Company phones that set themselves up: iPhone and Android with Intune
How iPhones enrol in Intune through Apple Business Manager and Android devices through zero-touch the first time they are switched on, how personal phones are protected with app protection policies, and what to watch for with privately bought devices.
A new company phone should reach the employee, be switched on and then be ready for work: with email, Teams, Wi-Fi and the company’s security settings. With Microsoft Intune, Apple Business Manager and Android zero-touch enrolment, this works without a stop at the IT desk. Here I describe how I set it up and where personal phones fit in. The experience comes from rollouts in 2024 and 2025.
Where the time goes without automation
Without device management, setting up a company phone usually goes like this: someone unpacks it, signs in with an Apple ID or a Google account, sets up the mailbox, installs Teams and hands the device over. Whether a screen lock is set or the operating system stays up to date is never checked again. When someone leaves, it is often unclear which accounts are still on the device.
With automated enrolment the order is reversed. The settings are ready centrally beforehand, and the device collects them itself as soon as it first goes online.
iPhones: Apple Business Manager and Intune
Apple Business Manager (Apple now calls the service “Apple Business”) is the register of devices the company owns. If you buy from Apple or a participating reseller using your organisation ID, the devices appear there automatically. I connect Apple Business Manager to Intune once and define which enrolment profile new devices receive.
The iPhone is switched on, connected to Wi-Fi and shows in Setup Assistant that it is managed by the company. After signing in with the work account, apps, email and settings arrive by themselves.
The device is supervised. That allows more settings to be enforced than on a privately set-up iPhone, and management can be configured so that the user cannot remove it.
The order matters: the enrolment profile has to be assigned to the device before anyone switches it on for the first time. Otherwise setup completes without management and the device has to be erased. That is why I set a default profile that every new device receives automatically.
Android: zero-touch enrolment
On Android the counterpart is called zero-touch. The principle is the same: on first boot the device checks whether a company configuration has been assigned to it, downloads the Intune app and sets itself up as a fully managed company device. The prerequisite is that it was bought from a reseller that takes part in zero-touch. Devices from ordinary consumer shops cannot be enrolled this way.
So before devices are ordered, I ask which reseller they will come from. Otherwise this is one of the points where a rollout stalls, because the phones are already unpacked before the configuration is in place.
Personal phones: protecting company data without managing the device
Many employees read their work email on their own phone. Understandably, hardly anyone wants to put their whole phone under device management. That is what app protection policies are for: they apply not to the device, only to the work account in specific apps such as Outlook, Teams, OneDrive or Word.
- What is protected: company data cannot be copied into or saved in personal apps, the apps require their own PIN, and company data can be removed selectively if the phone is lost or the employee leaves.
- What stays private: IT neither sees nor manages photos, personal apps or personal accounts.
- What belongs with it: Conditional Access is what ensures company data is only opened in protected apps. On Android, the Intune Company Portal app must also be installed.
I use this split whenever clients allow personal phones: full management for company devices, app-level protection for personal ones.
When devices were bought outside Apple Business Manager
This happens often: an iPhone was bought in a high-street shop or privately and then expensed to the company. Apple Business Manager doesn’t know it. I add such devices afterwards with Apple Configurator. The iPhone has to be erased and sitting in Setup Assistant for this, so any data on it is lost or has to be backed up first.
One thing worth knowing: after handover, the user has 30 days to release a device added this way from management. After that it behaves like any other company device. For new devices I therefore recommend organising purchasing so that devices are registered in Apple Business Manager automatically.
When it pays off
From around ten devices I almost always recommend device management. The threshold is not a technical one, though. If nobody in the company makes sure phones are kept up to date, locked and can be wiped when lost, management makes sense from the very first device. With Intune, getting started is manageable today, not least because it is already included in Microsoft 365 Business Premium.
How Intune differs from specialist Apple solutions such as Mosyle, Jamf or Iru, and when another system is the better fit, is covered in my comparison of MDM systems.
Sources
- Automated enrolment of iPhones and iPads in Intune: Microsoft Learn – Tutorial: Set up Intune enrollment for iOS/iPadOS devices in Apple Business
- Zero-touch enrolment for Android in Intune: Microsoft Learn – Enroll Android Enterprise devices
- Zero-touch from Google’s side, purchase through participating resellers: Android Enterprise Help – Zero-touch enrollment for IT admins
- App protection policies without device management: Microsoft Learn – App Protection Policies Overview
- Adding devices with Apple Configurator, 30-day provisional period: Apple Business – Add devices using Apple Configurator
- Supervised devices: Apple Platform Deployment – About Apple device supervision
Server move in one day: why the preparation takes longer than the move
A new server, a new domain, every workstation moved across and normal work the next morning. What has to happen beforehand, what the schedule and fallback plan look like, and where the time really goes.
Read→
Several companies, one site: how to share a network cleanly
A shared internet connection and firewall, separate networks and a Microsoft 365 tenant for each company. What is shared, what stays separate, how costs are split and where such projects are most likely to snag.
Read→
Taking over Macs in Intune: what I check first
Which points decide the effort before existing Macs are taken over into Intune, when a Mac has to be erased, how Platform SSO, FileVault and software deployment are set up, and where Intune reaches its limits on Macs.
Read→