Mobile enrollment is where Intune’s flexibility becomes its complexity. Windows and Mac enrollment paths are relatively constrained. Mobile is not.
iOS and Android each have multiple enrollment modes, each with different management capabilities, different user experiences, and different implications for what you can and can’t control. The decisions you make here – before a single device enrolls – determine what’s possible later. Phase 9 covers the full design in depth. This article establishes the framework you need before you get there.
The fundamental split
Every mobile device in your environment falls into one of two categories: corporate-owned or personally owned. That distinction drives almost every other decision in mobile management. Corporate-owned devices can be fully managed – you control the device, the apps, the configuration, and what happens to it when employment ends. Personally owned devices can be partially managed – you control the work data and the work apps, but the device itself remains outside your authority.
The management model follows ownership. For corporate-owned devices, full MDM enrollment is appropriate. For personally owned devices, MAM-only – app protection policies without device enrollment – is usually the right answer. The middle ground of enrolling personally owned devices into full MDM exists, but it creates privacy and consent complications that most organizations would rather avoid.
Decide the ownership model before you configure anything. Every enrollment path branches from that decision.
iOS enrollment paths
For corporate-owned iOS devices, Automated Device Enrollment through Apple Business Manager is the correct path. ADE enrolls devices silently at setup, ties them to your MDM server before the user touches the device, and prevents unenrollment. It’s the only enrollment method that gives you full supervised mode, which unlocks the management capabilities that matter – silent app installation, certain restriction controls, and the ability to prevent the user from removing the MDM profile.
For personally owned iOS devices, MAM-only is the right posture in most environments. Users install Microsoft 365 apps, app protection policies apply to those apps, and work data is protected inside the app boundary without the device being enrolled in MDM. The user’s personal apps and personal data remain entirely outside your management surface.
Full MDM enrollment for personally owned iOS devices is possible but limited, and it now comes in two flavors: the traditional Company Portal app flow and a web-based enrollment that runs entirely in Safari and the Settings app with no app install, mirroring the browser-first direction Android BYOD enrollment has taken. Without supervised mode, which requires ADE, many management capabilities aren’t available. You end up with an enrolled device you can’t fully manage, and a user who has handed their personal device over to corporate MDM. That’s not a good position for either party.
Android enrollment paths
Android Enterprise is the management framework that matters. The legacy Android Device Administrator mode is dead for practical purposes – unsupported on devices with Google services since the end of 2024 – and should not exist in new deployments. Everything in a modern Android management strategy runs through Android Enterprise, which splits into several sub-modes depending on ownership and use case.
For personally owned devices, Android Enterprise Work Profile is the right mode. It creates a separate, managed container on the device for work apps and data. The personal side of the device is completely invisible to Intune – you can’t see personal apps, personal data, or personal usage. The work profile can be wiped independently of the device, which means offboarding removes work data without touching anything personal.
For corporate-owned devices, the choice is between Fully Managed and Corporate-Owned Work Profile. Fully Managed gives you complete control of the device – it’s a single-purpose corporate device with no personal use case. Corporate-Owned Work Profile gives you the same work/personal separation as the personally owned work profile mode, but with additional corporate controls on the device side. It’s the right model for corporate devices that employees also use personally – a common reality even when policy says otherwise.
Dedicated devices – kiosks, shared devices, single-purpose hardware – run in a separate mode that locks the device to a specific app or set of apps. This is covered in detail in Phase 9.
What to configure before Phase 9
Before you get into the detail of mobile management, two things need to be in place. Apple Business Manager connected to Intune, if you’re managing iOS devices. And Android Enterprise binding – connecting your Intune tenant to a managed Google Play account. Both are tenant-level configurations that everything else in mobile management depends on.
The ABM connection establishes the token relationship that allows ADE enrollment and app licensing through VPP. Without it, iOS management is limited to manual enrollment with no supervised mode. The Android Enterprise binding establishes the managed Google Play relationship that allows you to approve and distribute Android apps through Intune. Without it, Android app deployment is restricted to side-loading or public store apps without management controls.
Get those two connections established and validated before building out enrollment profiles, compliance policies, or app protection policies for mobile. Everything downstream depends on them being in place and functioning correctly.
Intune Deployment Guide · Phase 3: Device Entry
‹ Previous: [3.3] MacOS Enrollment




