# iOS/iPadOS Self Enrollment ## Steps to enroll the iOS/iPadOS devices: 1. Open the Safari browser on your iOS or iPadOS device. Scan the QR code using the built-in camera. Alternatively you can enter the Self Enrollment URL provided by your organization in the Safari browser. **Note:** If a security delay or review occurs during device enrollment for Stolen Device Protection, pause further enrollment steps until the review is complete. Allow the system to automatically resolve the review, which may take from a few minutes to several hours. Only proceed with enrollment once the security review has been successfully cleared to avoid additional delays or restrictions. | | | | | | |---|---|---|---|---| | ![](https://www.manageengine.com/mobile-device-management/help/images/ios_enroll1.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/ios_enroll2.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/ios_enroll3.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/ios_enroll4.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/ios_enroll5.png) | | ![](https://www.manageengine.com/mobile-device-management/help/images/ios_enroll6.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/ios_enroll7.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/ios_enroll8.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/ios_enroll9.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/ios_enroll10.png) | 2. Users will be prompted to authenticate. Enter the required credentials. 3. Once authenticated, accept the Terms and Conditions. 4. Download the MDM enrollment profile. A pop-up will appear asking for permission to download the profile; tap **Allow** to proceed. 5. After the profile has been downloaded, navigate to **Settings > General > Device Management** to install the profile. 6. Tap **Install** in the upper-right corner, and enter your device passcode if prompted to complete the installation process. 7. Once the MDM profile is installed, the device is automatically enrolled in MDM. 8. If the admin has configured the ME MDM app and other work apps, they will be pushed to the device automatically. It may take a few minutes to complete. 9. If the admin configured any policies and configurations, MDM will apply all relevant policies and configurations to the device after enrollment. ## MacOS Self Enrollment 1. To enroll a Mac device, first access the Self Enrollment URL. Open a web browser and enter the provided URL. 2. Click on **Continue with Microsoft Entra ID** and authenticate yourself by providing the required credentials. 3. Click on **Download MDM Profile** and allow the profile download when prompted. | | | |---|---| | ![](https://www.manageengine.com/mobile-device-management/help/images/enroll_mac1.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/enroll_mac2.png) | | ![](https://www.manageengine.com/mobile-device-management/help/images/enroll_mac3.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/enroll_mac4.png) | | ![](https://www.manageengine.com/mobile-device-management/help/images/enroll_mac5.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/enroll_mac6.png) | | ![](https://www.manageengine.com/mobile-device-management/help/images/enroll_mac7.png) | | 4. After the profile has been downloaded, navigate to **Settings -> General -> Device Management**. Double click on the downloaded profile to install. 5. Click on **Enrol** to enroll the device. Once the MDM profile is installed successfully, the device will automatically be enrolled in MDM. ## Troubleshooting Tips If users experience issues during the Self Enrollment process, here are some troubleshooting steps: ## iOS Device Self Enrollment - **Authentication Failure:** Ensure that the correct username, password, or Managed Apple ID is entered during the enrollment process. Confirm that the user has the necessary permissions to enroll their iOS device through self-enrollment. This helps prevent enrollment issues and ensures a smooth onboarding experience while adhering to organizational policies. - **Unable to Install the Profile:** Check if the iOS device is running the latest version of iOS and meets the organization's specified requirements for enrollment. Ensure that the device has a stable internet connection and sufficient storage space available for downloading the necessary MDM profile and applications. Verifying these prerequisites facilitates a smooth enrollment process and ensures that the device can properly receive and apply the required configurations and policies. ## What's Next? ## Apple Enrollment For step-by-step guidance on enrolling Apple devices—such as iOS, iPadOS, and macOS—refer to our [Apple Enrollment](https://www.manageengine.com/mobile-device-management/help/enrollment/enroll_ios_devices.html) Guide. It covers the enrollment processes, configuration settings, and best practices for efficiently managing Apple devices within your organization. ## Configure Profiles and Policies Once the MDM profile is installed, admins can configure a variety of profiles and policies to enhance device security and functionality. For detailed instructions on these configurations, visit the [Device Restrictions and Configurations](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_profile_management.html) section. ## Distribute Work Applications After enrollment, administrators can distribute work applications silently via the app repository. This includes apps from Apple Business/School Manager, custom apps, and enterprise applications. For more details, refer to our [App Management](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_app_management.html) section. ## FAQs ### 1. How do I enable location tracking for a self-enrolled iOS device in MDM? Location tracking for iOS devices is provided by the ME MDM app. This capability is available for devices enrolled via any method, including self-enrollment. To ensure location tracking is working, verify the following prerequisites: 1. Check that the ME MDM app is installed on the device. If it is not available, enable ME MDM app distribution from **Enrollment > Apple > ME MDM Settings** on the MDM console. 2. Verify that location tracking is allowed for your organization from **Admin > Device Privacy** settings. This setting is typically configured by your administrator or security admin. 3. Check the location tracking settings from **Inventory**. 4. Ensure the device is not showing any location tracking errors, such as ME MDM app permission requirements. ### 2. How can I reset the one-hour enrollment block timer for a failed iPhone BYOD Face ID attempt? The one-hour enrollment block is caused by Apple’s Stolen Device Protection, which prevents changes to critical security settings (including MDM profile installation) for one hour from an unfamiliar location. This timer cannot be reset manually. Either wait one hour (a notification appears when enrollment can continue), or disable Stolen Device Protection via **Settings > Face ID & Passcode > Stolen Device Protection** and turn it off.