- 27 Sep 2024
- 3 Minutes to read
- Print
- PDF
Enrolling iOS devices with Managed Apple Id using Sign in to Work or School
- Updated on 27 Sep 2024
- 3 Minutes to read
- Print
- PDF
With managed Apple IDs users can also enroll their iOS devices using Sign in to Work or School option in Settings making the enrollment procedure extremely simple. With this approach, IT admins can use Scalefusion to manage employee/personal-owned devices and drive BYOD strategy on iOS devices creating a separate container on the devices segregating work and personal data.
This document covers the configurations required to enable Apple User Enrollment on iOS devices with Sign in to Work or School account.
Pre-requisites
- You should have a managed Apple ID. These are the Ids provided by Apple when you have a Business Manager or School Manager account.
- The managed apple ID should be imported on the Scalefusion Dashboard under User Enrollment
- Minimum Supported OS: iOS 15 onwards
- Apple User Enrollment Profile is created
- Users should be assigned a User Group with Apple User Enrollment Profile.
- Your domain name should be verified in Apple Business Manager or Apple School Manager
To enroll devices with this method, following are the steps:
Step 1: Configure Apple User Enrollment Settings
- On Scalefusion Dashboard, navigate to Getting Started > Apple Setup > Apple User Enrollment
- There are two tabs under Apple User Enrollment Settings, viz.
- Enrollment Settings: Allows you to configure basic enrollment settings. They are:
- Show Terms of Use during Enrollment: If enabled, Users will be shown the Terms of Use configured in Organization Info before they enroll the devices.
- Force Sign In again After: Users will be asked to sign in to Work or school again after the configured time. Select time from the drop-down:
- Never
- 8 hours
- 12 hours
- 24 hours
- 36 hours
- 48 hours
- 72 hours
- After configuring, click Save
- Domain Configuration: Next step is to download the JSON file and host it in the domain that you have verified. To do so,
- Under Domain Configuration, click on the button Download JSON. This downloads the json file on your system.
- Please rename the downloaded file to com.apple.remotemanagement
- Now host it on your domain. For example, if your domain name is 'onplex.com', then download the JSON file and host it at https://*onplex*/.well-known/com.apple.remotemanagementPlease ensure and confirm the content type for this file is set to application/json. This may also be known as MIME type in some server softwares
- Under Domain Configuration, click on the button Download JSON. This downloads the json file on your system.
- Enrollment Settings: Allows you to configure basic enrollment settings. They are:
Step 2: Enrolling iOS device
After configuring Apple User Enrollment settings, follow these steps on your iOS device to enroll it with Scalefusion:
- Navigate to Settings app on the device and go to VPN & Device Management
- Click on Sign in to Work or School account.. under VPN & Device Management
- Here, enter your managed Apple ID and click Continue
- You will get the Terms of Service page. Review the terms and click Accept
- Now, Click on Confirm on this screen. An OTP will be sent on your registered email id.
- On the next screen, enter the OTP (you have received on the email id) and click Confirm
- On the next screen, click on Sign In to iCloud
- Now, enter the password for your managed Apple ID and click Sign In
- On the next screen, click on Allow Remote Management
- It may take few minutes to configure. You will get the screen to wait.
- Once done, you should get the following screen with the managed Apple ID showing up under Managed Account. This confirms that the enrollment process is complete, and your device is now managed. The applications and policies pushed by your IT Admin will start getting installed.
Frequently Asked Questions
Question: While enrolling iOS device via Apple User Enrollment, the users get an error Sign-In Failed. What can be the reason?
Answer: It appears the server is not configured to correctly identify the file type. Please ensure and confirm the content type is set to application/json. This may also be known as MIME type in some server softwares.
Question: Will the process of enrollment be same if I have a GSuite/O365 account?
Answer: If you have a GSuite/O365 account federated, the process is slightly different. On the device, you will be asked to authenticate with the respective provider after accepting Terms & Conditions. Hence,
- After Step #4 (mentioned above) you will get the following screen. Click on Authenticate.
- This will take you to the Microsoft authentication screen (this is for O365 account). Select your Apple ID
- Enter password and click on Sign In to authenticate.
- Once authenticated, you will get the screen to Sign In to iCloud (Step #7 above). After that the steps will be same as above for enrolling device.