Popular Post Garacesh Posted October 19, 2015 Popular Post Posted October 19, 2015 (edited) Firstly I'm going to stress that this is not a complete guide to getting your iPads working! It's just a run-down of how I've gotten them working-ish to the point that I can push them out of the door and the staff and pupils can use them. You may wish to spend more time with your iPads trying to figure it out or waiting for bugfixes, but if getting them out the door is a higher priority, this may help you out. We use no third-party MDM software. This is just for Apple Configurator 2 and Profile Manager. Create your pupil profile. In Apple Configurator 2, select File, New Profile. Give it a name and configure your settings. This profile must include Wi-Fi and proxy settings. It does not have to include restrictions, but mine does. 1 3 [*]Get your Trust Profile. Login to your Apple server and select Profile Manager Click the button in the top right-hand corner and select 'Download Trust Profile' Rename the Trust Profile to something suitable so you can tell what it is. [*]Create your first blueprint. I called this one '0 - General Settings' so that it's always at the top of the list. Assign your first profile (Step 1) and the Trust Profile to this group (Add, Profiles) [*] Create an AutoEnroll profile in Profile Manager Login to Profile Manager and select Device Groups Add a new device group for that set. Create any restrictions as necessary.3 Select 'New Enrollment Profile' and add the correct group. Download the profile. Rename it something appropriate. [*]Get your apps. Login to Apple VPP and grab the apps you need. This bit is about the only bit you can do 'safely' - it actually works. [*]Create your second blueprint. I personally am using a blueprint per set/department. You don't have to do this, but it makes sense to group them wherever possible. If your first profile (Step 1) did not involve Restrictions, create a profile with restrictions and assign it to this blueprint.1 Add the AutoEnroll profile from Profile Manager Login to VPP through Configurator (Add, Apps) to assign apps to this blueprint. It does not have to include restrictions, but mine does. 1 [*]Manage the devices Connect your iPads up to the machine running Configurator. Ensure all of them show up. Click Pepare, select Manual Configuration, Select your server2, ensure Supervise Devices is checked, and allow pairing if you wish, Select your organisation and whatever screens you want to show. Cross your fingers and hope. [*]Apply your general blueprint The General blueprint will connect it to your WiFi and apply restrictions if required. It will also ensure the iPad trusts your Apple server, allowing Profile Manager to configure it. [*]Apply the second blueprint. The second blueprint will deploy any apps. It will also push the settings for the device to enrol itself with Profile Manager. Can fail for no reason if it feels like it. Cross your fingers and hope. [*]Finish configuring Take the iPad and swipe to begin setup Select your wifi network (Should already be done for you) I select Skip configuration. If your iPads can talk to your Apple server properly, you may be able to select Apply. I can't promise.[/i] Read those T's&C's. Done. If everything goes as planned, then you'll have iPads talking to Profile Manager with the right apps and settings on. This isn't foolproof. Configurator 2 is buggy as heck. I still can't name my devices. App deployment still randomly fails. But it'll at least get your iPads to a state where you can give them to a class and get them being used. I suspect Apple will release numerous bugfixes to Configurator 2 in the coming weeks, so if you can afford to be patient, I'd advise waiting. Ask away if you have any questions and I'll use what limited knowledge I have to give you a hand. 1 Wherever you reply restrictions, ensure that 'Allow installing apps using Apple Configurator and iTunes' is enabled. The subsequent options can be disabled. 2 You will need to have imported your server certificates, I'm not 100% on how this is done but I know it involves exporting certificates from Keychain. This, however, was already done for me. However it's irrelevant because your Profile Manager profile configures joining for you, so it may not matter if the details are correct. 3 Profile Manager should be able to push out restrictions so there's no massive need for them to be in the General profile. We're having some problems with ours though so we're using local profile restrictions and that appears to be working, so you have multiple options here. Edited October 19, 2015 by Garacesh 10
Garacesh Posted November 11, 2015 Author Posted November 11, 2015 (edited) Sorry to bump the thread, just a few more observations I've noticed since I still have more iPads to sort out. Might help out a few people. If your profile contains a restriction to stop them changing the device name (which it should do, I'd say, else you, like I, will likely end up with iPads named "C*nt"), set the device name before applying the profile. Even though you're using the device that supervises them, if you've flagged no name changes, that means no name changes. Users can still tell the device to factory reset if you've restricted it. It looks like it's doing it, it turns off and gives the Apple logo and progress bar. It actually doesn't reset anything at all. We had issues with Smoothwall packet inspection and letting the iPads access https web pages. The fix was to import Smoothwall's root CA certificate (Guardian » HTTPS inspection » Settings, Export certificate authority certificate) and a modified version of the Client Certificate (Web proxy » Global Proxy » Settings, Download certificate) If you have sets of iPads that need almost the same restrictions, with one or two tweaks (in our case, one set needing the camera disabled), copy the primary restrictions profile and modify the copy, apply the copy to your second (set-specific) blueprint. Since you copied the first, the second profile carries the same unique identifier and you're given the option to replace the first when you apply the second blueprint. Set the security on your profiles! Make sure you apply removal passcodes (General (Mandatory) » Security) - users can delete the profiles if you don't do this. I haven't tested whether 'Never' stops Configurator removing them, so I've just applied passcodes. This, annoyingly, may not be possible with automatically-created profiles (such as the trust certificates from Profile Manager) as once they're signed, they can't be modified. Edited November 11, 2015 by Garacesh
furby Posted November 11, 2015 Posted November 11, 2015 Hope you don't mind a curiosity question. Just because I haven't used it, is there any particular advantage of using Configurator and Profile Manager? Rather than just Profile Manager on it's own.
Garacesh Posted November 11, 2015 Author Posted November 11, 2015 (edited) Not a problem, @furby! I would've said "Not really, Configurator just gives you an easy way to push out autoenroll profiles" if it weren't for the issues I discovered today. However, the autoenroll profiles Profile Manager can create cannot be edited (and thus cannot have their removal password protected). I'm not sure how this would affect the iPads after they're enrolled with Profile Manager. If you're manually enrolling them, this may not be an issue, just please be sure to double-check that the profiles can't be deleted. I can't guarantee they're safe. What I do know is that profiles applied to Device Groups in Profile Manager do have a password protection setting if you edit General (Mandatory) and change "Security, Controls when the profile can be removed" from Always to With Authorization.. Unfortunately I don't actually have Profile Manager working fully here (I think it's a routing across VLANs issue), so I'm unable to test extensively. At this point I'm just applying profiles and apps locally with a MacBook that's running Configurator. So, realistically, grab yourself 1 iPad and get testing. I'd be interested to know the results. Edited November 11, 2015 by Garacesh 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now