Skip to content
Avanet

Sophos Mobile: Understanding policies for Apple User Enrollment

Check the management mode first: The iOS user policy in Sophos Mobile is intended for iPhones and iPads enrolled through Apple User Enrollment. This enrollment mode is for personal devices (BYOD). It is not Apple Device Enrollment, where Sophos Mobile manages the entire device, nor is it Automated Device Enrollment (ADE) through Apple Business. iPhones and iPads automatically enrolled in that way are supervised. A supervised device cannot be enrolled through Apple User Enrollment. Do not apply settings from an iOS device policy or ADE instructions to a user policy without checking them first.

What separation actually means

Apple User Enrollment uses a managed Apple Account alongside the personal Apple Account. Business data resides on a managed APFS volume, including managed apps and app data, a managed keychain, and data from the managed Apple Account. When a user unenrolls from Sophos Mobile, iOS removes this managed volume from the device. This does not mean that an admin can reset the entire personal device or read personal content. With this enrollment type, Sophos Mobile cannot retrieve personal data or device identifiers such as the UDID, IMEI, and MAC address; because the MAC address is unavailable, NAC is not available for these devices.

Before deployment, confirm that the device is actually enrolled in User Enrollment mode and that the user has a managed Apple Account for enrollment. According to Sophos, profile-based enrollment is available only up to iOS/iPadOS 17; do not base newer rollouts on an old profile workflow. The Apple User Enrollment guide covers identities, tenant preparation and the appropriate enrollment path; this article remains a decision aid for the subsequent user policy.

This MDM management requires Sophos Mobile Device Management or the combined Sophos Mobile license; Sophos Mobile Threat Defense alone does not cover this branch. Before assignment, check the actual entitlement in the intended tenant against the Mobile license check.

Choose policies by purpose

  • Device passcode: When Password policies is assigned to a device enrolled through Apple User Enrollment, Sophos requires a six-digit device PIN and prohibits PINs with repeated or consecutive digits (Sophos gives 555555 and 987654 as examples). This also affects personal access to the device. Sophos Mobile cannot reset a forgotten device passcode. If the device does not meet the password requirements when this configuration is assigned, Sophos says a 60-minute grace period begins. During this period, the device prompts the user to change the device passcode every time they open the Home Screen. After the period expires, it may no longer be possible to launch any apps, including built-in and personal apps. Do not treat this configuration as a harmless workspace rule or deploy it without communicating with users first.
  • Business accounts: Email account adds Exchange Online or Exchange Server to Apple Mail; this account is managed. IMAP/POP configures the incoming and outgoing mail servers separately. Google account adds a Google account to the Mail app; when it is assigned, the user must enter their Google credentials. CalDAV and CardDAV handle calendar and contact synchronization, respectively. Servers, ports, authentication, and TLS must match the actual service; example URLs are not universal required settings. Both %_USERNAME_% and %_EMAILADDRESS_% appear in Email account and IMAP/POP, with different functions depending on the field. For both configurations, the user fields Exchange Login and Email Address must be populated in Sophos Fusion.
  • Exchange connection: In Email account, User is the login ID, whereas Email address is the account’s address. For Exchange Online, the login ID is normally the email address; %_EMAILADDRESS_% supplies the Email Address of the user assigned to the device. For Exchange Server, Sophos specifies %_USERNAME_% under User; the general placeholder help maps this value to the same user’s Exchange Login. Under Email address, %_EMAILADDRESS_% supplies the account address from Email Address. Neither the visible username nor a correctly formatted placeholder establishes a suitable login. First distinguish between the cloud environment and the authentication method. Without OAuth, Sophos specifies outlook.office365.com under Server name for the worldwide Microsoft 365 cloud. Do not apply this host to other Microsoft 365 clouds; determine their endpoints separately. For Exchange Server, enter the server URL; if using the Sophos Mobile EAS proxy, enter its URL instead. Domain remains empty for Exchange Online; for Exchange Server, enter the domain of the user account. Turn on OAuth 2.0 provides for sign-in with Microsoft credentials. According to Sophos, Server name remains empty when using OAuth because the Exchange host is determined automatically. The exception is when an OAuth authorization endpoint is entered: automatic discovery then no longer applies, and the mail server URL must be entered in Server name. Enter the authorization endpoint and the OAuth token endpoint only if the authentication provider requires them. According to Sophos, an empty Password means that the user must enter the password on the device. It is not a fallback to Basic Authentication or app passwords for Exchange Online EAS; Microsoft documents their removal. The Microsoft documentation reviewed also identifies a limitation for the native iOS Mail app in Gallatin and recommends Outlook mobile there. This does not establish approval for Apple Mail in all clouds.
  • Exchange transport and certificates: According to Sophos, SSL/TLS secures the connection to the Exchange server with SSL or TLS, depending on server support; Sophos recommends selecting the checkbox. For deployment, verify a TLS connection permitted under your security requirements and its certificate trust; do not treat the checkbox as proof of connectivity. Identity certificate concerns the connection identity for the Exchange server when the intended authentication method calls for it. Separately, Enable S/MIME enables encrypted messages; Signing certificate and Encryption certificate serve message signing and encryption, respectively. Before selection, upload the certificates required for each purpose as PKCS #12 (.pfx) under Client certificate > File > Upload a file in the same policy. Other policies require another upload; do not assume automatic reuse. These certificate branches are not mandatory for every Exchange account. Allow user to send unencrypted emails lets the user choose whether to encrypt each outgoing message; this choice is not a TLS setting.
  • Exchange synchronization: The five options control different account data: Synchronize calendar → Calendar (appointments and meetings), Synchronize contacts → Contacts, Synchronize mail → Mail, Synchronize notes → Notes and Synchronize tasks → Reminders (tasks). Each area has a separate permission to change it: User can change calendar synchronization, User can change contacts synchronization, User can change mail synchronization, User can change notes synchronization or User can change tasks synchronization, respectively. This permits the user to turn the corresponding synchronization on or off. Define data scope and permission to change it separately; enabling synchronization does not itself permit changing it on the device.
  • Google account: Google email address contains the full email address of the Google account. Here, User name is the user’s name for outgoing messages, not a mail server login ID. Do not apply the Exchange Login mapping from other configurations to this field.
  • IMAP/POP connection: Account type selects IMAP or POP for incoming messages. User display name is the display name for outgoing messages; the IMAP/POP help specifies %_USERNAME_% for this and describes its value as the name of the user assigned to the device. By contrast, the general Sophos placeholder help explicitly maps the same placeholder to the Exchange Login user field. It maps %_EMAILADDRESS_% to Email Address; here, this placeholder belongs in Email address, the account’s address. This identifies the documented field mapping, but does not resolve the differing descriptions of %_USERNAME_% as product behavior. Do not assume that the placeholder supplies an independent personal display name. Before use, check whether the configured Exchange Login value is suitable as the outgoing display name. For each of the incoming and outgoing mail servers, set User name as the connection ID and Authentication type as the sign-in method; Password is required in each case only if the server requires it. Use same password as for incoming email allows the outgoing account to use the incoming password. This does not imply identical usernames, ports, sign-in methods, or transport options. Each direction has its own SSL/TLS option. According to Sophos, it secures the respective connection with SSL or TLS, depending on server support. For deployment, both directions require a TLS connection permitted under your security requirements; these options establish neither certificate trust nor successful sign-in or mail transfer.
  • S/MIME for IMAP/POP: According to Sophos, users who need message encryption can send and receive encrypted messages with Enable S/MIME. For Signing certificate and Encryption certificate, the certificates must be uploaded to the Client certificate configuration in the same policy before they can be selected. Allow user to send unencrypted emails lets the user choose whether to encrypt each outgoing message. This optional message encryption is separate from SSL/TLS for transport; neither certificate trust nor compatibility with recipients has been verified here.
  • CalDAV account: In the user policy, Account name is the account’s display name on the device, not the login ID. Server specifies the hostname or IP address of the CalDAV server; User name and Password are the credentials for the CalDAV account. If the server requires it, enter the principal URL of the calendar resource under Principal URL. It identifies the required calendar resource and is not equivalent to the server name or the account’s display name. According to Sophos, the SSL/TLS option secures the connection to the CalDAV server with SSL or TLS, depending on what the server supports. Sophos recommends selecting this checkbox. For deployment, the service must support a TLS connection permitted under your security requirements; the checkbox alone confirms neither certificate trust nor successful sign-in or synchronization.
  • CardDAV account: Account name is the display name on the device; User name and Password are the credentials for the CardDAV account. Server contains the hostname or IP address of the CardDAV server; the port must match this service. If the server requires it, enter the principal URL of the contact resource under Principal URL. This resource address is not the server name or the account’s display name. According to Sophos, SSL/TLS secures the connection with SSL or TLS, depending on server support; Sophos recommends selecting the checkbox. For deployment, the service must support a TLS connection permitted under your security requirements. The checkbox alone establishes neither certificate trust nor successful sign-in or contact synchronization.
  • Mail data flows: A managed mail account and the managed APFS volume alone do not guarantee complete isolation. For Email account and IMAP/POP, separately check whether Allow move permits moving messages into other accounts or replying/forwarding through another account, whether Allow recent address syncing synchronizes recently used addresses through iCloud to other devices, and whether Use in Mail only restricts use as a sending account from other apps. For IMAP/POP, also check Allow Mail Drop as a separate data flow. Do not treat any one of these options as a proven DLP guarantee.
  • Data flows: Restrictions contains separate document rules for managed → unmanaged and unmanaged → managed, for unmanaged apps reading managed contacts, and for the clipboard and iCloud synchronization. The documented separation of managed mail attachments requires both a managed account and managed apps. If the rule for documents within managed apps/accounts is turned off, the following two options (contact sharing and the document rule for unmanaged apps/accounts) are disabled. According to Sophos, contacts from managed accounts can then be shared with unmanaged apps. With Force AirDrop documents to be used as unmanaged documents, AirDrop is treated as an unmanaged destination according to Sophos; this option is not a blanket AirDrop block. If both document rules are off, the clipboard restriction has no effect. Check the desired direction, contact sharing, iCloud synchronization, and observable data flows separately on a test device; do not promise blanket data isolation.
  • Device features and privacy: Restrictions > Device also includes choices that affect use of the personal device. Allow screen capture allows screenshots of the display; this capability is separate from document-sharing rules and is not a DLP guarantee. If Allow Siri is turned off, Sophos says Siri, voice commands and dictation cannot be used. If only Allow Siri while device is locked is turned off, the user must unlock the device by entering their password before using Siri. Force local translation prevents connections to Siri servers for translations, not all data transmission. Force Wrist Detection requires wrist detection on a paired Apple Watch. Force pairing password for outgoing AirPlay requests requires a pairing password on the other devices receiving an AirPlay request from this device; it is not a blanket AirPlay block.
  • Lock screen and Safari: Allow Control Center on lock screen, Allow Notification Center on lock screen and Allow Today view on lock screen provide separate choices for Control Center, Notification Center and Today view when the screen is locked. According to Sophos, clearing the respective checkbox makes that area unavailable while locked. Under Restrictions > Applications, Force fraud warning keeps Safari’s security setting for warning users when they visit a suspected phishing website permanently enabled; this is a warning requirement, not a guarantee that phishing sites are blocked. Agree these device and browser choices with the user before assignment and check their intended effects in the approved pilot; neither defaults nor effects tested here are promised.
  • Diagnostic data and backups: Under Restrictions, Allow diagnostic data to be sent to Apple controls the transmission of diagnostic information to Apple. According to Sophos, if the checkbox is cleared, this information is not sent to Apple. According to Sophos, Force encrypted backups requires users to encrypt their backups in iTunes. Do not extend this documented requirement to all backup methods or iCloud backups; it also does not replace a backup and retention plan. The diagnostic option is not an assurance that all other data transmissions are prevented.
  • Kerberos SSO: Single sign-on describes Kerberos SSO for third-party apps; the documented configuration applies only up to iOS 26 or iPadOS 26. Kerberos principal name contains the principal name; according to Sophos, if the field is left empty, the user must enter it. Enter the Kerberos realm in uppercase under Realm. The URLs list contains the URL prefixes that must match for Kerberos authentication over HTTP. Entries must begin with http:// or https://; if a trailing / is missing, Sophos Mobile adds it. For URL matching, a single asterisk (*) is permitted as a wildcard for arbitrary values. App IDs contains the apps’ bundle IDs: either exact values or prefixes ending in .*. These rules determine the target scope of the configuration; the source does not describe how URL and app ID matching are combined. They do not establish successful sign-in on the device.
  • Printers: AirPrint adds printers to the printer list. The IP address and resource path must match the printing service; Port specifies the port on which the AirPrint printer accepts connections. According to Sophos, Force TLS secures AirPrint connections with TLS. The port value and TLS support must match the respective printing service; this implies neither a default port nor an assurance of certificate trust or successful printing.
  • Web Clip: Web Clip adds a shortcut to the Home Screen. According to Sophos, the https:// prefix may be omitted under URL only for a bare domain name. In all other cases, the full URL is required, such as when it includes a path, a port specification, or a custom URL scheme. According to Sophos, Full screen opens the URL as a full-screen web app, not as an installed native app. Show external pages in full-screen determines whether full-screen mode is retained when navigating to other web pages; if the checkbox is cleared, the browser appears. Browser app offers a choice of the apps installed on the managed iPhones and iPads. Device default uses the default browser configured on the device. According to Sophos, if the selected app is unavailable on a device or cannot open web pages, the Web Clip opens in Safari. The selection therefore guarantees neither a specific browser nor kiosk mode nor the accessibility of the destination. According to Sophos, a non-removable Web Clip may disappear only when the policy that installed it is removed; do not plan this option without a way to undo it.

Managed apps and per-app VPN: no shortcuts

A managed app is not simply any app on the personal device. For User Enrollment, Sophos describes only apps acquired through Apple Business: distribution takes place through Sophos Mobile or by assignment to the managed Apple Account. If the same app is already installed personally, it cannot also be installed as a managed app. A managed app removed by the user remains managed when reinstalled. Mail, Notes, and Calendar, however, can hold data from both the personal and managed accounts; do not classify their data based on the app name alone.

Apple permits the AppLayerVPN payload under User Enrollment; that platform allowance does not prove that Sophos Mobile can assign a user-policy connection to an app. Sophos lists Per app VPN (German help: VPN pro App) as a configuration in an iOS user policy and links from it to app-assignment instructions. Those instructions, however, specify one or more device policies with Per app VPN as a prerequisite and describe selectable connections exclusively as configurations from device policies; at the same time, they link back to the iOS user policy. There is therefore an unresolved tension in the documentation between the user-policy page and the assignment description limited to device policies, not evidence of contradictory product behavior. Whether a connection from a user policy is actually available in the app VPN selector under Apple User Enrollment remains unresolved. Consequently, this draft neither instructs readers to assign such a connection to an app nor provides a click path or promises any VPN effect; no VPN assignment for personally installed apps can be inferred from it either. Any later operational instructions require independent confirmation in the approved User Enrollment tenant: an appropriately licensed managed app, availability of the user-policy configuration in the selector, on-demand behavior, the actual per-app data path, and removal of the assignment. The Send all traffic through VPN field (German help: Alle Daten über VPN übertragen) in the Per-App profile does not establish device-wide VPN routing.

Prepare accounts for a limited pilot

For Email account and IMAP/POP, first check the user actually assigned to the device. In Sophos Fusion, open the correct person under My Environment > Users & Groups > Users, use Edit to check or populate Exchange Login and Email Address, then choose Save. Account details imported from Active Directory cannot be changed there. In that case, clarify the values with the responsible directory administrator rather than creating a second user object. Do not apply this documented AD restriction indiscriminately to all Entra ID identities. For IMAP/POP, also check whether the Exchange Login value is suitable as the outgoing display name; the differing placeholder descriptions above remain unresolved.

Policy creation and targeted assignment describe the shared workflow. Explicitly select an iOS & iPadOS user policy, edit the required configurations and save them. For a separately authorized pilot, use an isolated policy and only approved devices. Before every change, record the previous settings and all assignments of that policy: a shared policy is not a single-device test. User policies synchronize automatically whenever the device connects to Sophos Mobile; neither Update devices nor the scheduling screen for direct device-policy assignment should be carried over to this workflow.

The following checks are planned acceptance criteria, not device results observed here. Use only approved test accounts and test data without customer data; define the intended data scope before assignment.

  • Exchange and IMAP/POP: In the correct account, compare the actual resolved account address, login ID and, for IMAP/POP, outgoing display name with the plan. Confirm sign-in, a permitted TLS connection and certificate trust separately. Check receipt of a test message and its outgoing delivery separately rather than treating the account display alone as success. For Exchange, check the selected synchronization areas in their respective apps and the separately permitted user changes. Observe the intended permitted and blocked mail data flows using test data. Only when certificates are intended for use, also check the connection identity or S/MIME signing, encryption and recipient compatibility, as applicable.
  • CardDAV: Compare the created account and intended contact resource. Expect a clearly identifiable test contact from the approved server resource on the device and compare its content. Test the reverse direction only if it is intended and approved for the specific service; do not promise universal write access or bidirectional synchronization. If the contact is missing or appears in the wrong account, first check the account/resource mapping, Server and Port, then credentials and any required Principal URL. For connection or trust failures, also clarify TLS support and certificate trust; do not disable transport security for diagnosis.

If the identity is incorrect or authentication, transport or data flows differ from expectations, stop expansion and clarify the issue with the service or Mobile administrators. A status such as Applied, a new policy version or a recent connection time does not replace any of these account checks.

Plan changes and rollback by management mode

For corrections to user policies, the general policy help specifies editing the policy or assigning another one. For planned recovery, use the documented previous payload settings and observe the account and data state again after the next connection and synchronization. This is not a proven lossless recovery path.

According to the uninstall instructions, the direct Devices > [device] > Policies > Uninstall action is restricted to certain device policies and is not intended for the iOS user policy. This does not mean there is no supported rollback task: For User Enrollment, Sophos explicitly documents Unassign iOS user policy in the task-bundle workflow. There, select the verified user policy under Select source > Policies and transfer the bundle only to approved target devices. For iOS/iPadOS, Uninstall policy belongs to Device Enrollment; the broad Unassign in the general uninstall instructions affects all devices with that assignment and is not a targeted pilot recovery path.

Before such a task, record the correct policy, target devices and existing accounts/contacts, and back up required business data through the approved path. Afterward, compare task/synchronization status and the actual account, contact and data state; check the intended preservation of required data separately. If results differ, stop and escalate rather than trying to resolve them through Unenroll, Wipe or group deletion. A successful task alone confirms neither complete payload removal nor data preservation.

Outstanding before approval

Before a production rollout, the affected person’s consent, an agreed backup and retention plan, and a test on a device approved for that purpose are still needed: record the enrollment mode, OS version, edition/license, app license and management status, accounts, and existing data. Agree on an escalation path for a forgotten device passcode instead of relying on a Sophos reset that is not available; after the documented 60-minute grace period, personal apps may also be blocked. Approve document and mail data flows and VPN traffic only on the basis of observable results.

Test rollback for each payload rather than inferring it from the removal of a policy assignment: check accounts and app status after policy removal; for a non-removable Web Clip, include the policy that installed it; for managed apps, also check uninstallation or license revocation and the state of a reinstalled app. Decide in advance which business data must be retained and how it will be backed up outside the device. Unenrollment removes the managed APFS volume, including the business data stored there; it is not a lossless rollback, even though it does not indiscriminately delete personal device data. Neither a tenant nor an iPhone/iPad was tested here; no rollback sequence has been confirmed in practice, and no payload effect has been technically approved. Approval of this article as documentation must be kept separate from technical approval of a production rollout; it does not confirm any effect in the tenant or on the device. In particular, do not use passcode enforcement, document-sharing rules, or VPN assignment as production instructions without that technical approval.