{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/",
        "slug": "dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/"
        },
        "title": "Check for duplicate Company Portal configuration during Apple ADE",
        "summary": "Why might Company Portal request a management policy that an ADE device has already installed?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:50+00:00",
        "modified_at": "2026-09-10T01:40:02+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 213,
        "potentially_affected": "Use this diagnosis for the specific initial-enrollment combination above. Distinguish that flow from a deliberate userless-device staging transition before changing an assignment.",
        "dse_recommendation": "Trace every Company Portal configuration assignment reaching the affected device and user.",
        "primary_source": {
            "name": "Set up automated device enrollment (ADE) for iOS/iPadOS - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>During initial iOS/iPadOS ADE with Setup Assistant modern authentication, Intune sends Company Portal app configuration automatically when Install Company Portal is enabled. Microsoft warns that manually targeting the same configuration to users creates a conflict and can prompt them to download a management policy already present. The separate userless-to-user staging procedure restricts its app-configuration targeting to ADE devices without user affinity. <a href=\"https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this diagnosis for the specific initial-enrollment combination above. Distinguish that flow from a deliberate userless-device staging transition before changing an assignment.</p>\n<h2>DSE recommendation</h2>\n<p>Trace every Company Portal configuration assignment reaching the affected device and user. Have the enrollment owner identify which settings arrive automatically and which were added for staging. Correct an unintended overlap through a reviewed targeting change; avoid instructing users to repeatedly install a management policy as the first response to this documented symptom.</p>\n<h2>Verification</h2>\n<p>Enroll a representative test device with the corrected assignments and observe the full Company Portal sequence. Confirm the expected registration and application access without the duplicate policy-download request. Test the separate staging population independently so the correction does not silently remove its needed configuration. Preserve assignment identities, enrollment options, and observed prompts without recording credentials.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Set up automated device enrollment (ADE) for iOS/iPadOS</a>.</p>",
        "content_text": "Source facts\nDuring initial iOS/iPadOS ADE with Setup Assistant modern authentication, Intune sends Company Portal app configuration automatically when Install Company Portal is enabled. Microsoft warns that manually targeting the same configuration to users creates a conflict and can prompt them to download a management policy already present. The separate userless-to-user staging procedure restricts its app-configuration targeting to ADE devices without user affinity. Microsoft Learn.\nApplicability\nUse this diagnosis for the specific initial-enrollment combination above. Distinguish that flow from a deliberate userless-device staging transition before changing an assignment.\nDSE recommendation\nTrace every Company Portal configuration assignment reaching the affected device and user. Have the enrollment owner identify which settings arrive automatically and which were added for staging. Correct an unintended overlap through a reviewed targeting change; avoid instructing users to repeatedly install a management policy as the first response to this documented symptom.\nVerification\nEnroll a representative test device with the corrected assignments and observe the full Company Portal sequence. Confirm the expected registration and application access without the duplicate policy-download request. Test the separate staging population independently so the correction does not silently remove its needed configuration. Preserve assignment identities, enrollment options, and observed prompts without recording credentials.\nOfficial references\nMicrosoft Learn: Set up automated device enrollment (ADE) for iOS/iPadOS.",
        "content_markdown": "## Source facts\n\nDuring initial iOS/iPadOS ADE with Setup Assistant modern authentication, Intune sends Company Portal app configuration automatically when Install Company Portal is enabled. Microsoft warns that manually targeting the same configuration to users creates a conflict and can prompt them to download a management policy already present. The separate userless-to-user staging procedure restricts its app-configuration targeting to ADE devices without user affinity. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios).\n\n## Applicability\n\nUse this diagnosis for the specific initial-enrollment combination above. Distinguish that flow from a deliberate userless-device staging transition before changing an assignment.\n\n## DSE recommendation\n\nTrace every Company Portal configuration assignment reaching the affected device and user. Have the enrollment owner identify which settings arrive automatically and which were added for staging. Correct an unintended overlap through a reviewed targeting change; avoid instructing users to repeatedly install a management policy as the first response to this documented symptom.\n\n## Verification\n\nEnroll a representative test device with the corrected assignments and observe the full Company Portal sequence. Confirm the expected registration and application access without the duplicate policy-download request. Test the separate staging population independently so the correction does not silently remove its needed configuration. Preserve assignment identities, enrollment options, and observed prompts without recording credentials.\n\n## Official references\n\n[Microsoft Learn: Set up automated device enrollment (ADE) for iOS/iPadOS](https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check for duplicate Company Portal configuration during Apple ADE",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/",
                "headline": "Check for duplicate Company Portal configuration during Apple ADE",
                "description": "Why might Company Portal request a management policy that an ADE device has already installed?",
                "abstract": "Why might Company Portal request a management policy that an ADE device has already installed?",
                "articleBody": "Source facts\nDuring initial iOS/iPadOS ADE with Setup Assistant modern authentication, Intune sends Company Portal app configuration automatically when Install Company Portal is enabled. Microsoft warns that manually targeting the same configuration to users creates a conflict and can prompt them to download a management policy already present. The separate userless-to-user staging procedure restricts its app-configuration targeting to ADE devices without user affinity. Microsoft Learn.\nApplicability\nUse this diagnosis for the specific initial-enrollment combination above. Distinguish that flow from a deliberate userless-device staging transition before changing an assignment.\nDSE recommendation\nTrace every Company Portal configuration assignment reaching the affected device and user. Have the enrollment owner identify which settings arrive automatically and which were added for staging. Correct an unintended overlap through a reviewed targeting change; avoid instructing users to repeatedly install a management policy as the first response to this documented symptom.\nVerification\nEnroll a representative test device with the corrected assignments and observe the full Company Portal sequence. Confirm the expected registration and application access without the duplicate policy-download request. Test the separate staging population independently so the correction does not silently remove its needed configuration. Preserve assignment identities, enrollment options, and observed prompts without recording credentials.\nOfficial references\nMicrosoft Learn: Set up automated device enrollment (ADE) for iOS/iPadOS.",
                "datePublished": "2026-09-10T00:26:50+00:00",
                "dateModified": "2026-09-10T01:40:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check for duplicate Company Portal configuration during Apple ADE"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 213,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Set up automated device enrollment (ADE) for iOS/iPadOS - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios"
                }
            }
        ]
    }
}