Each device in your organization’s deployment must be enrolled in your organization’s environment before it can communicate with Omnissa Workspace ONE UEM and access internal content and features using Mobile Device Management (MDM). visionOS devices enroll using MDM functionality built into the native OS.
Enrollment Requirements
To enroll a visionOS device, your end users must gather specific information. The information the users need depends on whether the device will be user enrolled or automatically enrolled using Apple Automated Device Enrollment.
For user enrollment, a user must have a Managed Apple ID linked to your organisation.
For Automated Device Enrollment, the user’s device must be running visionOS 2.0 or higher. If you specify authentication, the user must have a valid username and password for enrolling into UEM.
For more information on enrollment requirements, see visionOS Device Enrollment Requirements.
Types of Enrollment Supported
The device management capabilities available for enrolled devices depend on the type of enrollment you choose. Omnissa Workspace ONE UEM provides support for user enrollment for BYO use cases and Automated Device Enrollment for corporate owned supervised use cases.
User enrolled devices have limitations on what can be managed to protect user privacy and device ownership.
Devices enrolled using Automated Device Enrollment are supervised and there are very few limitations on what can be managed on the device.
Account Driven User Enrollment
visionOS supports Apple’s Account Driven User Enrollment for user based enrolment. This is aimed at users who have purchased their own device and want to access corporate resources using their device. The user can opt out of device management at anytime. There are limitations on what can be managed via MDM and what is shared with MDM. For more information, see the documentation from Apple, User Enrolment and MDM.
Automated Device Enrollment
Depending on your deployment type and device ownership model, you may want to enroll devices in bulk. Omnissa Workspace ONE UEM provides bulk enrollment capabilities using Apple Business Manager’s Automated Device Enrollment functionality (ADE).
Bulk Enrollment with Automated Device Enrollment (ADE)
Deploying a bulk enrollment through the Apple Automated Device Enrollment (ADE) allows you to install a non-removable MDM profile on a device, which prevents end users from being able to remove the profile from their device. You can also provision devices in Supervised mode to access additional security and configuration settings.
For more information on enrollment with the Apple Business Manager, see Device Enrollment with the Apple Business Manager’s Device Enrollment Program.
visionOS Device Enrollment Requirements
To enroll an visionOS device, you or your end users need information that depends on whether you are using Account Driven User Enrollment or Automated Device Enrollment with authentication.
Account Driven User Enrollment
- Requried OS - visionOS 1.1 and higher.
- Device - Can be purchased from an Apple store or via a business. Must not be registered with Apple Business Manager.
- Managed Apple ID - This Apple ID is needed for each user performing Account Driven User Enrollment.
- Apple Service Discovery - You need to setup infrastructure to support. See Account Driven User Enrollment for more information.
Automated Device Enrollment
- Required OS - visionOS 2.0 and higher.
- Device - Must be purchased through a business and registered to your Apple Business Manager instance by Apple or your reseller.
- Username & Password - If your ADE profile requires the user to authenticate, you will need to provide them with a valid username and password for enrollment.
Capabilities Based on Enrollment Type for visionOS Devices
| Features | Account Driven User Enrollment | Automated Device Enrollment |
|---|---|---|
| Enrollment | ||
| Requires Managed Apple ID | Required | Optional |
| Force EULA/Terms of Use Acceptance | Yes | Yes |
| Active Directory/LDAP/SAML Integration | Yes | Active Directory/LDAP/SAML Integration |
| Two Factor Authentication | Yes | Yes |
| BYOD Support | Yes | No |
| Device Staging Support | No | Yes |
| Configuration Profile Management | ||
| View and Manage Profiles | Yes | Yes |
| Security Settings (Data Encryption, Password Policy, etc.) | Yes | Yes |
| Device Restrictions | Limited | Yes |
| Certificate Management | Yes | Yes |
| Wi-Fi Management | Yes | Yes |
| Email and Exchange ActiveSync management | Yes | Yes |
| Custom Settings | ||
| Device Information | ||
| Device Information (model, serial number etc.) | Limited | Yes |
| Storage Information | N/A | N/A |
| Battery Information | N/A | N/A |
| UDID | Yes | Yes |
| Compromised/Jailbreak Detection | Yes | Yes |
| Activation Lock Status | N/A | N/A |
| iCloud Back Up Status | N/A | N/A |
| Last Back Up Time | N/A | N/A |
| Network Information | ||
| IP Address | Yes | Yes |
| Bluetooth MAC address | Yes | Yes |
| Wi-Fi MAC address | Yes | Yes |
| Management Commands | ||
| Full Device Wipe | No | Yes |
| Enterprise Wipe | Yes | Yes |
| Lock Device | Yes | Yes |
| Clear Passcode | Yes | Yes |
| Restart Device | N/A | N/A |
| APNs Push Messaging | Yes | Yes |
| Custom Commands | Limited | Yes |
| Set Device Name | No | N/A |
| Application Management | ||
| View and Manage Applications | N/A | N/A |
| Volume Purchase Program (VPP) | N/A | N/A |
| Application List | Yes | Yes |
| Content Management | ||
| Content Management | N/A* | N/A* |
*Requires Workspace ONE Content
N/A - Not Available yet with Workspace ONE UEM
Device Enrollment with the Apple Business Manager’s Automated Device Enrollment
Automated Device Enrollment (ADE) maximizes the benefits of Apple devices enrolled in Mobile Device Management (MDM).
With ADE, you can perform the following.
-
Install a non-removable MDM profile on a device, preventing end users from being able to delete it.
-
Provision devices in Supervised mode. Devices in supervised mode can access additional security and configuration settings.
-
Enforce an enrollment for all end users.
-
Meet your organization’s needs by customizing and streamline the enrollment process.
-
Prevent iCloud back up by disabling users from signing in with their Apple ID when generating a ADE profile.
Once you have met the requirements for Automated Device Enrollment and your Apple Vision Pro is in Apple Business Manager (ABM), make sure the device in ABM has its MDM server set to your instance of Workspace ONE UEM.
You must now register your device with Workspace ONE UEM.
-
Go to the Workspace ONE UEM console.
-
Navigate to Devices > Lifecycle > Registration.
-
Select Sync Devices > Apple.
-
Select Sync.
You should now see your Apple Vision Pro device(s) in the list of registered devices.
You can now create an Automated Device Enrollment (ADE) profile for devices enrolled through ADE.
-
Navigate to Groups & Settings > All Settings > Devices & Users > Apple > Automated Device Enrollment.
-
To create a profile, select Add Profile.
-
Configure the ADE profile as required for your organization.
Note: Known issue (VOS-128) - On Apple Vision Pro, regular ADE with Authentication enabled may not prompt the user for credentials during enrollment, and the device can stop responding on that screen. To require user authentication during enrollment, use Custom enrollment in the ADE profile.
- Select Save.
This profile will be applied to valid Apple devices being enrolled into the Organizational Group where the profile has been set.
You can now power on the device and follow the device setup to enroll into Workspace ONE UEM.
For more information, see the following topics:
-
Apple Business Manager - Device Enrollment Program in Introduction to Apple Business Manager.
-
The Apple Business Support Portal.
-
The Apple Device Enrollment Program Guide, or contact your Apple representative.
User Enrollment and MDM
User Enrollment is designed for BYOD(Bring Your Own Device) deployments, where the user, not the organisation, owns the device. It works with an identity provider (IdP), Google Workspace or Microsoft Entra ID, and Apple School Manager or Apple Business Manager and an MDM solution such as Workspace ONE UEM.
The four stages of User Enrollment into MDM are:
-
Service discovery: The device identifies itself to Workspace ONE UEM.
-
User enrollment: The user provides credentials to an identity provider (IdP) for authorisation to enroll into Workspace ONE UEM.
-
Session token: A session token is issued to the device to allow ongoing authentication.
-
MDM enrollment: The enrollment profile is sent to the device with payloads configured by the Workspace ONE UEM administrator.
User Enrollment and Managed Apple Accounts
User Enrollment requires Managed Apple Accounts. These are owned and managed by an organisation and provide employees with access to certain Apple services. In addition, Managed Apple Accounts:
- Are created manually, or automatically using federated authentication
- Are integrated with a Student Information System (SIS) or uploading .csv files (Apple School Manager only)
- Can also be used to sign in with an assigned role in Apple School Manager, Apple Business Manager or Apple Business Essentials
When a user removes an enrollment profile, all configuration profiles, their settings and Managed Apps based on that enrollment profile are removed with it.
User Enrollment is integrated with Managed Apple Accounts to establish a user identity on the device. The user must successfully authenticate for enrollment to be completed. The Managed Apple Account can be used alongside the personal Apple Account that the user has already signed in with; the two don’t interact with each other.
Account Driven User Enrollment
Account Driven User Enrollment (ADUE) is a user enrollment method for visionOS 1.1 and later versions that allow you to effectively manage settings, applications, and corporate data while protecting user privacy and personal data. With ADUE, you are permitted to install applications, configure profiles, and issue commands only to a managed user container on the device rather than the entire device.
ADUE is achieved through MDM providing a user context called a Managed Apple ID in the MDM profile installed on the device during enrollment. The user context instructs the device to prompt the user for their Managed Apple ID credentials to install the MDM profile. After enrollment, a specific Apple File System (APFS) volume is created for the managed data. Data in the personal volume cannot be accessed from the managed volume keeping user data private.
Due to the creation of the new managed volume of data, there are several existing management capabilities that are not possible for privacy purposes. For example, if any app is manually installed by the user from the App Store, that app is considered personal and cannot be managed by MDM. Such user installed apps must first be uninstalled and then reinstalled by Omnissa Workspace ONE UEM to be managed.
User Enrollment Settings
Enable the User Enrollment option for visionOS devices by accessing the Enrollment settings page on the Omnissa Workspace ONE UEM console (Groups & Settings > All Settings > Devices & Users > General > Enrollment). Enabling the option allows the supported visionOS 1.1 and later devices to enroll to the Organization Group using Apple’s Account Driven User Enrollment method. User Enrollment uses the users’ Managed Apple IDs rather than the enrollment user name as a way to indicate which user the device is enrolling. The Managed Apple ID should correspond a user’s email address in Workspace ONE UEM.
Setting up Infrastructure for Account Driven User Enrollment
In order to use Account Driven User Enrollment it requires a company to host what Apple refers to as a Service Discovery URL. The purpose of the Service Discovery URL is to all the Apple device to lookup a company's domain name and then associate that domain name with an enrollment flow. For the technical details involving this lookup process see, Implementing the simple authentication user-enrollment flow in Apple Developer Documentation.
By publishing an external file named com.apple.remotemanagement on a company's webserver the process allows for a smooth enrollment experience.
The most important detail about a Service Discovery URL is that the web domain name used MUST MATCH the email address domain name configured in Apple Business Manager for Apple Managed IT. For example if the company name is company.com, and the Apple Managed ID is name@company.com, the service discovery URL must be hosted on www.company.com. Sub-domains and different domain names are not supported.
The technical configuration of the Service Discovery URL differs based on your web server platform. Here is an example setup for Apache2.
-
On the Apache2 web server in the main directory of your website (for example /var/www/mysite ) create a new sub-directory named .well-known (make sure you include the period in the directory name). The end result should be, for example, /var/www/mysite/.well-known.
-
Create a new file,
/var/www/mysite/.well-known/com.apple.remotemanagementthat contains the following text (change wxyz to match the UEM tenant):{ "Servers": [ { "Version" : "mdm-byod", "BaseURL" : "https://dswxyz.awmdm.com/DeviceManagement/Enrollment/AccountDrivenUserEnroll" } ] } -
Create a new file,
/var/www/mysite/.well-known/.htaccess(Do not forget the period) that contains the following text:AddDefaultCharset utf-8RequestHeader set Content-Type "application/json;charset=UTF-8" -
The .well-known directory is now a sub-directory of your main website with two files in it:
.htaccessandcom.apple.remotemanagement. This completes the required configuration. -
In order for the
.htaccessto apply to the .well-known folder, the main Apache2 configuration file located within your root web folder MUST include Override=Allow which lets Apache2 subfolders read the.htaccessfiles.
Enroll a visionOS Device Using Account Driven User Enrollment
Enroll an visionOS 1.1 and later device using Managed Apple IDs. You can directly sign in using Settings in the visionOS device.
Ensure that you have the following pre-requisites before the User Enrollment:
-
Unsupervised visionOS 1.1 and later device.
-
Exactly one enrollment user with an email address that matches a Managed Apple ID in Apple Business Manager.
-
Configured Discovery Service for account driven user enrollment.
To enroll an visionOS device:
-
Open Settings > General > VPN & Device Management > Sign In to Work or School Account.
-
Enter the enrollment user’s email address corresponding to their Managed Apple ID and tap Continue.
Note: User Enrollment does not currently support the custom Managed Apple ID feature possible for Shared iPads.
-
Continue through any authentication screens or prompts. This step will vary depending on your organization’s Apple Business Manager setup.
-
Tap Allow Remote Management and wait for the MDM profile to get installed on your visionOS device.
Account Driven User Enrollment is now complete.
Was this page helpful?