Resources
Company-owned vs personally owned devices: supervision, User Enrollment and privacy
Before you pick an MDM or write a single policy, you have to answer one question: who owns the device? Apple's management framework is built around that answer. A company-owned iPhone can be supervised and managed deeply. A personally owned iPhone can be enrolled, but the controls are deliberately narrower so the employee's private life stays private. This article explains the models Apple documents, what each one lets IT see and do, and how to choose and communicate your approach.
The two ownership models Apple documents
Apple's deployment guide splits devices into user-owned and organization-owned. For user-owned devices, enrollment is the user's choice unless it is automated, and the user can disassociate the device from the management service at any time. For organization-owned devices, Apple's Automated Device Enrollment (ADE) lets you enroll and supervise devices wirelessly during initial setup, with no hands on the device.
Within those models, Apple describes two broad routes for getting a device into management: enrollment profiles, where the user receives and installs a profile, and account-driven enrollment, where the user signs in with a Managed Apple Account in Settings. Account-driven enrollment comes in two forms, and the naming matters:
- Account-driven User Enrollment is meant for devices the employee owns. IT manages only the organization's accounts, settings and data, never the user's personal account.
- Account-driven Device Enrollment is for organization-owned devices, including ones already in use. It supports a wider range of configurations than User Enrollment.
- Profile-based Device Enrollment is the older route: the user installs an enrollment profile. Removing that profile removes every configuration profile, setting and managed app that came with it.
Note that "Device Enrollment" and "User Enrollment" are different Apple terms, not synonyms. Device Enrollment is the broader-control path. User Enrollment is the privacy-preserving path for personal devices.
What supervision unlocks on company devices
Supervision is Apple's term for an organization owning a device and having extra control over its configuration and restrictions. iPhone, iPad, Mac, Apple TV, Apple Vision Pro and Apple Watch are supervised automatically when enrolled through ADE, provided they meet minimum OS versions. iPhone, iPad and Apple TV can also be supervised with Apple Configurator for Mac, but that requires physical access and erases the device. Macs on macOS 11 or later can be supervised through account-driven or profile-based enrollment.
Apple publishes a restrictions reference with a column showing which settings need supervision. Some, such as AirDrop on iOS and iPadOS, are supervised-only. Apple also notes that several restrictions can't be fully enforced on unsupervised devices and says it plans to make them supervised-only in a future release. Examples it lists include camera, biometric unlock, iCloud Keychain and in-app purchases. Supervision also affects how apps can be installed automatically, and on unsupervised iPhone and iPad, a user who knows the passcode can remove manually installed legacy profiles even if removal is set to Never. On supervised iPhone and iPad, Apple notes the organization can also monitor internet traffic and locate the device.
If your policy depends on a restriction, check the supervision column in Apple's restrictions list before you promise it. A control that only partly works on an unsupervised device is a gap you should document, not assume away.
What MDM can and cannot do under User Enrollment
On a personally owned device, Apple limits the payloads and restrictions an administrator can apply, which protects the owner's privacy. A user can have a personal Apple Account and a Managed Apple Account on the same device, and the operating system keeps their data separate. Users can also see what the organization manages and how much iCloud storage it provides.
Based on Apple's User Enrollment reference for management services, here is the practical picture:
- Commands: erase device is not in the list for User Enrollment. Lock device on iOS and iPadOS, and pushing or removing apps, books and settings, are available.
- Queries: IT can read device details, security information, installed certificates and profiles, and the status of managed apps. It can list third-party apps but not apps the user installed themselves from the App Store.
- Payloads: many work-oriented payloads are supported, including Wi-Fi, Mail, Calendar, Contacts, certificates, app-layer VPN and extensible single sign-on, with availability varying by OS.
- Restrictions: a limited set applies, such as blocking screenshots and screen recording, turning off Siri, and controlling managed data movement to iCloud, AirDrop and the pasteboard.
The takeaway for admins: you protect work data and revoke work access, but you cannot reset the whole phone or inventory what the employee installed. Plan your offboarding around removing the managed accounts and apps rather than wiping.
Privacy implications and how to communicate them
Employees tend to assume the worst about MDM. The honest answer differs by model, so say it plainly and per model. Vague reassurance backfires the first time someone reads a profile.
- State the ownership model and what it means in one sentence: "This is a company-owned, supervised device" or "This is your personal device with a managed work area."
- List what the company can see and do, and what it cannot. Use the lists above as your starting point and confirm each item against your own MDM's behavior.
- Explain what happens at offboarding, including whether the device will be erased, and who initiates it.
- Tell employees how to see what is managed on their device, and who to contact with questions.
- Put it in writing and have it acknowledged before enrollment, not after.
Even on company-owned devices, describe the limits you intend to respect. For example, if you do not use location features routinely, say so, and say when you would. A written promise you keep builds more trust than a technical capability you hide.
A practical guide to choosing a model
Use these rules of thumb to map your situation to an approach:
- The company buys and owns the device, and you need strict controls or full erase: use ADE where possible so the device is supervised from first setup. Apple Configurator is the manual alternative for iPhone, iPad and Apple TV.
- The company owns a device that is already in use and not eligible for ADE: use Device Enrollment, either account-driven or profile-based. Check Apple's supervision rules for your platform and OS, since supervision on iPhone and iPad generally comes through ADE or Apple Configurator.
- The employee owns the device and you only need work email, Wi-Fi, VPN and a few managed apps: use account-driven User Enrollment with a Managed Apple Account.
- The employee owns the device but you need broad restrictions or full erase: reconsider. Either issue a company device, or accept the narrower control that User Enrollment provides.
- Mixed fleets: do not run one policy for both. Define separate baselines per ownership model and document the differences.
Write the policy down
Whichever model you choose, a clear written policy is what turns a technical choice into something employees can accept. It should name the ownership model, the data the organization can access, the actions it can take, and what happens when someone leaves. AAMDM publishes a template-style Employee Privacy page you can adapt as a starting point; have your legal counsel review whatever you adopt.
AAMDM is an Apple MDM service for company-owned iPhone, iPad and Mac, currently in early access. Phase 1 is in development and includes profile-based enrollment. Apple Business Manager Automated Device Enrollment is planned for Phase 2. See the platform page for current scope.
Sources
- Apple Platform Deployment: Intro to device management
- Apple Platform Deployment: About device supervision
- Apple Platform Deployment: Device Enrollment and device management
- Apple Platform Deployment: Account-driven enrollment methods
- Apple Platform Deployment: Device management service User Enrollment information
- Apple Platform Deployment: Review device management restrictions
AAMDM is not affiliated with Apple Inc. Apple documentation changes over time; check the linked pages for the latest details.
Related articles
Questions about your rollout?
Tell us about your devices. We will answer plainly and say what is available now.