internetuser Posted April 28, 2014 Posted April 28, 2014 After a lot of fun, reading and playing I am ready to deploy my first 20 iPads. It is for a 1: many student users. Have I missed anything... Deployed with Ios7.1.1 Each iPad has its own Apple ID They are deployed via Apple Conf, with a supervisor profile. Light speed pushes the apps out. The user enters apple ID to download new apps pushed out to it. Currently in the process signing up for VPP to push out paid apps. Users can not change the Apple ID on the device. By default we sign into find my iPhone/ipad to ensure that this and location services work
kaphc Posted April 28, 2014 Posted April 28, 2014 Sounds good! We have a similar setup with 32 iPads but they are all linked to one Apple ID and we use Apple Configurator to push out the apps which then doesn't need the Apple ID entering. Some other points to consider - have you set up a profile with wireless settings / proxies / age restrictions / disabling Siri etc. I don't know what type of school you are at, but in primaries, I tend to lock down quite a lot of features and age related settings. We also have the restrictions set up so that apps cannot be deleted.
internetuser Posted April 28, 2014 Author Posted April 28, 2014 Sounds good! We have a similar setup with 32 iPads but they are all linked to one Apple ID and we use Apple Configurator to push out the apps which then doesn't need the Apple ID entering. Some other points to consider - have you set up a profile with wireless settings / proxies / age restrictions / disabling Siri etc. I don't know what type of school you are at, but in primaries, I tend to lock down quite a lot of features and age related settings. We also have the restrictions set up so that apps cannot be deleted. We use the Lightspeed MDM to do the majority of that. The proxy is transparant on the wireless range that these connect to, so thats not an issue.
Manuelpl Posted April 28, 2014 Posted April 28, 2014 I would consider a few things. 1. enroll devices using DEP. If you enroll devices with apple configuration , user can delete the mdm profile. Using DEP not only are they not allowed to remove the mdm profile, but if they attempt to wipe or restore to get rid of all your management settings, they are automagically pushed the mdm profile again. That's DEP. 2. Turn on restrictions. Just some added security. 3. Add a backup WiFi access point or two. In case your wireless network goes down, or password is changed on saved WiFi. I put all my iPads a wifi setting of my hotspot and a made up wifi. Just in case. 4. Tracking down iPads using find my iPhone, make sure location services is on. 5. Make sure automatic updates is turned on for apps and iOS updates. 6. In your MDM , Never allow removal of profiles or use via pass code. Manny
internetuser Posted April 28, 2014 Author Posted April 28, 2014 1. I am in the UK so no DEP currently. 2. I think I have done this will double check 3. I have done this, users can select other WiFi networks as some are used off site 4. Done, any way to stop them turning it off. 5. Can I do this via the MDM / Apple Confiurator ? 6. I need to check this, I am not sure its present in the current lightspeed.
Manuelpl Posted April 28, 2014 Posted April 28, 2014 4. I think they are not allowed to , because that would turn off find my iPhone , which requires the applied password. But you can always lock location services in restrictions. Again a manual process. 5. No, that's still a manual process. 6. It should be in there. Manny
Manuelpl Posted April 28, 2014 Posted April 28, 2014 6. It's under the general settings for all your profiles in MDM. You have 3 options. Security Controls when the profile can be removed Always With Authorization Never
internetuser Posted April 29, 2014 Author Posted April 29, 2014 I do not think this is included with the latest version of lightspeed, I am sure it was in the original release though, I will log a support call with them.
gsk Posted April 30, 2014 Posted April 30, 2014 Even if you set the configuration profiles to not be removable without a passcode, if the user erases the enrolment profile (which can't be locked to stay on the device without DEP) then it will take the config profiles with it and you'll just be left with the supervision profile.
eshaq786 Posted December 4, 2014 Posted December 4, 2014 I do not think this is included with the latest version of lightspeed, I am sure it was in the original release though, I will log a support call with them. Did they get back to you on this?
CharlieRich Posted December 4, 2014 Posted December 4, 2014 Even if you set the configuration profiles to not be removable without a passcode, if the user erases the enrolment profile (which can't be locked to stay on the device without DEP) then it will take the config profiles with it and you'll just be left with the supervision profile. This is what I'm most looking forward to about DEP being released in the UK!
Mr_Jiminy Posted December 4, 2014 Posted December 4, 2014 I would consider a few things. If you enroll devices with apple configuration , user can delete the mdm profile. I thought a pass code could be enforced to prevent this?
CharlieRich Posted December 4, 2014 Posted December 4, 2014 I thought a pass code could be enforced to prevent this? Nope! Seems daft but any user can rmeove the root MDM profile. All other profiles pushed from Apple Configurator can be locked down but not the most important one!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now