Skip to content
Call +49 40 88192642 Send an email [email protected] Chat in Teams [email protected]
← All articles ·Unkategorisiert · ·6 min read

Company phones that set themselves up: iPhone and Android with Intune

How iPhones enrol in Intune through Apple Business Manager and Android devices through zero-touch the first time they are switched on, how personal phones are protected with app protection policies, and what to watch for with privately bought devices.

Ein neues Smartphone richtet sich beim ersten Einschalten selbst ein

A new company phone should reach the employee, be switched on and then be ready for work: with email, Teams, Wi-Fi and the company’s security settings. With Microsoft Intune, Apple Business Manager and Android zero-touch enrolment, this works without a stop at the IT desk. Here I describe how I set it up and where personal phones fit in. The experience comes from rollouts in 2024 and 2025.

Where the time goes without automation

Without device management, setting up a company phone usually goes like this: someone unpacks it, signs in with an Apple ID or a Google account, sets up the mailbox, installs Teams and hands the device over. Whether a screen lock is set or the operating system stays up to date is never checked again. When someone leaves, it is often unclear which accounts are still on the device.

With automated enrolment the order is reversed. The settings are ready centrally beforehand, and the device collects them itself as soon as it first goes online.

iPhones: Apple Business Manager and Intune

Apple Business Manager (Apple now calls the service “Apple Business”) is the register of devices the company owns. If you buy from Apple or a participating reseller using your organisation ID, the devices appear there automatically. I connect Apple Business Manager to Intune once and define which enrolment profile new devices receive.

For the employee

The iPhone is switched on, connected to Wi-Fi and shows in Setup Assistant that it is managed by the company. After signing in with the work account, apps, email and settings arrive by themselves.

For management

The device is supervised. That allows more settings to be enforced than on a privately set-up iPhone, and management can be configured so that the user cannot remove it.

The order matters: the enrolment profile has to be assigned to the device before anyone switches it on for the first time. Otherwise setup completes without management and the device has to be erased. That is why I set a default profile that every new device receives automatically.

Android: zero-touch enrolment

On Android the counterpart is called zero-touch. The principle is the same: on first boot the device checks whether a company configuration has been assigned to it, downloads the Intune app and sets itself up as a fully managed company device. The prerequisite is that it was bought from a reseller that takes part in zero-touch. Devices from ordinary consumer shops cannot be enrolled this way.

So before devices are ordered, I ask which reseller they will come from. Otherwise this is one of the points where a rollout stalls, because the phones are already unpacked before the configuration is in place.

Personal phones: protecting company data without managing the device

Many employees read their work email on their own phone. Understandably, hardly anyone wants to put their whole phone under device management. That is what app protection policies are for: they apply not to the device, only to the work account in specific apps such as Outlook, Teams, OneDrive or Word.

  • What is protected: company data cannot be copied into or saved in personal apps, the apps require their own PIN, and company data can be removed selectively if the phone is lost or the employee leaves.
  • What stays private: IT neither sees nor manages photos, personal apps or personal accounts.
  • What belongs with it: Conditional Access is what ensures company data is only opened in protected apps. On Android, the Intune Company Portal app must also be installed.

I use this split whenever clients allow personal phones: full management for company devices, app-level protection for personal ones.

When devices were bought outside Apple Business Manager

This happens often: an iPhone was bought in a high-street shop or privately and then expensed to the company. Apple Business Manager doesn’t know it. I add such devices afterwards with Apple Configurator. The iPhone has to be erased and sitting in Setup Assistant for this, so any data on it is lost or has to be backed up first.

One thing worth knowing: after handover, the user has 30 days to release a device added this way from management. After that it behaves like any other company device. For new devices I therefore recommend organising purchasing so that devices are registered in Apple Business Manager automatically.

When it pays off

From around ten devices I almost always recommend device management. The threshold is not a technical one, though. If nobody in the company makes sure phones are kept up to date, locked and can be wiped when lost, management makes sense from the very first device. With Intune, getting started is manageable today, not least because it is already included in Microsoft 365 Business Premium.

How Intune differs from specialist Apple solutions such as Mosyle, Jamf or Iru, and when another system is the better fit, is covered in my comparison of MDM systems.

Sources