First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Microsoft Intune Initial Setup for iPhone & iPad Management
Security and Protection

Microsoft Intune Initial Setup for iPhone & iPad Management

Microsoft Intune Initial Setup for iPhone & iPad Management is a 10-day, fixed-fee add-on that extends your Intune tenant to corporate-owned iPhones and iPads (iOS and iPadOS). IT Partner configures the three Apple trust connections — MDM push certificate, Automated Device Enrollment token, and Apps and Books token — designs the enrollment and authentication experience, builds baseline compliance, configuration, and software-update policies, assigns managed apps, and proves it all on a pilot of up to five devices. Windows is covered by Microsoft Intune Initial Setup for Windows Device Management; Android by Microsoft Intune Initial Setup for Android Device Management.

Timeline 10 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

Apple device management runs on trust relationships that Windows management never touches: an MDM push certificate, an Automated Device Enrollment token, and an Apps and Books token, each tied to an Apple account and each on its own renewal clock. Getting them created under the right ownership — yours, not a consultant's personal Apple ID — is most of what separates a healthy Apple estate from one that breaks a year later. This add-on extends your Intune tenant to corporate-owned iPhones and iPads. The standard design uses Apple Business Manager with Automated Device Enrollment for supervised, user-affinity devices: IT Partner configures the three Apple connections, one enrollment profile with the authentication experience selected for your fleet, baseline compliance and configuration policies, a software-update policy, managed application assignments, and validates everything on up to five new or factory-reset pilot devices. Who this is for: US commercial organizations of roughly 100–500 seats on the Microsoft cloud that issue company iPhones or iPads. Who it is not for: BYOD-first fleets (that is Apple User Enrollment, a different design), shared-iPad or kiosk estates, and macOS management — each available as separately scoped work on this same foundation. The 10-day schedule is elapsed calendar time paced by Apple Business Manager processing and client dependencies. The price reflects the density of Apple trust work in those days — three token and certificate connections, supervision design, Setup Assistant authentication choices, and a renewal handoff your team can actually operate.

Success criteria

01The Apple MDM push certificate is active in Intune, was created with a client-controlled organizational Apple account, and has a documented owner and renewal procedure.
02The Apple Business Manager Automated Device Enrollment token is active, assigned devices synchronize to Intune, and the standard enrollment profile is assigned to every approved pilot device.
03The Apps and Books location token is active, device licenses for the required applications synchronize to Intune, and the included application assignments are documented.
04Up to five approved pilot iPhones or iPads receive the assigned enrollment profile during Setup Assistant, enroll in Intune, and appear as corporate-owned and supervised.
05Pilot users complete Setup Assistant with the approved authentication design and finish Microsoft Entra registration with the intended managed experience.
06The pilot devices receive the approved compliance, configuration, software-update, and application assignments, and report their resulting status in Intune.
07Your administrators can locate pilot devices, review inventory and compliance status, initiate a synchronization, and perform the agreed non-destructive remote action.
08Your administrators receive and can follow the as-built, enrollment, troubleshooting, and annual Apple certificate and token renewal procedures.

What you receive

iPhone and iPad readiness assessment: licensing, Apple Business Manager state, device ownership, supported iOS/iPadOS versions, existing MDM state, applications, network access, and identity-policy dependencies.
Target-state and decision record for one corporate-owned, supervised, user-affinity enrollment scenario — including the Microsoft Entra authentication and registration design selected for your fleet.
One active Apple MDM push certificate connection with documented client account ownership, expiration date, and annual renewal procedure.
One Apple Business Manager Automated Device Enrollment token connection, device synchronization configuration, and the standard supervised enrollment profile using Setup Assistant with modern authentication — with Company Portal registration or Just in Time registration per the approved design.
Pilot assignment group, enrollment restrictions that block personally owned iOS and iPadOS enrollment, and documented profile and policy assignments.
One baseline iOS/iPadOS compliance policy, one baseline device configuration profile, and one software-update policy for supervised devices using the current Intune-supported mechanism appropriate to your fleet's iOS/iPadOS versions.
One Apps and Books location token connection and assignment of the approved managed applications — Company Portal where the design requires it, plus up to three additional applications licensed through Apple Business Manager.
Enrollment and policy validation report for up to five client-provided pilot iPhones or iPads, including identified dependencies and unresolved items outside scope.
As-built configuration, pilot enrollment guide, administrator operations and troubleshooting runbook, annual certificate and token renewal calendar, and an administrator handoff session.

How the work unfolds

Days 1–2 — Kickoff and readiness review

Confirm the relationship to the core Intune service, device ownership and user-affinity requirements, Apple Business Manager readiness, pilot devices and users, applications, policies, success measures, and client responsibilities.

Days 2–3 — Apple trust and token connections

Review or configure the Apple MDM push certificate, the Automated Device Enrollment token, and the Apps and Books location token, each under a client-controlled organizational Apple account.

Days 3–4 — Enrollment and authentication design

Configure the pilot group, corporate-device enrollment restrictions, and the supervised user-affinity enrollment profile. Select and configure the authentication experience — Setup Assistant with modern authentication, with Company Portal registration or Just in Time registration — and document why.

Days 4–6 — Policies, updates, and applications

Configure the approved compliance baseline, device configuration baseline, and software-update policy, then the managed application assignments from Apps and Books.

Days 6–7 — Device synchronization and enrollment

Confirm that up to five pilot devices are assigned to the Intune MDM server in Apple Business Manager, synchronize them to Intune, and complete their new-device or post-reset enrollment.

Days 8–9 — Pilot validation and remediation

Validate supervision, Microsoft Entra registration, policy and application delivery, update assignment, compliance reporting, inventory, and approved administrative actions, then correct in-scope issues.

Day 10 — Documentation and handoff

Finalize the as-built and renewal procedures, review rollout recommendations and open dependencies, conduct the administrator handoff, and confirm acceptance criteria.

Prerequisites

An active Microsoft Intune tenant with MDM authority configured — through Microsoft Intune Initial Setup for Windows Device Management, an existing equivalent Intune foundation, or a concurrent implementation.
Assigned Microsoft Intune licensing for every pilot user, plus any other Microsoft or Apple licensing the approved features require. Licensing costs are not included.
A verified Apple Business Manager organization with client administrators holding the roles required to create MDM server connections, assign devices, download tokens, and manage Apps and Books.
Client-controlled organizational Apple accounts for the MDM push certificate, the Automated Device Enrollment token, and the Apps and Books token, with account recovery and long-term ownership retained by you.
Between one and five supported corporate-owned iPhones or iPads that are new or approved for factory reset, and that are (or can be) assigned to the correct Intune MDM server in Apple Business Manager.
Your authorization to erase pilot devices after required data is backed up. Automated Device Enrollment is validated from Setup Assistant on a new or freshly reset device.
Approved pilot users with Microsoft Entra accounts, the agreed user and device assignments, authentication requirements, and timely acceptance of any updated Apple Business Manager agreements.
An Apps and Books location token that is not active in another MDM service or Intune tenant. Token transfer, license reconciliation, and migration from an existing management service are separately scoped.
An approved list of up to three additional applications, sufficient device licenses for every required app, and any sign-in or testing credentials needed to validate them.
Reliable internet, DNS, firewall, and proxy access to the required Apple, Microsoft Entra, Microsoft Intune, application, and software-update endpoints.
Disclosure of existing MDM enrollment, Conditional Access, Terms of Use, authentication, compliance, certificate, VPN, Wi-Fi, and application policies that could affect Apple enrollment or management.
If pilot users are subject to phishing-resistant multifactor authentication, a client-approved alternate authentication method usable during Apple Setup Assistant. Tenant-wide authentication-policy redesign is not included.
A client project owner and technical decision-maker who can provide access, approvals, devices, user availability, testing feedback, and acceptance within the 10-day schedule.
Your agreement to own annual certificate and token renewals after handoff, using the same organizational accounts and the delivered renewal calendar — or a separately contracted renewal-management arrangement.

Who does what

IT Partner

  • Lead the iPhone and iPad discovery, readiness assessment, design decisions, implementation plan, pilot, and acceptance review.
  • Review or configure the Apple MDM push certificate, the Automated Device Enrollment token, and the Apps and Books location token in Intune.
  • Design and configure the supervised, user-affinity enrollment profile — including the Setup Assistant authentication experience and the Company Portal or Just in Time registration path.
  • Configure the pilot group, Apple enrollment restrictions, profile assignments, and the approved compliance, configuration, and software-update policies.
  • Approve, synchronize, and assign the required managed applications, including up to three client-selected applications licensed through Apple Business Manager.
  • Assist with synchronization and enrollment of up to five client-provided pilot devices, and troubleshoot issues caused by the implemented configuration.
  • Validate the agreed device, policy, application, update, compliance, and administrative outcomes, and document out-of-scope dependencies.
  • Provide the as-built configuration, enrollment guide, troubleshooting runbook, annual renewal calendar and procedures, rollout recommendations, and administrator handoff.

Your team

  • Provide and maintain Microsoft Intune licenses, Apple Business Manager, organizational Apple accounts, application licenses, supported devices, and any third-party subscriptions.
  • Provide approved administrative access to Microsoft Intune, Microsoft Entra, Apple Business Manager, the Apple Push Certificates Portal, and required client systems.
  • Complete the Apple Business Manager organization, domain, account-recovery, reseller, purchasing, and contractual tasks that only you or your vendors can perform.
  • Assign pilot devices to the correct Intune MDM server in Apple Business Manager and provide between one and five new or factory-reset pilot devices.
  • Back up pilot-device data, authorize erasure, make pilot users available, and perform any required physical device steps during enrollment and testing.
  • Provide policy decisions, application selections, device licenses, network access, authentication requirements, change approvals, and user communications.
  • Review testing results and deliverables, provide decisions and feedback within the agreed schedule, and approve acceptance against the published success criteria.
  • Retain ownership of the Apple accounts and renew the MDM push certificate, Automated Device Enrollment token, and Apps and Books token before expiration — annually, with the delivered renewal calendar — unless renewal management is separately contracted.

What's not included

Other platforms — Windows Intune configuration (provided by Microsoft Intune Initial Setup for Windows Device Management; Windows Autopilot zero-touch deployment is a further separate service), Android Enterprise (provided by Microsoft Intune Initial Setup for Android Device Management), endpoint detection and response (provided by Microsoft Defender for Endpoint Deployment for Intune-Managed Devices), and macOS, tvOS, or visionOS management.
Other Apple enrollment scenarios — personally owned or BYOD enrollment and Apple User Enrollment, web-based personal-device enrollment, mobile application management without enrollment, Shared iPad, kiosk and userless designs, Microsoft Entra shared-device mode, Apple School Manager, and Apple Configurator enrollment.
Migration and token transfer — migration from another MDM or Intune tenant, Apps and Books token transfer or license reconciliation, mass wipe or re-enrollment, manual addition of legacy devices to Apple Business Manager, and conversion of already-activated devices to supervised management.
Security and identity program work — tenant-wide Conditional Access, MFA redesign, identity federation, single sign-on extensions, app protection policies, Zero Trust architecture, Microsoft Defender for Endpoint and mobile threat defense, DLP, SIEM/SOC integration, PKI and certificate services (SCEP, NDES, Cloud PKI), custom VPN or Wi-Fi engineering, carrier and eSIM work, and network access control.
Commercial and logistics items — Microsoft and Apple licenses, paid applications, devices, accessories and carrier services, custom or private app signing and packaging, Apple Business Manager organization creation or federation remediation, organization-wide rollout beyond the five-device pilot, physical staging or shipping, backup or migration of personal data, formal end-user training, ongoing administration including certificate and token renewals after acceptance, travel, and taxes.

Limitations & technical notes

!What partners most often get wrong on Apple — three warnings worth reading first: (1) the Apple MDM push certificate must be renewed annually with the same Apple account — replacing it instead of renewing it can force every managed device to re-enroll; (2) an Apps and Books location token can be active in only one device-management service at a time, so a token still attached to an old MDM must be released before it can serve this one; (3) supervision is applied through Automated Device Enrollment — an already-activated, unsupervised iPhone generally cannot be converted without a reset. This engagement is designed around all three.
!The included design is one corporate-owned, supervised, user-affinity Automated Device Enrollment scenario. Other Apple ownership, authentication, and shared-device models require separate design and testing.
!Eligible devices must be assigned to Intune in Apple Business Manager before activation, and must be new or erased to receive the intended Automated Device Enrollment experience.
!Apple Setup Assistant does not support phishing-resistant multifactor authentication for the included Microsoft Entra sign-in flow. Affected pilot users need a client-approved alternate method during enrollment.
!Apple tokens and agreements are living dependencies: updated Apple Business Manager agreements or account changes can pause synchronization until you resolve them, and all three trust connections sit on annual renewal clocks under your ownership after handoff.
!Enrollment, application and policy delivery, software updates, synchronization, and compliance reporting are not instant. Timing depends on Apple and Microsoft service availability, connectivity, device state, licenses, and OS behavior. Update controls apply only where Apple and Intune support the selected behavior, and no exact install time is guaranteed.
!The 10-day schedule is elapsed calendar time. It assumes an active Intune foundation, a verified Apple Business Manager organization, usable organizational Apple accounts, assigned pilot devices, available application licenses, timely approvals, and no unresolved third-party MDM conflicts.
!The fixed project fee covers one Intune tenant, one standard enrollment scenario, up to five pilot devices, the required managed-app deployment, and up to three additional Apps and Books applications. Additional devices, applications, scenarios, platforms, or remediation require a written, approved change in scope.
!Intune management improves consistency and administrative control, but no management platform can guarantee prevention of every data-loss event, security incident, service outage, enrollment failure, or compliance issue.
!Technical content reviewed August 2026. Apple changes agreements, tokens, and Setup Assistant behavior on a roughly annual cycle; this page is re-verified against Microsoft Learn and Apple Business Manager documentation on that cadence.

Frequently asked questions

Which enrollment authentication design will our users see?

There are four options, and choosing between them is a design decision this engagement makes with you. Setup Assistant with modern authentication plus the Company Portal app: the classic supervised design — users authenticate with Microsoft Entra during setup, then sign in once more in Company Portal to finish Entra registration. Setup Assistant with modern authentication plus Just in Time (JIT) registration: the newer, smoother option — Entra registration completes during setup with no second Company Portal sign-in, a materially better first-day experience where the fleet supports it. Setup Assistant legacy authentication: for constrained scenarios without modern authentication. And for context, no-authentication designs exist for shared or kiosk devices, which are outside this scope. IT Partner recommends JIT registration where your iOS/iPadOS versions and identity configuration support it, and documents the choice in the design record.

What do partners most often get wrong on Apple — and how does this service avoid it?

Three mistakes cause most Apple-estate emergencies. First, creating the MDM push certificate under a consultant's personal Apple ID: renewal then depends on a person who may be gone — here every trust connection is created under client-controlled organizational accounts. Second, treating certificate renewal casually: the push certificate must be renewed annually with the same account, because replacing it can force every device to re-enroll — you receive a renewal calendar naming each token, its expiry, and its owner. Third, assuming supervision can be added later: it is applied through Automated Device Enrollment, and an activated unsupervised device generally needs a reset — which is why the pilot uses new or freshly reset devices.

Who is this service for — and who is it not for?

It fits US commercial organizations of roughly 100–500 seats on the Microsoft cloud that issue corporate-owned iPhones or iPads. It is not the right design for BYOD-first fleets (Apple User Enrollment is a different model), shared-iPad or kiosk estates, or macOS — each of those is available as separately scoped work on the same foundation.

What is included in Microsoft Intune Initial Setup for iPhone & iPad Management?

The service configures the Apple MDM push certificate, the Apple Business Manager Automated Device Enrollment connection and one supervised enrollment profile, the Apps and Books token, an approved compliance baseline, a device configuration baseline, a software-update policy, the required managed-app deployment plus up to three additional applications, pilot validation on up to five devices, documentation including the renewal calendar, and an administrator handoff.

How does this add-on relate to the other Intune services?

Microsoft Intune Initial Setup for Windows Device Management provides the core foundation every add-on builds on. This service is the iPhone & iPad add-on; the sibling mobile add-on is Microsoft Intune Initial Setup for Android Device Management; and Microsoft Defender for Endpoint Deployment for Intune-Managed Devices layers endpoint detection and response onto the managed Windows fleet. Windows Autopilot zero-touch deployment is a further separate engagement on the same foundation. Together they cover a complete, defended multi-platform estate.

How much does the iPhone and iPad setup cost — and why does it differ from the Windows service?

The fee is fixed per project — see the price on this page. It covers one tenant, one enrollment scenario, up to five pilot devices, the required managed-app deployment, and up to three additional applications. The price reflects the density of Apple trust work packed into 10 days: three separate certificate and token connections, supervision and authentication design, and a renewal handoff — work that has no Windows equivalent. No out-of-scope work is performed without your written approval.

How long does implementation take?

Ten calendar days, paced by Apple Business Manager processing and client dependencies rather than ten days of continuous engineering. The schedule assumes the Intune foundation and Apple Business Manager organization are ready, the Apple accounts and tokens are available, pilot devices can be erased and assigned, and decisions and testing arrive on time.

How are iOS and iPadOS software updates managed?

The engagement configures a software-update policy for the supervised pilot fleet using the mechanism Intune currently supports for your devices' OS versions — on current iOS/iPadOS releases that is the declarative device management (DDM) update approach, which enforces a target version by a deadline and shows the user a transparent countdown; older releases fall back to the legacy supervised update policy. The design records which mechanism applies to which devices.

Is Apple Business Manager required?

Yes. Apple Business Manager is required for the included Automated Device Enrollment design. You maintain the verified organization, assign eligible devices to the Intune MDM server, hold the required Apple roles and accounts, and accept Apple's agreements when they update.

Does this service manage employees' personal iPhones or iPads?

No. The included design is for corporate-owned, supervised devices enrolled through Apple Business Manager. BYOD and Apple User Enrollment, web-based personal-device enrollment, and app protection without device enrollment are different management models with different privacy postures, and each is separately scoped.

Are all iPhone and iPad applications included?

The required managed apps for the approved design are included, plus up to three client-selected applications licensed through Apple Business Manager Apps and Books. Private or custom app publishing, signing, packaging, SDK work, vendor troubleshooting, and additional assignments are separately scoped.

Who renews the Apple certificates and tokens after handoff?

You do, by default — using the delivered renewal calendar that names each trust connection, its expiration date, its owning account, and the exact renewal steps. All three renew on roughly annual cycles, and renewing on time with the same accounts is what keeps the fleet managed. If you would rather not carry that clock, IT Partner can quote an annual renewal-management arrangement separately.

What happens after implementation?

You receive the validated configuration, pilot results, as-built document, enrollment and troubleshooting runbooks, the renewal calendar, and an administrator handoff. Natural next steps, each separately scoped: the production rollout, macOS management, BYOD via Apple User Enrollment, an annual renewal-management arrangement, and the multi-platform bundle completing Windows, iPhone/iPad, and Android under one management design.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,500 per project
10 days
Book an Apple scoping call