Enroll Employee Owned (BYOD) Mac (macOS) Device
  • 14 Aug 2024
  • 2 Minutes to read
  • PDF

Enroll Employee Owned (BYOD) Mac (macOS) Device

  • PDF

Article summary

If you have got an invite from your IT Admin to enroll your devices, as shown below, please follow the steps below to enroll your Mac device.

Steps

  1. To start the enrollment process, Click Enroll your Device if you are accessing the email on the Mac device that you are trying to enroll.
  2. This will open your default browser and load up a page to begin enrollment. Verify your email address and Click CONFIRM to receive an OTP.
    We recommend using Safari or Chrome to enroll your devices.
  3. In this screen, enter the OTP that you received and click CONFIRM

  4. Read the Terms of Service set by your organization and click ACCEPT
    GSuite / O365 / SAML users who have the setting Enforce Users to sign in using GSuite/O365/SAML SSO enabled in User Management on Dashboard will be asked to authenticate by signing in with their GSuite/O365/SAML credentials.
  5. On the enrollment screen, click ENROLL.
  6. Depending upon which browser you used to start the enrollment, either of the following will happen,
    1. Google Chrome: A *.mobileconfig will be downloaded. Once it is downloaded, click on the downloaded file to go to the next step.
    2. Apple Safari: If you have enabled Auto-Open, then the file will be downloaded, and you will be automatically directed to the next step. If you are not directed to the next step, please double-click on the downloaded file.
  7. This will open the System Preferences pane, and the following dialog will be shown. Click on Install to proceed with enrollment.
  8. You will be shown the details of the enrollment profile and asked to confirm the installation. Click Install

  9. If you are enrolling from a non-administrator user, you will be asked to enter administrator credentials to confirm the installation. Please enter the administrator credentials and Click OK.
  10. It will take around a minute or so for the enrollment to complete, and you will see the following screen,
  11. It will take around 2-3 minutes for the enrollment to be complete, and the following screen confirms that the enrollment is complete. Depending upon the type of policies applied, you would see at most 3 Profiles that are installed,
    1. Device Profiles: This section lists all the Profiles/Policies that are applicable at a device level. The items marked 1 & 2 are device-level profiles, and the policies applied by these profiles are applied to all the users of this machine.
    2. User Profiles: This section lists all the Profiles/Policies that are applicable at a user level. Identified by point 3 in the image below, these policies are applicable only to the Mac user account from where the enrollment was done.

Enrollment when Settings are enforced

GSuite / O365 / SAML users who have the setting Enforce Users to sign in using GSuite/O365/SAML SSO enabled in User Management on Dashboard will be asked to authenticate by signing in with their GSuite/O365/SAML credentials. Please refer to the following guides to learn how to enroll the devices when settings are enforced:

  1. GSuite
  2. O365
  3. Okta
  4. PingOne

Frequently Asked Questions

Question: We see the following error while enrolling the devices.

Answer: This error may appear if your IT Admin has limited you to enrolling a specific number of devices and you have exceeded the limit. Please contact your IT Admin with this error for further support.

Question: Why do we see an error "Profile Failed to Install" while installing the Profile?

Answer: This can happen if the Serial number or IMEI of your iOS device does not match the Serial number or IMEI that your IT Admin has allowed. Please contact your IT Admin with this error for further support.


Was this article helpful?