Single Sign-on Profiles
Before users register for Microsoft Device Compliance, deploy Single Sign-on so devices can authenticate to Microsoft Entra ID during registration. Skip this section if the Microsoft Single Sign-on Extension—or Platform SSO with Microsoft Entra ID—is already deployed for the platforms you configured.- macOS
- iOS and iPadOS
Name the Library Item
Select Platform
Assign to Blueprints
Configure Microsoft SSO Extension Settings
Save the Library Item
Microsoft Company Portal Auto App (macOS)
To add the Microsoft Company Portal Auto App Library Item to your Iru Endpoint Library, follow the steps outlined in the Library Overview article.Assign Label and Blueprints
Configure Installation Type
Set Version Enforcement
- Do not manage updates
- Automatically enforce new updates
- Manually enforce a minimum version
Save Configuration
Microsoft Authenticator & Iru Self Service (iOS & iPadOS)
Navigate to Library
Select Microsoft Authenticator
Assign to Blueprints
Configure Installation Type
Enable Microsoft Device Compliance
Save Configuration
Configure Iru Self Service
User Registration
macOS
Once the Microsoft Company portal is installed on the Mac, the Iru Agent will attempt to launch the app automatically, following a specific process required by Microsoft so that end users can begin the registration process. For more information about what users should expect, see our Microsoft Device Compliance: User Registration Experience support article.iOS & iPadOS
Once the Microsoft Authenticator app is installed on a mobile device, users will find an option in the Iru Self Service app labeled ‘Microsoft Device Compliance Device.’ This is where they can start the registration process.How to Reset Microsoft Device Registration
You can use the Reset Microsoft Registration action on macOS, iOS, and iPadOS to reset the registration. This command does not require any supervision. Prerequisites that should be in place before the action will appear in the action menu- The Microsoft Device Compliance integration should be set up both in Iru Endpoint and in Microsoft Intune portal.
- On macOS, the Microsoft Company Portal Auto App Library Item is scoped to the device and installed.
- On iOS and iPadOS, the Microsoft Authenticator App Store app Library Item is scoped to the device and the Microsoft Device Compliance setting is toggled on and installed.
Navigate to Device Record
Open Device Action Menu
Select Reset Microsoft Registration
Confirm Reset
Wait for Processing
Reset Registration Status
Re-register Device
-
On macOS, the Iru Agent sees that the device is no longer registered and prompts the user to register their device again.
- This will happen at agent check in or if a manual check in is performed on the Mac.
- If the Microsoft Company Portal app is open, it will need to be closed to get the re-registration prompt.
- If the Microsoft Company Portal app is closed, once the device checks in with the Iru Agent, they will receive a prompt to re-register.
- If the Microsoft Company Portal app is closed, re-launching the Microsoft Company Portal will prompt to re-register immediately.
- On iOS and iPadOS, the user can follow the registration process as if registering the device for the first time.
Update Device Record
| Message | Description |
|---|---|
| ”No active Microsoft device registration found.” | This means that the device has a record in Iru Endpoint, and there is a Microsoft device registration for the device in Iru Endpoint but is not active. This is generally due to the device no longer being enrolled in Iru Endpoint either because the MDM profile was removed locally on the device or the erased device action was sent from Iru Endpoint. To remediate, the device needs to be reenrolled to Iru Endpoint and the MSDC registration needs to be completed again locally on the device. |
| ”Device is not registered” | This means that the device has all of the prerequisites in place but has not yet registered with Microsoft through the Iru Endpoint MSDC integration. If the device was registered with Microsoft previously through another MDM solution, the end-user will need to complete the registration process again through the Iru Endpoint integration. See MSDC registration for more details. |
| ”Reset Registration failed” | Default error message if none of the above. |
Compliance Status
After a user has registered their device, see Microsoft Device Compliance Validating Compliance to verify the compliance status.Next Steps
After SSO profiles and registration apps are deployed:Have Users Register Their Devices