Support self-enrollment using directory service credentials
Provide for directory service (AD et al) user authentication information to be used for self-enrollment of devices. The authenticated user information should also be written to the device record so we know that user is tied to the enrolled device.

Please see our authentication options under enrollments. If you have a particular use case that is not supported by our current implementation, please create a new ticket with specific information so that we may keep track of the request.
-
Per Olofsson commented
SAML enrollment solves this for us.
-
Andy Semak commented
I’d like to echo Per’s comments above. As part of our agreement with the network provider, we require users to be identifiable and AD authenticated enroll would help us greatly as we move towards local accounts.
-
Per Olofsson commented
We need AD authenticated enroll so that the user creation dialog is pre-populated with the user's verified AD credentials, as we require the user's local account to match their directory account. The chance of users manually getting their usernames and passwords correct is a lot less than 100% :)