Skip to content

Set up Apple User Enrollment

To set up Apple User Management in Sophos Mobile, you create a policy and configure enrollment settings for Sophos Central Self Service Portal.

Requirements

Before you set up Apple User Enrollment in Sophos Mobile, you need to do the following:

  1. Enroll your organization in Apple Business Manager. See Apple Business Manager User Guide: Sign up for Apple Business Manager.
  2. Set up managing Apple Business Manager apps (formerly VPP apps) in Sophos Mobile. See Manage Apple Business Manager apps.
  3. For account-driven Apple User Enrollment, configure service discovery. See Configure service discovery.

Set up Apple User Enrollment

To set up Apple User Enrollment, do as follows:

  1. Create an iOS & iPadOS user policy.
  2. Create a task bundle with an Enroll task.

    When in the Add enrollment task assistant, select iOS User Enrollment.

    Select the "iOS User Enrollment" enrollment type.

  3. Optional: Add a policy to the task bundle to assign it to devices when they enroll.

    You can choose to assign the policy later or assign no policy.

    Select a policy.

  4. Optional: If required, you can add Install app and Send message tasks to the task bundle.

  5. Optional: Create a device group for devices with Apple User Enrollment.
  6. Create a Self Service Portal configuration or edit an existing configuration.

    When you configure the platform settings, do as follows:

    • In Enrollment package, select your task bundle.
    • Select Account-driven Apple User Enrollment to use the configuration for account-driven Apple User Enrollment. Clear the checkbox to use the configuration for profile-based Apple User Enrollment.

      For the differences between account-driven and profile-based Apple User Enrollment, see Account-driven vs. profile-based Apple User Enrollment.

    SSP platform settings for Apple User Enrollment.

    For a detailed description of creating Self Service Portal configurations, see Create Self Service Portal configurations.

  7. If necessary, repeat the previous step to create more Apple User Enrollment configurations. When enrolling their devices, users can choose from all the configurations you created.

Before a user can enroll a personal iPhone or iPad, you must create a Managed Apple ID for them in Apple Business Manager. See Apple Business Manager User Guide: Use Managed Apple IDs in Apple Business Manager.