<!--
{
  "documentType" : "article",
  "framework" : "DeviceManagement",
  "identifier" : "/documentation/DeviceManagement/authenticating-through-web-views",
  "metadataVersion" : "0.1.0",
  "role" : "article",
  "title" : "Authenticating through web views"
}
-->

# Authenticating through web views

Use your own custom web interfaces to authenticate users.

## Discussion

Beginning with iOS 13 and macOS 10.15, you can present a custom web interface to the user during Automated Device Enrollment. The `configuration_web_url` key in the Automated Device Enrollment [`Profile`](/documentation/DeviceManagement/Profile) defines the value of a custom URL to be presented in a web view and also supports the <doc://com.apple.documentation/documentation/AuthenticationServices/ASWebAuthenticationSession>. Use this key to define your own UI for authentication, with your preferred authentication method. After authenticating the user, the device management (MDM) enrollment profile downloads to their device.

On the initial page load of the `configuration_web_url`:

- The URL must have an `https` scheme and is a `GET` request.
- Use the certificates in the `AnchorCerts` property of the Automated Device Enrollment [`Profile`](/documentation/DeviceManagement/Profile) to pin the host to the certificates.
- A custom header `x-apple-aspen-deviceinfo` is appended to the request. It contains a base64 encoding of a Cryptographic Message Syntax (CMS) envelope that contains a property list file with device attributes. This is the same information, in the same format, as provided in the initial `POST` request with token-based ADE enrollments.

On subsequent page loads:

- If navigation requires trust evaluation using certificates not normally trusted by the system, they must be included in `AnchorCerts`.
- The user interacts with the web view until the device management service provides a `.mobileconfig` file to the client. The `.mobileconfig` file must have a MIME type of `application/x-apple-aspen-config`. Then web view closes and the device attempts to install the profile, which must be a device management (MDM) enrollment profile.
- Although the web view allows the user to navigate to arbitrary pages at arbitrary sites, the device management (MDM) enrollment profile must originate from a host where the last two components of the domain name match the last two components of the `configuration_web_url` domain name.

For iOS, iPadOS, tvOS, and visionOS this flow is supported during initial setup of an erased device. For macOS, this flow is supported both within Setup Assistant and when enrollment is enforced when it was skipped during Setup Assistant.

---

Copyright &copy; 2026 Apple Inc. All rights reserved. | [Terms of Use](https://www.apple.com/legal/internet-services/terms/site.html) | [Privacy Policy](https://www.apple.com/privacy/privacy-policy)