Device enrollment lets your organization decide which devices are trusted to access Famly at each site. Once a device is enrolled, you can use it in two ways:
As an alternative to MFA (multi-factor authentication) so staff on enrolled devices don't need to verify their identity every time they log in
As a hard requirement so certain roles can only access child data when they're on an enrolled device
Together, these tools give you full control over who can see sensitive information, and from where.
What to expect from device enrollment
Setting up device enrollment involves a few steps, and getting the order right makes things much smoother, especially if you're rolling this out across multiple sites. Here's a quick overview before you dive in.
Start with permissions, then enroll your devices. This has to be done on-site from the actual device, and enrollment is site specific, so if you're a multi-site organization, build in extra time to get every site done.
You can hand this off to your team if you'd like. Just grant staff the Can enroll device permission and they can do it themselves.
Only once devices are enrolled should you move on to setting verification methods, assigning the MFA or enrolled device option to roles.
One thing to flag: "device enrollment" really means enrolling a browser or app installation, not the physical device itself.
Can you use this feature?
On shared devices, each browser or app installation gets its own device ID, which is what Famly remembers as "enrolled". On desktop, that means each Windows or Mac user account on a shared computer has its own device ID, even if everyone's using the same browser, so if staff each log into their own account, enrolling one person doesn't enroll the others. On mobile, the device ID belongs to the app installation, so Famly on your phone is one device ID, and uninstalling or clearing the app resets it.
Basically, anything that wipes the underlying browser profile or app data, like shared browser profiles that reset after each use, incognito mode, kiosk mode, or a policy that clears data on logout, will cause enrollment to be lost. Worth checking this with whoever manages your devices, especially for shared desktops, tablets, or kiosks.
💡 We recommend using this feature for classroom-based staff only. HQ or office staff should stick with other security methods like SSO or MFA
Checklist before you start enrolling devices
Before you jump into settings, it's worth deciding a few things upfront so you're not going back and forth later. You should decide:
Whether to restrict child data to enrolled devices only, for any roles
Who should hold the Can enroll device and Can manage enrolled devices permissions
If you use MFA at any of your sites, also decide:
Which roles would benefit from using an enrolled device instead of MFA, usually room-based staff who can't carry phones
Which roles should keep standard MFA
Recommended Setup for Device Enrollment
For the most secure setup, follow these steps in order.
💡 We recommend that only room-level devices be enrolled and allowed to bypass the additional verification measures
Step 1: Set up permissions
Decide who at your organization can enroll and manage devices. You have two permission levels:
Create enrolled devices
This person can add new devices to the trusted list when on-site. They can't remove or manage existing devices.
Manage enrolled devices
This person has full control and can enrol new devices and manage the full device list, including removing devices.
To give someone permission, go to Settings → Staff → Roles and permissions. From here, click on the Compare permissions button. Find the role, and check the relevant permission under Security.
💡 For the tightest security, keep the Manage enrolled devices permission to a small group of trusted admins and use Create enrolled devices for on-site staff who need to add devices day-to-day
Step 2: Enroll your devices
Once permissions are in place, you can start to enroll the devices your staff use at each site. Only someone with one of the permissions above can do this.
To enroll a device:
Log into Famly on the device you want to enrol
Go to Settings → Security → Device enrollment
Click on Enroll this device
Give the device an easily recognisable name
Choose whether the device should skip MFA verification. Toggle Require MFA on this device off if you'd like staff on this device to log in without needing to type in a verification code
Click Enroll this device and confirm
The device will appear in your enrolled devices list straight away
If you are part of an organization or center group, an organization-level Device enrollment overview can be accessed at Organization settings → Device enrollment
💡 Enrollment is site-specific. Devices cannot be used across multiple sites
Step 3: Configure enrolled devices as a verification method for any role
Once your devices are enrolled, decide how each role should verify their identity when logging in. You can configure this per role.
Go to Settings → Staff → Roles and permissions, and select a role. In the verification method options, you'll now also see Enrolled device or MFA.
Setting this as the required method means staff in that role can use either an enrolled device or MFA to verify, giving front-line staff a smoother login experience without compromising security.
💡 A good starting point: keep MFA for roles with sensitive admin access, and allow enrolled devices for front-line staff who log in frequently throughout the day.
Step 4: Restrict child data access (optional)
For even tighter security, you can restrict certain roles so they can only access child data when they're on an enrolled device.
This is separate from the verification setting above. Here's the difference:
Verification method | Child data restriction |
Controls how staff log in and prove their identity. | Controls whether they can access child data at all, regardless of how they logged in. |
Example: a staff member using MFA can still access child data from any device. | Example: with this restriction on, a staff member can only view child profiles on an enrolled device, even if they've completed MFA. |
To restrict a role, go to Settings → Staff → Roles and permissions, select the role, and enable Can only access child data from an enrolled device.
💡 If a staff member in a restricted role isn't on an enrolled device, they can still log in to Famly, but they won't be able to view any child data until they switch to an enrolled device. Make sure staff know which devices are enrolled before you turn this on
Managing Enrolled Devices
Anyone with the Can manage enrolled devices permission can view and manage the full device list from Settings → Security → Device enrollment.
From here you can:
See all enrolled devices across your sites, including when they were last used.
Remove a device from the list; for example, if a device is lost, stolen, or taken off-site
See which site each device is enrolled for, by whom, and whether it's allowed to skip MFA verification
💡 Review your enrolled devices list regularly, especially if staff leave or devices are replaced. Removing a device straight away means it can no longer be used to bypass MFA or access child data
FAQ about Device Enrollment
Who can enroll a device?
Only staff with the Can enroll device or Can manage enrolled devices permission can enroll devices. Admins can grant these permissions from Settings → Staff → Roles and permissions.
What's the difference between Can enroll device and Can manage enrolled devices?
Can enroll device only lets someone add new devices to the list. Can manage enrolled devices gives full control; adding, viewing, and removing devices. For everyday on-site use, Can enroll device is usually enough.
Can the same device be used at more than one site?
No. Enrollment is site-specific, so a device enrolled at one center can't be used at another.
Can I choose whether MFA is required on a specific device?
Yes. When enrolling a device, you'll see a Require MFA on this device toggle. Turn it off if you'd like staff on that device to log in without a verification code. You can always update this later from the enrolled devices list.
What happens if a staff member uses a non-enrolled device?
It depends on how you've set up their role. If their role uses enrolled devices as the verification method, they'll need to use MFA instead. If you've also turned on the child data restriction for their role, they'll be able to log in, but they won't be able to view any child data until they're on an enrolled device.
What happens if a device is lost or a staff member leaves?
Remove the device from your enrolled devices list straight away. Go to Settings → Security → Device enrollment, find the device, and remove it. Once removed, it can no longer be used to bypass MFA or access restricted child data.
Can I restrict child data access for some roles but not others?
Yes. The child data restriction is configured per role, so you can apply it selectively. For example, you might restrict it for a 'Parent helper' role but not for a 'Room leader' role.
Does device enrollment affect how staff log in?
Not directly; enrollment just tells Famly that a device is trusted. What changes the login experience is the verification method you set for each role. If a role is set to use enrolled devices for verification, staff on those devices won't need to complete MFA every time.
Is there a limit to how many devices I can enrol?
No, you can enroll as many devices as your site needs.
Can I set up device enrollment for just one site in my organization?
Yes. Device enrollment can be set up for individual centers without affecting the rest of your organization. However, if you're using roles that are shared across your organization (such as the default Manager role or any custom org-wide roles), any device enrollment settings applied to those roles will apply across all centers. If you only want device enrollment to apply to one site, you'll need to use a role that's specific to that site.







