Mobile Device Management (MDM) Enrollment Checklist Template

An MDM rollout rarely fails on the first hundred devices. It stalls on the laptops that never come back to the office, the personal phones whose owners will not enrol, and the iPads that stop taking commands the week an Apple certificate expires.

This free MDM enrollment checklist is for IT teams and MSPs bringing Windows PCs, Macs, iPhones, iPads and Android devices under management, corporate-owned or personal. It runs once per enrolment wave: platform prerequisites, profiles by ownership, compliance and conditional access, a signed-off pilot, bulk enrolment and a straggler chase with a cut-off date. It ends by recording every Apple certificate and token expiry and booking the yearly renewal.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

Enrolment, the Build Standard and New-Hire Setup Are Three Jobs

Enrolment is the moment a device starts taking instructions from your MDM. Every app, setting and compliance rule written afterwards depends on that link. Get it wrong and your policies are aimed at devices that never receive them.

Three jobs are often run as one ticket and then fall apart. This checklist covers the first. The Laptop Provisioning & Imaging Checklist defines what a managed laptop gets once it is enrolled, and one new starter’s accounts and day-one handover sit in the new hire IT setup guide.

MDM enrollment

Is the device under management?

Covers: prerequisites, profiles, compliance, pilot, waves and renewals.

Runs: once per wave or new platform.

Output: an enrolment rate and a renewal date.

Laptop provisioning

What does a managed laptop get?

Covers: app set, security baseline, OS version, naming and spares.

Runs: when the standard, OS or hardware changes.

Output: a versioned build standard.

New-hire IT setup

Can this person work on day one?

Covers: accounts, access, the device handover and sign-in.

Runs: once per new starter.

Output: a person ready to work.

Ownership changes the rules more than platform does. A corporate device can be supervised, locked into management and wiped. On a personal device the organisation manages a work container only: Apple User Enrollment keeps work data on a separate volume, and an Android work profile leaves personal apps and usage private. Decide which model applies to each group before anyone is asked to enrol.

What the MDM Enrollment Checklist Covers

Seven phases take one enrolment wave from scope to renewal dates. The platforms, ownership and device source recorded in Phase 1 show only the tasks this wave needs, and a named approver signs off the pilot before bulk enrolment starts.

Phase 1

Phase 1: Scope the Wave & Name Owners

The answers on task 1 decide which later tasks appear. Task 5 appears only when personal devices are in scope.

  • Open the wave and record platforms, ownership, device source and approver — Windows, Apple or Android; corporate, personal or both; new devices or ones already in use; and who signs off the pilot
  • Export the device and user list for this wave — from purchase records and the asset register, with serial numbers, so progress is measured against a real number
  • Confirm every user in the wave has the licences enrolment needs — a missing MDM or identity licence shows up as a vague error on the user’s screen
  • Set the cut-off date after which unenrolled devices lose access — conditional access enforces it, and without a date the wave never ends
  • Write down what the organisation can and cannot see on personal devices — in plain words, agreed with HR, before anyone is asked to enrol
Phase 2

Phase 2: Platform Prerequisites

Each prerequisite appears only for the platforms in this wave. Enrolment restrictions apply to every wave.

  • Create or confirm the Apple MDM push certificate on a shared company account — it is valid for 365 days, and a personal Apple Account here becomes a problem the day that person leaves
  • Link Apple Business to the MDM and set the default device assignment — upload the server token and pick a service per device type, so new purchases arrive already pointed at your MDM
  • Register corporate Windows devices for Autopilot or plan device association — classic profiles need the hardware hash from the OEM, reseller or a CSV upload; device preparation does not
  • Bind the MDM to managed Google Play with an organisation account — every Android Enterprise mode, personal or corporate, depends on it
  • Set enrolment restrictions by platform, OS version and ownership — block personal devices where only corporate ones belong; restrictions stop honest mistakes, not attackers
Phase 3

Phase 3: Enrolment Profiles

Windows, Apple and Android profiles appear by platform. The two personal-device tasks appear only when the wave includes BYOD.

  • Create the Windows Autopilot profile or device preparation policy — Microsoft Entra join, users as standard accounts, and the device group that receives the build
  • Create the Automated Device Enrollment policy for Macs, iPhones and iPads — user affinity, Setup Assistant with modern authentication, supervision and locked enrolment
  • Set a default ADE policy before any new Apple device is switched on — a synced device with no policy fails enrolment, and most policy changes need a factory reset to apply
  • Create the Android Enterprise profile for each corporate use — fully managed for work-only phones, corporate-owned work profile where personal use is allowed, dedicated for kiosks
  • Set up account-driven User Enrollment for personal iPhones and iPads — work data sits on a separate volume, and the MDM can retire it but not wipe the phone
  • Set up the Android work profile for personal phones — IT manages the work apps; personal apps and usage stay private
Phase 4

Phase 4: Compliance & Conditional Access

  • Write one compliance policy per platform — minimum OS version, encryption, passcode and jailbreak or root detection, limited to what you will enforce
  • Mark devices with no compliance policy assigned as not compliant — Intune’s default treats them as compliant, which lets gaps through conditional access
  • Set actions for noncompliance with a grace period — email the user first and block later; three to seven days is a common starting point
  • Build the conditional access policy in report-only mode first — require a compliant device for the apps in scope, with emergency access accounts excluded
  • Check how long a device can go without checking in — Intune’s compliance status validity period is 30 days by default, after which the device counts as not compliant
Phase 5

Phase 5: Pilot & Go/No-Go

The consent walkthrough appears only for BYOD waves. The approver named in Phase 1 records a decision on task 5, and the checklist halts until they do.

  • Enrol a pilot group covering every platform and ownership type in the wave — IT staff plus a few volunteers per department, at least one of them remote
  • Time each pilot enrolment from power-on or sign-in to compliant — a slow or failing step is cheaper to fix for ten people than for five hundred
  • Walk a personal-device user through consent and unenrolment — check the privacy text matches what Phase 1 promised
  • Turn conditional access on for the pilot group and test a blocked device — the user should be told why and how to fix it, not just refused
  • Approve the move from pilot to bulk enrolment — the approver named in Phase 1 records Approved or Not approved; no wider wave starts until they do
Phase 6

Phase 6: Bulk Enrolment & Stragglers

The two existing-device tasks appear only when the wave includes devices already in use.

  • Send enrolment instructions by group with the cut-off date — one short page per platform and ownership type, with a screenshot of each screen
  • Add existing company Apple devices bought outside Apple Business — Apple Configurator adds them after an erase, and users can remove management for the first 30 days
  • Bring existing Windows PCs into management without a rebuild where possible — enrol PCs already joined to Microsoft Entra ID, and register hashes so the next reset runs through Autopilot
  • Reconcile enrolled devices against the wave list every week — by serial number, so duplicates, unknown devices and missing ones all show up
  • Chase stragglers by name through the service desk — a booked call with each person beats a third reminder email
  • Enforce conditional access for the whole wave on the cut-off date — with an exceptions list where each entry has an owner and an end date
Phase 7

Phase 7: Renewals & Hand Over

The two Apple tasks appear only when Apple devices are in scope. Task 3 books the renewal as a yearly recurring checklist.

  • Record the expiry dates of every Apple certificate and token — the push certificate, the Apple Business server token and any app content token
  • Move the Apple Account behind them to a monitored shared mailbox — if the person who created the server token leaves, the token has to be renewed
  • Book the yearly renewal run a month before the first expiry — as a recurring checklist owned by a team, not one person’s calendar reminder
  • Document how new devices enter management after this wave — default Apple assignment, Autopilot registration at purchase and zero-touch for Android
  • Close the wave with enrolment and compliance figures — enrolled against the wave list, open exceptions with end dates, and devices retired instead of enrolled

Enrolment Methods by Platform and Ownership

The table uses Microsoft Intune’s terms. Jamf Pro and other MDMs use the same Apple and Google mechanisms under their own names, such as Jamf’s PreStage enrollments for ADE.

DeviceEnrolment pathNeeds firstWhat IT controls
Corporate Windows PCWindows Autopilot, classic profile or device preparationHardware hash registration for classic profiles; Windows 11 and Microsoft Entra join for device preparationThe whole device, including wipe
Corporate MacAutomated Device EnrollmentPush certificate, Apple Business server token, device assigned to your MDM serverThe whole device; locked enrolment stops the user removing management
Corporate iPhone or iPadAutomated Device Enrollment, supervisedAs for the MacThe whole device; supervised devices have Activation Lock off by default
Personal iPhone or iPadAccount-driven User Enrollment (iOS and iPadOS 15 or later)Push certificate; Microsoft Authenticator on the deviceWork apps and accounts on a separate volume; retire, lock and sync, but no wipe
Corporate AndroidFully managed, corporate-owned work profile or dedicatedManaged Google Play binding; a factory-reset device; zero-touch needs devices bought from a reseller partnerThe whole device, or the work profile plus device-level rules
Personal AndroidWork profileManaged Google Play bindingThe work profile only

Two Apple items expire every year. Intune’s documentation gives the MDM push certificate 365 days, with a 30-day grace period after expiry, and says to renew it with the same Apple Account that created it. Creating a new certificate instead forces every Apple device to re-enrol, and Jamf gives Jamf Pro customers the same warning. Apple says external service tokens expire after one year, and Intune adds that the server token needs renewing when the account owner’s password changes or they leave. Apple Business Manager became Apple Business in April 2026; the token steps are the same under the new name.

Nothing on the Windows or Android side expires like this, but Microsoft says a device permanently leaving the organisation should always be deregistered from Autopilot.

Why Run MDM Enrolment in CheckFlow?

1

Only the tasks this wave needs

Conditional logic reads the platforms, ownership and device source on the first task. An Android BYOD wave never sees Autopilot or Apple token steps.

2

A pilot nobody can skip

The go/no-go goes to the approver picked in Phase 1, and Phase 6 waits for their decision. Pilot timings sit in a table inside the task, and the activity trail shows who did what and when.

3

Renewals that outlive staff changes

A yearly recurring schedule opens the renewal run a month before expiry, assigned to a group rather than one admin. Keep the expiry register as a data set every run reads.

CheckFlow’s IT onboarding software runs the per-person side, and the new hire IT setup checklist shows where an enrolled device meets a named starter. Conditional access works best with MFA already in place, so roll that out first with the MFA Rollout Checklist.

Once devices are enrolled, the Laptop Provisioning & Imaging Checklist decides what they receive and the Operating System Upgrade Rollout Checklist moves them to new OS versions. The IT Asset Management Checklist keeps the register Phase 6 reconciles against, and the Remote Work Security Checklist covers remote staff.

Frequently Asked Questions

What is MDM enrollment?

+

It is the step that connects a device to your mobile device management service so it can receive apps, settings and compliance rules, and be locked or wiped if lost. Corporate devices usually enrol during setup through Windows Autopilot, Apple Automated Device Enrollment or Android zero-touch. Personal devices enrol through a user-started flow that manages a work container only.

What is the difference between Windows Autopilot and Autopilot device preparation?

+

Classic Windows Autopilot needs each device registered by its hardware hash before setup, and supports pre-provisioning, self-deploying mode and hybrid join. Autopilot device preparation needs no registration, supports Windows 11 with Microsoft Entra join only, and adds a device to its group at enrolment. A registered device runs the classic profile unless it has been associated with your tenant through device preparation’s device association feature.

What happens if the Apple MDM push certificate expires?

+

Your MDM can no longer reach Apple devices, so policies, apps and remote actions stop arriving. Intune allows a 30-day grace period. Renew the existing certificate with the same Apple Account; a new certificate means every enrolled Mac, iPhone and iPad has to enrol again.

What can my employer see if I enrol my personal phone?

+

With Apple User Enrollment or an Android work profile, the organisation manages the work apps and accounts it installed and the settings it applies. It cannot see personal apps, photos or messages. On iPhone and iPad, Intune does not collect the serial number, phone number or IMEI, and IT can remove the work data but cannot wipe the phone.

How do you enrol devices that are already in use?

+

Windows PCs already joined to Microsoft Entra ID can often enrol in place, with corporate identifiers uploaded first if personal devices are blocked. Others can have their hardware hash uploaded so the next reset runs through Autopilot. Company iPhones and iPads bought outside Apple Business can be added with Apple Configurator after an erase. Corporate Android devices need a factory reset before they can be fully managed.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Get Every Device Enrolled, and Keep It That Way

Free trial — no credit card required.