Enrollment methods for Apple devices

There are three main methods of device enrollment in a device management service. One of those methods—Device Enrollment—has two different ways for a user to enroll: account-driven and profile-based. When you enroll Apple devices in a device management service, depending on the enrollment method, those devices can be supervised. Supervision generally denotes that the organization owns the device, which provides additional control over its configuration and restrictions. The table below summarizes the enrollment methods and whether they result in the device being supervised. For more information on supervision, see About Apple device supervision.

Enrollment method

Minimum supported operating system versions

Supervised upon enrollment?

Account-driven User Enrollment

iOS 15

iPadOS 15

macOS 14

visionOS 1.1

No

Account-driven Device Enrollment

iOS 17

iPadOS 17

macOS 14

visionOS 1.1

No (iPhone, iPad, Apple Vision Pro)

Yes (Mac)

Profile-based Device Enrollment

iOS 4

iPadOS 13.1

OS X 10.7

tvOS 9

No (iPhone, iPad, Apple TV)

Yes (Mac)

Automated Device Enrollment

iOS 13

iPadOS 13.1

macOS 10.14.4

tvOS 13

watchOS 10

visionOS 2.0

Yes

Note: Not all enrollment options are available in all device management services. To learn which options are available for your devices, consult your developer’s device management service documentation.

How enrollment methods help to protect the user’s privacy

The table below shows what information and capabilities are available to a device management service depending on the enrollment method. For more information on additional data separation capabilities that account-driven enrollment methods support, see Account-driven enrollment methods.

Depending on the method an organization uses to enroll the device in a device management service, information about the user, their data, and the device vary. Account-driven User Enrollment and account-driven Device Enrollment provide the user with the most privacy and data separation. Profile-based Device Enrollment and Automated Device Enrollment provide IT teams the most control over the device.

Note: The table below illustrates key differences of enrollment methods, but isn’t a fully comprehensive list:

Ability

Account-driven User Enrollment

Account-driven Device Enrollment

Profile-based Device Enrollment

Automated Device Enrollment

Enforceable restrictions

Curated list

Unsupervised only

Unsupervised only

All

Require passcode

Allowed
Allowed
Allowed
Allowed

Remotely erase managed data

Allowed
Allowed
Allowed
Allowed

Configure per-app VPN

Allowed
Allowed
Allowed
Allowed

Install and configure managed apps

Allowed
Allowed
Allowed
Allowed

Query the operating system version number

Allowed
Allowed
Allowed
Allowed

Query unique device identifiers like serial number

Not allowed
Allowed
Allowed
Allowed

Query the device’s time zone

Not allowed
Allowed
Allowed
Allowed

Query the device phone number

Not allowed
Allowed
Allowed
Allowed

Query the roaming status

Not allowed
Allowed
Allowed
Allowed

Query list of all apps

Not allowed
Allowed
Allowed
Allowed

Configure VPN

Not allowed
Allowed
Allowed
Allowed

Remotely erase all content and settings

Not allowed
Allowed
Allowed
Allowed

Require complex passcode or password

Not allowed
Allowed
Allowed
Allowed

Enforce software updates

Not allowed
Allowed
Allowed
Allowed

Enforce and manage FileVault

Not allowed
Allowed
Allowed
Allowed

Set the device name in macOS

Not allowed
Allowed
Allowed
Allowed

Manage Activation Lock in macOS

Not allowed
Allowed
Allowed
Allowed

Take over management of a personal app

Not allowed
Not allowed
Allowed
Allowed

Manage Activation Lock in iOS, iPadOS, and visionOS

Not allowed
Not allowed
Not allowed
Allowed

Configure Always On VPN

Not allowed
Not allowed
Not allowed
Allowed

Configure a global HTTP proxy

Not allowed
Not allowed
Not allowed
Allowed

Set the device name in iOS, iPadOS, and visionOS

Not allowed
Not allowed
Not allowed
Allowed

Turn on Managed Lost Mode

Not allowed
Not allowed
Not allowed
Allowed

Query the device location

Not allowed
Not allowed
Not allowed
Not allowed

Collect frequency of app usage

Not allowed
Not allowed
Not allowed
Not allowed

View personal calendars, contacts, mail, notes, reminders

Not allowed
Not allowed
Not allowed
Not allowed

View iMessage or SMS messages

Not allowed
Not allowed
Not allowed
Not allowed

View FaceTime or phone call logs

Not allowed
Not allowed
Not allowed
Not allowed

View Safari browser history

Not allowed
Not allowed
Not allowed
Not allowed
Published Date: January 28, 2025
Morty Proxy This is a proxified and sanitized view of the page, visit original site.
Helpful?
Character limit: 250
Maximum character limit is 250.
Thanks for your feedback.
Morty Proxy This is a proxified and sanitized view of the page, visit original site.