# Check for duplicate Company Portal configuration during Apple ADE

> Why might Company Portal request a management policy that an ADE device has already installed?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:50+00:00
- Modified: 2026-09-10T01:40:02+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Why might Company Portal request a management policy that an ADE device has already installed?

## Potentially affected

Use this diagnosis for the specific initial-enrollment combination above. Distinguish that flow from a deliberate userless-device staging transition before changing an assignment.

## DSE recommendation

Trace every Company Portal configuration assignment reaching the affected device and user.

## Article

## Source facts

During initial iOS/iPadOS ADE with Setup Assistant modern authentication, Intune sends Company Portal app configuration automatically when Install Company Portal is enabled. Microsoft warns that manually targeting the same configuration to users creates a conflict and can prompt them to download a management policy already present. The separate userless-to-user staging procedure restricts its app-configuration targeting to ADE devices without user affinity. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios).

## Applicability

Use this diagnosis for the specific initial-enrollment combination above. Distinguish that flow from a deliberate userless-device staging transition before changing an assignment.

## DSE recommendation

Trace every Company Portal configuration assignment reaching the affected device and user. Have the enrollment owner identify which settings arrive automatically and which were added for staging. Correct an unintended overlap through a reviewed targeting change; avoid instructing users to repeatedly install a management policy as the first response to this documented symptom.

## Verification

Enroll a representative test device with the corrected assignments and observe the full Company Portal sequence. Confirm the expected registration and application access without the duplicate policy-download request. Test the separate staging population independently so the correction does not silently remove its needed configuration. Preserve assignment identities, enrollment options, and observed prompts without recording credentials.

## Official references

[Microsoft Learn: Set up automated device enrollment (ADE) for iOS/iPadOS](https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios).

## Primary reference

- Name: Set up automated device enrollment (ADE) for iOS/iPadOS - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check for duplicate Company Portal configuration during Apple ADE,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-306-check-for-duplicate-company-portal-configuration-during-apple-ade/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
