# Test Shared iPad guest sessions without assuming user-targeted policy applies

> Do user-targeted profiles and their reports prove the configuration of a Shared iPad guest session?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-538-test-shared-ipad-guest-sessions-without-assuming-user-targeted-policy-applies/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:58+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Do user-targeted profiles and their reports prove the configuration of a Shared iPad guest session?

## Potentially affected

Review a Shared iPad design that permits temporary sessions alongside named users. Separate the guest requirements from role-specific customization, and identify which assignment object supplies each intended control.

## DSE recommendation

Make the temporary-session configuration an explicit device-targeted acceptance set.

## Article

## Source facts

Shared iPad temporary sessions use the Guest sign-in rather than a Managed Apple ID, and session data is removed at sign-out. Only device-assigned apps and profiles apply to those temporary sessions. Intune does not report device or user status for Shared iPad apps and profiles assigned to user groups. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-enrollment/apple/shared-ipad).

## Applicability

Review a Shared iPad design that permits temporary sessions alongside named users. Separate the guest requirements from role-specific customization, and identify which assignment object supplies each intended control.

## DSE recommendation

Make the temporary-session configuration an explicit device-targeted acceptance set. Do not copy a named user’s expected experience into the guest test without checking applicability. Ask the endpoint owner to document the intended applications, network access, and restrictions for an unauthenticated session. Keep user-profile reporting gaps visible rather than translating missing status into success.

## Verification

Start a controlled guest session and inspect the approved applications and settings directly. Then end the session and confirm the expected data-removal behavior using harmless test content. Run a separate named-user test where required. Retain observed results alongside assignment scope, and investigate any guest capability that the design intended only for a named role.

## Official references

[Microsoft Learn: Shared iPad devices](https://learn.microsoft.com/en-us/intune/device-enrollment/apple/shared-ipad).

## Primary reference

- Name: Shared iPad devices - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-enrollment/apple/shared-ipad
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Test Shared iPad guest sessions without assuming user-targeted policy applies,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-538-test-shared-ipad-guest-sessions-without-assuming-user-targeted-policy-applies/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
