iPhone and iPad work-profile setup
Cadence’s device-management proposal is approved. Apple Business setup and validation are still required before inviting employees to enroll their iPhones. Fleet Premium is excluded.
The recommended route
Section titled “The recommended route”Use Apple Business’s built-in device management with Account-driven User Enrollment for personal iPhones and iPads. Apple made its built-in MDM free with the April 2026 Apple Business launch. Paid storage and AppleCare are optional extras. A paid Apple Developer Program membership is not part of this setup. Apple’s announcement
This is Apple’s counterpart to an Android work profile: managed work accounts and apps have data separation, while the personal Apple Account stays personal. It is not a second home screen or a separate copy of every app. Apple’s User Enrollment keeps the device unsupervised and limits organizational management. Apple enrollment methods
Tradeoff: iPhone management and evidence will live in Apple Business. Windows, Linux, Mac computer agents, and Android work profiles can continue in Fleet Free. We have not implemented synchronization between the two inventories.
Apple lists built-in MDM and Managed Apple Accounts as available in both the United States and Costa Rica. Register using the company’s real legal details and applicable country. Feature availability
IT: set up a small pilot
Section titled “IT: set up a small pilot”1. Create or verify the organization
Section titled “1. Create or verify the organization”- Go to Apple Business and select Sign up now, or sign in to Cadence’s existing organization if one exists.
- Enter Cadence OneFive’s legal business name, US business address, and company website. Use your own legal name as the administrator, your work email, and a phone number for verification. Complete the email and phone checks.
- Open Settings > Organization > Verify Now. Submit two verification methods. For Cadence, the EIN plus an accepted business document is a straightforward option; domain verification with a DNS TXT record is another. Apple also accepts a D-U-N-S number. Use the methods offered for the organization’s country.
- Submit for review. Apple says verification can take up to five working days, longer during busy periods; complete it within 60 days of signup.
- Add a second organization administrator for continuity.
Apple’s signup and verification instructions
This involves business identity verification, not publishing an app. There is no custom iPhone installer to build and no Fleet APNs certificate to upload for the Apple-hosted route.
2. Create Managed Apple Accounts
Section titled “2. Create Managed Apple Accounts”Under People > Users > Add, create a Managed Apple Account for each participant and generate their sign-in instructions. Use the reserved domain Apple gives the organization initially; it needs no DNS verification. This avoids domain capture and Google Workspace federation during the pilot. Record each work-account identifier alongside the person’s Cadence email. Reserved domains · Manual user creation
Send the initial credentials privately. These are additional work accounts; employees keep their personal Apple Accounts. Federation with the company identity provider can be evaluated later.
3. Enable Apple’s included MDM
Section titled “3. Enable Apple’s included MDM”Under Devices > Management Services, select Add new device management service > Turn on included device management. Apple’s enablement instructions
In the service’s Device Enrollment tab, select Enroll as personal device for iPhone and iPad. Assign a Blueprint to the pilot users or user group. Do not select organization-owned enrollment for these personal phones. Personal enrollment configuration
4. Assign work apps and settings
Section titled “4. Assign work apps and settings”Create a Blueprint such as Cadence personal iPhones — pilot, with only the work apps and configurations needed for the pilot. Assign it to people or their pilot group. Obtain the needed app licenses, including licenses for free apps, through Apple Business. Blueprint assignment
Under Devices > Configurations, prepare:
| Configuration | Pilot intent |
|---|---|
| Password and Screen Unlock | Require a passcode; verify what User Enrollment actually enforces on the test phone. |
| Data Management | Block unmanaged apps from opening managed data; make copy/paste follow managed-data controls; treat AirDrop as an unmanaged destination. |
| Work apps | Assign the apps employees need for company data and test their managed sign-in and removal behavior. |
Apple describes the password configuration and managed-data controls. Test work-to-personal sharing and clipboard behavior with harmless sample data before rolling the Blueprint out.
User Enrollment supports fewer controls than full device management. Do not copy Android’s password-expiry, wipe-attempt, auto-lock, or minimum-OS settings and assume equivalent enforcement. Apple’s passcode declaration documentation explicitly limits the keys honored for User Enrollment. Record unsupported or unverified controls in the pilot evidence. The existing BYOD policy still applies, including weekly updates and a maximum five-minute auto-lock; a requested setting is not proof it is enforced.
Employee: enroll your iPhone or iPad
Section titled “Employee: enroll your iPhone or iPad”Wait for IT to supply your Managed Apple Account and confirm the pilot is ready. Use iOS/iPadOS 26 or later for this walkthrough: the Apple Business companion app requires it. Apple supports basic User Enrollment on some older OS versions, but that older-device experience needs separate validation. Companion-app requirements
- Back up your personal data and install the supported OS updates available for your device.
- Leave your personal Apple Account signed in.
- Open Settings > General > VPN & Device Management > Sign In to Work or School Account.
- Sign in with the Managed Apple Account supplied by IT, which may differ from your normal work email during the pilot. Follow the authentication and enrollment prompts.
- Review the organization and management details. If the flow asks for a factory reset or device supervision, stop and contact IT: that is not this personal-device pilot.
- Open the Apple Business app and install the work apps assigned to you. Tell IT when enrollment is complete.
Apple documents the account-driven sign-in flow. The Apple Business app is delivered through enrollment; downloading an arbitrary “MDM app” is not a substitute.
If the work-account option is missing, IT should check whether the device already has another organization’s management or restrictions. Do not remove another organization’s management without coordinating with its administrator.
IT: verify enrollment and offboarding
Section titled “IT: verify enrollment and offboarding”For each pilot device, record its owner, Managed Apple Account, enrollment method, OS version, Blueprint, and the date of the last verification in the company asset register. Confirm the device is personal/User Enrolled, the intended settings applied, and work apps can sign in.
Test opening a work document in a personal app and copying sample work text into a personal app. Document actual results. Review personal-data visibility with the participant; do not treat mobile MDM as an osquery inventory or mark all desktop security checks as supported on iOS.
For the offboarding test, preserve needed work data in company storage, then use Unenroll on the selected device in Apple Business. Confirm removal of the work account, managed settings, and applicable work data, while personal apps and settings remain. Apple’s unenrollment behavior
Keep Apple Business evidence with the Fleet evidence, and identify Apple Business as the iPhone management provider in the asset register. Successful enrollment alone is not evidence that every BYOD control is met.
Why not enroll the phone directly in Fleet Free?
Section titled “Why not enroll the phone directly in Fleet Free?”Fleet’s enrollment-link method uses profile-based Device Enrollment. It can be set up with a Fleet-issued CSR and an Apple Push Certificates Portal account; a paid Developer membership is not needed. The push certificate must be renewed annually. However, Device Enrollment has broader management powers than User Enrollment and does not provide the same privacy boundary. Fleet’s enrollment guide · Fleet’s Apple setup
Fleet’s Account-driven User Enrollment is a Premium feature. Paying Apple for a Developer membership does not change that Fleet licensing requirement. Fleet’s account-driven guide
A standalone .mobileconfig or an ordinary App Store app does not by itself establish Apple’s managed work-data separation. For our preferred privacy boundary without Fleet Premium, use Apple’s included MDM and accept a separate iPhone management console.
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
