Device enrollment allowlist for one-time pin users


I’m trying to configure one-time pin access for some users and want to restrict device enrollment to a list of allowed email addresses but can’t seem to configure this correctly. I’ve tried both “Includes” and “Required” rules with the “Emails” option containing a list of allowed emails, but this just leads to no one being sent one-time pins. Is there something I am misunderstanding around “Includes” and “Required” perhaps?

Many thanks in advance!

