Using account driven user enrollment for macOS
Account driven user enrollment helps users and organizations to configure the Apple devices securely by using their managed Apple IDs. The managed IDs and personal IDs can coexist in the same device with complete separation of work and personal data.
Before you begin
Important:
- The account driven user enrollment is applicable to the devices that run on macOS version 15.2 and later.
- The enrollment is supported from Mac MaaS360® version 2.53.000 and later.
- Distributing macOS applications with user-based VPP licensed are not supported for account driven enrolled devices
You must have the following before you can enroll your macOS device.
- Setup Apple Business Manager (ABM)
- Create Managed Apple Accounts by using federated authentication between
Apple and your IdP, or create them manually in
Apple Business ManagerorApple School Manager. - Under Managed Apple Accounts, make sure that the
Domain is verified for the managed ID. For more information, see Add and verify a domain in Apple School Manager, Add and verify a domain in Apple Business Manager, and About Managed Apple Accounts in Apple Business Manager.Important: The managed Apple IDs can be created only under the verified domains.
- Set the Default MDM Server Assignment that is required for service
discovery for iPads, iPhones, and Mac. For more information, Set the default device assignment in Apple Business Manager.Tip: Create a separate DEP enrollment token for account driven user enrollment. The admin can use the same token to sync with the IBM® MaaS360.
- Create Managed Apple Accounts by using federated authentication between
Apple and your IdP, or create them manually in
- In IBM MaaS360, create an Apple user with the email ID same as the managed Apple ID.
- IBM
MaaS360 Settings
- From the IBM MaaS360 Portal, go to and select Prompt user for ownership.
- Under , enable User enrollment mode - Manage only corporate resources.
- Under , select the Use Email Address as Managed Apple ID checkbox. This setting is to make sure that the user created in ABM is the same as the Portal.
- Account Driven DEP Token Upload
The DEP token is used to sync ABM with IBM MaaS360.
Procedure
Results
- The device enrolls successfully.
- In the Summary page of the IBM
MaaS360 Portal, the device is
listed and the Device Enrollment Mode for the device is
User Enrollment.