# Check the app model before choosing non-wiping Apple direct enrollment

> What user-affinity limitation accompanies Apple Configurator direct enrollment into Intune?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:23+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What user-affinity limitation accompanies Apple Configurator direct enrollment into Intune?

## Potentially affected

Use this decision for corporate iOS or iPadOS devices being prepared with Apple Configurator. Confirm the required application experience before choosing a method merely because it avoids erasure.

## DSE recommendation

Approve the enrollment method against the application's user-association requirements.

## Article

## Source facts

Apple Configurator direct enrollment does not wipe an iOS or iPadOS device, but supports only enrollment without user affinity. Setup Assistant enrollment is the separate path that wipes and prepares a device for enrollment. Apps requiring a user association, including Company Portal for line-of-business app installation, do not work with the userless path. The exported direct-enrollment policy file is valid for two weeks and must then be recreated. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-configurator-ios).

## Applicability

Use this decision for corporate iOS or iPadOS devices being prepared with Apple Configurator. Confirm the required application experience before choosing a method merely because it avoids erasure.

## DSE recommendation

Approve the enrollment method against the application’s user-association requirements. Have the device owner and app owner agree on whether a shared, unaffiliated device meets the intended task. Check the actual deployment and sign-in path for every required app, and refresh the exported profile for the planned staging date. Preserve device data through the organization’s approved process before considering any alternative that wipes the device.

## Verification

On a representative test device, confirm the expected enrollment association, management profile, and usable application workflow. Do not use Company Portal availability as the acceptance criterion for this userless method. Check the profile’s age before troubleshooting a failed installation, and record why direct enrollment is suitable before distributing devices.

## Official references

[Microsoft Learn: iOS/iPadOS direct enrollment – Apple Configurator-Setup Assistant](https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-configurator-ios).

## Primary reference

- Name: iOS/iPadOS direct enrollment - Apple Configurator-Setup Assistant - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-configurator-ios
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check the app model before choosing non-wiping Apple direct enrollment,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-393-check-the-app-model-before-choosing-non-wiping-apple-direct-enrollment/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
