes.
The MDM server token in Intune will be created by Hwb but needs to be renewed annually by the local authority – see guide on Renew the MDM Token.
iPadOS - Manual enrolment using Apple Configurator for Mac
iPads can also be enrolled directly into Intune using Apple Configurator for Mac. Enrolment configurations are set in the Apple Configurator profile, and the iPad must be physically plugged into the Mac with app installed. Macs cannot be enrolled using this method.
The enrolment process is outlined in Apple Configurator User Guide (Prepare an iPhone, iPad or Apple TV manually in Apple Configurator)
We recommend only showing location services in the Setup Assistant, as that allows it to be turned on to set the correct region.
Remember to rename the devices from Apple Configurator as the default name will be ‘iPad’ otherwise.
Directly enrolling an iPad using Apple Configurator 2 allows the user to remove the management profile from the iPad within 30 days of enrolment. In iPadOS 14 or later, the device is reset and automatically released from Apple School Manager if the enrolment profile is removed during this period.
Before enrolment, the devices must be authorised in Intune, otherwise the process with fail. You will also need the MDM server URL, which can be exported from the Apple Configurator enrolment profile in Intune.
MacOS - Direct enrolment
Use direct enrollment for macOS devices | Microsoft Learn
With direct enrolment of MacOS, an enrolment profile is downloaded from Intune and installed on the Mac manually. It requires direct physical interaction with the Mac, and sets it up as a device without user affinity (shared device). The Mac must already be setup and logged in with a local admin account.
- Open System Preferences -> Sharing.
- Change the name of the Mac so that it starts with the relevant device provisioning identifier – this is to satisfy the provisioning devices group rule so the Mac appears in the right scope.
- Go to Intune -> Devices -> Enroll Devices -> Apple enrollment -> Apple Configurator
- Select Profiles
- Create the profile, if necessary:
- Name the profile (this should be prefixed with the school or local authority number)
- Select the user affinity required
- Select the profile
- Click on Export Profile then Download profile.
- Install the downloaded profile on the Mac, following the prompts.
It may a little time for the Mac to show in the Intune portal. If the device does not appear after some time, check the device name is correct.
White glove service
The white glove service, available from the reseller at time of purchase, enables the device to be fully setup before being shipped. This means it can be delivered straight to the school and is ready to use immediately.
For iPads, this service adds the device to Apple School Manager and enrols it, installing policies, apps, and updates, and applies any asset tags, screen protectors and cases.
Once the devices have been added to Apple School Manager, the reseller will need to notify an Intune admin in the local authority. The Intune admin will need to assign the devices to the MDM token in Apple School Manager, and the enrolment profile in Intune, before the reseller can continue. They may also need to add the device to additional device groups once enrolled to pick up additional policies or apps.