If a device is institutionally owned, it is recommended you enroll it using on-device enrollment. Institutional and personal data on devices enrolled using on-device enrollment is stored together. Because this enrollment method is for institutionally owned devices, your management capabilities are more extensive than those for devices enrolled using User Enrollment. You can perform any management tasks that do not require device supervision on devices enrolled using on-device enrollment.
On-device enrollment prevents administrators from:
Clearing the device passcode or reducing the security of the device
Enforcing certain restrictions
Accessing any cellular features
Adding payloads that collect logs on the device
Adding any supervised restrictions to the user’s device