# How to enroll your first iOS device? Last updated: July 24, 2026 Enroll your first iOS device into Mobile Device Manager Plus by choosing an enrollment method for your use case: unsupervised for BYOD devices using QR codes or self-enrollment, or supervised for corporate-owned devices using Automated Device Enrollment or Apple Configurator. ## Enrolling your first iOS device in ME MDM Device enrollment is the process of registering and configuring devices to be managed centrally within a mobile device management system. ## Understanding management of iOS | iOS Management Mode | Scenarios | Enrollment Methods | |---|---|---| | Personal device management (Device Enrolment or User Enrolment) (Unsupervised) | • Used for employee-owned devices or BYOD; • Work apps and data are protected separately from personal apps; • No control over personal apps and data | 1. Using a direct QR Code or Enrollment link; 2. Self Enrollment; 3. User invitations | | Company-owned device management (Device enrolment or Automated device enrolment) (supervised) | • Used for Company-owned devices; • Devices deployed in kiosk mode; dedicated devices locked down to run only work applications; • Company-owned devices used for both work and personal purposes | 1. Automated Device Enrollment (ABM/ASM); 2. Using Apple Configurator App in iphone/mac | To learn more about the different enrolment methods, please refer to the [Help Guide](https://www.manageengine.com/mobile-device-management/help/enrollment/device_enrollment.html). ## Evaluating iOS device management with Personal device enrolment This guide walks through quickly enrolling the first iOS device using a QR Code to initiate your MDM evaluation. For comprehensive device management features such as Kiosk mode or app lockdown, alternative enrollment methods are available as outlined in the preceding sections. ![How to enroll your first iOS device? illustration 3](https://cdn.manageengine.com/mobile-device-management/images/enrollios1.png) ![How to enroll your first iOS device? illustration 4](https://cdn.manageengine.com/mobile-device-management/images/enrollios2.png) ## Pre-requisites 1. **APNs:** Apple Push Notifications (APNS) is mandatory to enroll an iOS device. MDM utilizes APNs for continuous communication with devices. To know more about how to configure an APNs Certificate, please refer to [Create APNs Certificate](https://www.manageengine.com/mobile-device-management/help/enrollment/mdm_creating_apns_certificate.html). If you are using the MDM Cloud version, configure the APNs Certificate and skip the below steps and proceed directly to the enrollment steps to register your first iOS device. 2. **On-Premise Version:** 1. **Firewall and Proxy Rules:** To ensure proper functionality, the MDM (Mobile Device Management) server needs to connect to essential services such as Google Cloud Messaging. If you are utilizing a proxy or firewall, it is imperative to configure these settings within the MDM console. 2. **MDM server address:** Devices need to access the server address even from the internet for remote management. You can configure NAT settings so your public domain directs to the MDM server and port. Alternatively, use the default address for evaluation. You can set up NAT settings later when you plan on enrolling more devices. ![How to enroll your first iOS device? illustration 5](https://cdn.manageengine.com/mobile-device-management/images/enrollandroid3.png) Ensure the device is part of the server network during testing. To know more about the MDM On-Premise, please visit the [Help Guide](https://www.manageengine.com/mobile-device-management/help/configuring_mobile_device_manager/configuring_mdmp_on_premises.html). ## Methods to enroll the first iOS device [Embed code](https://workdrive.zohoexternal.com/embed/0f11t894cedbdb8e84156874c2cdf16cd63ae?toolbar=false&appearance=light&themecolor=green) - **Download and install MDM Profile:** 1. Scan QR Code using the camera to download the MDM profile in Safari Browser. 2. User needs to allow the download of the configuration profile. The user will receive a notification of successful download. 3. Users need to open Settings on the iOS device and install the MDM profile from the downloaded section. Once the MDM profile is installed, users will receive a notification. - **Self Service app (previously ME MDM app):** Once the MDM profile is installed, users will be prompted to install the ManageEngine MDM Self Service app (previously ManageEngine MDM application). Within the Self Service app (previously ME MDM app), users can access organization announcements, compliance and policy details, shared documents, and organization-managed work applications in the App Catalog, which they can view or install. ![How to enroll your first iOS device? illustration 6](https://cdn.manageengine.com/mobile-device-management/images/enrollios3.png) - **View and Manage Enrolled Device:** To access enrolled devices, users can navigate to the Devices section within the Enrollment Tab in the MDM Console, where the status of each device will be displayed as "Enrolled". Furthermore, users can execute actions on enrolled devices not only from the Devices section within the Enrollment Tab but also from the Inventory Tab and Management Tab. ## What's Next? ### Configure Profile and Policies After installing the MDM profile on the device, users can customize profiles and policies to utilize the advantages of device enrollment. This includes establishing passcode regulations, implementing restrictions on data sharing between work and personal apps, configuring WiFi and VPN settings, and other measures to manage the device and enhance security. To learn more about Configuring Profiles and Policies, please refer to [Device Restrictions and Configurations](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_profile_management.html). ### Distribute Work Applications Following successful device enrollment, users can commence the distribution of apps to devices acquired from Apple Business/School Manager purchases, custom apps, and enterprise apps. To learn about App Distribution, please visit [App Management](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_app_management.html). **If you are encountering errors, please refer to these [troubleshooting](https://www.manageengine.com/mobile-device-management/knowledge-base.html?apple-enrollment-device) documents.** ## Frequently asked questions ### Which enrollment method should I use for a personal (BYOD) iOS device? Use unsupervised personal device management (Device Enrollment or User Enrollment) via a direct QR code or enrollment link, Self Enrollment, or user invitations. This keeps work apps and data protected separately from personal apps. ### Which enrollment method should I use for a company-owned iOS device? Use supervised company-owned device management through Automated Device Enrollment (ABM/ASM) or the Apple Configurator app. Supervised enrollment supports kiosk-mode deployments where devices are locked down to run only work applications. ### Can a company-owned iOS device be used for both work and personal purposes? Yes, supervised company-owned device management also supports devices used for both work and personal purposes, in addition to dedicated single-purpose deployments.