Skip to content

Allow only AB Enrollments: Guide updates #52066

Description

@JordanMontgomery

Related user story

#51484

Task

articles/what-is-device-attestation.md — add the section the parent story asks for: Fleet's philosophy that SCEP is the default and "Allow only Apple Business enrollments" (+ "Use hardware attestation") is the opt-in path to force ACME; spell out what a customer gives up (manual enrollment; and in ACME-only mode: Intel Macs, macOS < 14, iPhones/iPads without an A11 Bionic or later chip or below iOS/iPadOS 16, BYOD, Silent-Migration) and that ineligible enrolled hosts age out at cert expiry.

State plainly that enabling both settings blocks non-attesting ABM hardware (Intel Macs, pre-A11 or pre-iOS-16 iPhones/iPads) from enrolling at all, and that enrolled hosts which are no longer eligible — any non-ABM host under AB-only, plus non-attesting ABM hardware under both — stop renewing and age out at certificate expiry. Apply the content-style guidance for article edits.

Also update the following guides which reference Apple MDM enrollment:

  • apple-mdm-setup.md - Turn on MDM on a host - Manual enroll is blocked when this setting is enabeld
  • enroll-byod-ios-ipados-hosts.md - this whole feature is blocked when this setting is on
  • enroll-personal-byod-ios-ipad-hosts-with-managed-apple-account.md - ADUE is completely disabled when this feature is on
  • what-is-apple-mdm.md - Has some notes about enrollment types. May need an update
  • apple-device-enrollment-program.md - Has a section on ADE vs manual. May need an update to call out that this can enforce only ADE enrollment

Condition of satisfaction

Guides updated

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

#g-apple-at-workProduct group focused on Apple devices~sub-taskA technical sub-task that is part of a story. (Not QA'd. Not estimated.)

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions