Sophos Mobile on personal iPhones and iPads: set up Apple User Enrollment
Apple User Enrollment manages work data on a personal, unsupervised iPhone or iPad. It is not the same as the broader device management available for a company-owned or supervised device. A supervised device cannot be enrolled in this mode. First prepare the user identities, task bundle, and Mobile configuration in the Self Service Portal. The account-driven method also requires service discovery. The person then starts enrollment and consents on the device.
No authorization for activation or rollout: The steps below are documented workflows, not tests in a production tenant or on BYOD hardware, and not a tested guarantee of data removal. Licensing, operating-system support, administrator permissions, user consent, and the specific management requirements must be settled before an authorized pilot. Check the English menu and field names against your own tenant and device interface. If an option is missing or the mode differs, do not switch to general iPhone device enrollment. Approval remains pending until the configuration and its effects have been checked in the intended context.
What the organisation can see — and what it cannot
A Managed Apple Account coexists with the personal Apple Account. Apple separates managed apps and app data, the managed keychain, and managed-account data in iCloud, Mail, Calendar, and Notes on a managed APFS volume.
- MDM cannot: Read personal content or retrieve the UDID, IMEI, or MAC address through User Enrollment. MAC-based NAC and resetting a forgotten device passcode are not possible in this mode. Sophos Find/location tracking is unavailable for User Enrollment devices.
- MDM can still: Query managed objects and certain non-identifying device and security details, such as the operating-system version. Apple lists locking the device as a possible User Enrollment command; whether this action is available in a particular Sophos tenant must be checked.
If an iOS user policy contains the Sophos Password policies configuration and that policy is actually assigned to and applied on the device in Apple User Enrollment mode, the configuration requires a six-digit PIN without repeated or consecutive digits. According to Sophos, if the device is noncompliant at that assignment, a 60-minute grace period begins; after that, even personal apps may be unable to launch until the requirement is met. Not every tenant assigns such a policy to the device; merely creating the policy does not enforce a PIN, and this does not establish that an arbitrarily complex device-passcode requirement can be imposed. These limits on what MDM can see are not assurances about other apps, data shared voluntarily, or cloud services.
Apps that Sophos Mobile installs as managed apps or assigns to the Managed Apple Account for installation in this mode must be sourced through Apple Business. This does not apply across the board to every personally installed app someone uses for work. If the same app is already installed personally, it cannot also be installed as a managed app. For Mail, Calendar, and Notes, separation is account-based: the same app can display both personal and work content. User Enrollment is therefore not an appropriate assumption where full device control or hardware identifiers are required; a different management mode calls for a separate decision about privacy and ownership.
The person can uninstall a managed app themselves; if they reinstall it, however, the app remains managed. To install an app previously installed as managed as a personal app, you must uninstall it through Sophos Mobile or remove its app license from the Managed Apple Account. Withdrawing the license does not prove that the app is removed immediately or that local app data is preserved. Review the data-loss preflight and license withdrawal for iPhone/iPad apps before making such a change.
Prepare identities and prerequisites
Before setup, the organization must be registered in Apple Business. Apple Business app management in Sophos Mobile must also already be configured. Prepare Apple Business apps describes the content-token, license, and assignment workflow. This setup is an enrollment dependency, not merely a later step for additional apps. The unresolved mapping of invitation and license activation to the account-driven identity discussed there still needs to be checked. An invitation to a personal Apple Account is neither a substitute for the managed account nor a general BYOD prerequisite.
Before people sign in on an iPhone or iPad with their Managed Apple Accounts, Apple must have verified the organization. Registration in Apple Business alone is not enough. Apple’s guide Sign up and verify your organization describes the organizational process. Domain registration and the certificate checks for service discovery do not replace this organization verification.
For newly registered organizations that have not yet been verified: You have 60 days from registration in Apple Business to complete organization verification. Apple warns that if the organization is not approved within this window, the organization, its data, and its Managed Apple Accounts will be deleted. Complete verification early; submitting the organization for review does not yet constitute approval. This deadline applies to the new organization, not to enrollment of individual BYOD devices or recurring account renewal. It also does not imply deletion of organizations that have already been verified.
Create users and hand over credentials
- Add the person in Sophos Fusion if they are not already present. For an existing or synchronized person, check the assignment and email address instead of creating a second user object. Establish the correct person and their intended user groups for later selection.
- Have an authorized administrator add the person in Apple Business and create an individual Managed Apple Account for them. These accounts belong to and are managed by the organization. Each person needs a unique account. A shared work account is not a substitute for an individual identity.
- Apple Business can optionally be federated with Microsoft Entra ID. In that case, Apple Business creates the Managed Apple Accounts, and people sign in with their Microsoft Entra ID credentials. Federation is not mandatory for the manually created account path. Its setup must be settled in advance through the Apple Business identity process, not replaced with improvised settings here.
- Before either user path, give the person their Managed Apple Account credentials through the approved secure handoff channel. If federation is used, explain the intended Entra sign-in path. Passwords belong neither in the enrollment ticket nor in public examples. The person enters them themselves.
- Provide the separate Sophos Fusion Self Service Portal access and check sign-in. General portal access explains approval and invitations. It configures neither the Mobile enrollment package nor the Apple Account. Even if both accounts use the same email address, Apple sign-in and portal sign-in are separate steps.
Before consent, confirm personal ownership and that the device is unsupervised. Do not confuse Sophos Mobile MDM with Mobile Threat Defense used on its own. The person needs to know which device and security details remain queryable, that device locking may be possible, and that a PIN policy actually assigned to the device may affect personal apps. Check the intended policies and available actions beforehand.
Also disclose that an authorized administrator can later end management through Unenroll. The iOS/iPadOS unenrollment task requires no further confirmation on the device. Once unenrollment takes effect, the Managed Apple Account, managed apps, and local work data are removed. This is not a remote wipe of the entire personal device.
Choose the appropriate enrollment path
The account-driven method starts with work or school account sign-in in device settings and requires service discovery through the managed account’s domain. Sophos Mobile Admin cannot initiate it.
The profile-based method uses a separate profile path and, according to Sophos, is available only on iOS/iPadOS 17 and earlier. The person can start it in the Self Service Portal, or an administrator can start it in Sophos Mobile. Consent on the target device remains necessary in both cases. A deadline in general profile instructions is not evidence of a deadline for account-driven User Enrollment.
The separate general setup route, which requires IT approval for the specific device, is described in the section “General iPhone/iPad setup with Mobile Control” in the Self Service Portal user handoff. This route is not Apple User Enrollment. It replaces neither the account-driven nor the profile-based method and adds no app setup steps, prerequisites, or deadlines to either method.
Set up service discovery for account-driven enrollment
Service discovery tells the device how to reach Sophos Mobile. The device uses the domain part of the Managed Apple Account’s email address for this. Before a pilot, this domain registered in Apple Business, certificate trust, and the discovery resource must align. This discovery setup is not a prerequisite for the purely profile-based path.
Check the domain and certificate trust
According to Sophos, the registered domain must match the Common Name (CN) or a Subject Alternative Name (SAN) in the discovery web server’s TLS certificate. The enrolling device must trust the full certificate chain. For public certificate authorities, the required trust chain is normally already present on iOS/iPadOS.
For a self-signed certificate or an internal PKI, the certificates in the trust chain must be manually distributed to and installed on the device through an approved channel. Do not accept unknown certificates without verification. Successful retrieval on an administrator’s computer does not prove certificate trust on the target device.
Copy and publish the tenant JSON
Before making a change, check the correct Sophos Mobile tenant and registered Apple Business domain. If a discovery resource already exists, back up its current content and web server configuration through the approved change process. Do not overwrite another tenant’s mapping without checking it.
- In Sophos Mobile, open Setup > Apple setup > Apple User Enrollment.
- Select Set up account-driven Apple User Enrollment. The documented page displays the JSON code for setup. If the tenant interface differs, resolve permissions and the available workflow first.
- Use Copy to clipboard to copy the displayed JSON code and paste it unchanged into a new text file. The data must come from your own intended tenant. Do not add JSON fields yourself or use an example payload from another tenant.
- Publish the file on the web server over HTTPS at
/.well-known/com.apple.remotemanagementon the registered domain. The full documented URL placeholder ishttps://your-domain.com/.well-known/com.apple.remotemanagement. Replace onlyyour-domain.comwith the domain registered in Apple Business for the Managed Apple Accounts. Leave the resource path unchanged. - In the web server configuration, set this resource’s Content-Type to
application/jsonand allow HTTP GET for the URL.
Before users start, check actual GET retrieval from the intended network. The response must match the copied tenant JSON, not an HTML error page. Check the response Content-Type and certificate trust on the intended iPhone or iPad separately. These are prospective checks, not tests performed here. An accessible discovery file proves neither the person’s consent nor completed enrollment or applied policies.
If the tenant mapping, domain, or certificate chain is wrong, do not enroll more devices. Resolve the approved change or recovery path first and repeat the checks. Removing the discovery resource does not unenroll existing devices or restore deleted work data.
The screenshot in the Sophos setup instructions also shows Disable account-driven Apple User Enrollment. The confirmation and specific effects of this option, whether it can be reversed, and what it means for already enrolled devices are not documented here. It establishes neither a tested recovery path nor device unenrollment. This option must therefore not be equated with removing the discovery resource, Unenroll, or Delete.
Prepare the task bundle and Mobile Self Service Portal
User policy and enrollment task
- Create an iOS & iPadOS user policy for the intended BYOD use. Before assigning it later, check its settings against the restricted User Enrollment mode and the PIN effects explained above.
- Create a task bundle with an Enroll task. In the Add enrollment task wizard, select iOS User Enrollment. General iOS device enrollment is not a substitute.
- If needed, include the prepared user policy in the bundle to assign it during enrollment. Assignment is optional. You can assign the policy later or assign no policy. Creating the policy alone does not apply it.
- Include additional Install app and Send message tasks only if needed. The Apple Business and personal-app limitations above apply to the app task. A separate device group for Apple User Enrollment can optionally be prepared.
Before use, check the Enroll type, intended policy assignment, and all additional tasks in the bundle. The completed bundle is then selected as Enrollment package in the platform settings. Neither creating nor selecting the bundle enrolls a device.
Link the configuration, user groups, and platform
In Sophos Mobile, open Setup > Self Service Portal. Under Enrollment texts, prepare the texts shown before and after enrollment if needed. On Self Service Portal configurations, use Create to create a configuration or deliberately edit an existing one.
The configuration determines which devices its users may enroll and which self-service actions are available:
- Enter a clear label under Name. People select the configuration in the portal by this name.
- Add the intended user groups under User groups > Add. A configuration can contain several groups, but the same group cannot be assigned to different configurations. Check actual group memberships before approval.
- Use Maximum number of devices to set the permitted number of devices per person for the portal. Choose the value according to the approved BYOD scope, not an unchecked default.
- Under Actions > Show, select only the intended management actions supported for the platform. A general action list does not mean every action is usable in User Enrollment mode.
Use Add to add the iOS & iPadOS platform. In Configure platform settings, define both the visible choice and its technical target:
- Display name names the enrollment type in the portal. Description appears beside it. Choose a name that lets the person recognize the intended account-driven or profile-based path.
- Set Owner to personal for this personal BYOD scenario. Corporate and personal devices can be configured separately for each platform. The ownership setting does not make a supervised device eligible for User Enrollment.
- Under Device group, select the intended device group. A group created specifically for User Enrollment is optional. The assignment must not inadvertently lead into a different management workflow.
- Under Enrollment package, select the task bundle prepared earlier.
- Enable Account-driven Apple User Enrollment for the account-driven path. Clear the checkbox for the profile-based path. This selection must match discovery readiness, operating system, and user instructions.
- Under Terms of use, select the pre-enrollment text if needed. If the field is empty, no text appears. If set, the person must agree to continue. Post-enrollment text determines the text shown after enrollment. Here, too, an empty field means no text is displayed. The confirmation of these configured texts documented in the account-driven user workflow still comes before Download profile.
Use Apply to apply the platform settings to the configuration. Add further platform settings if needed. Then save the configuration with Save on Edit Self Service Portal configuration. Apply and Save are separate steps.
If several suitable Apple User Enrollment options are needed, deliberately create additional configurations or platform settings. Distinguish two levels here. If a person belongs to groups with several self-service configurations, the highest-priority configuration applies. The arrow icons on Self Service Portal configurations change this order. The always-present Default configuration has the lowest priority and applies only when no other configuration matches. Within the enrollment workflow offered, the person selects the intended Apple User Enrollment option. Do not assume an option is visible to everyone merely because it has been created.
Before rollout, test with authorized pilot users from the different user groups which configuration and enrollment types are actually offered. Check the name, ownership, package, mode checkbox, displayed texts, and permitted actions against the plan. A saved configuration does not replace this group-specific test.
Account-driven enrollment on an iPhone or iPad
The person starts this path on the target device. Beforehand, credentials must have been handed over, portal access and the account-driven configuration prepared, and discovery checked. Administrators cannot initiate this path in the Add device wizard.
- On the target device, open Settings > General > VPN & Device Management and select Sign in to Work or School Account.
- Enter the Managed Apple Account email address. Do not substitute a personal Apple Account address or another portal user’s address.
- The device redirects to a Sophos Mobile page. Sign in there with the Sophos Fusion Self Service Portal credentials. This is the separate portal sign-in, not entry of the Apple Account password.
- Select the intended configuration from the account-driven enrollment configurations offered. If the name or mode does not match the instructions, do not proceed with a different enrollment.
- Confirm the terms of use and post-enrollment text if configured in the tenant. Confirming these texts alone does not enroll the device.
- Select Download profile. The portal redirects back to the Settings app.
- Now use the Managed Apple Account password or the sign-in path intended for the prepared federation.
- Consent with Allow Remote Management and enter the device passcode. According to the documented workflow, the Settings app then downloads and installs the Sophos Mobile enrollment profile.
Then carry out the verification below. A completed dialog or redirect alone proves neither full enrollment nor the effects of policies and apps.
Profile-based enrollment on iOS/iPadOS 17 and earlier
Initiation by the person
For this separate path, credentials must also have been handed over in advance. The Mobile platform configuration must offer profile-based Apple User Enrollment, with Account-driven Apple User Enrollment unchecked.
- Sign in to the Sophos Fusion Self Service Portal, open Mobile, and select Enroll Device. Sign-in can take place on the device to be enrolled or on another device.
- The portal leads to the Sophos Mobile enrollment web form. Check the intended profile-based option and target device. After the form is confirmed, the device downloads a configuration profile from Sophos Mobile. Portal sign-in on another device does not replace the download and subsequent consent on the actual target device.
- On the iPhone or iPad to be enrolled, open the Settings app and select Enrol in.
- On the next page, read the User Enrollment information. Confirm enrollment with Enrol My iPhone or Enrol My iPad. This starts the enrollment process; it does not yet prove success.
Then check the Sophos Mobile entry and intended management mode as described below. Do not use this profile path, limited to version 17 and earlier, as a general substitute on newer systems.
Initiation by administrators and handoff to the target device
Sophos Mobile Admin can initiate only profile-based Apple User Enrollment. The iOS/iPadOS 17-and-earlier limit applies here too. The person must still consent to enrollment on the device.
- In Sophos Mobile, open Devices > Add > Add device wizard.
- Select Search for user, search for the intended person, and select them. Check the selection against the prepared Fusion identity.
- On Device details, select the iOS & iPadOS platform and enter the other details required in your own tenant. Do not use details from a computer/server inventory as enrollment data.
- On Enrollment type, either select Apple User Enrollment and enter the Managed Apple Account email address, or select Apple User Enrollment with task bundle, choose the intended task bundle, and also enter the Managed Apple Account address. The bundle variant is for additional tasks, not a different type of Apple identity.
- On Enrollment, scan the QR code with the Camera app on the device to be enrolled. The target device opens the Sophos Mobile enrollment web form. Confirm this form.
- The person continues the device workflow from step 3 of the previous section. On the target device, open Settings > Enrol in, read the information, and confirm Enrol My iPhone or Enrol My iPad. Then verify the outcome.
Creating the entry in the wizard and displaying a QR code do not complete enrollment. Administrator initiation replaces neither consent nor the appropriate Managed Apple Account.
Verify enrollment and investigate discrepancies
Sophos lists the same success indicator for both user paths: after successful enrollment, a Sophos Mobile entry appears on the device under Settings > General > Device Management. The actual UI label may differ. In an authorized pilot, check this entry on the correct device and verify the person, managed account, and management mode. The entry alone does not prove that policies have been applied, apps have been installed, or a rollout has been tested. Check those outcomes separately on the pilot device.
If something differs, identify the missing stage rather than blindly repeating enrollment:
- If the account-driven path does not reach the Sophos page, first check the Managed Apple Account domain, GET resource, copied tenant JSON, Content-Type, and device trust.
- If portal sign-in is not possible, check the separate Fusion access and user assignment. A working Apple sign-in does not prove portal access.
- If the intended option is missing, check user groups, priority and Default behavior, platform settings, Enrollment package, and the mode checkbox.
- If the Sophos Mobile entry is missing after consent, do not report enrollment as complete. Check the device step, supported profile path, and actual outcome in the Mobile tenant. Establish the current management state before enrolling again.
Unenrollment, not a remote wipe
Sophos explicitly rules out Wipe/Factory Reset for Apple User Enrollment devices. This does not prevent the person from erasing their own device. For offboarding, Unenroll is the separately documented management action.
- Before: Transfer needed work data through an approved channel before planned offboarding, without collecting personal content. Inform the person where possible, and verify the correct person, device, and management status. Unenroll does not provide for renewed consent on the device; neither notification nor recovery of lost work data is guaranteed.
After this approval, open Devices in Sophos Mobile, select only the intended devices, choose Actions > Unenroll, and confirm the administrator dialog with Yes. This administrator confirmation is not additional user consent on the iPhone or iPad.
- After: According to Sophos, unenrollment removes the Managed Apple Account and its associated data locally; iOS deletes the managed APFS volume. Managed apps, policies, and MDM certificates are also removed, but personal apps or copies held in third-party cloud services are not removed as a matter of course. Only after the specific device has synced should you check that the management entry and managed work data are gone and personal data remains. Sending the action alone does not prove this has happened.
Treat record deletion and reenrollment separately
Do not conflate the actions: “Delete” irreversibly removes the Sophos Mobile device record and all data about that device stored there. Data already sent to the Sophos Data Lake is separate and remains subject to the applicable XDR retention rules. Deleting the record does not prove that an offline iPhone has been unenrolled: for a device that is still enrolled, Sophos describes unenrollment as occurring only at the next sync. The documented Fusion deletion path shows a “Not managed” filter; this does not establish an available deletion path for BYOD devices that are still enrolled. Consider optional record cleanup only after confirming removal on the device; if a sync is pending, do not claim offboarding succeeded merely because the record was deleted. “Delete” replaces neither Unenroll nor verification on the device.
After unenrollment and reenrollment, iOS generates a new device-specific enrollment ID. Sophos Mobile treats this enrollment as a new device, not as a continuation of the old Mobile record. Reenrollment requires the person’s consent again. In the intended pilot, therefore, check the correct person and the old and new Mobile entries before considering any cleanup. This implies neither automatic merging nor a demonstrably safe duplicate-deletion path or recovery of deleted work data.
The separate Fusion inventory explains the computer, server, and Mobile views. Its endpoint recovery windows are not a recovery path for this Apple User Enrollment registration. Verify the actual UI, permissions, and behaviour of offline devices in an authorised pilot before approval.