Skip to main content
Solved

Restricted User Initiated Enrollments to Specific Group

  • April 29, 2024
  • 4 replies
  • 50 views

DBrowning
Forum|alt.badge.img+24

Looking to limit UIE to a specific group via SSO and/or Cloud Identity Provider (Azure).

Currently we have SSO configured via Okta and CIP setup with Azure.  Anyone got ideas on how to do the restrictions?  I've tried adding the group under Access, but it still allows all users.  

Best answer by DBrowning

You have to remove the all user access

set all to no


Think I found my issue.  I had a setting incorrect under SSO.

4 replies

RaxiaDK
Forum|alt.badge.img+10
  • Valued Contributor
  • April 29, 2024

You have to remove the all user access

set all to no


DBrowning
Forum|alt.badge.img+24
  • Author
  • Esteemed Contributor
  • Answer
  • April 29, 2024

You have to remove the all user access

set all to no


Think I found my issue.  I had a setting incorrect under SSO.


Jay_007
Forum|alt.badge.img+7
  • Valued Contributor
  • May 26, 2024

Think I found my issue.  I had a setting incorrect under SSO.


Can you please elaborate on what you had to change in the SSO settings? I'm currently looking for a solution to the same issue you had. I see you can specify Enrollment Access under the SSO settings and apply to a certain group there, but it looks like this affects SSO Self Service logins on macOS too and we only want to limit iOS enrollments.


DBrowning
Forum|alt.badge.img+24
  • Author
  • Esteemed Contributor
  • May 28, 2024

Can you please elaborate on what you had to change in the SSO settings? I'm currently looking for a solution to the same issue you had. I see you can specify Enrollment Access under the SSO settings and apply to a certain group there, but it looks like this affects SSO Self Service logins on macOS too and we only want to limit iOS enrollments.


I had incorrectly assigned a group under the enrollment access.  I just tried an account that is not in our allowed enrollment group and Self Service on macOS worked fine.