Intune Web-based Enrollment Prerequisites
- Intune is the MDM Authority
- Apple MDM certificate is configured
- Intune license for the end-user
- iOS Enrollment profile
- Just-in-Time(JIT) device configuration profile
Step 1: Create Web-based device enrollment profile for iOS in Intune
In the Intune admin center, browse to Devices/Enrollment/Apple and select Enrollment types
Step 2:
Select Create Profile/iOS/iPadOS
Step 3:
Provide a name of the enrollment profile
Step 4:
Select Web-based device enrollment
Step 5:
Like other enrollment profiles, select a target group of users allowed to use it
Step 5:
Note : Use the left section to change the priority order of the various profiles in case the user is targeted by multiple enrollment profiles.
Create a Just-in-time registration device configuration profile
Why JIT configuration?
Just-in-time registration is required to use the Apple Single sign-on(SSO) extension to complete the Microsoft Entra registration of the device. Just in time will limit the number of authentication prompts by establishing the SSO across the whole device for Microsoft products
Step 1 :
In theIntune admin center, browse to Devices/Configuration and create a new policy
Step 2:
Select iOS, Templates and Device Features. Click Create
Step 3 :
Provide the name
Step 4:
Under Single sign-on app extension, select Microsoft EntraID
Additional configurations are needed.
App Bundle ID isn’t required for our current need.
2 keys are needed
Key: device_registration
Type: String
Value: {{DEVICEREGISTRATION}}
Key: browser_sso_interaction_enabled
Type: Integer
Value: 1
Note : Avoid additional space before/after those values, otherwise Just-in-Time won’t work!!
Step 5:
Assign the device configuration to the same group as the Enrollment profile for convenience.
Enroll iOS using Web-based device enrollment
- Open Safari, and open one of those links:
- https://portal.manage.microsoft.com/conditionalaccess/enrollment
- https://portal.manage.microsoft.com/enrollment/webenrollment/ios
- This enrollment method is only supported from Safari browser!
Sign-in with Microsoft Entra ID credentials
Click on Get Started
Allow this website to download a configuration profile.
Go to Settings / General / VPN & device management
A prompt will ask to install the Microsoft Intune root certification authority, click on Install and Trust
Once the profile is installed, the enrollment is completed and the device will begin to process policies and applications!