{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/",
        "slug": "dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/"
        },
        "title": "Check the app model before choosing non-wiping Apple direct enrollment",
        "summary": "What user-affinity limitation accompanies Apple Configurator direct enrollment into Intune?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:23+00:00",
        "modified_at": "2026-09-10T02:01:56+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 229,
        "potentially_affected": "Use this decision for corporate iOS or iPadOS devices being prepared with Apple Configurator. Confirm the required application experience before choosing a method merely because it avoids erasure.",
        "dse_recommendation": "Approve the enrollment method against the application's user-association requirements.",
        "primary_source": {
            "name": "iOS/iPadOS direct enrollment - Apple Configurator-Setup Assistant - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-configurator-ios",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Apple Configurator direct enrollment does not wipe an iOS or iPadOS device, but supports only enrollment without user affinity. Setup Assistant enrollment is the separate path that wipes and prepares a device for enrollment. Apps requiring a user association, including Company Portal for line-of-business app installation, do not work with the userless path. The exported direct-enrollment policy file is valid for two weeks and must then be recreated. <a href=\"https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-configurator-ios\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this decision for corporate iOS or iPadOS devices being prepared with Apple Configurator. Confirm the required application experience before choosing a method merely because it avoids erasure.</p>\n<h2>DSE recommendation</h2>\n<p>Approve the enrollment method against the application&#8217;s user-association requirements. Have the device owner and app owner agree on whether a shared, unaffiliated device meets the intended task. Check the actual deployment and sign-in path for every required app, and refresh the exported profile for the planned staging date. Preserve device data through the organization&#8217;s approved process before considering any alternative that wipes the device.</p>\n<h2>Verification</h2>\n<p>On a representative test device, confirm the expected enrollment association, management profile, and usable application workflow. Do not use Company Portal availability as the acceptance criterion for this userless method. Check the profile&#8217;s age before troubleshooting a failed installation, and record why direct enrollment is suitable before distributing devices.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-configurator-ios\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: iOS/iPadOS direct enrollment &#8211; Apple Configurator-Setup Assistant</a>.</p>",
        "content_text": "Source facts\nApple Configurator direct enrollment does not wipe an iOS or iPadOS device, but supports only enrollment without user affinity. Setup Assistant enrollment is the separate path that wipes and prepares a device for enrollment. Apps requiring a user association, including Company Portal for line-of-business app installation, do not work with the userless path. The exported direct-enrollment policy file is valid for two weeks and must then be recreated. Microsoft Learn.\nApplicability\nUse this decision for corporate iOS or iPadOS devices being prepared with Apple Configurator. Confirm the required application experience before choosing a method merely because it avoids erasure.\nDSE recommendation\nApprove the enrollment method against the application’s user-association requirements. Have the device owner and app owner agree on whether a shared, unaffiliated device meets the intended task. Check the actual deployment and sign-in path for every required app, and refresh the exported profile for the planned staging date. Preserve device data through the organization’s approved process before considering any alternative that wipes the device.\nVerification\nOn a representative test device, confirm the expected enrollment association, management profile, and usable application workflow. Do not use Company Portal availability as the acceptance criterion for this userless method. Check the profile’s age before troubleshooting a failed installation, and record why direct enrollment is suitable before distributing devices.\nOfficial references\nMicrosoft Learn: iOS/iPadOS direct enrollment – Apple Configurator-Setup Assistant.",
        "content_markdown": "## Source facts\n\nApple Configurator direct enrollment does not wipe an iOS or iPadOS device, but supports only enrollment without user affinity. Setup Assistant enrollment is the separate path that wipes and prepares a device for enrollment. Apps requiring a user association, including Company Portal for line-of-business app installation, do not work with the userless path. The exported direct-enrollment policy file is valid for two weeks and must then be recreated. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-configurator-ios).\n\n## Applicability\n\nUse this decision for corporate iOS or iPadOS devices being prepared with Apple Configurator. Confirm the required application experience before choosing a method merely because it avoids erasure.\n\n## DSE recommendation\n\nApprove the enrollment method against the application’s user-association requirements. Have the device owner and app owner agree on whether a shared, unaffiliated device meets the intended task. Check the actual deployment and sign-in path for every required app, and refresh the exported profile for the planned staging date. Preserve device data through the organization’s approved process before considering any alternative that wipes the device.\n\n## Verification\n\nOn a representative test device, confirm the expected enrollment association, management profile, and usable application workflow. Do not use Company Portal availability as the acceptance criterion for this userless method. Check the profile’s age before troubleshooting a failed installation, and record why direct enrollment is suitable before distributing devices.\n\n## Official references\n\n[Microsoft Learn: iOS/iPadOS direct enrollment – Apple Configurator-Setup Assistant](https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-configurator-ios)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check the app model before choosing non-wiping Apple direct enrollment",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/",
                "headline": "Check the app model before choosing non-wiping Apple direct enrollment",
                "description": "What user-affinity limitation accompanies Apple Configurator direct enrollment into Intune?",
                "abstract": "What user-affinity limitation accompanies Apple Configurator direct enrollment into Intune?",
                "articleBody": "Source facts\nApple Configurator direct enrollment does not wipe an iOS or iPadOS device, but supports only enrollment without user affinity. Setup Assistant enrollment is the separate path that wipes and prepares a device for enrollment. Apps requiring a user association, including Company Portal for line-of-business app installation, do not work with the userless path. The exported direct-enrollment policy file is valid for two weeks and must then be recreated. Microsoft Learn.\nApplicability\nUse this decision for corporate iOS or iPadOS devices being prepared with Apple Configurator. Confirm the required application experience before choosing a method merely because it avoids erasure.\nDSE recommendation\nApprove the enrollment method against the application’s user-association requirements. Have the device owner and app owner agree on whether a shared, unaffiliated device meets the intended task. Check the actual deployment and sign-in path for every required app, and refresh the exported profile for the planned staging date. Preserve device data through the organization’s approved process before considering any alternative that wipes the device.\nVerification\nOn a representative test device, confirm the expected enrollment association, management profile, and usable application workflow. Do not use Company Portal availability as the acceptance criterion for this userless method. Check the profile’s age before troubleshooting a failed installation, and record why direct enrollment is suitable before distributing devices.\nOfficial references\nMicrosoft Learn: iOS/iPadOS direct enrollment – Apple Configurator-Setup Assistant.",
                "datePublished": "2026-09-10T00:25:23+00:00",
                "dateModified": "2026-09-10T02:01:56+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check the app model before choosing non-wiping Apple direct enrollment"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 229,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "iOS/iPadOS direct enrollment - Apple Configurator-Setup Assistant - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-configurator-ios"
                }
            }
        ]
    }
}