mikkydoos Posted May 18, 2016 Posted May 18, 2016 Hi all, This is for devices I haven't enrolled in DEP yet. Is it just me or does the Meraki profile password protection not work. The profiles I have installed with configurator ask for a password on removal, the Meraki Systems Manager app installed profiles do not. Anyone got any advice or a fix for this ? Cheers in advance
beany1 Posted May 18, 2016 Posted May 18, 2016 Isn't this a limitation when not using DEP? (design feature) Why can I remove the 'Meraki Management' profile even when I set a password policy? ? Systems Manager Support Community As a work around I've set our Meraki to deliver the wifi settings - so if profile removed so is the wifi. 1
mikkydoos Posted May 18, 2016 Author Posted May 18, 2016 Cheers @beany1 I read that too. Kind of defeats the object though doesn't it considering Meraki was around way before DEP
simonw Posted May 18, 2016 Posted May 18, 2016 May have got the wrong end of the stick, but in 'Restrictions' could you set a password and turn off permission to 'delete apps'. 1
robsonma Posted May 18, 2016 Posted May 18, 2016 Yes this is correct Meraki profile can be removed even if you set a passkey on the Profile, it does send an email to say it has been removed. 1
mikkydoos Posted May 18, 2016 Author Posted May 18, 2016 Yes this is correct Meraki profile can be removed even if you set a passkey on the Profile, it does send an email to say it has been removed. And then you can't managed it remotely anymore say in the event it was stolen, which is why I'm looking at this now. I'm scratching my head in disbelief. Apparently this is the same in all MDM's.
robsonma Posted May 18, 2016 Posted May 18, 2016 It can be wiped remoteley using https://www.icloud.com/ and view its last Location. 1
mikkydoos Posted May 18, 2016 Author Posted May 18, 2016 It can be wiped remoteley using https://www.icloud.com/ and view its last Location. I always forget about that. Well reminded @robsonma
Another Posted May 18, 2016 Posted May 18, 2016 We use Airwatch and with the combination of DEP and AW you can't remove the profile. Even with a forced reset/wipe you'd then get stuck in the DEP loop where it wouldn't activate until you authenticated (against AD in our case) again. We disable FMi and use Airwatch instead for finding devices. 1
PR-UK Posted May 19, 2016 Posted May 19, 2016 You have to use DEP, it's an Apple limitation rather than the fault of the MDMs, there's nothing they can do. If you implement DEP then the profile is non-removable and will always be re-applied even if the device is put in DFU mode and restored via iTunes. You'll really want to use DEP as from what I can tell if the user removes the profile you'll get a email notification but if the user puts it in restore mode and restores from iTunes the MDM will just think it's been switched off and you won't get an alert and you'll not realise you've got a un-enrolled, non-supervised device being used. 1
mikkydoos Posted May 19, 2016 Author Posted May 19, 2016 I'm about to roll out DEP. Thanks for the comments all
robsonma Posted May 19, 2016 Posted May 19, 2016 This is the stage I am up to rolling out DEP, Stuck now where only my Apple Seller can add devices to Dep :-(
mikkydoos Posted May 19, 2016 Author Posted May 19, 2016 I have absolutely no idea how Apple have got sales in any business environment. Their management platform is absolutely pathetic.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now