Skip to main content

017: Review enrolled vs unenrolled for BYOD/Corporate

Overview

BYOD vs. Corporate Devices for MDM in Intune for iOS

When managing iOS devices with Microsoft Intune, you have two primary options: Bring Your Own Device (BYOD) and Corporate-Owned Devices. Each approach has its own set of enrollment methods, benefits, and implications for your Zero Trust security posture.

Enrollment Options

  1. BYOD (Bring Your Own Device):

    • User Enrollment: This method allows users to enroll their personal devices while maintaining a separation between personal and corporate data. It uses a Managed Apple ID and provides a limited set of management capabilities.
    • Device Enrollment: Users enroll their personal devices through the Intune Company Portal app, which installs a management profile on the device.
  2. Corporate-Owned Devices:

    • Automated Device Enrollment (ADE): Formerly known as the Apple Device Enrollment Program (DEP), this method is used for devices purchased through Apple Business Manager or Apple School Manager. It allows for zero-touch deployment and supervision of devices.
    • Apple Configurator: This method is used for bulk enrollment of devices that are not purchased through Apple Business Manager. It requires physical access to the devices for initial setup.

Benefits of Each Method

  1. BYOD:

  2. Corporate-Owned Devices:

Zero Trust Security Posture

  1. BYOD:

  2. Corporate-Owned Devices:

By leveraging Intune's capabilities, both BYOD and corporate-owned device strategies can be aligned with Zero Trust principles to ensure secure access to corporate resources while maintaining a high level of user productivity and satisfaction.

Reference

(1) Corporate vs Personal Devices-Intune - T-minus365. https://tminus365.com/corporate-vs-personal-devices-intune/. (2) Device enrollment guide for Microsoft Intune | Microsoft Learn. https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment. (5) iOS/iPadOS device enrollment guide for Microsoft Intune. https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-ios-ipados. (6) Deployment guide: Manage iOS/iPadOS devices in Microsoft Intune. https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-platform-ios-ipados. (7) Tutorial: Set up Microsoft Intune enrollment for iOS/iPadOS devices in .... https://learn.microsoft.com/en-us/mem/intune/enrollment/tutorial-use-device-enrollment-program-enroll-ios. (10) Personal vs. Corporate Devices for Remote Work: Pros & Cons. https://www.bemopro.com/cybersecurity-blog/personal-vs.-corporate-devices-pros-cons. (11) How to have secure remote working with a BYOD policy. https://news.microsoft.com/en-xm/2021/03/18/how-to-have-secure-remote-working-with-a-byod-policy/. *