Microsoft Intune
Device enrollment

Setup Automated Ios

In brief

The option must be set to No and will soon be removed. The Sync with computers setting was deprecated by Apple in iOS 13 and is no longer included in enrollment policies.

What Intune admins need to know

Set Run Company Portal in Single App Mode until authentication to No in applicable enrollment policies.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

We recommend using **Setup Assistant with modern authentication** for your Apple devices for ADE (automated device enrollment) scenarios with user device affinity. Legacy authentication is deprecated and we don't recommend its use.
  1. If you select a token for Install Company Portal with VPP, you can lock the device in Single App Mode (specifically, the Company Portal app) right after the Setup Assistant completes. Select Yes forThe Run Company Portal in Single App Mode until authentication to set this option. To use the device, the user must first authenticate by signing in to the Company Portal.

    Note

    Multifactor authentication isn'toption is no longer supported on a single device locked in Single App Mode.and will soon be removed. This limitation exists because the device can't switch to a different app to complete the second factor of authentication. If you want multifactor authentication on a Single App Mode device, the second factoroption must be on a different device.

    This feature is supported only for iOS/iPadOS 11.3.1 and later.

    Screenshot that shows the Run Company Portal in Single App Mode option.set to No.

  2. If you want devices using this policy to be supervised, select Yes in the Supervised list.

    Supervised devices give you more management options and disabled Activation Lock by default. We recommend that you use ADE as the mechanism for enabling supervised mode, especially if you're deploying large numbers of iOS/iPadOS devices. Apple Shared iPad for Business devices must be supervised. Important

    This setting is different from the remove and reset options in the Company Portal app. Regardless of how you configure locked enrollment, the Remove Device or Factory Reset options in the Company Portal app remain unavailable on devices enrolled through automated device enrollment. Users won't be able to remove the device on the Company Portal website either. For more information about the self-service actions available on enrolled devices, see Self-service actions.

    Note

    The Sync with computers setting was deprecated by Apple in iOS 13 and is not included in enrollment policies.

  3. If you selected Enroll without User Affinity and Supervised in the previous steps, you need to decide whether to configure the devices to be Apple Shared iPad for Business devices. Select Yes for Shared iPad to enable multiple users to sign in to a single device. Users authenticate by using their Managed Apple IDs and federated authentication accounts or by using a temporary session (like the Guest account). This option requires iOS/iPadOS 13.4 or later. With Shared iPad, all Setup Assistant panes after activation are automatically skipped.

    Note

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…