> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure Require Authentication for Enrollment

> Require user authentication during device enrollment in Iru Endpoint. Configure identity verification for Apple, Windows, and Android platforms.

<Callout icon="earth-americas" color="#B84A7A" iconType="regular">This guide applies to all device platforms</Callout>

## What is Require Authentication?

Require authentication is an enrollment setting that requires the enrolling user to complete single sign-on before device enrollment can finish. You choose which SSO connection to use from those configured in **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**).

Require authentication can also be used alongside [Blueprint Routing](/en/endpoint/enrollment/blueprint-routing), which dynamically assigns devices to Blueprints during enrollment using Assignment Rules.

<Note>
  As of **April 8, 2026**, apps were updated from **Kandji** <img className="inline dark:hidden" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-light-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=3ac73eb9098c090ac2838a4902a70e35" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-light-icon.png" /><img className="hidden dark:inline" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-dark-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=1d4b643c8e1903aabdb072fdf211f2de" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-dark-icon.png" /> to **Iru** <img src="https://mintcdn.com/iru/8j4H0SpqtcKJ5JUM/assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg?fit=max&auto=format&n=8j4H0SpqtcKJ5JUM&q=85&s=befa6ce99e1df18d397deb65aec8edaf" alt="" style={{ display: 'inline', height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 -0.08em 0 0', padding: 0 }} width="14" height="15" data-path="assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg" /> branding. The manual enrollment portal now uses Iru branding.
</Note>

## Manual Enrollment (All Devices)

On the **Enrollment** page, open the **Manual Enrollment** tab. For each Blueprint, you can enable **Require authentication** so users who enroll through the enrollment portal must complete SSO sign-in before enrollment continues.

### Authentication Methods

Require authentication for manual enrollment supports [Passkeys](/en/iru/access/passkeys-and-social-login#passkeys), [Google Social and Microsoft Social](/en/iru/access/passkeys-and-social-login#social-login), [Custom SAML](/en/endpoint/integrations/single-sign-on-integrations/saml-based-single-sign-on), and [Native SSO](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on).

### Prerequisites

* Enrollment configured for your platform: [Apple](/en/endpoint/enrollment/apple/configuring-apple-enrollment), [Windows](/en/endpoint/enrollment/windows/configuring-windows-enrollment), or [Android](/en/endpoint/enrollment/android/configuring-android-enrollment)
* If using Custom SAML or Native SSO: a working [SSO configuration](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) in **Access**
* If using Google Social or Microsoft Social: [Limit Authentication to Domain](/en/iru/access/passkeys-and-social-login#limit-authentication-to-domain) enabled for that connection in **Access**

**User experience**: Share platform-specific enrollment instructions with your users: [Apple](/en/endpoint/enrollment/apple/user-experience-with-apple-enrollment), [Windows](/en/endpoint/enrollment/windows/user-experience-with-windows-enrollment), or [Android](/en/endpoint/enrollment/android/user-experience-with-android-enrollment).

### Configuring Require Authentication with Manual Enrollment

<Steps>
  <Step title="Navigate to Enrollment">
    Select **Enrollment** in the navigation bar.
  </Step>

  <Step title="Access Manual Enrollment">
    Navigate to the **Manual Enrollment** tab.
  </Step>

  <Step title="Open the Blueprint">
    Scroll down to the Blueprint you want. Click the Blueprint tile or the **chevron** (down arrow) on the row to expand it.

    <Frame>
      <img src="https://mintcdn.com/iru/49cA3ckigEsqbInf/assets/media/images/iru-manual-enrollment-page-select-blueprint.png?fit=max&auto=format&n=49cA3ckigEsqbInf&q=85&s=96c817af03d539a27aeb674180cb50e0" alt="Manual Enrollment page with Blueprint row and expand chevron" width="2714" height="2062" data-path="assets/media/images/iru-manual-enrollment-page-select-blueprint.png" />
    </Frame>
  </Step>

  <Step title="Edit Settings">
    Click **Edit Settings**.

    <Frame>
      <img src="https://mintcdn.com/iru/49cA3ckigEsqbInf/assets/media/images/iru-manual-enrollment-page-edit-settings.png?fit=max&auto=format&n=49cA3ckigEsqbInf&q=85&s=8c0f7dc3f0f629421579e8a257354a68" alt="Manual Enrollment Blueprint row with Edit Settings" width="2048" height="368" data-path="assets/media/images/iru-manual-enrollment-page-edit-settings.png" />
    </Frame>
  </Step>

  <Step title="Require authentication">
    Check the **Require authentication** box.
  </Step>

  <Step title="Connection">
    Choose a connection from the dropdown menu.

    <Tip>
      To use Google Social or Microsoft Social for **Require authentication** during enrollment, **Limit Authentication to Domain** must be enabled for that connection. See [Limit Authentication to Domain](/en/iru/access/passkeys-and-social-login#limit-authentication-to-domain) in Passkeys & Social Login.
    </Tip>
  </Step>

  <Step title="Assign user to device record">
    If desired, check **Assign user to device record**.

    <Note>
      When enabled, this option tries to match the authenticated user to a user in your directory integration(s) by email address. If a match is found, the user is automatically assigned to the device.
    </Note>
  </Step>

  <Step title="Save">
    Click **Save**.

    <Frame>
      <img src="https://mintcdn.com/iru/49cA3ckigEsqbInf/assets/media/images/iru-manual-enrollment-page-edit-settings-define-and-save.png?fit=max&auto=format&n=49cA3ckigEsqbInf&q=85&s=02a82df463afd20825d750de53bb2d34" alt="Manual Enrollment Edit Settings panel with options and Save" width="2046" height="720" data-path="assets/media/images/iru-manual-enrollment-page-edit-settings-define-and-save.png" />
    </Frame>
  </Step>
</Steps>

## Automated Device Enrollment (Apple only)

### Authentication Methods

Require authentication for Automated Device Enrollment supports only [Custom SAML](/en/endpoint/integrations/single-sign-on-integrations/saml-based-single-sign-on), [Google Workspace Native](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-native), and [Microsoft Entra ID Native](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-microsoft-entra-id-native) authentication methods.

### Prerequisites

* A working [SSO configuration](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) in **Access**
* Apple devices with Automated Device Enrollment configured. See [Configure Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment).

### Configuring Require Authentication with Automated Device Enrollment

To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. If you already have an Automated Device Enrollment Library Item, open it, click **Edit**, and skip to step 3.

<Steps>
  <Step title="Create Library Item">
    Give the new Automated Device Enrollment Library Item a **Name**.
  </Step>

  <Step title="Assign to Blueprints">
    Assign it to your [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints).
  </Step>

  <Step title="Require authentication">
    Check **Require authentication**. This requires a user to authenticate through single sign-on during device enrollment.
  </Step>

  <Step title="Connection">
    Under **Connection**, select the single sign-on connector to use for authentication.
  </Step>

  <Step title="Assign user to device record">
    Optionally, check **Assign user to device record** to automatically assign the authenticated user to the device.

    <Note>
      When enabled, this option tries to match the authenticated user to a user in your directory integration(s) by email address. If a match is found, the user is automatically assigned to the device.
    </Note>
  </Step>

  <Step title="Prefill initial account creation details">
    When **Assign user to device record** is enabled, optionally check **Prefill initial account creation details** to prepopulate the new computer account in Setup Assistant with the assigned user's details.

    <Info>
      If you're using [Passport](/en/endpoint/library/passport/configure-the-passport-library-item), make sure to turn off **Prefill initial account creation details** and **Lock pre-filled account creation details**. These settings conflict with Passport's account creation process and can cause Setup Assistant errors.
    </Info>
  </Step>

  <Step title="Lock pre-filled account creation details">
    Optionally check **Lock pre-filled account creation details**. If enabled, the user cannot modify the account creation details.

    <Frame>
      <img src="https://mintcdn.com/iru/WpzG08StF4QNxPlu/assets/media/images/iru-ade-require-authentication.png?fit=max&auto=format&n=WpzG08StF4QNxPlu&q=85&s=1e0e6568f3a9aea1517234a5aa23f6bb" alt="Automated Device Enrollment Require Authentication settings showing the Lock pre-filled account creation details option" width="1962" height="1008" data-path="assets/media/images/iru-ade-require-authentication.png" />
    </Frame>
  </Step>

  <Step title="Save configuration">
    Configure any remaining settings and click **Save**.
  </Step>
</Steps>

## Considerations

### General

<AccordionGroup>
  <Accordion title="Tenant Authentication Status" icon="toggle-on">
    An SSO connection does not need to have **Enable Tenant Authentication** turned on to be used for Require authentication. Only enable tenant authentication if you also want Iru Endpoint admins to use that same connection to sign in to the Iru Endpoint Web App.
  </Accordion>

  <Accordion title="User Experience" icon="eye">
    If you use the same connection for both admin access and device enrollment, your end users will see the Iru Endpoint app in their identity provider's catalog. This won't give them admin access to your Iru Endpoint tenant.
  </Accordion>
</AccordionGroup>

### Apple

<AccordionGroup>
  <Accordion title="Google Workspace: Use Custom SAML" icon="google" iconType="brands">
    When using Google Workspace as your identity provider, you must create your SSO connection [using Custom SAML](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-saml). The [built-in Google Workspace integration](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-native) will cause a 403 error during enrollment.
  </Accordion>

  <Accordion title="Google Workspace: 2-Step Verification" icon="shield-check">
    Here's what happens depending on the user's 2-Step Verification status:

    **Already set up**: Users see the normal Google authentication window with options for text, authenticator app, or backup codes.

    **Past enrollment period**: Users get an error message about not meeting the 2-Step Verification policy. They'll need to contact their admin to resolve this.

    **Never enabled, still in grace period**: Users will see a 404 error.
  </Accordion>

  <Accordion title="Passport Integration (Automated Device Enrollment)" icon="key">
    If you're using [Passport](/en/endpoint/library/passport/configure-the-passport-library-item), make sure to turn off **Prefill initial account creation details** and **Lock pre-filled account creation details**. These settings conflict with Passport's account creation process and can cause Setup Assistant errors.
  </Accordion>
</AccordionGroup>

### Windows

<AccordionGroup>
  <Accordion title="Administrator Rights" icon="user-shield">
    Make sure the user enrolling the device has local administrator rights on the Windows machine.
  </Accordion>

  <Accordion title="Network Requirements" icon="wifi">
    Make sure the device has internet access and Microsoft Edge browser. You'll also need to open the required firewall ports for enrollment to work. For more information, see [Microsoft's documentation on MDM enrollment](https://learn.microsoft.com/en-us/windows/client-management/mdm-enrollment-of-windows-devices#connect-your-windows-device-to-work-using-a-deep-link).
  </Accordion>

  <Accordion title="Microsoft Account Prompt" icon="circle-info">
    During enrollment, users will see a "This site is trying to open Microsoft account" prompt. Tell them to click **Open** to continue the process.
  </Accordion>
</AccordionGroup>

### Android

<AccordionGroup>
  <Accordion title="Device State" icon="mobile">
    Make sure Android devices are in a factory restored state before attempting enrollment.
  </Accordion>

  <Accordion title="Work Profile" icon="briefcase">
    Enrollment creates a work profile that keeps work and personal data completely separate. Work apps go in the work profile, while personal apps stay in the personal profile.
  </Accordion>
</AccordionGroup>

## Related Articles

<CardGroup cols={3}>
  <Card title="Configuring Apple Enrollment" icon="apple" href="/en/endpoint/enrollment/apple/configuring-apple-enrollment">
    Configure Apple device enrollment with Automated Device Enrollment (ADE)
  </Card>

  <Card title="Configuring Windows Enrollment" icon="microsoft" href="/en/endpoint/enrollment/windows/configuring-windows-enrollment">
    Windows device enrollment and management setup
  </Card>

  <Card title="Configuring Android Enrollment" icon="android" href="/en/endpoint/enrollment/android/configuring-android-enrollment">
    Android device enrollment and work profile setup
  </Card>

  <Card title="User Experience with Apple Enrollment" icon="user" href="/en/endpoint/enrollment/apple/user-experience-with-apple-enrollment">
    What to expect when enrolling your device through the enrollment portal
  </Card>

  <Card title="User Experience with Windows Enrollment" icon="user" href="/en/endpoint/enrollment/windows/user-experience-with-windows-enrollment">
    What to expect when enrolling your Windows device through the enrollment portal
  </Card>

  <Card title="User Experience with Android Enrollment" icon="user" href="/en/endpoint/enrollment/android/user-experience-with-android-enrollment">
    What to expect when enrolling your Android devices and setting up a work profile
  </Card>
</CardGroup>
