How It Works
Iru Endpoint supports two approaches: Automated Device Enrollment (ADE) for corporate-owned devices (they enroll automatically during setup), and manual enrollment through the Enrollment Portal for Bring Your Own Device (BYOD). For ADE, you assign devices in Apple Business or Apple School Manager to Iru Endpoint, then assign them to a Blueprint in Iru Endpoint. For manual enrollment, you share the Enrollment Portal link and Enrollment code with users; they enter the Enrollment code, then sign in (if you require authentication) and install the enrollment profile. In both cases, devices are assigned to a Blueprint and configured according to your policies.Automated Device Enrollment (ADE)
ADE allows devices to enroll automatically during the initial setup process. This is the recommended method for corporate-owned devices.Prerequisites
- Apple Push Notification service (APNs) configured in Iru Endpoint
- Apple Business or Apple School Manager account configured
- Automated Device Enrollment token set up in Iru Endpoint
- Devices added to your Apple Business or Apple School Manager account
- Blueprints configured for device assignment
ADE Enrollment Flow
When users set up their devices, each device connects to Apple’s servers during setup and Iru Endpoint automatically applies the assigned Blueprint. Each device gets enrolled and configured according to your policies, then the user completes setup with pre-configured settings.Assign devices in Apple Business or Apple School Manager
Navigate to Devices
Select Devices
Assign to MDM
Select Iru Endpoint
Confirm Assignment
Configure Blueprint assignment
Navigate to Automated Device Enrollment
Filter and View Devices
Assign to Blueprint
Configure Authentication (optional)
Confirm and Sync
ADE Library Item Assignment
Optionally set or override the ADE Library Item for a device (or multiple devices) instead of using the one from its Blueprint or Blueprint Routing.Navigate to Automated Device Enrollment
Filter and Select Devices
View the ADE Library Item Column

Unlink from Blueprint
Re-link or select an ADE Library Item

Manual Enrollment
Manual enrollment allows users to enroll their devices through the Iru Endpoint Enrollment Portal.Setup Manual Enrollment
Configure Enrollment Portal
Configure Authentication
Share Enrollment Information
User Enrollment Process
When users access the Enrollment Portal, they’ll enter the provided Enrollment code and authenticate using SSO if you’ve enabled that option. They then download and install the enrollment profile to complete enrollment and receive device configuration.Enrollment Authentication
SSO Authentication
To enhance security, you can require SSO authentication during enrollment. Configure SSO in Iru Endpoint (see SSO Setup), then enable Require authentication on your Blueprint. Users will authenticate with their identity provider before enrollment.Enrollment Codes
Each Blueprint has a unique Enrollment code that users need to enroll their devices. You can share codes directly with users, use SSO authentication to automatically assign users to the correct Blueprint, or create multiple Blueprints for different user groups or departments.Best Practices
Test your Blueprints on designated testing devices before enrolling production hardware. Use Automated Device Enrollment for corporate-owned devices, as it provides the best user experience. Enable SSO authentication for secure enrollment and provide clear instructions to users about the enrollment process. You can monitor enrollment success and troubleshoot issues using the Activity Page.Troubleshooting
Trial Tenant Device Limit
Trial tenants are limited to a total of 10 devices. Once this limit is reached, a banner will be displayed until the device count becomes less than 10 again.Common Issues
If devices aren’t appearing, check your Apple Business or Apple School Manager configuration and device assignment. For enrollment failures, verify your Blueprint configuration and network connectivity. If you’re seeing authentication issues, check that SSO is configured correctly and that users have the right access.Support Resources
Check the Activity Page for enrollment logs and errors, and review Device records for enrollment status. Contact Support if you need additional assistance.Related Articles
Blueprint Routing
Configuring Apple Enrollment
User Experience with Apple Enrollment
Configure Require Authentication for Enrollment
Next Steps
After setting up Apple enrollment:Test Enrollment
Set Up Enrollment for Other Platforms (optional)