msnugget
Intune Now supports tvOS and visionOS
8 By Jannik Reinhard & Florian Salzmann · Published · Updated

Intune Now supports tvOS and visionOS

Intune has added automated device enrollment (ADE) support for tvOS and visionOS, covering Apple TV and Apple Vision Pro. Neither platform was supported in Intune at all before this. Both enrol without user affinity only, and require devices to be managed through Apple Business Manager or Apple School Manager.

What It Enables

Apple TV and Vision Pro can now be enrolled and managed in Intune for the first time. Devices purchased through ABM or ASM enrol automatically via Setup Assistant and receive device-targeted configuration policies over the air. No manual provisioning, no physical touches during deployment.

Enrolled devices appear under the Apple mobile tab alongside iOS and iPadOS devices in the admin centre. You can filter by platform. Both platforms support locked enrollment, Await Final Configuration, and custom configuration profiles uploaded via the settings catalog. Remote device actions match what is available for iOS/iPadOS ADE devices.

When to Use It

This is the right path for any corporate-owned Apple TV or Vision Pro purchased through ABM or ASM and managed as a shared or kiosk device. Conference room Apple TVs, digital signage, or Vision Pro units used for demos or specialised workflows are the obvious use cases. Zero-touch deployment works here: Devices can ship directly to a site and enrol on first boot.

Where the limitations are

There are real gaps you need to know about before rolling this out at scale.

Feature / CapabilitytvOSvisionOSUser affinity❌ Not supported❌ Not supportedCompliance policies❌ Not supported❌ Not supportedSetup Assistant screen customisation❌ Not supported❌ Not supportedCustom config profiles (settings catalog)✅ Supported✅ SupportedLocked enrollment✅ Supported✅ SupportedAwait Final Configuration✅ Supported✅ SupportedRemote device actions (same as iOS/iPadOS)✅ Supported✅ SupportedACME certificate protocol✅ tvOS 26+✅ visionOS 26+Hardware inventory (storage capacity)⚠️ Shows as 0 (known bug)⚠️ Shows as 0 (known bug)Microsoft Entra shared device mode❌ Not supported❌ Not supportedDEM accounts❌ Not supported❌ Not supportedBYOD / personal devices❌ Not supported❌ Not supported

No compliance policies means no Conditional Access enforcement based on device compliance state. If your security model depends on that signal, these platforms cannot participate in it. Do not expect feature parity with iOS/iPadOS ADE anytime soon.

OS requirements are firm: tvOS 26 and visionOS 26 are the minimums. No support for older OS versions.

Licensing

This requires Intune Plan 2 (part of the Microsoft Intune Suite or Microsoft 365 suite). Plan 1 is not sufficient for tvOS or visionOS management. Verify your licensing before building out a deployment process.

Recommendation

If you have Apple TVs or Vision Pro devices in your environment and are on Intune Plan 2, set this up. The absence of compliance policies is a notable limitation, but for kiosk and shared-use scenarios it rarely blocks deployment. Prioritise enabling locked enrollment and setting a default enrollment policy on your token from day one — skipping that step leads to devices enrolling without any policy assignment on first boot.

🔗 ADE overview for Apple mobile (Microsoft Learn) 🔗 Set up ADE for tvOS 🔗 Set up ADE for visionOS

Userless ADE for tvOS and visionOS closes a long-standing gap, but the missing compliance policy support means these platforms stay outside your Conditional Access perimeter for now.