Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

So finally got a mac mini with mountain lion serverr and profile manager set up, i've succesfully enrolled an Ipad and i can play about (I've added some test restrictions and they pushed out ok).

Question is so what exactly can I do with it?, its not the magic bullet I thought it would be.

Do I still have to manually enrol each Ipad before dishing it out? (I thought I could bulk add the devices)

Do I still need to manually add each exchange server settings per device? (exchange profile needs a user name)

I can see this taking up a lot of our time, or am I missing something?

Posted (edited)

You need to bind the server to Active Directory. This will let your users login to the /mydevices enrollment link with their AD credentials. That then allows you to use %short_name% for the user name within the Exchange payload, and %email% within the Email Address field, so when the profile is pushed out after they've enrolled it'll auto set all those from AD and just prompt them for their email password.

 

The way we do it, each iPad is unboxed and configured for our network (we use static IPs etc). Once that's done, I install the trust profile direct from profile manager and add a link to /mydevices on the homescreen. When staff collect their iPad, they simply tap the /mydevices link, and tap enroll.

 

If working with DHCP, then you can use the Apple Configurator to provide the WLAN key, drop on the trust profile, /mydevices Web Clip and batch name them... just plug each one in on USB and let Configurator do it's stuff, then users do as above - tap the /mydevices link, login with AD credentials, enrol, and let it configure itself.

Edited by Marci
  • Thanks 1
Posted

Cheers for that, sounds like what we need, *except* the mac mini and all apple stuff is on a seperate vlan and we don't want them anywhere near the main domain network - so I guess its manual all the way :/

The wifi is automatic (guest open network) with no key so thats ok.

All I can do is deploy per department and assign email settings per ipad.

Posted (edited)
Connect the MacMini to your Domain network via WiFi, and to the mobiledevices vlan by ethernet (or vice versa, or grab a USB NIC and connect to both by wire)... That way the Mac can bind to AD and access everything it needs to without the risk of the iPads or any other devices on the guest network being able to do so. The server won't allow routing through unless you tell it to, and there really is bugger all risk involved. Edited by Marci
Posted

Great suggestion, I wasn't sure you could do that - the mac mini is connected via wifi on the vlan, so sounds easier - i'll give it a go.

The mac isn't going to kill anything is it? (heh)

Posted
Your only issue may be if you use the macmini to provide dhcp on the guest vlan, but I'm presuming you don't. It won't kill anything. You need to set it's time server to your domain dc, and set up a DHCP reservation on your domain network for it, and give it a DNS entry also. Just makes life easier. Then bind it to AD. Back in Server on the mac, create some user groups (students, staff, ictsupport) and then add the relevant AD groups to those (rather than individual users). Voila. You can now use AD credentials to authenticate on /mydevices and populate payloads with content from AD fields.
  • Thanks 1
Posted
Forgot about this: you could just head to "manage virtual interfaces" in network setup, and connect to both vlans on a single wired connection (also assuming the switch port is configured correctly to allow this)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...