Jump to content

How I got Configurator 2/Profile Manager working... Ish. [Kludgy]


Recommended Posts

  • 4 weeks later...
Posted (edited)

Sorry to bump the thread, just a few more observations I've noticed since I still have more iPads to sort out. Might help out a few people.

 

  • If your profile contains a restriction to stop them changing the device name (which it should do, I'd say, else you, like I, will likely end up with iPads named "C*nt"), set the device name before applying the profile. Even though you're using the device that supervises them, if you've flagged no name changes, that means no name changes.
  • Users can still tell the device to factory reset if you've restricted it. It looks like it's doing it, it turns off and gives the Apple logo and progress bar. It actually doesn't reset anything at all.
  • We had issues with Smoothwall packet inspection and letting the iPads access https web pages. The fix was to import Smoothwall's root CA certificate (Guardian » HTTPS inspection » Settings, Export certificate authority certificate) and a modified version of the Client Certificate (Web proxy » Global Proxy » Settings, Download certificate)
  • If you have sets of iPads that need almost the same restrictions, with one or two tweaks (in our case, one set needing the camera disabled), copy the primary restrictions profile and modify the copy, apply the copy to your second (set-specific) blueprint. Since you copied the first, the second profile carries the same unique identifier and you're given the option to replace the first when you apply the second blueprint.
  • Set the security on your profiles! Make sure you apply removal passcodes (General (Mandatory) » Security) - users can delete the profiles if you don't do this. I haven't tested whether 'Never' stops Configurator removing them, so I've just applied passcodes. This, annoyingly, may not be possible with automatically-created profiles (such as the trust certificates from Profile Manager) as once they're signed, they can't be modified.

Edited by Garacesh
Posted

Hope you don't mind a curiosity question.

 

Just because I haven't used it, is there any particular advantage of using Configurator and Profile Manager? Rather than just Profile Manager on it's own.

Posted (edited)

Not a problem, @furby! I would've said "Not really, Configurator just gives you an easy way to push out autoenroll profiles" if it weren't for the issues I discovered today.

 

However, the autoenroll profiles Profile Manager can create cannot be edited (and thus cannot have their removal password protected). I'm not sure how this would affect the iPads after they're enrolled with Profile Manager. If you're manually enrolling them, this may not be an issue, just please be sure to double-check that the profiles can't be deleted. I can't guarantee they're safe. What I do know is that profiles applied to Device Groups in Profile Manager do have a password protection setting if you edit General (Mandatory) and change "Security, Controls when the profile can be removed" from Always to With Authorization.. Unfortunately I don't actually have Profile Manager working fully here (I think it's a routing across VLANs issue), so I'm unable to test extensively. At this point I'm just applying profiles and apps locally with a MacBook that's running Configurator.

 

So, realistically, grab yourself 1 iPad and get testing. I'd be interested to know the results.

Edited by Garacesh
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...