User enrollment options
You can have users enroll their devices in Endpoint Management in several ways. Before considering the specifics, decide which devices you want to enroll in MDM+MAM, MDM, or MAM. For more information about those management modes, see Management modes.
At the highest level, there are four enrollment options:
- Enrollment Invitation: Send an enrollment invitation or invitation link to users.
- Self-Help Portal: Set up a portal that users can visit to download Secure Hub and enroll their devices or send themselves an enrollment invitation.
- Manual Enrollment: Send out an email, handbook, or some other communication letting users know that the system is up and that they can enroll. Users then download Secure Hub and enroll their devices manually.
- Enterprise: Another option for device enrollment is through an Apple Deployment Program and Google Android Enterprise. Through each of these programs, you can purchase devices that are pre-configured and ready for employees to use. For more information, see Apple Deployment Program articles in Apple Support and Google Android Enterprise documentation on the Android Enterprise website.
You can email an enrollment invitation to users with iOS, macOS, or Android devices. You can also send an installation link through SMTP or SMS to users with iOS, macOS, Android, or Windows devices. For more information, see Enroll devices.
If you choose to use the enrollment invitation method, you can:
- Choose from up to seven enrollment modes, depending on platform.
- Use any combination of the modes.
- Enable or disable the modes from the Endpoint Management Settings page.
- Select a default from User name + Password, Two Factor, and User name + PIN. For information on each enrollment mode, see Configure enrollment modes.
If you choose certificate-based, consider excluding User name + Password traditional authentication from the allowed options. User name + Password authentication might expose a weak onboarding vector into your environment and potentially void the mandated security quality.
Invitations serve many purposes. The most common use of invitations is to notify users that the system is available, and that they can enroll. Invitation URLs are unique. After a user uses an invitation URL, the URL is no longer available. You can use this property to limit the users or devices enrolling to your system.
You can set up Endpoint Management so that iOS users provide credentials during enrollment in one of the following ways:
Users type their credentials during enrollment.
Users insert a smart card from a derived credentials provider into a reader attached to their desktop. For information about derived credentials, see Derived credentials.
When configuring an enrollment profile, you can control the number of devices specific users can enroll, based on Active Directory groups. For example, you might allow your Finance division only one device per user.
Be aware of the extra costs and pitfalls of certain enrollment options. To send invitations using SMS requires extra infrastructure. For more information on this option, see Notifications.
In addition, to send invitations by email, ensure that users have a way of accessing email outside of Secure Hub. You can use one-time password (OTP) enrollment modes as an alternative to Active Directory passwords for MDM enrollment.
Users can request an enrollment invitation through the Self-Help Portal. The default mode is User name + Password, but you can also change that requirement to Two Factor or User name + PIN. For information about setting up the Self-Help Portal, see Configure enrollment modes.
With manual enrollment, users connect to Endpoint Management either through autodiscovery or by entering the server information. With autodiscovery, users log on with only their email address or Active Directory credentials in User Principal Name format. Without autodiscovery, they must enter the server address and their Active Directory credentials. For more information about setting up autodiscovery, see Set up Endpoint Management AutoDiscovery Service.
You can facilitate manual enrollment in several ways. You can create a guide, distribute it to users, and have them enroll themselves. You can have your IT department manually enroll groups of users in certain time slots. You can use any similar method where users must enter their credentials or server information.
After you have your environment set up, you need to decide how to get users into your environment. An earlier section in this article discusses the specifics of user enrollment modes. This section discusses the way you reach out to users.
Open Enrollment vs. Selective Invitation
When onboarding users, you can allow enrollment through two basic methods:
- Open enrollment. By default, any user with LDAP credentials and the Endpoint Management environment information can enroll.
- Limited enrollment. You can limit the number of users by only allowing users with invitations to enroll. You can also limit open enrollment by Active Directory group.
With the invitation method, you can also limit the number of devices a user can enroll. In most situations, open enrollment is acceptable, but there are a few things to consider:
- For MAM enrollment, you can easily limit open enrollment through Active Directory group membership.
- For MDM enrollment, you can limit the number of devices that can enroll based on Active Directory group membership. If you only allow corporate devices in your environment, that limitation typically isn’t an issue. You might want to consider this method, however, in a BYOD workplace if you want to limit the number of devices in your environment.
Selective invitation is typically performed less often because it requires a bit more work than open enrollment. In order for users to enroll their devices in your environment, you must send an invitation unique to each user. For information on how to send an enrollment invitation, see Enrollment invitations.
Send an invitation for each user or group whom you want enrolled in your environment. That process can take a long time depending on the size of your organization. It is possible to use Active Directory groups to create invitations in batches, but you must carry out this approach in waves.
First Contact with Users
After deciding whether to use open enrollment or selective invitation and you set up those environments, inform users about their enrollment options.
If you use the selective invitation method, email and SMS messages are a part of the process. You can send emails through the Endpoint Management console for open enrollment as well. For details, see Enrollment invitations.
In either case, keep in mind that for email, you need an SMTP server. For text messages, you need an SMS server. Those servers might be extra costs to consider when making your decision. Before you select a method, consider how you expect new users to access information, like email. If you want all users to access their email through Endpoint Management, sending them an invitation email would be problematic.
You can also send communications by another means outside of Endpoint Management for an open enrollment environment. For that option, be sure to include all the relevant information. Let users know where they can get the Secure Hub app and what method to use to enroll. If you have discovery turned off, also provide users the Endpoint Management server address. To learn more about discovery, see Set up Endpoint Management AutoDiscovery Service.