Apple Device Enrollment for Microsoft Intune — Configured Right, Not Just Turned On
Personal iPhone and iPad enrollment in Intune has two enrollment paths, a prerequisite most setups skip, and a documented Company Portal bug that only shows up after go-live. We configure it once, correctly.
Built for IT Directors and Security Leadersrolling out BYOD policy who don't want to learn Apple device enrollment by debugging it in production.
Two Ways to Enroll a Personal iPhone or iPad in Intune
Microsoft Intune supports app-based and web-based Apple device enrollment for BYOD. Both keep the device tied to a single user, require no device reset, and are initiated by the employee — but they differ in what the employee has to install and how securely the device is attested.
Web-Based Enrollment (Recommended)
- Minimum OS:
- iOS/iPadOS 15 and later
- Required apps:
- Microsoft Authenticator only — no Company Portal app install required
- Takes place in:
- Safari and the device Settings app
Uses just-in-time (JIT) registration with the Apple SSO extension. Microsoft recommends it as the more secure enrollment path for device attestation.
App-Based Enrollment (Company Portal)
- Minimum OS:
- iOS/iPadOS 14 and later
- Required apps:
- Intune Company Portal app + Microsoft Authenticator
- Takes place in:
- Company Portal app, Safari, and the device Settings app
The familiar path most admins default to. Works fine, but it requires an extra app install on a device the employee owns.
Both methods support BYOD and personal devices, tie the device to a single user, require no device reset, and support just-in-time registration. Neither supports supervision — that requires corporate-owned enrollment instead.
What the Admin Guide Doesn't Warn You About
Microsoft's documentation covers what each setting does. It doesn't cover the order you have to deploy things in, or which of Apple's and Microsoft's own documented bugs you'll hit if you don't.
The SSO extension profile is a prerequisite, not an afterthought
JIT web enrollment only works once a device configuration profile with an SSO app extension is deployed first. Skip that step and you hit Microsoft's documented bug where Company Portal can't recognize a device that enrolled through the web — employees get stuck mid-onboarding.
Authenticator provisioning has a timing race
Right after enrollment, users can be locked out of work apps for several minutes while Microsoft Authenticator finishes deploying to the device. If your rollout communication doesn't account for this, IT gets a wave of "it's broken" tickets that resolve themselves in five minutes.
ACME certificates only cover part of your fleet
The ACME protocol (Intune's replacement for SCEP on this enrollment type) requires iOS 16.0 / iPadOS 16.1 or later, and devices already enrolled don't get one unless they re-enroll. On a mixed-OS BYOD fleet, that means two certificate behaviors running at once unless it's planned for.
Personal-device policies are a different management model
Configuration profiles written for supervised or corporate-owned devices don't behave the same way here — Apple device enrollment only applies a subset of Intune's settings catalog. A profile copied from a fully-managed device policy will silently do less than expected, or nothing at all.
Employees can rename, remove, lock, and check status — and IT needs to know the limits
Company Portal gives device users the ability to rename, remove, remote lock, and check the status of their own enrollment. "Remove" clears the management profile and company data; it isn't a full-device wipe. If your helpdesk scripts assume otherwise, expect confused end users.
Our Apple BYOD Enrollment Process
Three stages, one fixed project fee, and a policy that's tested against real device behavior before your employees ever see it.
Assessment & Enrollment Policy Design
- Review current Entra ID, Conditional Access, and Intune licensing (Intune Plan 1, Entra ID P1/P2 as needed)
- Decide app-based vs. web-based JIT enrollment for your environment and device mix
- Map which iOS/iPadOS versions are actually in your employee population
- Define what "personal device" means in your Conditional Access and compliance policies
Configuration & Deployment
- Build and deploy the SSO extension configuration profile ahead of web enrollment
- Configure ACME certificate settings for supported OS versions
- Set enrollment restrictions scoped correctly for BYOD — not copied from a corporate-owned template
- Configure Conditional Access to gate work data behind enrollment and compliance status
Pilot, Rollout & Support
- Pilot enrollment across a representative sample of OS versions before company-wide rollout
- Write enrollment instructions specific to your tenant and policy — not generic Apple or Microsoft docs
- Hand IT a helpdesk runbook for the enrollment issues that actually come up
- Ongoing monitoring and support as Apple and Microsoft update enrollment behavior
Why Call Iron Cove Instead of Just Reading the Admin Guide
The documentation is public and free. What it doesn't give you is the deployment order, the fix for the known Company Portal bug, or someone to call when a policy that worked in testing breaks on a real employee's phone.
Self-Deploy from the Docs
- IT staff spends days cross-referencing Microsoft Learn and Apple documentation instead of doing their actual job
- SSO extension prerequisite gets missed, triggering the documented Company Portal recognition bug after rollout
- Enrollment restrictions copied from a corporate-device template silently under-manage or over-manage personal devices
- Misconfiguration surfaces as a wave of helpdesk tickets, not a clean error message
Iron Cove Professional Services
- Fixed project fee scoped to your environment on the free consultation call — no hourly billing surprises
- Policy built and pilot-tested against real iOS/iPadOS versions before company-wide rollout
- Known Apple and Microsoft enrollment issues handled up front, not discovered by your employees
- 500+ Microsoft cloud deployments, 18+ years of enterprise identity and device management experience
Free consultation. No obligation.
Frequently Asked Questions
Straight answers about Apple BYOD enrollment in Intune — what it manages, what it doesn't, and what it costs to get it right.
What's the difference between app-based and web-based Apple enrollment in Intune?
App-based enrollment runs through the Company Portal app and requires an install on the employee's personal device. Web-based enrollment uses just-in-time registration with the Apple SSO extension and only requires Microsoft Authenticator — no extra app. Microsoft recommends web-based enrollment as the more secure option, but it requires iOS/iPadOS 15+ and the SSO extension profile has to be deployed first.
Does Intune see my employees' personal photos, texts, or apps on a BYOD iPhone?
No. Apple device enrollment for personal devices applies only a defined subset of Intune's management settings, and the end-user actions in Company Portal — rename, remove, remote lock, check status — operate on the management profile and company data, not personal content. Getting that boundary configured correctly is exactly what a BYOD enrollment policy is supposed to do.
Do we need the Company Portal app, or can we skip it?
You can skip it if you use web-based enrollment, which only needs Microsoft Authenticator. That said, web enrollment has a prerequisite most self-service setups miss — the SSO extension configuration profile — and skipping that step causes a known issue where Company Portal can't recognize devices that enrolled through the web.
What happens if an employee leaves — can IT wipe the whole phone?
On a personal device enrolled this way, IT removes the management profile and company data and access to work resources through Conditional Access. It is not a factory wipe of the employee's personal device. We configure offboarding to happen through this process consistently, so a departure doesn't leave lingering access on a phone you don't own.
How long does it take to get Apple BYOD enrollment working correctly?
Most engagements move from assessment to a working, tested enrollment policy in 1-2 weeks, depending on how much Conditional Access and app protection work is already in place. Fixed project fee, scoped to your environment on the initial consultation.
We already tried following Microsoft's docs and enrollment is broken — can you fix an existing setup?
Yes. The most common issues we're called in for are the SSO extension prerequisite being missed, enrollment restrictions copied from a corporate-device template, and ACME certificates behaving inconsistently across a mixed-OS fleet. We audit the existing configuration, fix what's misconfigured, and document what changed.
Get Apple Enrollment Working — Once, Correctly
Skip the trial-and-error against Microsoft Learn and Apple's developer docs. Tell us your device mix and current Intune setup, and we'll scope a fixed-fee project on the call.
Free assessment · No obligation · Fixed-fee projects
