Self-Help Article (External)
Intended Audience: IT Staff
Purpose
This article outlines the process for enrolling Apple devices into Microsoft Intune, including the use of Apple School Manager (ASM) for device assignment.
Requirements
- Access to Apple School Manager (ASM).
- Access to Microsoft Intune Admin Center.
- Device must have Internet connectivity.
- Device must be present in Apple School Manager (ASM).
Step-by-Step Procedures
Important (Before You Begin):
Devices not present in Apple School Manager (ASM) cannot be enrolled using this process.
If a device is not present and cannot be imported into ASM using standard methods performed by the STW Book Store staff, use the Apple Configurator enrollment directions.
- ASM: Sign in to Apple School Manager
- Go to: https://school.apple.com
- Enter: your Managed Apple ID
- Complete multi-factor authentication (MFA) if prompted.
- You’ll land on the ASM dashboard.
- ASM: Assign Device to Intune (MDM Server)
This step links the device to Intune via Apple Automated Device Enrollment (ADE).
- In ASM, click: Devices (left menu)
- Search for the device: By Serial Number, Order Number, or Device Name
- Choose: device(s)
- Click: Edit Device Management (top right).
- In the MDM Server / Device Management dropdown:
- Choose: Your Intune MDM server
- Click: Continue > Confirm
- The device is now assigned to Intune in Apple School Manager.
- Intune: Sync Device (Force Sync)
Devices in ASM will sync to Intune automatically. To force a sync manually, follow the steps below:
- Go to the Microsoft Intune Admin Center: https://intune.microsoft.com
- Click: Devices > macOS or iOS/iPadOS > enrollment
- Click: Enrollment Program Tokens
- Open: Your ASM token
- Click: Sync
Note: Devices may take several minutes to appear even after syncing.
- Intune: Verify Device Sync Status
- Still in the Microsoft Intune Admin Center
- Click: Devices > macOS or iOS/iPadOS > enrollment
- Click: Enrollment Program Tokens
- Open: Your ASM token
- Click: Devices
- Search: For the device by Serial Number
- If successful, the device should appear in the list.
- Intune: Assign Device to Enrollment Profile.
Important: Assign this before powering on or resetting the device.
The enrollment profile tells the device how to behave during setup.
- Still in the Microsoft Intune Admin Center.
- Click: Devices > macOS or iOS/iPadOS > enrollment
- Click: Enrollment Program Tokens
- Open: Your ASM token
- Click: Profiles
- Choose: Either an existing profile or Create profile
- If creating a profile, follow the wizard to create a profile.
- Assign device to enrollment profile:
- Open: The profile
- Click: Assign devices
- Click: Add device
- Search: For the device by Serial Number
- Choose: The device
- Click: Add
- Device: Trigger Enrollment
Important: Devices that have already completed Apple Setup Assistant must be erased/reset before Automated Device Enrollment (ADE) will occur successfully. ADE enrollment only happens during the initial Apple setup process. After the device is reset and setup begins again, the device will detect the Intune enrollment configuration and display the Remote Management screen for enrollment.
- Option A – New/Reset Device
- Power on: Device
- Connect to: Wi-Fi
- Device connects to Apple, detects Intune, shows the Remote Management screen, and enrolls automatically
- Option B – Already in use device
- iOS/iPad
- Go to: Settings > General > Transfer or Reset > Erase All Content and Settings
- Upon reboot, device will enroll via ADE.
- macOS
- Method 1 (macOS Monterey and newer – preferred)
- Go to: Apple Menu > System Settings > General > Transfer or Reset > Erase All Content and Settings
- Follow the prompts to wipe the device.
- Mac will restart.
- After reset, the Mac connects to Apple, detects Intune, shows the Remote Management screen, and enrolls automatically.
- Method 2 (Older macOS or fallback method)
- Restart and hold: Command (⌘) + R
- Enter: macOS Recovery
- Select: Disk Utility > Erase disk
- Then reinstall macOS.
- After reset, the Mac connects to Apple, detects Intune, shows the Remote Management screen, and enrolls automatically.
- Device: Verify Enrollment Status
- On the macOS:
- Click: Apple menu > System Settings (or System Preferences on older macOS)
- Go to: Privacy & Security
- Scroll down to: Profiles (or just “Profiles” directly if visible in sidebar)
- Look for an MDM Profile typically named something like: Microsoft Intune Management Profile or MDM Profile
- If present, the device is enrolled and managed.
- On the iPhone/iPad:
- Go to: Settings > General > VPN & Device Management
- You should see: Management Profile (Intune)
- Also: During setup you should see “Remote Management” screen