Menu
CCMEXEC.COM – Enterprise Mobility
  • Home
  • General
  • Configuration Manager
  • Windows 10
  • Intune
  • GitHub
  • Windows 11
  • About the author
CCMEXEC.COM – Enterprise Mobility

Intune and DEP some leasons learned

Posted on August 5, 2015 by Jörgen Nilsson

I have had the opportunity to implement Intune together with customers where we have implemented the Apple DEP program together with Intune. DEP stands for Device Enrollment Program and is the recommended way of managing company owned iOS devices as it can configure the iOS device to be enrolled during setup of the device even after a reset. It can also configure the iOS device to be in Supervised mode as well which allows for many more management capabilities. All this is done over-the-air so no cable or handling needed by the IT department just register the device in DEP and then send it directly to the end-user, you can configure the first time setup wizard using Intune and controlling which options should be available. You could say that DEP is the same as Apple Configurator over-the-air also note that DEP is not avilable in all countries which also could be a challenge.

In Intune you can configure one or more DEP policies in Intune where you can control the settings shown below.

DEP1dep2

A device registered in Apple DEP program cannot be “un-enrolled” if you reset the device it will force you to register with the Intune again in the first time experience. As your DEP enrollment policy dictates. Supervised mode is really important for at least company owned devices as you get more management capabilities like the following policies:

  • Global network proxy for HTTP
  • Allow iMessage
  • Allow Game Center
  • Allow removal of apps
  • Allow iBooks Store
  • Allow podcasts
  • Allow user-generated content in Siri
  • Allow manual installation of configuration files
  • Allow configuring restrictions
  • Allow pairing to computers for content sync
  • Allow AirDrop
  • Allow account modification
  • Allow cellular data settings modification
  • Allow Find My Friends
  • Allow Erase All Content and Settings
  • Restrict AirPlay connections with whitelist and optional connection passcodes
  • Enable Siri Profanity Filter
  • Single App Mode
  • Accessibility settings

More information about the Apple DEP program can be found here: https://www.apple.com/business/dep/

You can register iOS devices you have already bought as well in DEP, “Mac or iOS devices purchased on or after March 1, 2011 can be enrolled in DEP Mac or iOS devices purchased from participating Apple Authorized resellers or carriers must be added to your DEP instance to be included” from the DEP frequently asked questions section. This is a nice option once you got management commitments to actually take control of you device as in many companies these policies are still non-existent.

I have done this in a couple of implementations where we have imported iOS devices that are already in use by the end user, and here as some pointers that can be good to know.

  • If a device is enrolled in Intune using the Company Portal and then added to DEP and synced to Intune it will be removed from the Intune console and replaced by the object synced from DEP. You will need to reset the device and enroll it using DEP instead.
  • If a device is synced from DEP it cannot be enrolled using the Company Portal as it has an active DEP policy deployed to it.
  • You cannot “unenroll” a device that is enrolled using DEP
  • You can remove a device from DEP if it is stolen for instance but once removed it can never be added back to DEP.

DEP and Intune is best together! DEP is the way I would recommend managing your company owned iOS devices.

I hope that can be helpful

5 thoughts on “Intune and DEP some leasons learned”

  1. mirko says:
    August 5, 2015 at 2:49 pm

    Hi Jörgen
    Nice post, good to find anyone that has implementet in real. I have written a post all about befor you get the details and work with

    Reply
  2. Pingback: Apple DEP and Intune – Part 1 – The issues | Bindertech
  3. oro says:
    August 26, 2015 at 12:15 pm

    If a device is synced from DEP it cannot be enrolled using the Company Portal as it has an active DEP policy deployed to it. -> you can, set affinity in dep profiles (sccm console) then set supervised and “lock enrolmet process…” enable.
    You can use dep and intune client at the same time now

    Reply
  4. Zach Sheldon says:
    September 17, 2015 at 4:33 am

    Hey Jorgen –

    Any prereqs that you know of regarding DEP and Intune? Are there any specific networking/firewall ports that need to be opened? Do they need to be open bidirectionally?

    Do you know?

    Thanks!!

    Reply
  5. Pingback: Fatshark's Personal Blog

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

My name is Jörgen Nilsson and I work as a Senior Consultant at Onevinn in Malmö, Sweden. This is my blog where I will share tips and stuff for my own and everyone elses use on Enterprise Mobility and Windows related topics.
All code is provided "AS-IS" with no warranties.

Tweets by ccmexec

Recent Posts

  • Windows Servicing, Personal Teams and Success.cmd
  • Windows MDM Security Baseline – Settings Catalog
  • Configuring MS Edge Security Baseline v107 using Settings Catalog
  • Configuring Desktop App Installer using CSP and script?!
  • Customizing Taskbar and Start in Windows 11 22h2 with PowerShell

©2023 CCMEXEC.COM – Enterprise Mobility | WordPress Theme by Superb Themes
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish.Accept Reject Read More
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT