Enrolling BYOD Apple devices (User enrollment)

Read this section to understand how the users can enroll BYOD Apple devices to MDM when the admin shares the enrollment URL.

Before you begin

  • Ensure you have the Managed Apple ID
  • Ensure you have the AD credentials which is the associated business manager account

About this task

Users must visit the enrollment URL that is shared by BigFix administrator (via email or chat). This enrollment URL is the FQDN of the MDM Server (For example, https://enroll-mdm.bigfix.com).

To enroll the Apple device in MDM, follow these steps:

Procedure

  1. On the Apple device, launch a web browser and navigate to the MDM Server URL.
  2. Enter a valid email address and password associated with the Active Directory deployment configured when the MDM Server was set up.
  3. Select ownership type of the device as Personally Owned to enroll your BYOD device.
    Note:
    • Click the information button to read the information as to what an IT admin can and cannot do on a personally owned device.
    • The option "Institutionally Owned" is the default option. When selected, it takes you through the device enrollment flow to enroll the company-owned device.
  4. The text box to enter Managed Apple ID appears. Enter your managed Apple ID to install MDM profile.
  5. Click Enroll to download the Apple enrollment profile.
  6. OSX opens this Enrollment Profile and shows users the information about the MDM deployment they are about to enroll in. If things look okay, click Install to enroll the device in MDM.

Results

The MDM profile gets installed. User sees a personal profile and a company profile. The organization does not have access to the personal profile and hence cannot wipe, lock, or impose any control over the personal use of the device. The organization can manage only the company profile section.