We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Intune and MDM
  2. Device enrolment
Device enrolment in Microsoft Intune, UAE

Five of the nine enrolment paths require a factory reset. Finding that out after the devices are issued is an expensive week.

Enrolment installs a management certificate and starts policy enforcement. Which path you take decides whether the device has to be wiped first, what settings you can enforce afterwards, and whether the person holding it has to do anything at all. Those are procurement decisions as much as technical ones.

Book an enrolment design sessionSee which paths need a reset
Microsoft Intune device enrolment design for UAE organisations
  • Five platformsAndroid, Apple, Linux, macOS and Windows
  • Reset requiredFor iOS, macOS and three Android modes
  • 1,000 devicesWhat a device enrolment manager account can enrol
  • 180 daysBefore idle device records are deleted
What enrolment decides

Seven things that should be settled before any device is ordered.

Microsoft describes enrolment as installing a mobile device management certificate that communicates with the Intune service and enables policy enforcement, with enrolment, compliance and configuration policies typically deployed during the process. The choices below determine what that enforcement can actually reach.

Five enrolment paths require a factory reset first

Microsoft publishes the table. Reset required for iOS and iPadOS, macOS, Android Enterprise corporate-owned work profile, Android Enterprise fully managed, and Android Enterprise dedicated devices. Not required for Android Enterprise personally owned devices with a work profile, Android device administrator, Linux and Windows. That single table shapes device logistics entirely.

Corporate-owned gets more control than personal

Microsoft states Intune offers more granular settings and policies for devices classified as corporate-owned or organisation-owned, with more password settings available so you can enforce stricter password requirements. It also notes that Intune marks devices that are Microsoft Entra registered as personally owned, which is how devices end up in the wrong category by accident.

Apple platforms need a push certificate, others need nothing

The published prerequisites table is short. iOS and iPadOS need a mobile device management push certificate from Apple plus an Apple ID. macOS needs a push certificate. Android, Android Enterprise, Linux and Windows have no additional platform requirement. The Apple push certificate is also the one that expires annually and takes an estate offline when nobody renews it.

Enrolment restrictions, which are on by default in the permissive direction

Microsoft states enrolment is enabled for all platforms by default, and that you can restrict specific platforms from enrolling using an enrolment restriction policy. Combined with enrolment policies that limit the number or type of devices somebody can enrol, that is the control preventing an estate filling with device types nobody planned to support.

A device enrolment manager account for bulk work

Microsoft describes creating a device enrolment manager account for bulk enrolment, able to enrol up to 1,000 mobile devices, used to enrol and configure devices before giving them to users. It is an Intune permission applied to an Entra user account, and Microsoft notes it is not compatible with all enrolment methods, naming Apple automated device enrolment.

Settings survive on platforms that are not wiped

A quiet detail with real consequences. Microsoft states that on platforms not requiring a factory reset, devices start receiving your Intune policies on enrolment, but if you do not configure a setting in Intune then Intune does not change or update it, so previously configured settings can remain in place. A device migrated from another product can therefore carry old configuration indefinitely.

Idle records are deleted after a defined period

The management certificate renews automatically while devices communicate with the service, and does not renew for devices that are wiped or that fail to sync for an extended period. Microsoft states Intune deletes idle devices from record 180 days after the certificate expires, which is worth knowing before somebody concludes that historic devices have vanished unexpectedly.

The logistics question hiding inside a technical decision

A device already in a user hands cannot take five of the nine enrolment paths without being wiped.

Microsoft publishes the factory reset requirement per enrolment method, and it is the fact that most often changes a deployment plan after it has been agreed.

  • Factory reset required, as published: iOS and iPadOS, macOS, Android Enterprise corporate-owned work profile, Android Enterprise fully managed, and Android Enterprise dedicated devices.
  • Factory reset not required: Android Enterprise personally owned devices with a work profile, Android device administrator, Linux and Windows.
  • The consequence for an existing estate is stark. Moving in-use iPhones or Macs to a managed corporate enrolment means every device is wiped and rebuilt, which is a communications exercise, a data migration exercise and a support surge, not a configuration change.
  • The consequence for procurement is the opposite and much better. Devices ordered new and enrolled before issue take the corporate path at no user cost at all. Which is why this table belongs in the hardware refresh discussion rather than in the technical design that follows it.
Ask us to map your enrolment paths
How we approach it

Four things that make enrolment a decision rather than an accident.

Enrolment is the one part of device management that touches procurement, logistics, communications and support at the same time. Designing it as a technical task alone is what produces the surprises.

We put the factory reset table into the procurement conversation

Five of the published enrolment paths require a wipe. For new devices that is free. For devices already in use it is a data migration, a communications plan and a support surge. Establishing which population is which, before hardware is ordered, is what turns an expensive retrofit into a no-cost decision taken at the right moment.

We get the corporate classification right at the start

Microsoft offers more granular settings and stricter password requirements for devices classified as corporate-owned, and marks Entra registered devices as personally owned. Devices that end up in the wrong category are difficult to reclassify and quietly restrict what you can enforce, so getting the identification method right is worth more than it sounds.

We clean up what the previous product left behind

Microsoft is explicit that on platforms not requiring a factory reset, if you do not configure a setting in Intune then Intune does not change it, so previously configured settings can remain. A device migrated from another management product can carry old configuration indefinitely, which is an invisible problem until something behaves unexpectedly.

We use restrictions to keep the estate to what you support

Enrolment is enabled for all platforms by default. Restricting the platforms you do not intend to support, and limiting the number or type of devices any one person can enrol, is a five minute configuration that prevents years of accumulated exceptions nobody chose to accept.

Where this matters most

Six UAE situations where the enrolment decision has real consequences.

Enrolment looks like a technical step and behaves like a logistics project, because the path chosen determines whether a device has to be wiped, who touches it, and what can be enforced afterwards.

A business moving an existing iPhone estate under management

iOS and iPadOS enrolment requires a factory reset, so an in-use estate means every device wiped and rebuilt. That is a communications plan, a backup and restore path and a support surge rather than a configuration change. Timing it alongside a hardware refresh, where devices are new anyway, removes the cost entirely.

An organisation issuing devices to remote joiners

A device enrolment manager account can enrol up to 1,000 mobile devices, used to enrol and configure them before giving them to users. For an organisation shipping devices to people who will never visit an office, that is the difference between a device that works on arrival and a support call on day one. It is not compatible with Apple automated device enrolment.

A regulated firm that needs stricter controls on corporate devices

Microsoft offers more granular settings for devices classified as corporate-owned or organisation-owned, including more password settings so stricter requirements can be enforced. Where an obligation names password complexity or device controls, the classification decision is what determines whether you can meet it, and it is set at enrolment.

An operator deploying shared and single purpose devices

Android Enterprise dedicated devices require a factory reset and are provisioned centrally, which suits handhelds, scanners and shift-shared tablets. That is a very different enrolment model from a personally owned device with a work profile, and mixing the two in one project produces two incompatible sets of logistics.

An organisation migrating from another management product

Devices currently enrolled elsewhere must be unenrolled from the existing provider first, and Microsoft notes unenrolling typically does not remove the features and settings that were configured. On platforms not requiring a factory reset, those settings can persist after Intune enrolment unless Intune configures them explicitly, which is the source of a lot of unexplained behaviour.

An institution wanting to limit what people can enrol

Enrolment is enabled for all platforms by default, and an enrolment restriction policy blocks specific ones. Combined with policies limiting the number or type of devices somebody can enrol, that keeps a large and diverse user population from producing an estate with device types nobody planned to support or secure.

Three positions

How UAE organisations bring devices under management.

The middle column is what happens when enrolment was never designed. Devices arrive through whatever path each person happened to use, and the resulting estate has three categories nobody can explain.
Corporate devices marked as corporate
Designed enrolment modelYes
Whatever path people usedPartly
Unmanaged devicesNot applicable
Stricter policies available where appropriate
Designed enrolment modelYes
Whatever path people usedInconsistent
Unmanaged devicesNo
Unsupported platforms blocked
Designed enrolment modelYes
Whatever path people usedNo
Unmanaged devicesNot applicable
Device count per user limited
Designed enrolment modelYes
Whatever path people usedNo
Unmanaged devicesNot applicable
Bulk enrolment before issue
Designed enrolment modelYes
Whatever path people usedRarely
Unmanaged devicesNo
Old settings from a previous product removed
Designed enrolment modelYes
Whatever path people usedNo
Unmanaged devicesNot applicable
Enrolment failures monitored
Designed enrolment modelYes
Whatever path people usedNo
Unmanaged devicesNot applicable
Apple certificate renewal owned
Designed enrolment modelYes
Whatever path people usedDiscovered when it expires
Unmanaged devicesNot applicable
Stale records understood
Designed enrolment modelYes
Whatever path people usedNo
Unmanaged devicesNot applicable
User experience at enrolment
Designed enrolment modelDesigned
Whatever path people usedVaries
Unmanaged devicesNot applicable
Feature
Designed enrolment model
Whatever path people used
Unmanaged devices
Corporate devices marked as corporate
YesPartlyNot applicable
Stricter policies available where appropriate
YesInconsistentNo
Unsupported platforms blocked
YesNoNot applicable
Device count per user limited
YesNoNot applicable
Bulk enrolment before issue
YesRarelyNo
Old settings from a previous product removed
YesNoNot applicable
Enrolment failures monitored
YesNoNot applicable
Apple certificate renewal owned
YesDiscovered when it expiresNot applicable
Stale records understood
YesNoNot applicable
User experience at enrolment
DesignedVariesNot applicable
The published requirements

Factory reset and platform prerequisites, per enrolment path.

Reproduced from the two published tables. The right hand column is the practical consequence, which is ours.
Enrolment pathFactory reset requiredPractical consequence
Android Enterprise personally owned with a work profileNoThe cleanest path for an existing personal device, with a separated work profile
Android Enterprise corporate-owned work profileYesNew devices, or a planned wipe and reissue with user communication
Android Enterprise fully managedYesCorporate devices only, provisioned before issue
Android Enterprise dedicated devicesYesShared and single purpose devices, provisioned centrally
Android device administratorNoLegacy, and deprecated on devices with Google Mobile Services
iOS and iPadOSYesAlso needs an Apple push certificate and an Apple ID
macOSYesAlso needs an Apple push certificate
WindowsNoExisting devices can enrol in place, but old settings may persist
LinuxNoUser initiated enrolment on supported distributions
How an engagement runs

Five steps, and the pilot is not a formality.

Typically four to eight weeks to a designed and piloted enrolment model. The configuration is quick. Deciding the path per population, and communicating it, is the work.
  1. 1

    Confirm the prerequisites are actually in place

    The mobile device management authority set to Intune, which Microsoft notes is required even when using co-management with Configuration Manager. Intune licences assigned. Supported devices confirmed. Apple push certificate obtained where iOS, iPadOS or macOS are in scope, with a named owner for its renewal.

  2. 2

    Decide the path per population

    Personal or corporate-owned, and which enrolment method follows from that, checked against the published factory reset requirements. Whether devices are new or already in use, since that decides whether a reset is free or expensive. And whether any devices are currently enrolled in another management product, which requires unenrolment first.

  3. 3

    Set restrictions before opening enrolment

    Enrolment is enabled for all platforms by default, so the platforms you do not intend to support are blocked explicitly. Enrolment policies limiting the number or type of devices a person can enrol are set at the same time, because both are far easier to apply before an estate exists than to retrofit afterwards.

  4. 4

    Pilot in stages, starting genuinely small

    Microsoft recommends starting small with a staged approach: assign the enrolment policy to a pilot or test group, then after initial testing add more users to the pilot group, then assign to further pilot groups. That sequence surfaces the enrolment experience problems while the population is small enough to phone individually.

  5. 5

    Establish the operational rhythm

    Incomplete user enrolments monitored, since there is a published report for exactly that. Apple push certificate renewal owned by a named person with a reminder well ahead of expiry. And an understanding that idle device records are deleted 180 days after the management certificate expires, so historic records are not a permanent inventory.

Straight answers

What organisations ask about device enrolment.

Microsoft publishes the table. Reset required for iOS and iPadOS, macOS, Android Enterprise corporate-owned work profile, Android Enterprise fully managed, and Android Enterprise dedicated devices. Not required for Android Enterprise personally owned devices with a work profile, Android device administrator, Linux and Windows. That distinction usually determines the cost of the whole project.

Microsoft describes Intune installing a mobile device management certificate on the device, which communicates with the Intune service and enables Intune to start enforcing your policies. Those typically include enrolment policies limiting the number or type of devices somebody can enrol, compliance policies, and configuration policies that set work-appropriate features and settings.

Control. Microsoft states Intune offers more granular settings and policies for devices classified as corporate-owned or organisation-owned, with more password settings available so stricter password requirements can be enforced. It also notes Intune marks devices that are Microsoft Entra registered as personally owned, which is how a device sometimes lands in the wrong category.

The mobile device management authority set to Intune, which Microsoft says applies even when using co-management with Configuration Manager. Intune licences assigned. Supported devices. And signing in as a member of the Policy and Profile Manager built-in Intune role, though Microsoft notes some enrolment platforms might require a more privileged Entra role such as Intune Administrator.

Only Apple. The published table shows iOS and iPadOS requiring a mobile device management push certificate and an Apple ID, and macOS requiring a push certificate. Android, Android Enterprise, Linux and Windows have no additional platform requirement listed. The Apple certificate is the one to assign an owner to, because it expires.

Yes. Microsoft states enrolment is enabled for all platforms by default, and that you can restrict specific platforms from enrolling using an Intune enrolment restriction policy. There are also enrolment policies that limit the number or type of devices a single person can enrol, which is the other half of keeping an estate to what you intended.

The device enrolment manager account. Microsoft describes it as an Intune permission applied to an Entra user account, able to enrol up to 1,000 mobile devices, used to enrol and configure devices before giving them to users. One important caveat is published: it is not compatible with all enrolment methods, and Apple automated device enrolment is named specifically.

Unenrol them from the existing provider first. Microsoft notes that unenrolling typically does not remove the existing features and settings you configured, and that most providers have remote actions to remove organisation-specific data. Removing that data before enrolling in Intune is possible but not required, and depending on the platform a factory reset may be needed anyway.

Not necessarily, and this catches people out. Microsoft states that on platforms not requiring a factory reset, devices start receiving your Intune policies on enrolment, but if you do not configure a setting in Intune then Intune does not change or update that setting. So previously configured settings can remain in place indefinitely on Windows, Linux and the Android paths that do not wipe.

In stages, and Microsoft is specific about the shape. Start small, assign the enrolment policy to a pilot or test group, then after initial testing add more users to that pilot group, then assign to more pilot groups. Enrolment is the part of device management users experience most directly, so problems found at ten people are far cheaper than at a thousand.

Record cleanup. Microsoft states the management certificate renews automatically while devices communicate with the service, does not renew for devices that are wiped or that fail to sync for an extended period, and that Intune deletes idle devices from record 180 days after the certificate expires. It is expected behaviour rather than data loss, but it means Intune is not a permanent asset register.

Android, iOS and iPadOS, Linux, macOS and Windows, with supported versions published separately. Each has its own platform enrolment guide, and there is also an application management without enrolment path for scenarios where the device itself is not being managed but organisational data on it needs protecting.

For some scenarios, yes. Microsoft lists application management without enrolment alongside the per-platform enrolment guides. That path protects organisational data inside managed applications on a device that is not itself enrolled, which suits contractors and personal devices where full enrolment is neither proportionate nor acceptable to the user.

There is a published report for incomplete user enrolments, alongside enrolment troubleshooting guidance. Watching that report during a rollout is how you find out that a population is silently not completing enrolment, which otherwise surfaces weeks later as an unexplained gap between the number of devices issued and the number under management.

The mobile device management authority still has to be set to Intune, and Microsoft states this explicitly, including when using co-management with Intune and Configuration Manager together. Beyond that, co-managed and Microsoft Entra hybrid joined devices are included in the supported device requirement, so they are in scope for enrolment rather than being a separate track. What co-management changes is which product owns which workload afterwards, not whether the device is enrolled.

That is a deliberate choice rather than a default to accept. Microsoft lists enrolment policies that limit the number or type of devices someone can enrol among the policies typically deployed during enrolment. In organisations where people carry a phone, a tablet and a laptop, a generous limit is reasonable. In organisations where nobody can explain why one user has eleven enrolled devices, the limit is the control that was never set.

We scope per organisation, driven by how many platforms and populations are involved and whether an existing estate needs migrating, which is where the factory reset requirements make the difference. The path mapping exercise is quick and usually the most valuable single output, because it frequently changes when the work should happen.
Before the first device

Fifteen decisions that determine the enrolment experience.

The first group is prerequisites, the second is the path decision, and the third is the operational half that determines whether the estate stays clean.

Prerequisites

  • Is the MDM authority set to Intune?
    Required even with co-management.
  • Are Intune licences assigned?
    To every user who will enrol.
  • Is the Apple push certificate in place?
    Needed for iOS, iPadOS and macOS.
  • Who renews the Apple certificate?
    It expires, and the estate goes with it.
  • Which administrative role is being used?
    Policy and Profile Manager is the least privileged.

Path decision

  • Are these new or existing devices?
    Five paths require a factory reset.
  • Personal or corporate-owned?
    Corporate allows stricter password settings.
  • Are devices already in another MDM?
    They must be unenrolled first.
  • Do you need bulk enrolment before issue?
    That is the DEM account, up to 1,000 devices.
  • Is Apple automated device enrolment in scope?
    The DEM account is not compatible with it.

Keeping it clean

  • Which platforms should be blocked?
    All are enabled by default.
  • How many devices may one person enrol?
    Enrolment policies can limit it.
  • Are settings from a previous product still present?
    They can persist where no wipe occurred.
  • Is there a pilot group?
    Microsoft recommends a staged approach.
  • Who watches incomplete enrolments?
    There is a report for exactly this.
Related reading

The pages around this one.

Zero touch deployment

Where enrolment becomes provisioning, with the device configured before the user sees it.

Learn more

Windows Autopilot

The Windows provisioning path in detail.

Learn more

MDM solutions

The cross-platform view of what management looks like after enrolment.

Learn more
Next step

Check which of your device populations would need wiping. That number is the project.

Five of the published enrolment paths require a factory reset. If most of your estate is due for refresh anyway, this is nearly free. If it is not, the timing decision is worth taking deliberately rather than discovering.

Book an enrolment design sessionCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Apple Configurator

Bring retail-bought Apple devices under management

Learn more

Zero-Touch Deployment UAE

Sealed box to working device without IT touching it

Learn more

Windows Autopilot Dubai

Zero-touch laptop deployment, supplier registration onward

Learn more

MDM Solutions Dubai

Device management across Windows, Apple and Android

Learn more

Microsoft Intune

Device management and endpoint security

Learn more

Android Enterprise

Choose the enrolment method before you buy the phones

Learn more

Apple Device Management

Mac and iPhone fleets, encryption, patching and the September cycle

Learn more

Intune Compliance Policies

The default that lets unassessed devices through Conditional Access

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy