Search all guides & tools⌘ / Ctrl KReader Hub
LAlite£14.99 · Buy on Gumroad ↗

Novice route · iOS and iPadOS

Manage iPhones and iPads without getting lost in Intune.

Eight short stages. Open only the stage you need, follow the portal path, then verify one pilot device before moving on.

Enrol a school-owned iPad ↓

Prerequisites

Make the green lights real.

Users and groups

Pilot users and device groups exist, with an owner and intentional membership.

Licences

Every enrolling user has an Intune-capable licence, unless the documented device-only model applies.

MDM authority

Microsoft Intune is set as the tenant’s mobile-device-management authority.

Apple MDM push certificate

The APNs certificate is active, its Apple account is recorded and renewal has an owner.

Renew, do not replace: renew the existing Apple MDM push certificate with the same Apple account. Replacing it can interrupt management of enrolled Apple devices.

iPad enrolment · administrator and user · checked 8 September 2026

Enrol a school-owned iPad with ADE

  1. Prepare: confirm the Apple MDM push certificate, Intune licensing and Apple School Manager or Apple Business Manager connection. Record certificate and token renewal owners.
  2. Assign and sync: assign the iPad serial to the Intune MDM server in Apple’s portal; sync the enrolment-program token in Intune.
  3. Create the policy: Devices → Device onboarding → Enrollment → Apple mobile → Enrollment program tokens → your token → Enrollment policies → Create policy → iOS/iPadOS.
  4. Choose the design: for a named user, use user affinity and Setup Assistant with modern authentication. Shared or user-less equipment needs a separate design; Apple Shared iPad and Microsoft Entra shared device mode are different features.
  5. Assign before activation: confirm the policy targets the serial before starting a new or authorised erased iPad. Configure Company Portal deployment through Apps and Books with device licensing where required; do not substitute a manual App Store installation for the ADE deployment.
  6. Complete setup: connect to the approved network, follow Remote Management and the configured school sign-in prompts. Complete the required registration flow.
  7. Verify: check the serial, supervision, ownership, intended user affinity, recent check-in and required apps. Test access on the actual iPad before expanding deployment.

Do not reset a working iPad without authorisation and a recovery plan. Assigning a different ADE policy after enrolment does not automatically replay Setup Assistant.

Microsoft’s current ADE procedure and prerequisites. Older deployments may show Profiles instead of Enrollment policies.

Personally owned iPad: follow the approved Company Portal route

Confirm which personal-device enrolment method your organisation permits. In Company Portal, sign in with the organisation account and select Begin. Read the privacy information, then follow the offered enrolment steps. For a downloaded management profile, open Settings, install the profile when prompted and return to Company Portal to finish the checks.

Microsoft Company Portal enrolment checklist with Begin highlighted
Microsoft’s iOS/iPadOS Company Portal example is pictured on an iPhone. Recognise the checklist and Begin button; iPad layout and organisation name vary. This is manual enrolment, not the ADE Setup Assistant screen. Used with permission from Microsoft. Source and full user instructions.

Deployment picture

Move in controlled waves.

Define an exit test for every wave. “The profile was assigned” is not enough; a device must receive it, behave correctly and remain usable after restart and update.

Eight-stage runbook

Open one stage. Finish it. Record the result.

01Plan the deploymentDefine ownership, users, apps and what success looks like.

Portal pathIntune admin center → Devices → Overview

Do this now

Create a named pilot group. List the devices, applications, networks and services the pilot must use. Decide whether each device is personal, 1:1 school-owned, shared or dedicated.

Verify

The pilot has an owner, 5–10 representative devices, entry criteria, exit criteria, a support contact and a rollback decision.

Common trap

Starting with All users or All devices before enrolment, licences and dependencies have been tested.

02Create compliance rulesMeasure health first; enforce access only after reporting works.

Portal pathDevices → Compliance → Policies → Create policy → iOS/iPadOS

Do this now

Begin with supported OS, passcode and threat-level controls that your environment can actually report. Add a clear grace period and a useful noncompliance message.

Verify

Per-setting status shows why the pilot device passes or fails. Only then pilot Conditional Access with tested exclusions and emergency-access accounts.

Common trap

Treating compliance and Conditional Access as the same policy, or blocking users before the device has checked in.

03Configure endpoint securityCombine device posture, mobile threat defence and access decisions.

Portal pathEndpoint security → Overview; Tenant administration → Connectors and tokens

Do this now

Decide whether Microsoft Defender for Endpoint or another supported mobile-threat-defence connector will provide risk. Connect it, test reporting and set a realistic threat threshold.

Verify

A safe device reports an expected risk level and a deliberately risky test can trigger the planned response without affecting production.

Common trap

Creating a threat-level rule without the connector, application and data feed that make the setting meaningful.

04Configure device settingsDeliver Wi-Fi, restrictions, updates and other controls in small profiles.

Portal pathDevices → Manage devices → Configuration → Create → New policy → iOS/iPadOS

Do this now

Create separate profiles for Wi-Fi, certificates, restrictions and updates. Name each with platform, purpose and pilot status. Use Settings Catalog where the required setting is available.

Verify

The profile reports Succeeded and the setting appears on the device after sync. Check per-setting status when it does not.

Common trap

Configuring the same setting in multiple profiles or copying restrictions without testing the classroom and accessibility impact.

05Set up authenticationUse MFA for enrolment and certificates where they solve a defined need.

Portal pathEntra admin center → Protection → Conditional Access; Intune → Configuration

Do this now

Require MFA through the approved Entra policy. For certificate-based Wi-Fi, VPN or email, deploy the trusted root first, then the tested SCEP or PKCS profile.

Verify

A pilot user can enrol, complete MFA and connect to the intended service. Certificate subject, chain and renewal timing are correct.

Common trap

Deploying a certificate profile before the connector, issuing authority, network trust and renewal path are ready.

06Deploy applicationsMake first-day apps required and everything else deliberate.

Portal pathApps → All apps → Create

Do this now

Add required store or Apps and Books applications, web apps and signed line-of-business apps. Use Available for optional applications and app protection where only organisation data needs management.

Verify

Each required app installs under the intended user or device assignment, opens, updates and reports its state in Intune.

Common trap

Mixing user and device assignments without intent, or assigning every application as Required on day one.

07Enrol devicesMatch the method to ownership and whether the device needs a user.

Portal pathDevices → Device onboarding → Enrollment → Apple mobile

Do this now

Use Apple School or Business Manager with Automated Device Enrollment for new school-owned devices. Use Apple Configurator when a wired route is required. Use Apple User or Device enrollment for approved personal devices.

Verify

The serial is assigned to Intune, the enrolment policy is assigned, supervision and ownership are correct, and the expected user affinity appears.

Common trap

Using a personal-device method for organisation-owned equipment or expecting ADE to apply to an already configured device without the documented migration or reset route.

08Run remote actionsBegin with Sync; reserve destructive actions for approved incidents.

Portal pathDevices → All devices → select device → device action

Do this now

Test Sync on a pilot. Document when to use Lost mode, restart, passcode removal, retire, wipe or delete and who can authorise each action.

Verify

The action status, last check-in and behaviour on the physical device agree. Record the result in the support case.

Common trap

Assuming a server-side action status proves an offline device received the command, or deleting evidence before an incident is understood.

Enrolment in one picture

Ownership chooses the route.

School-owned · new or reset

Apple School Manager + ADE

Best fit for scalable, supervised deployment. Assign the device to the Intune MDM server, sync the token, assign an enrolment policy and complete Setup Assistant.

School-owned · wired route

Apple Configurator

Use when a physical Mac connection is appropriate, including direct enrolment for user-less devices. It takes more hands-on time.

Personally owned · approved

User or Device enrollment

Use the least intrusive approved route. If only organisation data in supported apps needs protection, assess whether app protection without device enrolment is sufficient.

Next Apple guide

Need to enrol a Mac instead?

Choose a Mac enrolment route →Search 203 support scenarios →

Search LAlite

A guide, a scenario or a checklist. Find it here.