Device Enrollment
Device Enrollment is the mandatory process to register your company device so it can be managed securely. In this case, we use Microsoft Endpoint Manager (MEM) — also known as Intune — to manage and protect your device.
[!Note] New Agilers must wait for their corporate account credentials (provided on their first working day) and must not use personal accounts for device enrollment.
macOS
When you first turn on your Mac, macOS will guide you through the automated setup wizard. The device has been pre-configured for corporate enrollment via Apple's Automated Device Enrollment (ADE), which streamlines the onboarding process.
- Initial Personalization
Configure your preferred language, region, voice-over preferences, accessibility options, and other system preferences as needed. - Network Connection
Connect your Mac to a Wi-Fi network to enable automatic enrollment and policy deployment. - Sign in with Your Corporate Account
When prompted, log in using your company credentials (email and password). This will initiate the automated enrollment process. - Set Your Mac Password
Create a secure local password for your Mac account. You'll use this password to unlock your device. - Additional Personalization
Complete the setup by selecting your time zone, configuring Touch ID (if available), and choosing your preferred system theme (Light/Dark/Auto). - Automated Software Installation
A welcome screen will appear showing the Welcome to Agile Lab! enrollment status and the progress of automatic software installations.
➤ Wait for all installations to complete, then click "Proceed to Desktop" to continue. - Microsoft Company Portal Sign-In
The Company Portal // Portale Aziendale app will open automatically. Sign in using your company credentials to complete device registration. - Device Category Selection
When prompted to select a device category, choose: "Agilelab" - System Restart
After a few minutes, an Agile Lab notification will appear prompting you to restart your Mac.
➤ Click "Restart Now" to apply the corporate security policies. - Enable FileVault Disk Encryption
After restarting and logging in with your Mac password, you'll be prompted to enable FileVault encryption.
➤ Click "Enable Now" to secure your device. - Complete Company Portal Enrollment
Open the Company Portal // Portale Aziendale app again and sign in if needed. - Verify Compliance Status
Wait a few minutes for all policies to apply. If the device status remains "Not Compliant":
➤ Click the three dots (•••) menu in Company Portal
➤ Select "Check Status" to refresh the compliance state
Once the device shows as "Compliant", your Mac is fully enrolled and ready to use.
[!NOTE] When prompted by Keychain Access, select "Always Allow" instead of just "Allow". Otherwise, the prompt may reappear repeatedly.
Final Step
Please reach out to InternalIT/DeviceManager to:
- Confirm that your device has been correctly enrolled
- Request support in case of issues during setup or enrollment
--
Note: If Internal IT explicitly informs you that your device is not eligible for the automatic enrollment procedure, click here to access the legacy manual enrollment guide.
Windows
Important:
To avoid compliance issues during setup, we recommend disconnecting all USB devices (such as mouse, keyboard, docking stations, etc.) until the process is complete.
Initial Setup
Make sure your device is connected to the internet and has access to the Microsoft Store.
- Open the Start Menu
- Search for Microsoft Store, then open it
- In the store, search for Company Portal // Portale Aziendale
- Download and install the Company Portal // Portale Aziendale app
MEM Enrollment
- Launch the Company Portal // Portale Aziendale application
- Sign in using your company credentials
- Follow the on-screen instructions, making sure to accept all required permissions
- Once the process is complete, restart your laptop to allow corporate policies to apply properly
- Download and install the desktop version of Teams from this link
Final Step
Please reach out to InternalIT/DeviceManager to:
- Confirm that your device has been correctly enrolled
- Request support in case of issues during setup or enrollment
Android
Note: Even personal (BYOD) devices must be enrolled to access company data and apps.
Initial Setup
- Open your device’s default app store (Google Play Store).
- Search for and install Company Portal // Portale Aziendale.
MEM Enrollment
- Launch the Company Portal // Portale Aziendale app.
- Log in with your company credentials.
- Follow the on-screen instructions to enroll your device.
- After enrollment, you will have access to a company-managed Play Store, where you can install approved apps like Microsoft Teams, Outlook, etc.
- All apps in this store, including the Play Store itself, will be marked with a lock icon.
- If you need an app that is not available in the company store, please contact InternalIT / DeviceManager for assistance.
Please reach out to InternalIT/DeviceManager if you encounter any issues during enrollment or need further support.
iOS
Note: Even personal (BYOD) devices must be enrolled to access company data and apps.
Initial Setup
- Open the App Store on your iPhone.
- Search for and install Company Portal // Portale Aziendale.
MEM Enrollment
- Launch the Company Portal // Portale Aziendale app.
- Log in with your company credentials.
- Follow the on-screen instructions to complete enrollment.
- When prompted by the Select device and enrollment type screen, choose:
- Agile Lab owns this device if the device was provided by the company.
- Secure entire device if you are enrolling a personal iPhone.
- Once enrolled, Office 365 apps and other company apps will be protected and managed by Microsoft Endpoint Manager.
Please reach out to InternalIT / DeviceManager if you encounter any issues during enrollment or need further support.