> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Apple Enrollment

> Set up Apple device enrollment in Iru Endpoint as part of initial setup. Configure ADE, create enrollment URLs, and enroll your first Apple device.

<Callout icon="apple" color="#4f46e5" iconType="regular">This guide applies to Mac computers, iOS devices, iPadOS devices, Apple TV, and Apple Vision Pro</Callout>

<Note title="Apple Business name change">
  **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web).
</Note>

Set up Apple enrollment so you can add Mac computers, iPhone, iPad, Apple TV, and Apple Vision Pro devices to Iru Endpoint and get the right apps, settings, and security controls applied so people can get to work.

<Note>
  As of **April 8, 2026**, apps were updated from **Kandji** <img className="inline dark:hidden" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-light-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=3ac73eb9098c090ac2838a4902a70e35" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-light-icon.png" /><img className="hidden dark:inline" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-dark-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=1d4b643c8e1903aabdb072fdf211f2de" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-dark-icon.png" /> to **Iru** <img src="https://mintcdn.com/iru/8j4H0SpqtcKJ5JUM/assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg?fit=max&auto=format&n=8j4H0SpqtcKJ5JUM&q=85&s=befa6ce99e1df18d397deb65aec8edaf" alt="" style={{ display: 'inline', height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 -0.08em 0 0', padding: 0 }} width="14" height="15" data-path="assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg" /> branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names.
</Note>

### How It Works

Iru Endpoint supports two approaches: **Automated Device Enrollment (ADE)** for corporate-owned devices (they enroll automatically during setup), and **manual enrollment** through the Enrollment Portal for Bring Your Own Device (BYOD). For ADE, you assign devices in Apple Business or Apple School Manager to Iru Endpoint, then assign them to a Blueprint in Iru Endpoint. For manual enrollment, you share the Enrollment Portal link and Enrollment code with users; they enter the Enrollment code, then sign in (if you require authentication) and install the enrollment profile. In both cases, devices are assigned to a Blueprint and configured according to your policies.

## Automated Device Enrollment (ADE)

ADE allows devices to enroll automatically during the initial setup process. This is the recommended method for corporate-owned devices.

### Prerequisites

* [Apple Push Notification service (APNs)](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service) configured in Iru Endpoint
* Apple Business or Apple School Manager account configured
* [Automated Device Enrollment token](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment) set up in Iru Endpoint
* Devices added to your Apple Business or Apple School Manager account
* Blueprints configured for device assignment

### ADE Enrollment Flow

When users set up their devices, each device connects to Apple's servers during setup and Iru Endpoint automatically applies the assigned Blueprint. Each device gets enrolled and configured according to your policies, then the user completes setup with pre-configured settings.

### Assign devices in Apple Business or Apple School Manager

<Steps>
  <Step title="Navigate to Devices">
    In Apple Business or Apple School Manager, navigate to **Devices**.
  </Step>

  <Step title="Select Devices">
    Select the devices you want to assign.
  </Step>

  <Step title="Assign to MDM">
    Choose **Assign to Mobile Device Management (MDM) Server**.
  </Step>

  <Step title="Select Iru Endpoint">
    Select Iru Endpoint as the MDM server.
  </Step>

  <Step title="Confirm Assignment">
    Confirm the assignment when prompted.
  </Step>
</Steps>

### Configure Blueprint assignment

<Steps>
  <Step title="Navigate to Automated Device Enrollment">
    In Iru Endpoint, navigate to **Enrollment** → **Automated Device Enrollment**.
  </Step>

  <Step title="Filter and View Devices">
    Filter by **Awaiting Enrollment** (or **All**) to view unenrolled devices.
  </Step>

  <Step title="Assign to Blueprint">
    Select the devices and assign them to the appropriate **Blueprint**.
  </Step>

  <Step title="Configure Authentication (optional)">
    Configure any required authentication settings. See [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment) for details.
  </Step>

  <Step title="Confirm and Sync">
    Confirm devices appear and use **Fetch devices** to sync from Apple if they do not.
  </Step>
</Steps>

### ADE Library Item Assignment

Optionally set or override the ADE Library Item for a device (or multiple devices) instead of using the one from its Blueprint or Blueprint Routing.

<Steps>
  <Step title="Navigate to Automated Device Enrollment">
    In Iru Endpoint, go to **Enrollment** → **Automated Device Enrollment**.
  </Step>

  <Step title="Filter and Select Devices">
    Filter by **Awaiting Enrollment** (or **All**) to view unenrolled devices, then select the device(s) whose ADE Library Item you want to set or override.
  </Step>

  <Step title="View the ADE Library Item Column">
    The **ADE Library Item** column shows the name of the ADE Library Item assigned to the Blueprint selected for enrollment or Blueprint Routing, or **None** if none is assigned.

    <Frame>
      <img src="https://mintcdn.com/iru/CVmlkJ7omYtYwEGw/assets/media/images/iru-ade-library-item-unlink-from-blueprint.png?fit=max&auto=format&n=CVmlkJ7omYtYwEGw&q=85&s=65516a3ce4998d75a3c412983e4ad9d1" alt="ADE Library Item column showing None and Unlink from Blueprint button" width="878" height="174" data-path="assets/media/images/iru-ade-library-item-unlink-from-blueprint.png" />
    </Frame>
  </Step>

  <Step title="Unlink from Blueprint">
    To override the assignment so you can choose a different ADE Library Item, click **Unlink from Blueprint** or **Unlink from Blueprint Routing**, whichever appears.
  </Step>

  <Step title="Re-link or select an ADE Library Item">
    Once unlinked, choose **Re-link to Blueprint** or **Re-link to Blueprint Routing**, or select an **ADE Library Item** from the list. You can do this for one device or for many via multi-select.

    <Frame>
      <img src="https://mintcdn.com/iru/CVmlkJ7omYtYwEGw/assets/media/images/iru-ade-library-item-select-or-relink.png?fit=max&auto=format&n=CVmlkJ7omYtYwEGw&q=85&s=e63eae7cd50bcce6164613d35cafd773" alt="ADE Library Item dropdown with Select ADE Library Item and Re-link to Blueprint options" width="458" height="482" data-path="assets/media/images/iru-ade-library-item-select-or-relink.png" />
    </Frame>

    <Note>
      A direct assignment is sticky and will always apply to the device unless you manually re-link it to the Blueprint or Blueprint Routing. Re-linking can be done one device at a time or in bulk.
    </Note>
  </Step>
</Steps>

## Manual Enrollment

Manual enrollment allows users to enroll their devices through the Iru Endpoint Enrollment Portal.

### Setup Manual Enrollment

<Steps>
  <Step title="Configure Enrollment Portal">
    a. Go to **Endpoint** → **Enrollment** → **Manual Enrollment** in Iru Endpoint.

    b. Ensure the **Enrollment Portal** is active.

    c. Determine which **Blueprint** you want devices to be added to after enrollment.
  </Step>

  <Step title="Configure Authentication">
    a. Click the **Blueprint** and select **Require authentication** if you want users to authenticate prior to enrollment.

    b. This integrates with your Single Sign-On (SSO) configuration for secure enrollment. If you see a banner that **No single sign-on connections are configured**, go to **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**) and configure Single sign-on, then return and select **Require authentication**. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for setup steps.
  </Step>

  <Step title="Share Enrollment Information">
    a. Copy the **Enrollment Portal link** from **Enrollment** → **Manual Enrollment**.

    b. Copy the **Enrollment code** for the Blueprint you chose.

    c. Share the Enrollment Portal link and Enrollment code with your end users.

    d. Provide a short note that they'll enter the Enrollment code, then sign in (if required), and follow on-screen prompts to complete enrollment.
  </Step>
</Steps>

### User Enrollment Process

When users access the Enrollment Portal, they'll enter the provided Enrollment code and authenticate using SSO if you've enabled that option. They then download and install the enrollment profile to complete enrollment and receive device configuration.

## Enrollment Authentication

### SSO Authentication

To enhance security, you can require SSO authentication during enrollment. Configure SSO in Iru Endpoint (see [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup)), then enable **Require authentication** on your Blueprint. Users will authenticate with their identity provider before enrollment.

### Enrollment Codes

Each Blueprint has a unique Enrollment code that users need to enroll their devices. You can share codes directly with users, use SSO authentication to automatically assign users to the correct Blueprint, or create multiple Blueprints for different user groups or departments.

## Best Practices

Test your Blueprints on designated testing devices before enrolling production hardware. Use Automated Device Enrollment for corporate-owned devices, as it provides the best user experience. Enable SSO authentication for secure enrollment and provide clear instructions to users about the enrollment process. You can monitor enrollment success and troubleshoot issues using the [Activity Page](/en/endpoint/devices/activity-page).

## Troubleshooting

### Trial Tenant Device Limit

Trial tenants are limited to a total of 10 devices. Once this limit is reached, a banner will be displayed until the device count becomes less than 10 again.

### Common Issues

If devices aren't appearing, check your Apple Business or Apple School Manager configuration and device assignment. For enrollment failures, verify your Blueprint configuration and network connectivity. If you're seeing authentication issues, check that SSO is configured correctly and that users have the right access.

### Support Resources

Check the [Activity Page](/en/endpoint/devices/activity-page) for enrollment logs and errors, and review Device records for enrollment status. [Contact Support](/en/iru/iru-support/access-to-iru-support) if you need additional assistance.

## Related Articles

<CardGroup cols={2}>
  <Card title="Blueprint Routing" icon="route" href="/en/endpoint/enrollment/blueprint-routing">
    Configure dynamic Blueprint assignment during device enrollment using Assignment Rules
  </Card>

  <Card title="Configuring Apple Enrollment" icon="apple" href="/en/endpoint/enrollment/apple/configuring-apple-enrollment">
    Configure Apple device enrollment with Automated Device Enrollment (ADE)
  </Card>

  <Card title="User Experience with Apple Enrollment" icon="user" href="/en/endpoint/enrollment/apple/user-experience-with-apple-enrollment">
    What to expect when enrolling your device through the Enrollment Portal
  </Card>

  <Card title="Configure Require Authentication for Enrollment" icon="shield" href="/en/endpoint/enrollment/configure-require-authentication-for-enrollment">
    Configure authentication requirements for device enrollment across Apple, Windows, and Android platforms
  </Card>
</CardGroup>

## Next Steps

After setting up Apple enrollment:

<Steps>
  <Step title="Test Enrollment">
    Test the process with a few devices and monitor compliance and policy enforcement on the [Activity Page](/en/endpoint/devices/activity-page).
  </Step>

  <Step title="Set Up Enrollment for Other Platforms (optional)">
    To enroll Windows or Android devices as well, see [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment) or [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment).
  </Step>
</Steps>

If you missed a step or want to review the path, see [Getting Started](/en/endpoint/getting-started/getting-started) for the full guide.
