Back

Account-driven device enrolment

Account-driven enrolment lets employees enrol their own iPhone or iPad with their work email, keeping work and personal data separate.

Overview

Use this when employees use personal iPhones or iPads for work and privacy is the sticking point. Nothing personal on the device is visible to the organisation.

Platform

Supported

iOS, iPadOS 16+

Yes

macOS

Coming

Windows, Linux, Android

No

Two prerequisites, and both are hard requirements:

  • An Apple Business account.
  • Identity provider federation — Google Workspace or Microsoft Entra federated with Apple Business, so employees can authenticate with their work credentials.

Without federation the method simply does not appear as an option.


 

How to use

The employee does all of this themselves:

  1. Open Settings on the iPhone or iPad and tap Sign in to work or school. (The alternative route is Settings > General > VPN & Device Management.)
  2. Enter the work email address. The device looks up the email domain and finds your enrolment server on its own.
  3. Authenticate with the work credentials, through your federated identity provider.
  4. Done. A separate work partition is created. Company apps and data live inside it; personal apps and data stay outside and remain invisible to the organisation.

 

Tips and Best Practices

  • Sort the federation before you announce this method. It is the whole dependency, and without it there is nothing to demonstrate.
  • Lead with the privacy argument when you communicate it. The separate partition is a genuine technical guarantee, not a policy promise, and it is much more persuasive than asking someone to trust a setting.
  • Keep employee enrolment available alongside it. Account-driven enrolment covers iPhone and iPad only, so Android and laptops still need another route.
  • Explain that there is nothing to download. The whole flow happens in Settings, which removes the most common objection to enrolling a personal phone.
 

 

Troubleshooting and FAQ

Troubleshooting

  • "Sign in to work or school" does nothing, or the device cannot find a server. The email domain lookup failed. Check that federation between your identity provider and Apple Business is complete and that the employee used their work email, not a personal one.
  • The employee cannot authenticate. The credentials are checked by your identity provider, not by the device. Verify the account is active there and that the person is in scope for federation.
  • The device is on iOS 15 or earlier. iOS 16 is the minimum. Update the device or use employee enrolment.
     

FAQ

  1. Can we see the employee's photos, messages or personal apps?
    No. They sit outside the work partition and are not visible to the organisation.
     
  2. Does this work on a Mac?
    Not yet. It is announced for macOS but only iOS and iPadOS are supported today.
     
  3. What happens to company data when the person leaves?
    The work partition is removed with its contents. Personal data on the device is untouched.

Was this article helpful?

Give feedback about this article

Can’t find what you’re looking for?

Our customer care team is here for you.

Contact us

Knowledge Base Software powered by Helpjuice