Glossary
User Enrollment
User Enrollment is Apple's BYOD management mode, available since iOS 13 and iPadOS 13.1, where an employee's own iPhone gets work apps and work accounts without the company taking control of the device. Managed data lives in its own cryptographically separated volume, and the MDM can remove that volume while being unable to wipe the phone, see personal apps or read the device serial number.
How it works
The user signs in to a work account on their own iPhone. They keep their personal Apple Account, and a Managed Apple ID from Apple Business Manager is added next to it. That second identity is the hinge of the whole design: iOS creates a separate APFS volume with its own encryption keys for anything the company sends, and work mail, calendars, notes and managed apps write there.
Apple has changed the starting point twice. The original flow in 2019 installed an enrollment profile. Since iOS 15 in 2021, Account-Driven User Enrollment is the preferred route: the user goes to Settings, General, VPN and Device Management, Sign In to Work or School Account, and types their work email. iOS discovers the MDM server through a well-known URL on your domain, sends the user to your identity provider, and enrollment finishes without anyone downloading a profile. Apple has flagged the older profile-based variant as deprecated and points new deployments at the account-driven one.
An app that already exists in personal form is installed as a second managed instance, so the work Outlook and the personal Outlook coexist with separate data. Managed open-in rules stop a file moving from the managed side to a personal cloud drive.
Why it matters for a fleet
This is the mode that lets you say yes to BYOD without a works council fight. Write down what IT genuinely cannot do under User Enrollment, because it's a short list that answers most employee objections.
- No device wipe. Unenrolling removes the managed volume and nothing else.
- No serial number or UDID. The MDM gets an enrollment-specific identifier, so the phone can't be tracked as an asset.
- No inventory of personal apps, no access to photos, messages, personal mail or location.
- No device-level restrictions, no passcode clearing, no device lock, no device-wide VPN (per-app VPN only).
The cost of that restraint is control. If you need single app mode, kiosk, app removal enforcement or a guaranteed wipe, you need a company-owned device with Automated Device Enrollment and supervision. Two modes, two ownership models: decide by who paid for the phone.
One prerequisite trips teams up more than anything else. No Managed Apple ID, no User Enrollment. Which means Apple Business Manager, a verified domain, and ideally federation with Entra ID or Google Workspace before you start.
How Appaloosa handles it
Appaloosa does not use Apple's User Enrollment. Personal iPhones and iPads are enrolled through a BYOD link the employee opens on the device, which installs a management profile scoped to work apps and accounts: managed apps with their configuration, certificates, compliance rules, and a selective wipe that removes company apps and accounts while leaving the phone intact. It's a different trade-off from User Enrollment: no Managed Apple ID is required, and IT keeps more control over the managed apps. The Android equivalent is the work profile.
Appaloosa supports BYOD enrollment on iOS and iPadOS with work data kept separate from personal data, distributes managed apps and applies managed app configuration to them, and performs selective wipe that removes company apps and accounts while leaving the employee's phone intact. The Android equivalent is the work profile. Both are covered from the iOS MDM page.
Explore
See the full platform
Enrollment, apps, security, remote support: all in one place.
Explore Appaloosa →See Appaloosa run on your fleet Book a demo