Jump to content

Azure Logon with iPad (Suppressing Setup Assistant and PIN) Intune EndPoint Manager


Recommended Posts

Posted

Afternoon,

 

For reasons, I've decided to try and configure the iPads that are enrolled into Intune Endpoint Manager to have user accounts via Azure AAD. This is all now setup with federated domain within Apple School Manager.

 

My last hurdle it seems is, each new logon to a device, first askes for your email/password (thats great), but then the setup assistant kicks in and asks for Language/Location and to setup a PIN. If nothing else, I want to suppress the PIN requirement.

 

See attached screenshots.

 

Has anyone any experience with Shared iPads in Schools using user profiles on Intune MDM?

 

Passcode.jpgCountry.jpgLanguage.jpgPassword.jpgProfile Screen.jpg

Posted

Pin requirement is part of Apple's Shared iPad, you can not get around it, iPads are not Windows PC's and Shared iPad is NOT designed for lots of different users. Users need to turn on Location Services when they enrol but you can turn off the country selection.

 

If I'm wrong tell me but I hope you seeing this when a new user logs in for the first time?

 

Also, bear in mind currently...

  • Signing-out of one Office app also signs you out of the others, but leaves OneDrive, Outlook and Authenticator logged-in.

  • Users need to sign-in to one Microsoft app normally first, which then stores their credentials and removes the need to enter credentials when signing-in to the other MS apps. It does not yet work with MS Websites yet

 

 

 

 

 

 


 

 

 

 

 

 

Posted

I was trying to set this up (albeit with a focus on SCEP and user certificates issued by our on prem PKI) only yesterday, and even though it's not what i was looking at, i never got a request for ping when setting up an iPad as a shared iPad. I'm also using AAD for logins.

 

When you provisioned your devices what profile type did you use per chance? I was doing without user affinity initially, and while i got asked for language etc. PIN was never one of the options it required from me.

Posted
I was trying to set this up (albeit with a focus on SCEP and user certificates issued by our on prem PKI) only yesterday, and even though it's not what i was looking at, i never got a request for ping when setting up an iPad as a shared iPad. I'm also using AAD for logins.

When you provisioned your devices what profile type did you use per chance? I was doing without user affinity initially, and while i got asked for language etc. PIN was never one of the options it required from me.

When you say config profile do you mean this screen (see attached). Yes it was set to "Enroll without User Affinity"

20231116 config profile.png

Posted

Leave the setting "Maximum seconds after screen lock before password is required" blank and it probably wont' ask you for the pin code to be set anymore.

 

I wasn't setting that setting at all in my testing, and i never got asked for a pin.

Posted

So after spending the day testing etc. I settled on using the Temporary Session Option. This way the device when powered on is in Guest Mode. They reach the homepage, and all published apps such as MS Teams are already present and they just sign in with their email credentials.

 

Then either after a timeout or the next person picks up the device they sign in with guest mode and in testing, Apps like MS Teams prompt for logon again which resolves the initial issue I was having of credentials being too persistent between classes. Also when logging in as guest, there is no Language/Location or Pin setup screen prompts, just straight in. :)

 

Guest.png

Posted
Guest mode always seemed to fill up the iPad's storage no matter what settings I used but only tried it on a couple. it was meant to clear them but never did

 

That'll be interesting to monitor, because you would think it would remain static in remaining space as it warns you on use that all data will not be retained.

Posted
That'll be interesting to monitor, because you would think it would remain static in remaining space as it warns you on use that all data will not be retained.

 

Saw this when I was searching for it again so might be fixed

 

What’s new for enterprise in iPadOS 17

 

  • Temporary session: A Shared iPad configured for temporary sessions now honors the QuotaSize key for the temporary user. This key helps reserve sufficient space to install apps or other media while a user is signed in.

https://support.apple.com/en-jo/HT213891

Posted
That'll be interesting to monitor, because you would think it would remain static in remaining space as it warns you on use that all data will not be retained.

While this works you are effectively now using iPads as netbooks, users can't leave any data on the device when they sign out as it's deleted...

Posted

Thats fine. We are a Microsoft 365 school so all data should be saved to OneDrive anyway.

 

The iPads are just in iPad carts, so from one lesson to the next a student will pick up a iPad at random, they are not assigned to particular students so once again any data on a device is surplus.

Posted
Quick update, had a slight wobble on Friday evening re-enrolling the iPads to pick up the new profile. When you log in as a guest only user, you only get allocated 2GB of Guest storage. This wasn't enough for the assigned apps to install into. However it seems to have managed to deploy over the weekend successfully. You can either sign out and sign back in to gain the 2gb of storage again, or it might be the apps continue to push out and install whilst the device is on the lock screen / sleep.
Posted (edited)

oh shared ipads. I had no end of pain and suffering with this. In the end we managed to get more funds so I could 1-1 but when we had shared trolley they would fill up without warning (blocking access), unconfigurable screen timeouts, spotty SSO to 365 with authenticator (it was preview back then to be fair), app installation when each shared user logged in (this was fun at the start of a class and hogged out the bandwidth from a couple of APs). IOS updates would fail and also download to user areas before failing, filling up the unknown size user profile. Wait until your user forgets their PIN and you have to reset it, hint this is not the same as resetting the lock PIN in the MDM.

 

It may well be better now but it was awful when I tried.

Edited by KK20

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...