Jump to content

Recommended Posts

Posted

After a lot of fun, reading and playing I am ready to deploy my first 20 iPads. It is for a 1: many student users.

 

Have I missed anything...

 

Deployed with Ios7.1.1

Each iPad has its own Apple ID

They are deployed via Apple Conf, with a supervisor profile.

Light speed pushes the apps out.

The user enters apple ID to download new apps pushed out to it.

Currently in the process signing up for VPP to push out paid apps.

Users can not change the Apple ID on the device.

By default we sign into find my iPhone/ipad to ensure that this and location services work

Posted

Sounds good! We have a similar setup with 32 iPads but they are all linked to one Apple ID and we use Apple Configurator to push out the apps which then doesn't need the Apple ID entering.

 

Some other points to consider - have you set up a profile with wireless settings / proxies / age restrictions / disabling Siri etc. I don't know what type of school you are at, but in primaries, I tend to lock down quite a lot of features and age related settings. We also have the restrictions set up so that apps cannot be deleted.

Posted
Sounds good! We have a similar setup with 32 iPads but they are all linked to one Apple ID and we use Apple Configurator to push out the apps which then doesn't need the Apple ID entering.

 

Some other points to consider - have you set up a profile with wireless settings / proxies / age restrictions / disabling Siri etc. I don't know what type of school you are at, but in primaries, I tend to lock down quite a lot of features and age related settings. We also have the restrictions set up so that apps cannot be deleted.

 

We use the Lightspeed MDM to do the majority of that. The proxy is transparant on the wireless range that these connect to, so thats not an issue.

Posted

I would consider a few things.

 

1. enroll devices using DEP.

 

If you enroll devices with apple configuration , user can delete the mdm profile.

Using DEP not only are they not allowed to remove the mdm profile, but if they attempt to wipe or restore to get rid of all your management settings, they are automagically pushed the mdm profile again. That's DEP.

 

2. Turn on restrictions. Just some added security.

 

3. Add a backup WiFi access point or two. In case your wireless network goes down, or password is changed on saved WiFi. I put all my iPads a wifi setting of my hotspot and a made up wifi. Just in case.

 

4. Tracking down iPads using find my iPhone, make sure location services is on.

 

5. Make sure automatic updates is turned on for apps and iOS updates.

 

6. In your MDM , Never allow removal of profiles or use via pass code.

 

Manny

Posted

1. I am in the UK so no DEP currently.

2. I think I have done this will double check

3. I have done this, users can select other WiFi networks as some are used off site

4. Done, any way to stop them turning it off.

5. Can I do this via the MDM / Apple Confiurator ?

6. I need to check this, I am not sure its present in the current lightspeed.

Posted

4. I think they are not allowed to , because that would turn off find my iPhone , which requires the applied password. But you can always lock location services in restrictions. Again a manual process.

 

5. No, that's still a manual process.

 

6. It should be in there.

 

Manny

Posted

6. It's under the general settings for all your profiles in MDM. You have 3 options.

 

Security

Controls when the profile can be removed

 

Always

With Authorization

Never

Posted
Even if you set the configuration profiles to not be removable without a passcode, if the user erases the enrolment profile (which can't be locked to stay on the device without DEP) then it will take the config profiles with it and you'll just be left with the supervision profile.
  • 7 months later...
Posted
I do not think this is included with the latest version of lightspeed, I am sure it was in the original release though, I will log a support call with them.

 

Did they get back to you on this?

Posted
Even if you set the configuration profiles to not be removable without a passcode, if the user erases the enrolment profile (which can't be locked to stay on the device without DEP) then it will take the config profiles with it and you'll just be left with the supervision profile.

 

This is what I'm most looking forward to about DEP being released in the UK!

Posted
I would consider a few things.

 

If you enroll devices with apple configuration , user can delete the mdm profile.

 

I thought a pass code could be enforced to prevent this?

Posted
I thought a pass code could be enforced to prevent this?

 

Nope! Seems daft but any user can rmeove the root MDM profile. All other profiles pushed from Apple Configurator can be locked down but not the most important one!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...