Skip to main content

Device Enrolment

Keep child data safe by controlling which devices your staff can use to access Famly, and how they verify who they are.

Written by Josie

Device enrolment lets your organisation decide which devices are trusted to access Famly at each site. Once a device is enrolled, you can use it in two ways:

  • As an alternative to MFA (multi-factor authentication) so staff on enrolled devices don't need to verify their identity every time they log in

  • As a hard requirement so certain roles can only access child data when they're on an enrolled device

Together, these tools give you full control over who can see sensitive information, and from where.

What to expect from device enrolment

Setting up device enrolment involves a few steps, and getting the order right makes things much smoother, especially if you're rolling this out across multiple sites. Here's a quick overview before you dive in.

  • Start with permissions, then enrol your devices. This has to be done on-site from the actual device, and enrolment is site specific, so if you're a multi-site organisation, build in extra time to get every site done.

  • You can hand this off to your team if you'd like. Just grant staff the Can enrol device permission and they can do it themselves.

  • Only once devices are enrolled should you move on to setting verification methods, assigning the MFA or enrolled device option to roles.

  • One thing to flag: "device enrolment" really means enrolling a browser or app installation, not the physical device itself.

Can you use this feature?

On shared devices, each browser or app installation gets its own device ID, which is what Famly remembers as "enrolled". On desktop, that means each Windows or Mac user account on a shared computer has its own device ID, even if everyone's using the same browser, so if staff each log into their own account, enrolling one person doesn't enrol the others. On mobile, the device ID belongs to the app installation, so Famly on your phone is one device ID, and uninstalling or clearing the app resets it.

Basically, anything that wipes the underlying browser profile or app data, like shared browser profiles that reset after each use, incognito mode, kiosk mode, or a policy that clears data on logout, will cause enrolment to be lost. Worth checking this with whoever manages your devices, especially for shared desktops, tablets, or kiosks.

💡 We recommend using this feature for room-based staff only. HQ or office staff should stick with other security methods like SSO or MFA

Checklist before you start enrolling devices

Before you jump into settings, it's worth deciding a few things upfront so you're not going back and forth later. You should decide:

  1. Whether to restrict child data to enrolled devices only, for any roles

  2. Who should hold the Can enrol device and Can manage enrolled devices permissions

If you use MFA at any of your sites, also decide:

  1. Which roles would benefit from using an enrolled device instead of MFA, usually room-based staff who can't carry phones

  2. Which roles should keep standard MFA

To learn how to enable device enrolment, check out the video below:


Recommended Setup for Device Enrolment

For the most secure setup, follow these steps in order.

💡 We recommend that only room-level devices be enrolled and allowed to bypass the additional verification measures

Step 1: Set up permissions

Decide who at your organisation can enrol and manage devices. You have two permission levels:

Create enrolled devices

  • This person can add new devices to the trusted list when on-site. They can't remove or manage existing devices.

Manage enrolled devices

  • This person has full control and can enrol new devices and manage the full device list, including removing devices.

To give someone permission, go to Settings → Staff → Roles and permissions. From here, click on the Compare permissions button. Find the role, and check the relevant permission under Security.

💡 For the tightest security, keep the Manage enrolled devices permission to a small group of trusted admins and use Create enrolled devices for on-site staff who need to add devices day-to-day


Step 2: Enrol your devices

Once permissions are in place, you can start to enrol the devices your staff use at each site. Only someone with one of the permissions above can do this.

To enrol a device:

  • Log into Famly on the device you want to enrol

  • Go to Settings → Security → Device enrolment

  • Click on Enrol this device

  • Give the device an easily recognisable name

  • Choose whether the device should skip MFA verification. Toggle Require MFA on this device off if you'd like staff on this device to log in without needing to type in a verification code

  • Click Enrol this device and confirm

  • The device will appear in your enrolled devices list straight away

If you are part of an organisation or nursery group, an organisation-level Device enrolment overview can be accessed at Organisation settings → Device enrolment

💡 Enrolment is site-specific. Devices cannot be used across multiple sites


Step 3: Configure enrolled devices as a verification method for any role

Once your devices are enrolled, decide how each role should verify their identity when logging in. You can configure this per role.

Go to Settings → Staff → Roles and permissions, and select a role. In the verification method options, you'll now also see Enrolled device or MFA.

Setting this as the required method means staff in that role can use either an enrolled device or MFA to verify, giving front-line staff a smoother login experience without compromising security.

💡 A good starting point: keep MFA for roles with sensitive admin access, and allow enrolled devices for front-line staff who log in frequently throughout the day.


Step 4: Restrict child data access (optional)

For even tighter security, you can restrict certain roles so they can only access child data when they're on an enrolled device.

This is separate from the verification setting above. Here's the difference:

Verification method

Child data restriction

Controls how staff log in and prove their identity.

Controls whether they can access child data at all, regardless of how they logged in.

Example: a staff member using MFA can still access child data from any device.

Example: with this restriction on, a staff member can only view child profiles on an enrolled device, even if they've completed MFA.

To restrict a role, go to Settings → Staff → Roles and permissions, select the role, and enable Can only access child data from an enrolled device.

💡 If a staff member in a restricted role isn't on an enrolled device, they can still log in to Famly, but they won't be able to view any child data until they switch to an enrolled device. Make sure staff know which devices are enrolled before you turn this on


Managing Enrolled Devices

Anyone with the Can manage enrolled devices permission can view and manage the full device list from Settings → Security → Device enrolment.

From here you can:

  • See all enrolled devices across your sites, including when they were last used.

  • Remove a device from the list; for example, if a device is lost, stolen, or taken off-site

  • See which site each device is enrolled for, by whom, and whether it's allowed to skip MFA verification

💡 Review your enrolled devices list regularly, especially if staff leave or devices are replaced. Removing a device straight away means it can no longer be used to bypass MFA or access child data


FAQ about Device Enrolment

Who can enrol a device?

  • Only staff with the Can enrol device or Can manage enrolled devices permission can enrol devices. Admins can grant these permissions from Settings → Staff → Roles and permissions.

What's the difference between Can enrol device and Can manage enrolled devices?

  • Can enrol device only lets someone add new devices to the list. Can manage enrolled devices gives full control; adding, viewing, and removing devices. For everyday on-site use, Can enrol device is usually enough.

Can the same device be used at more than one site?

  • No. Enrolment is site-specific, so a device enrolled at one nursery can't be used at another.

Can I choose whether MFA is required on a specific device?

  • Yes. When enrolling a device, you'll see a Require MFA on this device toggle. Turn it off if you'd like staff on that device to log in without a verification code. You can always update this later from the enrolled devices list.

What happens if a staff member uses a non-enrolled device?

  • It depends on how you've set up their role. If their role uses enrolled devices as the verification method, they'll need to use MFA instead. If you've also turned on the child data restriction for their role, they'll be able to log in, but they won't be able to view any child data until they're on an enrolled device.

What happens if a device is lost or a staff member leaves?

  • Remove the device from your enrolled devices list straight away. Go to Settings → Security → Device enrolment, find the device, and remove it. Once removed, it can no longer be used to bypass MFA or access restricted child data.

Can I restrict child data access for some roles but not others?

  • Yes. The child data restriction is configured per role, so you can apply it selectively. For example, you might restrict it for a 'Parent helper' role but not for a 'Room leader' role.

Does device enrolment affect how staff log in?

  • Not directly; enrolment just tells Famly that a device is trusted. What changes the login experience is the verification method you set for each role. If a role is set to use enrolled devices for verification, staff on those devices won't need to complete MFA every time.

Is there a limit to how many devices I can enrol?

  • No, you can enrol as many devices as your site needs.

Can I set up device enrolment for just one site in my organisation?

  • Yes. Device enrolment can be set up for individual sites without affecting the rest of your organisation. However, if you're using roles that are shared across your organisation (such as the default Manager role or any custom org-wide roles), any device enrolment settings applied to those roles will apply across all sites. If you only want device enrolment to apply to one site, you'll need to use a role that's specific to that site.

Did this answer your question?