Skip to main content
An MDM connection links Iru to your mobile device management (MDM) service so devices can enroll and so Iru can recognize them as managed in device-trust decisions. You manage these under Policies → MDM Connections.

Choose a connection type

When you choose + MDM Connection, Iru Identity asks you to Select a connection type:

Connection settings

A connection has a display name and covers one or both platforms:
Not sure where to find these values? Run the Collect MDM details helper scripts on a device already enrolled in your MDM; the macOS script returns the APNs topic and Check-in URL, and the Windows script returns the Provider ID and Discovery service URL. See Resources.

Enrollment profiles

For Apple platforms, download configuration profiles from Policies → MDM Connections in Iru Identity. Click the download button to the left of + MDM Connection, then choose macOS Profile or iOS Profile. These configure Iru Access on a managed device (its privacy permissions and single sign-on extension) for deployment through your MDM; they don’t enroll the device into MDM itself.

Connection secrets

A connection uses a client secret that you can rotate from the connection’s Client secrets list:
  • Rotate issues a new secret while the previous one keeps working for 24 hours, so you can update the MDM before the old secret stops. The previous secret shows an Expires Soon badge until it expires.
  • Invalidate ends a secret immediately; use it if a secret may have been exposed.

How this relates to device trust

A connected MDM is how Iru can tell that a device is managed. Combined with the health signals the Iru Access app reports, your authentication policies can require a known, managed, healthy device before granting access.

Where to go next

Device trust

Use managed and health signals as conditions in a policy.

Authenticators

How users install and register Iru Access on their devices.