Category filter
How to set up user enrollment on Mac?
This article will help you initiate User Enrollment on Mac via Hexnode UEM.
Privacy is a critical concern when personal devices are enrolled in remote management solutions, especially in BYOD environments. On macOS and iOS devices, User Enrollment offers a solution by creating a clear separation between work and personal data. This ensures that users’ personal information stays private, while administrators retain the ability to securely manage work-related configurations and data.
User Enrollment requires a Managed Apple ID to establish a user identity on the device. These IDs, created by the organization, provide end-users access to specific Apple services and can co-exist with the user’s personal Apple ID without interaction.
Unlike Automated Device Enrollment, where the Mobile Device Management (MDM) system has complete control over the device, User Enrollment supports only a limited set of payloads and restrictions. For instance, critical MDM commands such as enabling or disabling lost mode, allowing or clearing activation lock, and retrieving device-specific information like serial number, UDID, IMEI, or MEID from the MDM console, cannot be executed. This ensures a balanced approach to device management that respects user privacy while maintaining organizational security.
Setting up User Enrollment in the Hexnode UEM portal
- Log in to your Hexnode UEM portal.
- Go to Enroll > Platform – Specific > macOS > Email or SMS.
- Choose the authentication mode as Authenticated Enrollment.
- Select the type of users for Enrollment Request and Self Enrollment needed to authenticate the enrollment.
- Select the Ownership of the device as Personal.
- Choose the Apple Enrollment Type as User Enrollment from the below options:
- Profile-driven
- Account-driven
- Click on Next.
- Configure the necessary details for sending enrollment requests and hit Send.
Enrollment requests comprising the enrollment URL, username, and password will be sent to the users via email or SMS.
On the device,
Case – 1:
If Ownership is selected as Personal and Apple Enrollment Type is selected as Profile-driven > User Enrollment from the portal,
- Open the Safari browser and enter the enrollment URL specified in the enrollment request. For example, https://portalname.hexnodemdm.com/enroll/.
- On the enrollment screen, enable the checkbox to agree with the terms and conditions. Click Enroll.
- Authenticate with the user account credentials configured in the Hexnode UEM console. Click Authenticate.
- Enter your “Managed Apple ID” and click on Download Profile.
- Open System Settings and navigate to Privacy & Security > Others > Profiles. Double click on the downloaded profile to install it.
- Authenticate with the device’s administrator credentials for profile installation.
- Authenticate with the Managed Apple ID password to sign in to the Mac.
Case – 2:
If Ownership is selected as Personal and Apple Enrollment Type is selected as Account-driven > User Enrollment from the portal,
Before enrolling your macOS device with Account-driven User Enrollment, you need to set up a web server with enrollment information. Please complete the “Step 1: Set up a web server with enrollment information” under Steps to perform Account driven enrollment.
After setting up the server, follow the steps below on the device,
- Open System Settings and navigate to Privacy & Security > Others > Profiles. Adjacent to the Work or School Account, click Sign In.
- Enter the Managed Apple ID and click Continue. When prompted authentication using a web browser click Open Browser.
- On the enrollment screen, enable the checkbox to agree with the terms and conditions. Click Enroll.
- Authenticate with the user account credentials configured in the Hexnode UEM console. After the authentication, you will be redirected back to the System Settings.
- Sign in to the iCloud using the Managed Apple ID password, click Next.
- When prompted to allow Remote Management, click Allow.
- Authenticate using the device’s administrator password to install the remote management profile. Click Enroll.
Case – 3:
If Ownership is selected as Let the user choose/Allow user to choose.
For Profile-driven enrollment,
- Open the Safari browser and enter the enrollment URL specified in the enrollment request. For example, https://portalname.hexnodemdm.com/enroll/.
- On the enrollment screen, enable the checkbox to agree with the terms and conditions. Click Enroll.
- Authenticate with the user account credentials configured in the Hexnode UEM console.
- Under Ownership, choose I own this device. Click Authenticate. This will set the device ownership to Personal.
- On the next page, “How do you want Hexnode to manage your device?” select Manage only work related data and apps. This will set the Apple Enrollment Type to Profile-driven User Enrollment.
- Enter your “Managed Apple ID” and click on Download Profile.
- Open System Settings and navigate to Privacy & Security > Others > Profiles. Double click on the downloaded profile to install it.
- Authenticate with the device’s administrator credentials for profile installation.
- Authenticate with the Managed Apple ID password to sign in to the Mac.
For Account-driven enrollment,
- Open System Settings and navigate to Privacy & Security > Others > Profiles. Adjacent to the Work or School Account, click Sign In.
- Enter the Managed Apple ID and click Continue. When prompted authentication using a web browser click Open Browser.
- On the enrollment screen, enable the checkbox to agree with the terms and conditions. Click Enroll.
- Authenticate with the user account credentials configured in the Hexnode UEM console.
- Under Ownership, choose I own this device. Click Authenticate. This will set the device ownership to Personal.
- On the next page, “How do you want Hexnode to manage your device?” select Manage only work related data and apps. This will set the Apple Enrollment Type to Account-driven User Enrollment. Click Authenticate.
- You will be redirected back to the System Settings. Sign in to the iCloud using the Managed Apple ID password, click Next.
- When prompted to Allow Remote Management, click Allow.
- Authenticate using the device’s administrator password to install the remote management profile. Click Enroll.
MDM functionalities in User enrolled devices
Compared to other enrollment types, User Enrollment severely limits the permissions that an MDM has when administering a device. Unlike device enrollment, device details such as Serial Number, UDID, IMEI and MEID cannot be retrieved in this case.
Here is a comprehensive list of available Hexnode UEM functionalities on devices enrolled using User Enrollment.
- Remote Actions
- Restrictions
- Device Functionality and Personalization
- Screen Capture
- Device Functionality and Personalization
- Network
- Accounts
- Security
- Configurations