Self Enrollment


Mobile Device Manager Plus MSP provides an option for self enrollment, where the end users can enroll the devices by themselves. Follow the steps mentioned below to configure Self Enrollment settings. Ensure AD/Azure authentication is enabled for Self Enrollment to work. Self Enrollment process is the same for iOS, Android and Windows devices. User should access the following URL from the device which needs to be enrolled http://<server name:port number>/MDM/enroll.

Enabling Self Enrollment

The following steps needs to be performed to enable Self Enrollment:

  1. On the web console, navigate to Enrollment.

  2. Click Self Enrollment and click on Configure.

Change the Default Group for Self Enrollment

Follow the steps mentioned below to change the default group:

  1. On the web console, navigate to Enrollment

  2. Click Settings, and choose Groups for Enrolled Devices Under Self Enrollment

  3. Select the device type for which you wanted to change the default group and Click Edit Default Group button.
    All the groups available based on the operating system will be listed from which you can choose and save the default group.

Restrict Self Enrollment to specific AD groups

The self enrollment URL is usually shared across the organization and any device can be enrolled with the URL as it is device/ user independent. Thus, administrators may want to restrict self enrollment to specific AD groups. MDM allows you to restrict self enrollment only to specific AD groups, ensuring only specific devices get enrolled with MDM. Follow the steps specified below to restrict self enrollment:

  1. For the option Allow Self Enrollment for, select All AD Groups, to allow users in all the AD groups to self enroll the devices. You can optionally exclude specific groups as well by specifying the groups to be excluded the option of Self Enrollment.
  2. If you choose Selected AD Groups, only users of specific groups are allowed to self enroll the devices. Specify the groups to be allowed self enrollment.

Restrict Self Enrollment to specific number of devices

Self Enrollment allows users to enroll multiple devices without any admin intervention. While it reduces admin intervention, allowing users to enroll multiple devices could lead to security concerns in organizations and hence most organizations prefer restricting the number of devices that can be enrolled per user. MDM allows admins to regulate the number of devices that can be enrolled by the user.

While configuring Self enrollment, admins can enter the number of devices that can be enrolled per user under the option Number of devices per user. This will ensure the user can access the URL only to enroll the specified number of devices.

Auto assign device to Groups

The devices which are enrolled need to be added to groups. When devices are enrolled using Self Enrollment, we can choose the groups to which the devices will be added upon enrollment.

  1. Under Auto Assign Groups , enter the platform and owned by details along with the group to which the devices which satify these criteria be added.
  2. Once all the required groups have been added, click on Save to save the settings.

When a new device is enrolled into a specific group, all the profiles and apps distributed to that group will automatically be applied to the newly added device. This will ensure that all the policies and restrictions applied to the device as soon as it is enrolled.

If no groups are added while configuring Self Enrollment,the devices will be considered as unassigned. In this case, the devices will not be part of any group and will be considered as individual devices. Therefore, these devices will not receive any of the profiles or apps upon enrollment. Follow the steps given here to manually add the devices to Groups.

It is recommended to promote Self Enrollment to users by publishing/promoting the Self Enrollment URL, through the internal forums, blogs, mails to reach more users.

Self Enrollment process on iOS devices

  1. End user uses the self enrollment URL, to access the Enrollment window

  2. The following information should be filled in.

    1. E-mail

    2. User Name

    3. Password

    4. Owned By

  3. End user will be prompted to install the Mobile Device Manager Plus MSP profile. Click Continue to complete the profile installation.

As soon as the device gets enrolled, users will receive an App catalog from where they can install apps that are distributed through Mobile Device Manager Plus MSP. Administrators will also be notified that a new user has enrolled the device.

Self Enrollment process on Android devices

  1. Download ME MDM app, using the self enrollment URL.

  2. Once the download is successful, user will have to click on the downloaded ME MDM app to install it.

  3. After the installation is complete, user should open the app and click on On Premises.

  4. User should specify the following details

    1. Server name
    2. Server port
    3. E-mail
  5. User needs to authenticate using their Active Directory credentials.

  6. User has to follow the on-screen instructions to create a Work profile.

  7. User should accept the Terms and Conditions by clicking Continue

  8. User needs to enable Device Administrator on their mobile device and click Activate to complete enrollment.

ME MDM app icon will be listed on all enrolled mobile devices. By clicking the ME MDM app icon, MDM app opens and the end user can see the distributed Apps and associated profiles listed here. Profiles that are associated to the devices will be listed under Policies and Restrictions. Device Details will provide the complete information about the device.

In case of Knox devices, an exclusive Knox container is created within the mobile device. By clicking the Knox container icon, the user can access the corporate resources. Apps that are distributed by Mobile Device Manager Plus MSP for the Knox container can be accessed by clicking "Apps" icon within the container. By clicking the "Personal home" icon, the user can exit the Knox container and view the personal data and apps in the device.

Self Enrollment process on Windows devices

Users can follow the steps mentioned below on their windows mobile device, to get their mobile devices enrolled with the Mobile Device Manager Plus MSP  server. Users must access the self enrollment url and subsequently will be instructed to following the steps mentioned below:

  1. On the mobile device that needs to be enrolled, go to Settings.

  2. Click Company Apps (in Windows 8) / Workplace  (in Windows 8.1) / Accounts -> Access work or school (in Windows 10).

  3. Click Add Account (in Windows 8 and 8.1) / Enrol only in device management (in Windows 10).

  4. Enter the following details:

    1. Email Address: Specify the user email address.

    2. Password : Active Directory/Azure Password.

    3. User name : Active Directory/Azure User Name.

    4. Server : Specify the server name.

  5. Click Sign In.

  6. It can be seen that the account has been added. Click Done.

Users can see that they have successfully enrolled the windows device. Upon device enrollment, the ME MDM app will be available in the device. Distributed profiles and apps can be viewed from this app. Once the enrollment is completed, the admin will be notified.


See Also: Device Authentication,Enroll iOS Devices, Enroll Android Devices, Enroll KNOX Devices, Enroll Windows Devices,Customize ME MDM App
Copyright © 2021, ZOHO Corp. All Rights Reserved.