Five of the nine enrolment paths require a factory reset. Finding that out after the devices are issued is an expensive week.
Enrolment installs a management certificate and starts policy enforcement. Which path you take decides whether the device has to be wiped first, what settings you can enforce afterwards, and whether the person holding it has to do anything at all. Those are procurement decisions as much as technical ones.

- Five platformsAndroid, Apple, Linux, macOS and Windows
- Reset requiredFor iOS, macOS and three Android modes
- 1,000 devicesWhat a device enrolment manager account can enrol
- 180 daysBefore idle device records are deleted
Seven things that should be settled before any device is ordered.
Five enrolment paths require a factory reset first
Microsoft publishes the table. Reset required for iOS and iPadOS, macOS, Android Enterprise corporate-owned work profile, Android Enterprise fully managed, and Android Enterprise dedicated devices. Not required for Android Enterprise personally owned devices with a work profile, Android device administrator, Linux and Windows. That single table shapes device logistics entirely.
Corporate-owned gets more control than personal
Microsoft states Intune offers more granular settings and policies for devices classified as corporate-owned or organisation-owned, with more password settings available so you can enforce stricter password requirements. It also notes that Intune marks devices that are Microsoft Entra registered as personally owned, which is how devices end up in the wrong category by accident.
Apple platforms need a push certificate, others need nothing
The published prerequisites table is short. iOS and iPadOS need a mobile device management push certificate from Apple plus an Apple ID. macOS needs a push certificate. Android, Android Enterprise, Linux and Windows have no additional platform requirement. The Apple push certificate is also the one that expires annually and takes an estate offline when nobody renews it.
Enrolment restrictions, which are on by default in the permissive direction
Microsoft states enrolment is enabled for all platforms by default, and that you can restrict specific platforms from enrolling using an enrolment restriction policy. Combined with enrolment policies that limit the number or type of devices somebody can enrol, that is the control preventing an estate filling with device types nobody planned to support.
A device enrolment manager account for bulk work
Microsoft describes creating a device enrolment manager account for bulk enrolment, able to enrol up to 1,000 mobile devices, used to enrol and configure devices before giving them to users. It is an Intune permission applied to an Entra user account, and Microsoft notes it is not compatible with all enrolment methods, naming Apple automated device enrolment.
Settings survive on platforms that are not wiped
A quiet detail with real consequences. Microsoft states that on platforms not requiring a factory reset, devices start receiving your Intune policies on enrolment, but if you do not configure a setting in Intune then Intune does not change or update it, so previously configured settings can remain in place. A device migrated from another product can therefore carry old configuration indefinitely.
Idle records are deleted after a defined period
The management certificate renews automatically while devices communicate with the service, and does not renew for devices that are wiped or that fail to sync for an extended period. Microsoft states Intune deletes idle devices from record 180 days after the certificate expires, which is worth knowing before somebody concludes that historic devices have vanished unexpectedly.
A device already in a user hands cannot take five of the nine enrolment paths without being wiped.
Microsoft publishes the factory reset requirement per enrolment method, and it is the fact that most often changes a deployment plan after it has been agreed.
- Factory reset required, as published: iOS and iPadOS, macOS, Android Enterprise corporate-owned work profile, Android Enterprise fully managed, and Android Enterprise dedicated devices.
- Factory reset not required: Android Enterprise personally owned devices with a work profile, Android device administrator, Linux and Windows.
- The consequence for an existing estate is stark. Moving in-use iPhones or Macs to a managed corporate enrolment means every device is wiped and rebuilt, which is a communications exercise, a data migration exercise and a support surge, not a configuration change.
- The consequence for procurement is the opposite and much better. Devices ordered new and enrolled before issue take the corporate path at no user cost at all. Which is why this table belongs in the hardware refresh discussion rather than in the technical design that follows it.
Four things that make enrolment a decision rather than an accident.
We put the factory reset table into the procurement conversation
Five of the published enrolment paths require a wipe. For new devices that is free. For devices already in use it is a data migration, a communications plan and a support surge. Establishing which population is which, before hardware is ordered, is what turns an expensive retrofit into a no-cost decision taken at the right moment.
We get the corporate classification right at the start
Microsoft offers more granular settings and stricter password requirements for devices classified as corporate-owned, and marks Entra registered devices as personally owned. Devices that end up in the wrong category are difficult to reclassify and quietly restrict what you can enforce, so getting the identification method right is worth more than it sounds.
We clean up what the previous product left behind
Microsoft is explicit that on platforms not requiring a factory reset, if you do not configure a setting in Intune then Intune does not change it, so previously configured settings can remain. A device migrated from another management product can carry old configuration indefinitely, which is an invisible problem until something behaves unexpectedly.
We use restrictions to keep the estate to what you support
Enrolment is enabled for all platforms by default. Restricting the platforms you do not intend to support, and limiting the number or type of devices any one person can enrol, is a five minute configuration that prevents years of accumulated exceptions nobody chose to accept.
Six UAE situations where the enrolment decision has real consequences.
A business moving an existing iPhone estate under management
iOS and iPadOS enrolment requires a factory reset, so an in-use estate means every device wiped and rebuilt. That is a communications plan, a backup and restore path and a support surge rather than a configuration change. Timing it alongside a hardware refresh, where devices are new anyway, removes the cost entirely.
An organisation issuing devices to remote joiners
A device enrolment manager account can enrol up to 1,000 mobile devices, used to enrol and configure them before giving them to users. For an organisation shipping devices to people who will never visit an office, that is the difference between a device that works on arrival and a support call on day one. It is not compatible with Apple automated device enrolment.
A regulated firm that needs stricter controls on corporate devices
Microsoft offers more granular settings for devices classified as corporate-owned or organisation-owned, including more password settings so stricter requirements can be enforced. Where an obligation names password complexity or device controls, the classification decision is what determines whether you can meet it, and it is set at enrolment.
An operator deploying shared and single purpose devices
Android Enterprise dedicated devices require a factory reset and are provisioned centrally, which suits handhelds, scanners and shift-shared tablets. That is a very different enrolment model from a personally owned device with a work profile, and mixing the two in one project produces two incompatible sets of logistics.
An organisation migrating from another management product
Devices currently enrolled elsewhere must be unenrolled from the existing provider first, and Microsoft notes unenrolling typically does not remove the features and settings that were configured. On platforms not requiring a factory reset, those settings can persist after Intune enrolment unless Intune configures them explicitly, which is the source of a lot of unexplained behaviour.
An institution wanting to limit what people can enrol
Enrolment is enabled for all platforms by default, and an enrolment restriction policy blocks specific ones. Combined with policies limiting the number or type of devices somebody can enrol, that keeps a large and diverse user population from producing an estate with device types nobody planned to support or secure.
How UAE organisations bring devices under management.
| Feature | Designed enrolment model | Whatever path people used | Unmanaged devices |
|---|---|---|---|
Corporate devices marked as corporate | Yes | Partly | Not applicable |
Stricter policies available where appropriate | Yes | Inconsistent | No |
Unsupported platforms blocked | Yes | No | Not applicable |
Device count per user limited | Yes | No | Not applicable |
Bulk enrolment before issue | Yes | Rarely | No |
Old settings from a previous product removed | Yes | No | Not applicable |
Enrolment failures monitored | Yes | No | Not applicable |
Apple certificate renewal owned | Yes | Discovered when it expires | Not applicable |
Stale records understood | Yes | No | Not applicable |
User experience at enrolment | Designed | Varies | Not applicable |
Factory reset and platform prerequisites, per enrolment path.
| Enrolment path | Factory reset required | Practical consequence | |
|---|---|---|---|
| Android Enterprise personally owned with a work profile | No | The cleanest path for an existing personal device, with a separated work profile | |
| Android Enterprise corporate-owned work profile | Yes | New devices, or a planned wipe and reissue with user communication | |
| Android Enterprise fully managed | Yes | Corporate devices only, provisioned before issue | |
| Android Enterprise dedicated devices | Yes | Shared and single purpose devices, provisioned centrally | |
| Android device administrator | No | Legacy, and deprecated on devices with Google Mobile Services | |
| iOS and iPadOS | Yes | Also needs an Apple push certificate and an Apple ID | |
| macOS | Yes | Also needs an Apple push certificate | |
| Windows | No | Existing devices can enrol in place, but old settings may persist | |
| Linux | No | User initiated enrolment on supported distributions |
Five steps, and the pilot is not a formality.
- 1
Confirm the prerequisites are actually in place
The mobile device management authority set to Intune, which Microsoft notes is required even when using co-management with Configuration Manager. Intune licences assigned. Supported devices confirmed. Apple push certificate obtained where iOS, iPadOS or macOS are in scope, with a named owner for its renewal.
- 2
Decide the path per population
Personal or corporate-owned, and which enrolment method follows from that, checked against the published factory reset requirements. Whether devices are new or already in use, since that decides whether a reset is free or expensive. And whether any devices are currently enrolled in another management product, which requires unenrolment first.
- 3
Set restrictions before opening enrolment
Enrolment is enabled for all platforms by default, so the platforms you do not intend to support are blocked explicitly. Enrolment policies limiting the number or type of devices a person can enrol are set at the same time, because both are far easier to apply before an estate exists than to retrofit afterwards.
- 4
Pilot in stages, starting genuinely small
Microsoft recommends starting small with a staged approach: assign the enrolment policy to a pilot or test group, then after initial testing add more users to the pilot group, then assign to further pilot groups. That sequence surfaces the enrolment experience problems while the population is small enough to phone individually.
- 5
Establish the operational rhythm
Incomplete user enrolments monitored, since there is a published report for exactly that. Apple push certificate renewal owned by a named person with a reminder well ahead of expiry. And an understanding that idle device records are deleted 180 days after the management certificate expires, so historic records are not a permanent inventory.
What organisations ask about device enrolment.
Fifteen decisions that determine the enrolment experience.
Prerequisites
- Is the MDM authority set to Intune?Required even with co-management.
- Are Intune licences assigned?To every user who will enrol.
- Is the Apple push certificate in place?Needed for iOS, iPadOS and macOS.
- Who renews the Apple certificate?It expires, and the estate goes with it.
- Which administrative role is being used?Policy and Profile Manager is the least privileged.
Path decision
- Are these new or existing devices?Five paths require a factory reset.
- Personal or corporate-owned?Corporate allows stricter password settings.
- Are devices already in another MDM?They must be unenrolled first.
- Do you need bulk enrolment before issue?That is the DEM account, up to 1,000 devices.
- Is Apple automated device enrolment in scope?The DEM account is not compatible with it.
Keeping it clean
- Which platforms should be blocked?All are enabled by default.
- How many devices may one person enrol?Enrolment policies can limit it.
- Are settings from a previous product still present?They can persist where no wipe occurred.
- Is there a pilot group?Microsoft recommends a staged approach.
- Who watches incomplete enrolments?There is a report for exactly this.
Check which of your device populations would need wiping. That number is the project.
Five of the published enrolment paths require a factory reset. If most of your estate is due for refresh anyway, this is nearly free. If it is not, the timing decision is worth taking deliberately rather than discovering.
Related Services
Explore more solutions that work great with this service
Apple Configurator
Bring retail-bought Apple devices under management
Zero-Touch Deployment UAE
Sealed box to working device without IT touching it
Windows Autopilot Dubai
Zero-touch laptop deployment, supplier registration onward
MDM Solutions Dubai
Device management across Windows, Apple and Android
Microsoft Intune
Device management and endpoint security
Android Enterprise
Choose the enrolment method before you buy the phones
Apple Device Management
Mac and iPhone fleets, encryption, patching and the September cycle
Intune Compliance Policies
The default that lets unassessed devices through Conditional Access