What is Require Authentication?
Require authentication is an enrollment setting that requires the enrolling user to complete single sign-on before device enrollment can finish. You choose which SSO connection to use from those configured in Access (Account Menu Button → Access). Require authentication can also be used alongside Blueprint Routing, which dynamically assigns devices to Blueprints during enrollment using Assignment Rules.Manual Enrollment (All Devices)
On the Enrollment page, open the Manual Enrollment tab. For each Blueprint, you can enable Require authentication so users who enroll through the enrollment portal must complete SSO sign-in before enrollment continues.Authentication Methods
Require authentication for manual enrollment supports Passkeys, Google Social and Microsoft Social, Custom SAML, and Native SSO.Prerequisites
- Enrollment configured for your platform: Apple, Windows, or Android
- If using Custom SAML or Native SSO: a working SSO configuration in Access
- If using Google Social or Microsoft Social: Limit Authentication to Domain enabled for that connection in Access
Configuring Require Authentication with Manual Enrollment
Navigate to Enrollment
Access Manual Enrollment
Open the Blueprint

Edit Settings

Require authentication
Connection
Assign user to device record
Save

Automated Device Enrollment (Apple only)
Authentication Methods
Require authentication for Automated Device Enrollment supports only Custom SAML, Google Workspace Native, and Microsoft Entra ID Native authentication methods.Prerequisites
- A working SSO configuration in Access
- Apple devices with Automated Device Enrollment configured. See Configure Automated Device Enrollment.
Configuring Require Authentication with Automated Device Enrollment
To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the Library Overview article. If you already have an Automated Device Enrollment Library Item, open it, click Edit, and skip to step 3.Create Library Item
Assign to Blueprints
Require authentication
Connection
Assign user to device record
Prefill initial account creation details
Lock pre-filled account creation details

Save configuration
Considerations
General
Tenant Authentication Status
Tenant Authentication Status
User Experience
User Experience
Apple
Google Workspace: Use Custom SAML
Google Workspace: Use Custom SAML
Google Workspace: 2-Step Verification
Google Workspace: 2-Step Verification
Passport Integration (Automated Device Enrollment)
Passport Integration (Automated Device Enrollment)
Windows
Administrator Rights
Administrator Rights
Network Requirements
Network Requirements
Microsoft Account Prompt
Microsoft Account Prompt
Android
Device State
Device State
Work Profile
Work Profile