Jump to content

Recommended Posts

Posted

I look after well over 300 iPads now. All different models and across a large site. 200 are managed by Apple Config 2 and Meraki. The rest I'm attempting to manage through ASM so I don't have to have accounts set up for any of them.

 

The consistent problem I've got no matter which MDM I've tried, is that I am unable to hide the 'Settings' app. Does anyone know if this is possible?

 

If you try and hide it then all the settings you have push to the iPad then go and nothing is restricted. Yet if you leave it people attempt to attach them to their own Hotspots or remove the profile and restrictions.

 

Possibly driving me crazy trying to get an answer for this.

Posted

Settings app cannot be hidden, Apple don't allow it.

 

If you want to prevent profile removal the only water tight solution is an MDM via auto-enrollment using DEP. Yes you can supervise them with Apple Configurator and prevent profile removal but they can still force the device in to DFU mode and wipe it with iTunes assuming they have that level of access to the device.

 

Either way there's a lot of settings you'll have no ability to restrict and that's unfortunately the Apple Way!

Posted

DEP will allow you to prevent removal of an MDM profile. You can add a removal passcode in AC2 to prevent removal of your profiles.

 

Edit: As above it isn't possible to hide the settings app.

Posted
It's been two years of wishful thinking on being able to hide that Settings icon. I've only recently started using DEP with the iPads. I love the fact I don't need an account to be assigned to them. As for looking the profile with a password, I've yet to find that option in Meraki.
Posted (edited)
It's been two years of wishful thinking on being able to hide that Settings icon. I've only recently started using DEP with the iPads. I love the fact I don't need an account to be assigned to them. As for looking the profile with a password, I've yet to find that option in Meraki.

Sorry ignore me. That removal password through Meraki is Legacy and no longer works. Looks like your options are deploying your restrictions using AC2 instead of Meraki or rolling DEP out fully.

Screen Shot 2017-03-10 at 10.11.57.png

Edited by tmoon-mint
  • Thanks 1
Posted
Sorry ignore me. That removal password through Meraki is Legacy and no longer works. Looks like your options are deploying your restrictions using AC2 instead of Meraki or rolling DEP out fully.

Thank you for showing me that. It's nice to know other people have looked and had the same sort of issues. Having to manage iPads in an educational environment can be a complete nightmare.

Posted
I thought you could add passwords to profiles so they couldn't be removed?

You are correct, there's an option in most MDMs for this however it will not apply to iPads that aren't enrolled during their supervision. If you use DEP the profile cannot be removed, if you use Apple Configurator and enroll the device during supervision it cannot be removed (unless it's reset via DFU or Erase All Data & Settings). If however you supervise the device in Apple Configurator (or don't supervise it at all) and hand it over for manual enrollment that can be removed.

 

From memory the Password option does actually work in that if you try to remove the password protected profile you'll be asked for it, but the easy way around this is to remove the trust profile with the MDM which isn't password protected and once removed will also revoke any other related profiles e.g. your password protected one!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...