Iron Cove Solutions Logo
  • MIGRATION

Apple Device Enrollment for Microsoft Intune — Configured Right, Not Just Turned On

Personal iPhone and iPad enrollment in Intune has two enrollment paths, a prerequisite most setups skip, and a documented Company Portal bug that only shows up after go-live. We configure it once, correctly.

Built for IT Directors and Security Leadersrolling out BYOD policy who don't want to learn Apple device enrollment by debugging it in production.

Call (213) 545-0601
500+
Microsoft Cloud Deployments
18+
Years of Experience
1-2 wks
Typical Time to Go-Live
24/7
Ongoing Support
Enrollment MethodsWhat Trips Up Self-DeployOur ProcessWhy Iron CoveFAQ
Microsoft Intune✦Apple BYOD Enrollment✦iOS & iPadOS✦SSO Extension & JIT Registration✦Conditional Access✦ACME Certificates✦Company Portal✦Fixed-Fee Projects✦US-Based Support✦Microsoft Intune✦Apple BYOD Enrollment✦iOS & iPadOS✦SSO Extension & JIT Registration✦Conditional Access✦ACME Certificates✦Company Portal✦Fixed-Fee Projects✦US-Based Support✦

Two Ways to Enroll a Personal iPhone or iPad in Intune

Microsoft Intune supports app-based and web-based Apple device enrollment for BYOD. Both keep the device tied to a single user, require no device reset, and are initiated by the employee — but they differ in what the employee has to install and how securely the device is attested.

Web-Based Enrollment (Recommended)

Minimum OS:
iOS/iPadOS 15 and later
Required apps:
Microsoft Authenticator only — no Company Portal app install required
Takes place in:
Safari and the device Settings app

Uses just-in-time (JIT) registration with the Apple SSO extension. Microsoft recommends it as the more secure enrollment path for device attestation.

App-Based Enrollment (Company Portal)

Minimum OS:
iOS/iPadOS 14 and later
Required apps:
Intune Company Portal app + Microsoft Authenticator
Takes place in:
Company Portal app, Safari, and the device Settings app

The familiar path most admins default to. Works fine, but it requires an extra app install on a device the employee owns.

Both methods support BYOD and personal devices, tie the device to a single user, require no device reset, and support just-in-time registration. Neither supports supervision — that requires corporate-owned enrollment instead.

What the Admin Guide Doesn't Warn You About

Microsoft's documentation covers what each setting does. It doesn't cover the order you have to deploy things in, or which of Apple's and Microsoft's own documented bugs you'll hit if you don't.

The SSO extension profile is a prerequisite, not an afterthought

JIT web enrollment only works once a device configuration profile with an SSO app extension is deployed first. Skip that step and you hit Microsoft's documented bug where Company Portal can't recognize a device that enrolled through the web — employees get stuck mid-onboarding.

Authenticator provisioning has a timing race

Right after enrollment, users can be locked out of work apps for several minutes while Microsoft Authenticator finishes deploying to the device. If your rollout communication doesn't account for this, IT gets a wave of "it's broken" tickets that resolve themselves in five minutes.

ACME certificates only cover part of your fleet

The ACME protocol (Intune's replacement for SCEP on this enrollment type) requires iOS 16.0 / iPadOS 16.1 or later, and devices already enrolled don't get one unless they re-enroll. On a mixed-OS BYOD fleet, that means two certificate behaviors running at once unless it's planned for.

Personal-device policies are a different management model

Configuration profiles written for supervised or corporate-owned devices don't behave the same way here — Apple device enrollment only applies a subset of Intune's settings catalog. A profile copied from a fully-managed device policy will silently do less than expected, or nothing at all.

Employees can rename, remove, lock, and check status — and IT needs to know the limits

Company Portal gives device users the ability to rename, remove, remote lock, and check the status of their own enrollment. "Remove" clears the management profile and company data; it isn't a full-device wipe. If your helpdesk scripts assume otherwise, expect confused end users.

Our Apple BYOD Enrollment Process

Three stages, one fixed project fee, and a policy that's tested against real device behavior before your employees ever see it.

1

Assessment & Enrollment Policy Design

  • Review current Entra ID, Conditional Access, and Intune licensing (Intune Plan 1, Entra ID P1/P2 as needed)
  • Decide app-based vs. web-based JIT enrollment for your environment and device mix
  • Map which iOS/iPadOS versions are actually in your employee population
  • Define what "personal device" means in your Conditional Access and compliance policies
2

Configuration & Deployment

  • Build and deploy the SSO extension configuration profile ahead of web enrollment
  • Configure ACME certificate settings for supported OS versions
  • Set enrollment restrictions scoped correctly for BYOD — not copied from a corporate-owned template
  • Configure Conditional Access to gate work data behind enrollment and compliance status
3

Pilot, Rollout & Support

  • Pilot enrollment across a representative sample of OS versions before company-wide rollout
  • Write enrollment instructions specific to your tenant and policy — not generic Apple or Microsoft docs
  • Hand IT a helpdesk runbook for the enrollment issues that actually come up
  • Ongoing monitoring and support as Apple and Microsoft update enrollment behavior

Why Call Iron Cove Instead of Just Reading the Admin Guide

The documentation is public and free. What it doesn't give you is the deployment order, the fix for the known Company Portal bug, or someone to call when a policy that worked in testing breaks on a real employee's phone.

Self-Deploy from the Docs

  • IT staff spends days cross-referencing Microsoft Learn and Apple documentation instead of doing their actual job
  • SSO extension prerequisite gets missed, triggering the documented Company Portal recognition bug after rollout
  • Enrollment restrictions copied from a corporate-device template silently under-manage or over-manage personal devices
  • Misconfiguration surfaces as a wave of helpdesk tickets, not a clean error message

Iron Cove Professional Services

  • Fixed project fee scoped to your environment on the free consultation call — no hourly billing surprises
  • Policy built and pilot-tested against real iOS/iPadOS versions before company-wide rollout
  • Known Apple and Microsoft enrollment issues handled up front, not discovered by your employees
  • 500+ Microsoft cloud deployments, 18+ years of enterprise identity and device management experience

Free consultation. No obligation.

Frequently Asked Questions

Straight answers about Apple BYOD enrollment in Intune — what it manages, what it doesn't, and what it costs to get it right.

What's the difference between app-based and web-based Apple enrollment in Intune?

App-based enrollment runs through the Company Portal app and requires an install on the employee's personal device. Web-based enrollment uses just-in-time registration with the Apple SSO extension and only requires Microsoft Authenticator — no extra app. Microsoft recommends web-based enrollment as the more secure option, but it requires iOS/iPadOS 15+ and the SSO extension profile has to be deployed first.

Does Intune see my employees' personal photos, texts, or apps on a BYOD iPhone?

No. Apple device enrollment for personal devices applies only a defined subset of Intune's management settings, and the end-user actions in Company Portal — rename, remove, remote lock, check status — operate on the management profile and company data, not personal content. Getting that boundary configured correctly is exactly what a BYOD enrollment policy is supposed to do.

Do we need the Company Portal app, or can we skip it?

You can skip it if you use web-based enrollment, which only needs Microsoft Authenticator. That said, web enrollment has a prerequisite most self-service setups miss — the SSO extension configuration profile — and skipping that step causes a known issue where Company Portal can't recognize devices that enrolled through the web.

What happens if an employee leaves — can IT wipe the whole phone?

On a personal device enrolled this way, IT removes the management profile and company data and access to work resources through Conditional Access. It is not a factory wipe of the employee's personal device. We configure offboarding to happen through this process consistently, so a departure doesn't leave lingering access on a phone you don't own.

How long does it take to get Apple BYOD enrollment working correctly?

Most engagements move from assessment to a working, tested enrollment policy in 1-2 weeks, depending on how much Conditional Access and app protection work is already in place. Fixed project fee, scoped to your environment on the initial consultation.

We already tried following Microsoft's docs and enrollment is broken — can you fix an existing setup?

Yes. The most common issues we're called in for are the SSO extension prerequisite being missed, enrollment restrictions copied from a corporate-device template, and ACME certificates behaving inconsistently across a mixed-OS fleet. We audit the existing configuration, fix what's misconfigured, and document what changed.

Get Apple Enrollment Working — Once, Correctly

Skip the trial-and-error against Microsoft Learn and Apple's developer docs. Tell us your device mix and current Intune setup, and we'll scope a fixed-fee project on the call.

Call (213) 545-0601

Free assessment · No obligation · Fixed-fee projects

Talk to us

Email

sales@ironcovesolutions.com

Phone & Hours

(213) 545-0601
Monday-Friday: 9am to 5pm

Address

8117 W. Manchester Ave
Suite 915
Playa Del Rey, CA 90293
Hello! My name is
and I work at
I heard about you from
and I'm looking for someone to help with
To start the conversation, you can reach me at:
Additionally:

Join Our Newsletter

Expert Cloud Consulting

  • AWS Management Services
  • Descope Identity Solutions
  • Dropbox Business
  • Google Workspace
  • Global Relay
  • Microsoft 365 & Office 365
  • Okta IAM Solutions
  • Okta Partner Near You
  • Proofpoint Email Security

Cloud Technologies

  • Cloud Orchestration Engine
  • Cloud Products
  • Dropbox Business Platform
  • Google Workspace SMB
  • Microsoft 365 Platform
  • Microsoft Copilot AI
  • Okta Identity Platform
  • Proofpoint Email Security

Micro Support

  • DNS Migration
  • Okta Backup
  • VPN Setup in AWS

Managed Cloud Services

  • Application SSO
  • Cloud Management
  • Cybersecurity Management
  • Google Workspace
  • Microsoft Office 365
  • Okta Managed Services
  • 2-Hour Support Session

Workflow Automation

  • BambooHR to Okta Integration
  • Microsoft 365 Workflows
  • Okta Business Process Automation
  • Okta Workflow Consulting
  • Workday to Okta Integration

Migration & Infrastructure

  • Email Migration
  • Email Migration to Exchange Online
  • Exchange to Exchange Online Migration
  • Datto Protection

Connect With Us

  • X
  • Facebook
  • LinkedIn
  • YouTube

Microsoft Solutions

  • Exchange Online Plan 1
  • Exchange Online Plan 2
  • Microsoft 365 & Office 365
  • Microsoft 365 E3 Enterprise
  • Microsoft 365 E5 Enterprise
  • Microsoft 365 Kiosk
  • Office 365 E1 Business
  • Microsoft 365 E3
  • Office 365 E5 Premium
  • View All Microsoft Plans & Pricing

Resources & Insights

  • Blog & Articles
  • Case Studies & Success Stories
  • Video Tutorials

Company Information

  • About Our Company
  • Careers & Opportunities
  • Project Management Portal
  • Technical Support

© 2026 | Iron Cove Solutions| Privacy | Simplifying Cloud-Based Intention

HomeEmailCall

  • Home
  • Consulting
  • Technology
  • Email Migration
  • Workflow
  • Resources
  • Support
  • Contact
Close