Overview
Swif lets organizations enroll iPhones and iPads to distribute work apps, apply supported policies, and manage devices remotely.
Apple provides three enrollment types:
User Enrollment, designed for personally owned devices.
Device Enrollment, which provides broader management through a manually installed profile or work-account sign-in.
Automated Device Enrollment (ADE), which enrolls organization-owned devices during setup through Apple Business Manager.
Choose the enrollment type before distributing enrollment instructions. It determines the available management controls and privacy protections.
Choose an Enrollment Method
Enrollment type | Typical use | Swif enrollment path | Supervision on iPhone and iPad |
User Enrollment (BYOD) | Employee-owned devices used for work, also called BYOD | Enrollment SSO configured for BYOD | Does not enable supervision |
Device Enrollment | Devices that need broader management without ADE | Manual enrollment profile (QR Code), or Enrollment SSO configured for account-driven Device Enrollment | Does not enable supervision by itself |
Automated Device Enrollment (ADE) | Organization-owned devices requiring automated setup and stronger controls | Assign the device to Swif in Apple Business Manager and enroll during Setup Assistant | Automatically enables supervision on supported iOS/iPadOS versions |
Apple explains supervision separately from enrollment in About device supervision. A device already supervised through Apple Configurator can remain supervised when manually enrolled.
For personal devices, use the BYOD User Enrollment flow.
For organization-owned devices that require supervision and enrollment enforcement, use ADE.
Understand Enrollment SSO, ADDE, and ADE
Swif’s Enrollment SSO supports two account-driven enrollment configurations:
Swif configuration | Apple enrollment type | Configuration identifier |
BYOD | Account-driven User Enrollment |
|
Non-BYOD | Account-driven Device Enrollment, or ADDE |
|
Both can start with the user signing in to a work or school account. The configuration determines the enrollment type. See Set up Enrollment SSO for Apple devices.
ADDE and ADE are different:
ADDE: Account-Driven Device Enrollment. The user starts enrollment by signing in with a Managed Apple Account.
ADE: Automated Device Enrollment. The device is assigned to Swif through Apple Business Manager and enrolls during setup.
Apple Business Manager also supplies Managed Apple Accounts used for account-driven enrollment. Using one of these accounts does not automatically place a personal device into ADE.
Before You Begin
Confirm that:
The iPhone or iPad runs a version supported by Swif and the selected enrollment method.
The device has internet access to complete authentication, enrollment, and policy delivery.
The organization has configured Apple device management in Swif.
The administrator has selected the intended enrollment type and device ownership.
Any existing management enrollment has been reviewed before attempting enrollment with Swif.
For account-driven enrollment, prepare the employee’s Managed Apple Account and configure Enrollment SSO. For ADE, link Apple Business Manager to Swif and assign the device to the correct management server.
Option 1: User Enrollment for BYOD
How It Works
User Enrollment lets employees use their personal iPhone or iPad for work while limiting management to the organization’s accounts, settings, and information. Apple supports a smaller set of policies and restrictions for this enrollment type. See Apple: User Enrollment and device management.
A personal Apple Account can coexist with the Managed Apple Account used for work. Employees should follow the work-account enrollment flow rather than replacing their personal account to begin enrollment.
Enroll the Device
Configure Swif’s BYOD Enrollment SSO flow using the Enrollment SSO setup guide.
Give the employee their Managed Apple Account and enrollment instructions.
On the iPhone or iPad, open Settings > General > VPN & Device Management.
Select Sign In to Work or School Account.
Enter the Managed Apple Account and complete the authentication and enrollment prompts.
Confirm that the enrollment appears on the device and in Swif.
Settings labels can vary by OS version. If your organization uses Swif’s proxy-based discovery flow, follow any instruction to close the sign-in screen and repeat enrollment.
Management Limits
Only policies that support User Enrollment can apply.
Restrictions requiring supervision are unavailable through this enrollment type.
Management does not include the user’s personal Apple Account.
Full-device remote erase is unavailable through User Enrollment. Offboarding should remove managed work content and access instead. See Apple: Erase Apple devices.
Learn more at BYOD limitation.
Option 2: Device Enrollment
How It Works
Device Enrollment provides broader management than User Enrollment, including support for remote device erasure. Apple supports two ways to initiate it: installing an enrollment profile or signing in with a Managed Apple Account. Neither requires ADE. See Apple: Device Enrollment and device management.
Manually enrolling an iPhone or iPad does not automatically supervise it. Policies that require supervision still need a supervised device.
Method A: Install an Enrollment Profile
Obtain the iOS/iPadOS enrollment QR code or link from Swif’s installer download page.
Open the enrollment link on the device and complete the enrollment prompts.
Allow the enrollment profile to download.
Open Settings and select Profile Downloaded or Enroll in [organization name].
Select Install, then complete the passcode and management approval prompts.
Verify enrollment in Settings > General > VPN & Device Management and in Swif.
Downloading the profile does not install it. Apple removes an uninstalled downloaded profile after eight minutes. If it expires, download it again and finish installation. See Apple: Install a configuration profile.
Method B: Use Account-Driven Device Enrollment
Configure Swif’s non-BYOD Enrollment SSO flow. The user then follows the work-account sign-in steps described above, using the organization’s Managed Apple Account.
This flow uses ADDE. It does not become ADE merely because the account was created in Apple Business Manager. Follow Swif’s Enrollment SSO configuration guide.
Management Considerations
Explain the broader management permissions before enrollment, especially if the device is personally owned. User Enrollment’s full-device erase restriction does not apply to Device Enrollment.
If the user removes the enrollment profile, the profiles and settings associated with that enrollment are removed, along with managed apps as described by Apple’s enrollment rules. Review the consequences before unenrolling a device.
Option 3: Automated Device Enrollment Through Apple Business Manager
How It Works
ADE connects a device’s organizational assignment in Apple Business Manager to Swif. During Setup Assistant, the iPhone or iPad contacts Apple and receives the management enrollment assigned to it.
ADE is intended for organization-owned devices. It supports automatic supervision, additional management restrictions, and an option to prevent users from removing the MDM enrollment profile. See Apple: Automated Device Enrollment.
Prepare Swif and Apple Business Manager
Link the organization’s Apple Business Manager account to Swif.
Confirm that the iPhone or iPad is listed in Apple Business Manager.
Assign the device to the Swif management server.
Confirm that the assignment has synchronized to Swif.
Configure the intended enrollment settings, policies, and app assignments before setup.
For the connection procedure, see Link Your Apple Business Manager Account With Swif.
Enroll During Setup
Start the new device at the Hello screen.
Connect it to the internet and continue through Setup Assistant.
Complete the organization’s Remote Management enrollment prompts.
Finish setup and allow assigned policies and apps to install.
Verify the device’s enrollment and supervision status.
For an already configured device, plan the appropriate re-enrollment or migration procedure before erasing it. The steps above describe enrollment during initial setup; changing an assignment alone is not proof that an existing device has completed enrollment into Swif.
Verify Enrollment
On the iPhone or iPad
Open Settings > General > VPN & Device Management and review the installed management enrollment.
For supervised devices, Settings also displays a supervision message. An installed management profile alone does not prove that an iPhone or iPad is supervised.
In Swif
Confirm that:
The device appears in the intended organization.
The employee and ownership assignment are correct.
The enrollment is active and the device has checked in.
Assigned policies report their expected results.
Required apps have installed or are awaiting user approval.
Use the enrollment configuration and device state to verify the enrollment type. A BYOD ownership label alone does not convert Device Enrollment into User Enrollment.
Install Work Apps
Swif supports managed app distribution through Apple Business Manager’s Apps and Books, also referred to as VPP.
After configuring the app-distribution connection, acquire the required licenses and assign the apps in Swif. On unsupervised devices, including BYOD devices, installation may require user confirmation. Supervised devices support silent managed app installation where applicable.
Managed Apple Accounts cannot acquire paid or free App Store content directly. Organizations should distribute work apps through managed distribution. A personal account used for personal App Store purchases is separate from the work account used for enrollment. See Apple: Service access with Managed Apple Accounts.
Troubleshooting
The Profile Downloaded, but the Device Is Missing in Swif
Check that the user completed Install in Settings and accepted all management prompts. If the downloaded profile expired, download it again. Confirm internet access and review any error shown during enrollment.
Work-Account Sign-In Does Not Complete
Check the Managed Apple Account, authentication requirements, and Enrollment SSO discovery configuration. Confirm that the domain routes the user to the intended BYOD or non-BYOD flow. Follow any retry instruction from Swif’s proxy-based enrollment process.
A Policy Does Not Apply
Check the policy’s minimum OS version, supported enrollment types, and supervision requirement. Successful enrollment does not make every Apple policy available.
Remote Management Does Not Appear During ADE Setup
Confirm that the device is registered in Apple Business Manager, assigned to Swif, and has synchronized with the correct enrollment settings. Check internet access during activation. Review the existing enrollment state if the device has already completed setup.
An App Does Not Install
Check available app licenses, assignment, OS compatibility, and any installation prompt on the device. If the user is trying to download an app directly with a Managed Apple Account, use managed app distribution instead.
A BYOD Device Appears as a New Record After Re-enrollment
User Enrollment (BYOD) uses an enrollment-specific identifier. After unenrollment and a new enrollment, Swif can display a new device ID. Confirm the active record and its assignments before removing any old inventory entry.
If enrollment still fails, contact Swif Support with the device’s OS version, enrollment method, and exact error message. Do not include account passwords or authentication codes.


