Skip to content
How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune

How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune

Written By Anoop C Nair
Last Updated March 18, 2025
Posted In Intune
SHARE

Let’s discuss How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune. As per Microsoft update, Q2CY25, iOS/iPadOS automated device enrollment (ADE) policies will move to a new infrastructure that enables Intune to speed up the delivery of new features.

You will get a better-organized authentication method with this update. And with this update, no automatic deployment of the Company Portal application. And one of the important update related to this are there will be more granular admin controls for the policies page and Apple-deprecated settings have been removed.

As you know, iOS/iPadOS ADE (Automated Device Enrollment) is a feature designed to simplify and streamline the process of enrolling Apple devices, like iPhones and iPads, into a mobile device management (MDM) system such as Microsoft Intune.

As per the update all newly created enrollment policies for iOS/iPadOS will automatically be part of the new experience. In this blog post, i would like to share more informations about iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune.

Patch My PC
How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune - Fig.1
How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune – Fig.1

How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune

As mentioned above iOS/iPadOS automated device enrollment (ADE) policies will move to a new infrastructure. With this update Existing enrollment profiles won’t be affected. You’ll be able to delete, edit, and assign existing enrollment profiles but you’ll no longer be able to create them with the old experience.

Microsoft recommend to create new enrollment policy and setting it as the default so new enrollments will use the new policy as soon as possible.  

Benefits of New Experience
The columns control can be used to select which columns should be default, which one should be the primary column, and which ones to show or hide. 
The search bar can be used to search by any column field contents and isn’t case sensitive. 
The filter control can be used to filter the policies by platform. We’ll add more filtering for the other columns soon. 
Sort each column in ascending or descending order by clicking on the column header.
No more automatic Company Portal app deployment. We recommend using Setup Assistant with modern authentication, however, if you still want to send down the Company Portal app to your users or devices, you can deploy the application as needed along with the required app configuration policy.
Shared iPad has its authentication method for devices with no user device affinity.
How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune – Table.1

Create a New ADE Policy for iOS/iPadOS Devices

From the Microsoft Intune admin center you can easily Create a new enrollment policy. To do this go to Devices > Enrollment > Apple > Enrollment program tokens > select a token > Enrollment policies > Create.

Here, new enrollment policies can be created and assigned to devices that have synced over from Apple Business Manager or Apple School Manager. Additionally, enrollment policies can be deleted or set as the default by navigating to the ellipsis in a policy. 

How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune - Fig.2 - Creds to MS
How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune – Fig.2 – Creds to MS

Assigning New Enrollment Policies to Devices

The device assignment flow for ADE policies is the same. Within the policy, navigate to the Devices tab to select a device(s) and select Assign policy. Ensure that you’re assigning a new enrollment policy to the devices.

Existing (old) Enrollment Profiles
Existing enrollment profiles will remain in Devices > Enrollment > Apple > Enrollment program tokens > select a token > Profiles. New enrollment profiles within Profiles cannot be created.
Existing enrollment profiles can be deleted, edited, and viewed. Their device assignments will not be affected or changed.
We recommend you migrate your ADE devices from being assigned to old enrollment profiles over to new enrollment policies and always have the Await final configuration setting set to Yes.
If you delete an old enrollment profile, the device rename is no longer enforced (that is if someone changes the device name).
How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune – Table.2

Sending the Company Portal App to ADE Devices with User Device Affinity (Optional)

With new enrollment policies, the Company Portal application will never be sent down automatically from the creation or assignment of the enrollment policy. For enrollment policy with user device affinity, we strongly recommend you set the authentication method to Setup Assistant with modern authentication.

But if you still want to send down the Company Portal app to your users or devices, you can deploy the application as needed, along with the required app configuration policy. For this you can use XML for the app configuration policy for the Company Portal authentication method.

<dict>
<key>IntuneUDAUserlessDevice</key>
<string>{{SIGNEDDEVICEID}}</string>
</dict>

    How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune - Fig.3 - Creds to MS
    How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune – Fig.3 – Creds to MS

    For the Setup Assistant with a modern authentication method, send the following XML for the app configuration policy.

    <dict>
    <key>IntuneCompanyPortalEnrollmentAfterUDA</key>
    <dict>
    <key>IntuneDeviceID</key>
    <string>{{deviceid}}</string>
    <key>UserId</key>
    <string>{{userid}}</string>
    </dict>
    </dict>

    How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune - Fig.4 - Creds to MS
    How to Create a New iOS or iPadOS ADE Enrollment Policies Experience in Microsoft Intune – Fig.4 – Creds to MS

    Need Further Assistance or Have Technical Questions?

    Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

    Resource

    New iOS/iPadOS ADE enrollment policies experience

    Author

    Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

    Written by

    Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

    Discussion · 4 comments

    1. the XML for app config didnt work. “unrecognized app configuration” with or with out company portal deployed via VPP is not recognizing the device as enrolled via ADE already and tries to user enroll it and you cant access anything in the company portal app “device needs to be managed before you can install apps”

    Join the discussion

    Your email address will not be published. Required fields are marked *

    Related guides

    Intune

    Simplify Windows Devices to Run Only the Required Applications using Intune

    Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

    AC Anoop C Nair 8 min read
    Intune

    Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

    Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

    AC Anoop C Nair 4 min read
    Intune

    Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

    Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

    AC Anoop C Nair 4 min read
    Intune

    MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

    Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

    AC Anoop C Nair 5 min read