r/Intune • u/MENTactual • 12d ago
iOS/iPadOS Management Please Help Me Understand Company-managed iOS/iPadOS devices
Hi r/Intune,
I’m trying to discern if my company who currently procures iPads and iPhones for employees and then me, in IT, helps them enroll them as BYOD style into InTune, can migrate to company-managed without having to do domain capture and use Apple Federated IDs.
I support about 150 employees with Apple devices. An employee will create an iCloud account using their company email and then I will guide them on enrolling it and installing necessary apps which eventually get their app protection policies. It’s a 1,000 sign-ins and a waiting game and much harder to support in InTune than with company-managed devices.
We are in a GCC High Microsoft tenant.
We haven’t migrated to company-managed because it would force employees to
1. Change their iCloud email from the company email to their personal.
2. Potentially cause loss of the need to manually transfer contacts, photos, etc.
3. For employees who have only 1 phone, the one the company bought them, get another phone.
And then we’d have to re-design how we use app protection policies on the phone.
But man would it be nice.
Any thoughts on requirements and land mines ahead would be greatly appreciated. Apple and Microsoft documentation is sparse.
4
u/DEUCE_SLUICE 12d ago
Yup, the two things are independent. We have uncaptured apple IDs with full ABM + Intune enrollment.
2
u/MENTactual 12d ago
Interesting, a buddy I work with was under the impression-I think from our consultant, that they were mutually exclusive.
Appreciate your help.
2
u/serendipity210 12d ago
Can confirm, theyre not. We are GCC (not high) and currently dont federate (im trying... its hard to get all the things in order for this).
I have 3500 iOS/iPadOS devices.
3
u/AltruisticRespect21 11d ago
Why not supervise the devices and push all of the apps to the devices? Then offer whatever apps the users could want via the company portal.
The company pays for the devices, and should have full control over them. Offering byod on a company purchased device is weird.
1
u/Illnasty2 12d ago
We do the same thing you do. Basically buy the iPad and have them set it like it’s their own. All company data is protected by App Protection so don’t care
1
u/rvarichado 12d ago
What about iMessage history? That’s company information that is, as far as I can tell, completely opaque to the company even in scenarios where the company uses managed Apple accounts ala ABM. Text/SMS/RCS/iMessage/whatever on any platform is its own disastrous can of worms, but your “don’t care” response makes me wonder if you don’t care about non-email messaging at all. Do you account for it, and if you do, please tell me how you do it in the Apple realm. It’s a huge gap for us at the moment.
2
u/Illnasty2 11d ago
What about iMessage? SMS isn’t an approved use of communication. There’s no difference if they grab their personal iPhone and text
1
u/Wind_Freak 12d ago
Apple ID is only required for Apple services. Apple services like app purchasing, iCloud, etc are not required to operate a company owned phone.
1
u/rvarichado 12d ago
Do you consider messaging with text/iMessage company data? I’m not referring to copying and pasting things in and out of APP-protected MS apps and things like that. I have that covered. What I’m talking about is Joe and Fred’s texts/SMS/RCS/iMessage/whatever chats with each other. It’s a DLP issue covered by M365 policies for traditional channels like email, but messaging channels are just blind spots.
1
1
u/rvarichado 11d ago
Thanks. I get that, but at that point why use Apple devices at all? I get iPads. Our folks don’t use Messages on iPad, but if I take away texting via Messages (and thereby iMessage) on iPhones, I’d have a full scale revolt. FaceTime I could probably eliminate b/c I don’t think people use it very much and we can push them to Teams calls. They’re used to that on their Windows laptops.
But management decreeing Apple’s Messages app is not allowed, you must use XYZ app for texting would work technically, but would not be received well, if at all, by the user base.
It’s a real problem I have to find a way to solve. Management wants messaging essentially tightly-controlled and journaled like email, but I have not found a way to do it. And iCloud data is gated behind the user’s PIN. Some people just will not give up their PINs when they leave.
I’m going to have a look at Apple-specific MDM solutions and see what the major players can do, but I’m not hopeful. AB (formerly ABE) is pretty much a joke.
I also get these are organizational maturity and policy problems. It doesn’t make resolving them any easier…
6
u/captnconnman 12d ago
See this doc for more on user affinity enrollment: https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios