HomeSetup guides › Enrol a test iPhone or iPad via Apple ADE
Setup guide · from scratch

Enrol a test iPhone or iPad via Apple ADE

Take an ADE-assigned iPhone or iPad from a factory-reset state through Setup Assistant to fully enrolled, supervised and compliant in Intune — the visible payoff of all the Apple token work. The trap: the enrolment profile must already be assigned and synced to the device's serial before you switch it on, or first boot skips the Remote Management screen entirely and there is nothing to sign into.

A supervised iPhone/iPad + Apple Setup Assistantassisted guide — Decolla walks you through this
≈ 25 min
Apple — iPhone, iPad & Mac · step 11 of 12 · ≈ 25 min‹ PreviousNext ›
The Decolla way — skip the clicks.

Every step below can be done by hand. Or connect your Microsoft tenant to Decolla once, and Decolla performs this for you over Microsoft Graph in your own tenant — then hands back a verified result you can see and roll back per item. It also puts the fundamentals this step depends on in place — the target group, the licence allocation — so a build is never blocked half-way by a missing dependency.

⏱ By hand: about 25 min of clicking, every build. The Decolla way: part of one tenant connect, then automatic.
0 of 10 done
Step 1. Before you touch the device, confirm the groundwork in Intune: go to Devices > Enrollment > Apple mobile > Enrollment program tokens (in newer tenants Enrollment sits under Devices > Device onboarding), open your token, and check that this device's serial appears under Devices with an enrolment policy assigned (or that the policy is Set as Default Policy for the token).
Screenshot: Intune token > Devices list showing the test serial with a profile/policy assigned (captured during a live customer build — coming to this page)
Why: ADE only fires if a policy is waiting for the serial before first boot. A synced-but-unassigned device that someone switches on fails enrolment and shows 'Invalid Profile'.
Watch for: A freshly added serial can take up to 12 hours to sync from Apple, or a manual token Sync — do not start the device-side flow until it actually shows in Intune.
Step 2. Erase the device back to an out-of-box state: on the device open Settings > General > Transfer or Reset iPhone (or iPad) > Erase All Content and Settings, and confirm. A brand-new, factory-sealed device is already in this state — skip straight to step 3.
Screenshot: Erase All Content and Settings confirmation screen on the device (captured during a live customer build — coming to this page)
Why: ADE enrolment is only offered during the first-boot Setup Assistant. A device already past setup will never present the Remote Management screen, no matter what is assigned in Intune.
Watch for: If the device is signed into a personal iCloud / Find My, the erase demands that Apple ID's password first (Activation Lock). Sign out of iCloud, or clear the lock, before wiping — otherwise it stalls at a hello screen asking for someone else's Apple ID.
Don’t: Do NOT try to enrol a device that is already set up and in daily use — erasing is not optional for ADE.
Step 3. Power on the erased device and work through the opening Setup Assistant panes: pick language and region, then join a Wi-Fi network (or use cellular) that has real internet access.
Screenshot: Setup Assistant Wi-Fi / network selection pane (captured during a live customer build — coming to this page)
Why: During activation the device reaches out to Apple over the internet to fetch its ADE enrolment profile. No connection means no Remote Management screen and no enrolment.
Watch for: Captive-portal or sign-in guest Wi-Fi can silently break the profile fetch. Use a plain WPA2/WPA3 network you trust for the test.
Step 4. At the Remote Management screen, read the message — it should name your organisation, e.g. 'Your organisation will automatically configure this iPhone' — then tap Continue (or Next) to accept management.
Screenshot: Remote Management pane naming your organisation, with the Continue button (captured during a live customer build — coming to this page)
Why: This screen appearing at all is the on-device proof that the ADE profile arrived. It is the moment management is accepted.
Watch for: If Remote Management never appears and the device just carries on to a normal personal setup, the serial is not assigned/synced or no policy is set as default — stop and fix step 1 rather than continuing.
Don’t: Do NOT expect a 'skip' or 'set up as personal' option — the Remote Management screen is mandatory for any ADE device assigned to your MDM server in ABM. 'Locked enrollment' in the policy is a separate setting - it controls whether the management profile can be REMOVED after enrolment, not whether this screen can be skipped.
Step 5. When the sign-in sheet appears, sign in with the user's work account: enter their Microsoft Entra email and password, then complete the MFA prompt. This is Setup Assistant with modern authentication.
Screenshot: The Microsoft work-account web sign-in sheet shown inside Setup Assistant (redact the address) (captured during a live customer build — coming to this page)
Why: This authenticates the user, registers the device in Microsoft Entra ID, and stamps the primary user — which is what later drives Company Portal, app assignment and Conditional Access.
Watch for: The account MUST have an Intune licence assigned or enrolment fails here; and MFA must be reachable on a second device, since this one is mid-setup and cannot switch apps.
Step 6. Complete any remaining Setup Assistant panes (most are usually hidden by the policy), then let the device sit on the 'Awaiting final configuration' locked screen while Intune installs your device configuration policies.
Screenshot: The 'Awaiting final configuration' / locked Setup Assistant screen (captured during a live customer build — coming to this page)
Why: This deliberate pause exists because 'Await final configuration' is set to Yes — it holds the device before the Home screen so your critical configuration policies land first.
Watch for: Only device configuration policies install during this screen — apps do not. Most devices release to the Home screen within about 15 minutes; markedly longer usually points to a conflicting or failing configuration policy, not slow app installs (see the related 'stuck at Awaiting final configuration' article).
Step 7. Once the Home screen loads, let Company Portal install itself. It arrives silently as a Required VPP app with device licensing — you deployed it through Intune, not from the App Store. Open it once and confirm it already recognises the device without asking you to sign in again.
Screenshot: Company Portal open on the device showing the enrolled device already recognised (captured during a live customer build — coming to this page)
Why: With Setup Assistant modern authentication and just-in-time registration, Company Portal completes the Entra registration automatically — a second sign-in should not be needed.
Watch for: If Company Portal prompts you to sign in and 'download a management profile' you clearly already have, you have deployed the Company Portal app-configuration manually as well as via enrolment — remove the manual app-config policy from ADE devices.
Don’t: Do NOT install the App Store version of Company Portal on ADE devices — it is not ADE-compatible and will not auto-update.
Step 8. Verify supervision on the device itself: open Settings and read the banner at the very top — it should say 'This iPhone is supervised and managed by [your organisation]'. Then open Settings > General > VPN & Device Management to see the installed management profile.
Screenshot: Settings supervision banner plus the management profile under VPN & Device Management (captured during a live customer build — coming to this page)
Why: The supervision banner is Apple's own on-device confirmation, and supervision is what unlocks the stricter controls (blocking AirDrop, screenshots, etc.) that separate a corporate device from a personal one.
Watch for: The exact path to the profile varies by iOS version — it is under Settings > General, labelled 'VPN & Device Management' on current iOS and 'Device Management' or 'Profiles & Device Management' on older builds. If the supervision banner is missing, the device did not enrol via ADE.
Step 9. Back in Intune, verify the enrolment: go to Devices > All devices and find the device by its serial or device name. On its Overview, confirm Ownership = Corporate, the Management name is populated, and Supervised = Yes.
Screenshot: Intune device Overview showing Supervised: Yes and Ownership: Corporate (captured during a live customer build — coming to this page)
Why: Supervised = Yes on the Intune record is the admin-side proof that ADE — not a manual or BYOD path — enrolled the device. This is the confirmation the whole Apple token chain was built to produce.
Step 10. Confirm compliance last: on the same device record check the Compliance state, and give your compliance policy a few minutes to evaluate (or trigger a sync from Company Portal on the device). Confirm it settles to Compliant.
Screenshot: Intune device record showing Compliance state = Compliant (captured during a live customer build — coming to this page)
Why: Compliance proves the device is not just enrolled but actually meeting your policy — the final tick that a real fleet device would need before Conditional Access lets it reach company resources.
Watch for: Compliance is not instant. A brand-new enrolment often shows 'Not evaluated', 'In grace period' or even 'Not compliant' at first — do not read that as a failure; it resolves after the first policy evaluation.
On a schedule: If it has not turned Compliant after roughly 15 minutes and a manual sync, check that a compliance policy is actually assigned to a group this device belongs to — an unassigned policy never evaluates.

Put these on a schedule

StepRecurring action to diarise
Step 10If it has not turned Compliant after roughly 15 minutes and a manual sync, check that a compliance policy is actually assigned to a group this device belongs to — an unassigned policy never evaluates.

If it goes wrong

The failures people actually hit on this process, each with the diagnosis and fix:

See it on a real device.

Decolla is in private build — early-access members see a build defined, deployed and rolled back first.

Get early access