Academy
Technical · Course T3

Lesson 4 of 4

BYOD profile enrollment

6 min read
In this lesson you'll learn to
  • Enroll a personal iOS device via QR or link
  • Explain what unsupervised management can and cannot do
  • Choose between ABM and profile enrollment for a given scenario

Not every iPhone arrives through the channel. Employees bring their own, execs buy at retail, pilots start on whatever's in the drawer. The profile path manages those — with limits everyone should agree to up front.

The flow

  1. In WeGuard, open the unsupervised iPhone & iPad policy and generate its enrollment QR code / link (same policy-table QR action you know from Android).
  2. The user scans the QR or opens the link on the device.
  3. Safari downloads the MDM profile; the user finishes in Settings, where iOS asks them to install the downloaded profile and approve management.
  4. The device appears in Devices as managed — unsupervised.

Two-minute flow, no factory reset, personal data untouched.

The honest limits

Everything about this path follows from one fact: the user installed the profile, so the user can remove it — Settings → remove profile, management gone. Alongside that:

  • Restriction depth is the unsupervised set — the supervised-only controls (the deepest lockdowns) aren't available.
  • Corporate data should therefore ride managed apps and accounts that vanish when the profile is removed — assume the profile is temporary.

Position it accordingly: profile enrollment is the right answer for personal devices touching corporate resources, and the wrong answer for corporate-owned hardware, which belongs in ABM.

Choosing the path

ScenarioPath
Company-bought fleet from Apple/resellerABM automated (supervised)
Employee's personal iPhone needs mail + appsProfile enrollment
Retail-bought device that must be supervisedBring it into ABM via Apple's device-onboarding tooling, then automated enrollment
Short pilot on borrowed hardwareProfile enrollment — fastest on, fastest off

One sentence for customer conversations: channel devices get supervised management, personal devices get respectful management — and WeGuard does both from the same console.

Knowledge check
1. How does a BYOD iPhone get enrolled?
2. What can the user of a profile-enrolled (unsupervised) device always do?
3. A customer's exec bought an iPhone at a retail store and wants it fully supervised. What do you tell them?