You can enroll personally owned iPhone, iPad, and Apple Vision Pro devices with Jamf Pro using Apple's account-driven User Enrollment method. Account-driven User Enrollment is designed for Bring Your Own Device (BYOD) deployments. It logically and transparently separates an end user's personal data from institutionally managed applications and accounts. Account-driven User Enrollment establishes strong privacy safeguards via the operating system that ensure organizations are only able to manage enterprise applications and accounts while personal applications and unique device identifiers are inaccessible to an MDM server. For more information, see User Enrollment and MDM in Apple Platform Deployment.
User Enrollment requires Managed Apple Accounts. End users must sign in to iCloud using a Managed Apple Account during enrollment. Managed Apple Accounts are owned and managed by an organization using Apple Business. They can exist on the device at the same time as the end user's personal Apple ID.
After devices are enrolled and managed, you can achieve Trusted Access outcomes by making device management a required step to access critical applications and services on the devices, such as email. Organizational data and applications can be secured at rest while on devices. Additional management settings can apply data loss prevention (DLP) controls to prevent sharing data from managed apps to unmanaged apps.
Network traffic from managed applications and accounts can also be secured through managed networking and Jamf Connect Zero Trust Network Access (ZTNA) so that personal data continues to stay private as users are in control of all other networking traffic from the device to the general internet. Users can confidently continue to be in control of the network traffic from personal applications and services. They can also use privacy-focused network anonymization technologies like iCloud Private Relay.
Trusted Access outcomes are achieved by leveraging native Apple frameworks, such as per-app networking, which allows for network traffic from managed applications and accounts—and only that traffic—to be secured by the Jamf Trust app. For more information, see User Enrollment and per-app networking in Apple Platform Deployment.
You can apply additional configuration profile payloads and restrictions to personal devices managed with User Enrollment. For more information, see User Enrollment MDM information in Apple Platform Deployment.