XenMobile Server Current Release

Enrollment profiles

An enrollment profile specifies the following:

  • Device management enrollment options for Android and iOS devices. For Android, the enrollment options available for the MDM+MAM (ENT) server mode differ from the options for MDM mode.
  • App management enrollment options for Android and iOS devices.
  • Other enrollment options:
    • Whether to limit the number of devices a user can enroll.

      If the device limit is reached, an error message lets the user know that they exceeded the device registration limit.

    • Whether to allow a user to decline device management.

You can use enrollment profiles to combine multiple use cases and device migration paths within a single XenMobile Server console. Some use cases include:

  • Mobile Device Management (MDM only)
  • MDM+Mobile Application Management (MAM)
  • MAM only
  • Corporate-owned enrollments
  • BYOD enrollment (the ability to opt out of MDM enrollment)
  • Migration of Android Device Administrator enrollments to Android Enterprise enrollments (fully managed, work profile, dedicated device)

When you create a delivery group, you can use the default enrollment profile named Global or specify a different enrollment profile.

Enrollment profile features by platform include the following.

  • For Android devices: You specify the device owner mode. For example: Fully managed, fully managed with work profile, and BYOD work profile. The Dedicated device option appears only when you have an Enterprise or Advanced license for XenMobile. New devices enroll in Android Enterprise and app management by default. The enrollment security modes User name + PIN, Invitation URL, Invitation URL + PIN, and Invitation URL + Password aren’t available for Android Enterprise.

  • For iOS devices: You specify the device enrollment type: Device enrollment or don’t manage devices. The iOS settings appear only when you have an Enterprise or Advanced license for XenMobile. New devices enroll in Apple device management and app management by default.

If you don’t need to enroll dedicated devices for Android devices or MAM-only enrollment for Android or iOS devices, you can disable the server property enable.multimode.xms. However, keeping this property enabled means you need only one XenMobile Server to handle all types of enrollment profiles. See Server properties.

When you disable enable.multimode.xms, only the settings in this screenshot are available:

Enrollment profile options without multimode

For more details about these settings, see Android Enterprise.

Global enrollment profile

The default enrollment profile is named Global. The Global profile is useful for testing until you have a chance to create enrollment profiles.

The following screenshots show the default settings for the Global enrollment profile.

Enrollment Profile Info page

Enrollment Profile page for Android, MDM+MAM mode

Enrollment Profile page for iOS

Enrollment profiles, delivery groups, and enrollment

Enrollment profiles and delivery groups interact as follows:

  • You can attach an enrollment profile to one or more delivery groups.

  • If a user belongs to multiple delivery groups that have different enrollment profiles, the name of the delivery group determines the enrollment profile used. XenMobile Server selects the delivery group that appears last in an alphabetized list of delivery groups. For example, suppose that you have the following:

    • Two enrollment profiles, named “EP1” and “EP2”.
    • Two delivery groups, named “DG1” and “DG2”.
    • “DG1” is associated with “EP1”.
    • “DG2” is associated with “EP2”.

    If the enrolling user is in both the “DG1” and “DG2” delivery groups, XenMobile Server uses the “EP2” enrollment profile to determine the enrollment type for the user.

  • The deployment order applies only to devices in a delivery group that has an enrollment profile configured for MDM (device management).

  • After a device enrolls, some changes to an enrollment profile require re-enrollment:

    • Adding MAM to an enrollment profile that’s configured for MDM.
    • Moving a device that’s enrolled in MDM to a delivery group configured for MDM+MAM. That change impacts new device enrollments only. Existing device enrollments aren’t affected.
    • Adding MDM to an enrollment profile that’s configured for MAM.
  • Switching to a different enrollment profile does not affect existing enrolled devices. However, users must unenroll and then reenroll those devices for the changes to take effect.

To create an enrollment profile

  1. In the XenMobile Server console, go to Configure > Enrollment Profiles.

  2. On the Enrollment Info page, type a descriptive name for the profile. By default, a user can enroll unlimited devices. Select a value to limit the number of devices per user. The limit applies to the sum of MAM or MDM managed Android and iOS devices that a user enrolls.

  3. Complete the platform pages. For information about enrollment settings specific to the platforms, see:

  4. On the Assignment page, attach one or more delivery groups to the enrollment profile.

    A user might belong to multiple delivery groups that have different enrollment profiles. In that case, the name of the delivery group determines the enrollment profile used. XenMobile selects the delivery group that appears last in an alphabetized list of delivery groups. To create delivery groups, go to Configure > Delivery Groups.

A list of your enrollment profiles appears on the Configure > Enrollment Profiles page. To edit the Global profile or reset it to the original default, select the row for the Global profile and click Reset. You can’t delete the Global profile.

Reset Global Enrollment Profile setting

Enrollment profiles