Registering devices with Intune for management and policy enforcement
What is happening matches the documented behavior when Setup Assistant with modern authentication is used.
With User Affinity + Setup Assistant with modern authentication:
- Company Portal can be installed during enrollment.
- When the user reaches the Home screen, Intune automatically applies the correct app configuration policy to Company Portal.
- A separate Company Portal app configuration policy must not be deployed after enrollment, because it causes errors.
- If Company Portal is installed outside that enrollment flow, the app can behave like a normal user-driven enrollment experience and prompt for company access / management profile.
The key point is that for Setup Assistant with modern authentication, the documented path is to enable Company Portal installation from the enrollment policy itself, not just assign Company Portal later as a required VPP app.
The documentation states:
- For ADE with user affinity, Setup Assistant with modern authentication is the recommended authentication method.
- In that flow, there is an Install Company Portal setting in the enrollment policy.
- If VPP is used, Company Portal can be installed automatically without user Apple IDs.
- Intune then pushes the correct Company Portal configuration automatically during initial enrollment.
It also explicitly warns:
- Don’t deploy the Company Portal configuration manually to users during initial enrollment with Setup Assistant with modern authentication, because it conflicts with the configuration Intune sends.
- Don’t send a separate app configuration policy to Company Portal for iOS/iPadOS devices after enrolling with Setup Assistant with modern authentication, because it results in an error.
Based on the described test, the likely issue is that Company Portal was only deployed as a required VPP app, instead of being installed through the ADE enrollment policy’s Company Portal installation path. In that case, Company Portal is not getting the enrollment-time configuration that ties it to the existing ADE-managed device, so it falls back to prompting for user-driven enrollment.
Use this path instead:
- In Intune admin center, open the Apple enrollment policy for the ADE token.
- Configure Enroll with User Affinity.
- Select Setup Assistant with modern authentication.
- Set Install Company Portal to Yes.
- If available in that policy flow, select the VPP token so Company Portal installs without Apple ID prompts.
- Do not separately target Company Portal with a manual app configuration policy for that same modern-auth ADE scenario.
- Re-enroll the test device so the enrollment-time configuration is applied from the start.
For already enrolled devices, the documented approach is different: add Company Portal as a required device licensed app, create an app configuration policy for Company Portal as a device licensed app, and deploy that policy to the same device group as the enrollment policy. But that guidance is for the already enrolled devices scenario, not the initial Setup Assistant with modern authentication enrollment flow.
So this does not read like a general bug from the documented behavior. It reads like the device is missing the enrollment-time Company Portal installation/configuration path that modern auth expects.
The duplicate device names in Company Portal are not explained in the provided documentation, so no supported conclusion can be made from that symptom alone.
References: