User Enrollment and device management

Account-driven User Enrollment is designed for BYOD—or bring-your-own-device deployments—where the user, not the organization, owns the device. It works with accounts you create in Apple School Manager or Apple Business, or with federated accounts that link to a device management service and an identity provider (IdP), like Google Workspace or Microsoft Entra ID.

After users successfully sign in on their device, they can see details about what’s being managed on that device and how much iCloud storage space is provided by their organization. As the user owns the device, account-driven User Enrollment can apply only a limited set of payloads and restrictions to it. For more information, see Device management service User Enrollment information.

With account-driven User Enrollment, IT teams can manage only an organization’s accounts, settings, and information provisioned with a device management service, never a user’s personal account. For more information, see How enrollment methods help to protect the user’s privacy.

Organizations can also choose to use account-driven Device Enrollment. This method provides the organization with more controls and configurations. For more information, see Device Enrollment and device management.

Published Date: December 11, 2024
Morty Proxy This is a proxified and sanitized view of the page, visit original site.
Helpful?
Character limit: 250
Maximum character limit is 250.
Thanks for your feedback.
Morty Proxy This is a proxified and sanitized view of the page, visit original site.