Restricted User Initiated Enrollments to Specific Group

DBrowning
Valued Contributor II

Looking to limit UIE to a specific group via SSO and/or Cloud Identity Provider (Azure).

Currently we have SSO configured via Okta and CIP setup with Azure.  Anyone got ideas on how to do the restrictions?  I've tried adding the group under Access, but it still allows all users.  

1 ACCEPTED SOLUTION

DBrowning
Valued Contributor II

Think I found my issue.  I had a setting incorrect under SSO.

View solution in original post

4 REPLIES 4

RaxiaDK
Contributor II

You have to remove the all user access

set all to no

DBrowning
Valued Contributor II

Think I found my issue.  I had a setting incorrect under SSO.

Can you please elaborate on what you had to change in the SSO settings? I'm currently looking for a solution to the same issue you had. I see you can specify Enrollment Access under the SSO settings and apply to a certain group there, but it looks like this affects SSO Self Service logins on macOS too and we only want to limit iOS enrollments.

DBrowning
Valued Contributor II

I had incorrectly assigned a group under the enrollment access.  I just tried an account that is not in our allowed enrollment group and Self Service on macOS worked fine.