{"id":13441,"date":"2022-06-07T03:31:20","date_gmt":"2022-06-07T03:31:20","guid":{"rendered":"https:\/\/www.applivery.com\/?post_type=docs&#038;p=13441"},"modified":"2024-10-10T23:48:45","modified_gmt":"2024-10-10T23:48:45","password":"","slug":"user-enrollment","status":"publish","type":"docs","link":"https:\/\/www.applivery.com\/pt-br\/docs\/mobile-device-management\/apple-mdm\/enrollment-apple-mdm\/user-enrollment\/","title":{"rendered":"User enrollment"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"13441\" class=\"elementor elementor-13441\" data-elementor-post-type=\"docs\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6ad93c6 e-con-full e-flex e-con e-parent\" data-id=\"6ad93c6\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fa72a9d elementor-widget elementor-widget-text-editor\" data-id=\"fa72a9d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Starting in iOS 13 and macOS 10.15 Catalina, Apple introduced a new enrollment method called User Enrollment.<\/p><p>This is a notably different mode of enrollment than the previously available through Apple DEP, Enrollment link, or Supervised mode.<\/p><p>While these modes still exist, <strong>User Enrollment (sometimes referred to as <em>UEMDM<\/em>) aims to address Bring Your Own Device (BYOD) deployment scenarios specifically.<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6812982 elementor-alert-warning elementor-widget elementor-widget-alert\" data-id=\"6812982\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"alert.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-alert\" role=\"alert\">\n\n\t\t\t\t\t\t<span class=\"elementor-alert-title\">Private beta feature<\/span>\n\t\t\t\n\t\t\t\t\t\t<span class=\"elementor-alert-description\">Please note that <strong>User Enrollment<\/strong> is still in private beta for a limited number of clients. If you want to learn more, please contact us at <a href=\"mailto:sales@applivery.com\">sales@applivery.com<\/a>.<\/span>\n\t\t\t\n\t\t\t\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a327f55 elementor-widget elementor-widget-heading\" data-id=\"a327f55\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Why Another Enrollment Mode?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d0b5030 elementor-widget elementor-widget-text-editor\" data-id=\"d0b5030\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\tExisting enrollment and supervision methods are very powerful. Administrators can wipe, lock, and heavily restrict access on a DEP-enrolled and supervised device. In macOS, administrators can run any type of root-level commands or scripts and apply highly intrusive configurations at the device and app levels. Additionally, administrators can list and obtain detailed information about the devices even about apps that have not been deployed through an MDM solution. In other words, administrators have almost full control over managed devices.\n\n<strong>User Enrollment aims to solve this use case by restricting what MDMs can do<\/strong>. Instead of having full access to the devices, <strong>business, and personal spaces are isolated<\/strong>. Commands and operations performed by the MDM are limited and restricted to tun under the business side of the device, providing a more comfortable scenario for end-users that can still get access to business services without requiring the users to sacrifice their privacy. This, in the end, provides <strong>a more balanced scenario between security and privacy, allowing users to easily switch from work to personal life<\/strong>.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ba79c39 elementor-widget elementor-widget-heading\" data-id=\"ba79c39\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What\u2019s different from other enrollment methods?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b56b6bb elementor-widget elementor-widget-text-editor\" data-id=\"b56b6bb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Device Information:<\/strong><br \/>The MDM is no longer able to retrieve device-identifying information, such as a serial number, universal device identifier (UDID), IMEI, or Mac addresses. Instead, the device provides an anonymized identifier specifically created for the MDM enrollment. If a device is unenrolled from the MDM and then re-enrolls at a later time, a new identifier is generated, maintaining the anonymity of the end-user and the hardware.<\/p><p><strong>App Management:<\/strong><br \/>MDMs can still install and remove Apps but now they can just see the information about managed Apps. The rest of the Apps installed by the user remain private and will not be visible by the MDM and they can not be configured as managed apps.<\/p><p>Additionally, some native apps are prepared for User Enrollment scenarios, providing also the possibility to isolate information at the App level.<\/p><p><strong>Profiles &amp; Configurations:<\/strong><br \/>Just a few profiles and configurations are available and can be enforced on the device:<\/p><ul><li>Wi-Fi.<\/li><li>Per-app VPN.<\/li><li>Account-related profiles, like email, calendar, contact, and Exchange\/ActiveSync.<\/li><\/ul><p>\u00a0<\/p><p><strong>Commands:<\/strong><br \/>User Enrollment also prevents administrators from setting or clearing passwords, wiping the device, and performing other device-level configurations.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4f61f28 elementor-widget elementor-widget-heading\" data-id=\"4f61f28\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What\u2019s different from other enrollment methods?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5202d35 elementor-widget elementor-widget-text-editor\" data-id=\"5202d35\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The User Enrollment method relies on Managed Apple IDs for user identification. This also enables two important features:<\/p><ul><li><strong>App &amp; media licensing:<\/strong> apps must be managed through Apple Business Manager and VPP so that necessary licenses are provisioned.<\/li><li><strong>iCloud access:<\/strong> Apple provides business-level iCloud services, such as shared storage for an organization. The Managed Apple ID acts as a credential to provide access to these resources.<\/li><\/ul><p>We highly recommend reading the documentation related to Managed Apple IDs to fully understand the benefits and features.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1619021 elementor-widget elementor-widget-heading\" data-id=\"1619021\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How is data separation being managed?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1c401ab elementor-widget elementor-widget-text-editor\" data-id=\"1c401ab\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\tAs part of the User Enrollment process, <strong>a new and separate APFS volume is created in the device<\/strong>. This new volume acts as a virtual hard drive with its encryption and is <strong>isolated from other data volumes in the device<\/strong>. This volume will store all User Enrollment-related data.\n\n<strong>When the device is unenrolled, the volume is erased<\/strong>, removing also all managed apps and managed data stored on it, returning the device to the original state before enrollment.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Discover how Apple devices can be enrolled by the user to support Bring Your Own Device (BYOD) scenarios<\/p>\n","protected":false},"author":1,"featured_media":32390,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"content-type":"","inline_featured_image":false,"footnotes":""},"product":[315],"doc_category":[319],"doc_tag":[],"class_list":["post-13441","docs","type-docs","status-publish","format-standard","has-post-thumbnail","hentry","product-apple-mdm","doc_category-enrollment-apple-mdm"],"aioseo_notices":[],"year_month":"2026-06","word_count":633,"total_views":"2851","reactions":{"happy":"1","normal":"0","sad":"0"},"author_info":{"name":"applivery","author_nicename":"applivery","author_url":"https:\/\/www.applivery.com\/pt-br\/blog\/author\/applivery\/"},"doc_category_info":[{"term_name":"Enrollment","term_url":"https:\/\/www.applivery.com\/docs\/mobile-device-management\/apple-mdm\/enrollment-apple-mdm\/"}],"doc_tag_info":[],"knowledge_base_info":[],"knowledge_base_slug":[],"_links":{"self":[{"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/docs\/13441","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/comments?post=13441"}],"version-history":[{"count":8,"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/docs\/13441\/revisions"}],"predecessor-version":[{"id":49210,"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/docs\/13441\/revisions\/49210"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/media\/32390"}],"wp:attachment":[{"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/media?parent=13441"}],"wp:term":[{"taxonomy":"product","embeddable":true,"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/product?post=13441"},{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/doc_category?post=13441"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/www.applivery.com\/pt-br\/wp-json\/wp\/v2\/doc_tag?post=13441"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}