MC703712: Move to Setup Assistant with modern authentication and JIT registration for iOS/iPadOS ADE devices

Announcement IDMC703712Published Date01-04-2024
ServiceIntuneLast Updated01-04-2024
CategoryPlan for changeExpiration Date06-29-2024
Roadmap IDAction Required by Date
TagsAdmin impact


Summary
                MC703712: Move to Setup Assistant with modern authentication and JIT registration for iOS/iPadOS ADE devices


More Information

In the first half of calendar year 2024, we will stop supporting the option to Run Company Portal in Single App Mode until authentication for iOS/iPadOS automated device enrollment (ADE). Existing enrollment profiles with this configuration will not work for enrolling new devices. Additionally, you will not be able to save new enrollment profiles with this configuration. For more details, read the blog: Transforming the iOS/iPadOS ADE experience in Microsoft Intune

How this will affect your organization:

You have likely already moved to use Setup Assistant with modern authentication and are using Just in time (JIT) registration and compliance remediation with await final configuration set to Yes. However, if you have not, we recommend moving to this authentication method and flow as soon as possible.

After this change, the setting Run Company Portal in Single App Mode until authentication (Devices > iOS/iPadOS > iOS/iPadOS enrollment > Enrollment Program Tokens > select/create Profile > Management Settings) will no longer take effect, regardless of the configuration shown in the UI. Additionally, if the Company Portal is the authentication method (Devices > iOS/iPadOS > iOS/iPadOS enrollment > Enrollment Program Tokens > select/create Profile > Enroll with user device affinity > Company Portal), the app will no longer be automatically sent with the creation of the enrollment profile.

What you need to do to prepare:

Review the updated documentation and several best practices blogs prior to moving. If you do not adopt the Setup Assistant with modern authentication method, new devices will be unable to enroll until you do one of the following:

  1. (Recommended) Select â€Å“Setup assistant with modern authentication†as the authentication method for existing and new enrollment profiles. Additionally, ensure Await final configuration is set to â€Å“Yes†within the enrollment profile and that JIT registration and compliance remediation is configured correctly for your ADE devices.
  2. Use ADE user affinity enrollment with the Company Portal as a required app with the correct app configuration policy attached. Note: The user will need to manually run the Company Portal and complete the enrollment and Microsoft Entra ID registration steps.
Previous Post Next Post