Intro to mobile device management profiles (2024)

Intro to mobile device management profiles (1)

iOS, iPadOS, macOS, tvOS, watchOS 10 or later, and visionOS 1.1 or later have a built-in framework that supports mobile device management (MDM). MDM lets you securely and wirelessly configure devices by sending profiles and commands to the device, whether they’re owned by the user or your organization. MDM capabilities include updating software and device settings, monitoring compliance with organizational policies, and remotely wiping or locking devices. Users can enroll their own devices in MDM, and organization-owned devices can be enrolled in MDM automatically using Apple School Manager or Apple Business Manager. If you’re using Apple Business Essentials, you can also use the device management that’s built right in.

There are a few concepts to understand if you’re going to use MDM, so read the following sections to understand how MDM uses enrollment and configuration profiles, supervision, and payloads.

How devices enroll

Enrollment in MDM involves enrolling client certificate identities using protocols such as Automated Certificate Management Environment (ACME), or Simple Certificate Enrollment Protocol (SCEP). Devices use these protocols to create unique identity certificates for authenticating an organization’s services.

Unless enrollment is automated, users decide whether to enroll in MDM, and they can disassociate their devices from MDM at any time. Therefore, you want to consider incentives for users to remain managed. For example, you can require MDM enrollment for Wi-Fi network access by using MDM to automatically provide the wireless credentials. When a user leaves MDM, their device attempts to notify the MDM solution that it can no longer be managed.

For devices your organization owns, you can use Apple School Manager, Apple Business Manager, or Apple Business Essentials to automatically enroll them in MDM and supervise them wirelessly during initial setup; this enrollment process is known as Automated Device Enrollment.

MDM and Stolen Device Protection

When Stolen Device Protection is turned on, if the user is in an unfamiliar location, the following actions are delayed by an hour:

  • Manually enroll their device in MDM

  • Manually install a passcode profile or configuration

  • Configure a Microsoft Exchange account in settings or with a profile or configuration

Enrollment profiles

An enrollment profile is one of two main ways users can enroll a personal device into an MDM solution (the other way is to use User Enrollment). With this profile, which contains an MDM payload, the MDM solution sends commands and—if necessary—additional configuration profiles to the device. It can also query the device for information, such as its Activation Lock status, battery level, and name.

When a user removes an enrollment profile, all configuration profiles, their settings, and Managed Apps based on that enrollment profile are removed with it. There can be only one enrollment profile on a device at a time.

After the enrollment profile is approved, either by the device or the user, configuration profiles containing payloads are delivered to the device. You can then wirelessly distribute, manage, and configure apps and books purchased through Apple School Manager, Apple Business Manager, or Apple Business Essentials. Users can install apps, or apps can be installed automatically, depending on the type of app it is, how it’s assigned, and whether the device is supervised. For more information, see About Apple device supervision.

Configuration profiles

A configuration profile is an XML file (ending in .mobileconfig) consisting of payloads that load settings and authorization information onto Apple devices. Configuration profiles automate the configuration of settings, accounts, restrictions, and credentials. These files can be created by an MDM solution or Apple Configurator for Mac, or they can be created manually. For more information on using Apple Configurator for Mac to create and install configuration profiles on iPhone, iPad, and Apple TV devices, see the Create and edit configuration profiles in the Apple Configurator for Mac User Guide.

Because configuration profiles can be encrypted and signed, you can restrict their use to a specific Apple device and—with the exception of user names and passwords—prevent anyone from changing the settings. You can also mark a configuration profile as being locked to the device.

If your MDM solution supports it, you can distribute configuration profiles as a mail attachment, through a link on your own webpage, or through the MDM solution’s built-in user portal. When users open the mail attachment or download the configuration profile using a web browser, they’re prompted to begin configuration profile installation.

You can deliver a configuration profile that can change settings for an entire device or for a single user:

  • Device profiles can be sent to devices and device groups, and apply device settings to the entire device.

    iPhone, iPad, Apple TV, Apple Watch, and Apple Vision Pro have no way to recognize more than one user, so configuration profiles created for iOS, iPadOS, tvOS, watchOS 10 or later, and visionOS 1.1 or later are always device profiles. Although iPadOS profiles are device profiles, iPad devices configured for Shared iPad can support profiles based on the device or the user.

  • User profiles can be sent to users and (if the MDM solution supports them) user groups and apply user settings to just the respective users. Mac computers can have multiple users, so payloads and settings for macOS profiles can be based on either the device or the user. The user account created during Setup Assistant is considered managed by the MDM solution and can receive profiles. In macOS 11 or later, an administrator account created by an MDM during enrollment can be optionally managed instead. For Active Directory–bound deployments, the currently logged in network user becomes manageable using MDM.

Device and user settings vary according to where they reside: Settings installed at the system level reside in a device channel. Settings installed for a user reside in a user channel.

For more information about profile installation and Lockdown Mode, see the Apple Support article, About Lockdown Mode.

Profile removal

How you remove profiles depends on how they were installed. The following sequence indicates how a profile can be removed:

1. All profiles can be removed by wiping the device of all data.

2. If the device was enrolled in MDM using Apple School Manager, Apple Business Manager, or Apple Business Essentials, the administrator can choose whether the enrollment profile can be removed by the user or whether it can be removed only by the MDM server itself.

3. If the profile is installed by an MDM solution, it can be removed by that specific MDM solution or by the user unenrolling from MDM by removing the enrollment configuration profile.

4. If the profile is installed on a supervised device using Apple Configurator, that supervising instance of Apple Configurator can remove the profile.

5. If the profile is installed on a supervised device manually or using Apple Configurator and the profile has a removal password payload, the user must enter the removal password to remove the profile.

6. All other profiles can be removed by the user.

An account installed by a configuration profile can be removed by removing the profile. A Microsoft Exchange ActiveSync account, including one installed using a configuration profile, can be removed by Microsoft Exchange Server by issuing the account-only remote wipe command.

Important: If users know the device passcode, they can remove manually installed configuration profiles from iPhone and iPad that aren’t supervised, even if the option is set to “never.” Users on Mac can do the same thing only if the user knows an administrator’s user name and password. They can do this using the profiles command-line tool, System Settings (in macOS 13 or later), or System Preferences (in macOS 12.0.1 or earlier). In macOS 10.15 or later, as with iOS and iPadOS, profiles installed with MDM must be removed with MDM, or they’re removed automatically upon unenrollment from MDM.

MDM communication requirements

Third-party MDM communication with Apple devices is most likely to be successful when:

  • The MDM solution is set up, successfully tested, and working properly

  • The APNs certificate is valid and not expired

  • The device is powered on

  • The device is currently enrolled into the MDM

  • The network the device is connected to has access to the internet (for APNs communication)

  • The network the device is connected to must be able to access MDM-related Apple hosts

    For more information, see the Apple Support article Use Apple products on enterprise networks.

Note: Apple doesn’t control third-party MDM solutions. Additional issues, such as a misconfigured MDM payload, may also cause MDM communication to fail.

Supported Apple devices

The following Apple devices have a built-in framework that supports MDM:

  • iPhone with iOS 4 or later

  • iPad with iOS 4.3 or later or iPadOS 13.1 or later

  • Mac computers with OS X 10.7 or later

  • Apple TV with tvOS 9 or later

  • Apple Watch with watchOS 10 or later

  • Apple Vision Pro with visionOS 1.1 or later

Note: Not all options are available in all MDM solutions. To learn which MDM options are available for your devices, consult your MDM vendor’s documentation.

See alsoDeploy devices using Apple School Manager, Apple Business Manager, or Apple Business EssentialsChoose an MDM solutionApple at Work websiteApple and Education

Intro to mobile device management profiles (2024)

FAQs

What is a mobile device management profile? ›

MDM lets you securely and wirelessly configure devices by sending profiles and commands to the device, whether they're owned by the user or your organization. MDM capabilities include updating software and device settings, monitoring compliance with organizational policies, and remotely wiping or locking devices.

What does mobile device management include? ›

Basic functions include:
  • OS configuration management.
  • Application inventory.
  • Hardware inventory.
  • Content management.
  • Admin remote actions (e.g., remote data wipe, troubleshooting, device lockout, etc.)

What can MDM profile see? ›

MDM software collects various hardware and software information on devices, which helps companies monitor and track company-owned and BYOD devices. You can, for example, view ownership information, installed configurations and applications, warranty and security status, and current location, among other data.

How to remove MDM on iPhone? ›

Get Rid of MDM Profile on iPhone/iPad via Settings
  1. Go to iPhone/iPad settings > General and scroll down to find VPN & Device Management.
  2. Tap on VPN & Device Management > MDM Profile > Remove Management.
  3. You will be prompted to enter your login information or passcode to remove MDM.
Apr 12, 2024

Can MDM see browsing history? ›

Without the user's approval, the MDM software is not allowed to collect information. Furthermore, it's unable to gain permission secretly. Because the MDM software must comply with app developer policies. Take Android and Apple for instance.

How do I turn off mobile device management on my Android phone? ›

Solution
  1. Log in to the Admin console.
  2. Go to Devices > Mobile & endpoints > Settings > Universal settings > General > Mobile Management.
  3. Select the proper OU.
  4. Set it as unmanaged.
Jan 28, 2024

Can MDM read my texts? ›

Regardless of your deployment model, the MDM framework can never access personal information, including email, messages, and browser history.

Can MDM track my phone? ›

Device Location History: Beyond just knowing where a device is now, MDM tools can track where it's been. This historical data can be invaluable, offering insights into usage patterns, identifying potential security risks, and helping recover lost or stolen devices by retracing their movements.

What can my company see with mobile device management? ›

On corporate-owned Android devices that have a work profile, your organization can only see the apps installed in the work profile. For all other corporate-owned devices, they see all installed apps. On personal devices, your organization can see the managed app inventory, which includes work and school apps.

How to check if iPhone is MDM locked? ›

Check if your iPhone is enrolled in an MDM program. Go to Settings > General > Device Management. If you see a "Profiles" or "Device Management" option, it means your device is enrolled in an MDM program.

Does factory resetting iPhone remove MDM? ›

A factory reset does not remove Mobile Device Management; instead, it triggers the Remote Management screen, which appears when setting up the iPhone. The Remote Management screen asks for the username and password that were assigned to you by the MDM administrator before you can access the iPhone.

Can MDM be removed permanently? ›

Open Settings app then scroll down to the General section > Device Management to open the enrolled management profile. Then tap on the MDM profile. Tap the Remove Management button.

What does mobile device management have access to? ›

Personal devices receive role-based access to enterprise data and email, a secure VPN, GPS tracking, password-protected applications and other MDM software for optimal data security. MDM software can then monitor the behaviors and business-critical data on enrolled devices.

Can MDM profile be removed? ›

You can remove the MDM profile from your devices manually if you are changing from another MDM provider to Jamf School and the device is not enrolled via automated enrollment, or if you want to remove the MDM profile from a device enrolled in Jamf School through on-device enrollment.

Is MDM profile safe? ›

Depending if you have an Android or Supervised iOS phone, once an MDM Policy is installed on your phone, administrators may: Track your phone (and you) in real-time by using the phone's GPS on Android and some iOS MDMs. Read text messages (on Android) by deploying routing text messages through an SMS Gateway.

Why is MDM on my phone? ›

The core purpose of MDM is to protect the corporate network by securing and optimizing mobile devices, including laptops, smartphones, tablets, and Internet-of-Things (IoT) devices, that connect to enterprise networks.

Top Articles
Uniform Domain-Name Dispute-Resolution Policy - ICANN
Don't worry — the machines won't be as smart as humans for a long time, because they've still got a lot to learn
Friskies Tender And Crunchy Recall
Umbc Baseball Camp
Swimgs Yuzzle Wuzzle Yups Wits Sadie Plant Tune 3 Tabs Winnie The Pooh Halloween Bob The Builder Christmas Autumns Cow Dog Pig Tim Cook’s Birthday Buff Work It Out Wombats Pineview Playtime Chronicles Day Of The Dead The Alpha Baa Baa Twinkle
Live Basketball Scores Flashscore
Coverage of the introduction of the Water (Special Measures) Bill
9192464227
Die Windows GDI+ (Teil 1)
Craigslist Nj North Cars By Owner
Produzione mondiale di vino
Conduent Connect Feps Login
Obituary | Shawn Alexander | Russell Funeral Home, Inc.
Pittsburgh Ultra Advanced Stain And Sealant Color Chart
Uhcs Patient Wallet
Playgirl Magazine Cover Template Free
Curtains - Cheap Ready Made Curtains - Deconovo UK
Xxn Abbreviation List 2023
Sport-News heute – Schweiz & International | aktuell im Ticker
25Cc To Tbsp
Pekin Soccer Tournament
Officialmilarosee
Puss In Boots: The Last Wish Showtimes Near Cinépolis Vista
Raz-Plus Literacy Essentials for PreK-6
R. Kelly Net Worth 2024: The King Of R&B's Rise And Fall
Academy Sports Meridian Ms
Nesb Routing Number
Essence Healthcare Otc 2023 Catalog
Expression Home XP-452 | Grand public | Imprimantes jet d'encre | Imprimantes | Produits | Epson France
Stockton (California) – Travel guide at Wikivoyage
950 Sqft 2 BHK Villa for sale in Devi Redhills Sirinium | Red Hills, Chennai | Property ID - 15334774
Funky Town Gore Cartel Video
Rays Salary Cap
Bfri Forum
Mumu Player Pokemon Go
Kokomo Mugshots Busted
Craigslist In Myrtle Beach
Samsung 9C8
Labyrinth enchantment | PoE Wiki
What Does Code 898 Mean On Irs Transcript
Wayne State Academica Login
Dcilottery Login
VDJdb in 2019: database extension, new analysis infrastructure and a T-cell receptor motif compendium
Powerspec G512
The Many Faces of the Craigslist Killer
A rough Sunday for some of the NFL's best teams in 2023 led to the three biggest upsets: Analysis
Kaamel Hasaun Wikipedia
Aurora Southeast Recreation Center And Fieldhouse Reviews
Mail2World Sign Up
300 Fort Monroe Industrial Parkway Monroeville Oh
Southwind Village, Southend Village, Southwood Village, Supervision Of Alcohol Sales In Church And Village Halls
Craigs List Sarasota
Latest Posts
Article information

Author: Rev. Leonie Wyman

Last Updated:

Views: 5907

Rating: 4.9 / 5 (79 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Rev. Leonie Wyman

Birthday: 1993-07-01

Address: Suite 763 6272 Lang Bypass, New Xochitlport, VT 72704-3308

Phone: +22014484519944

Job: Banking Officer

Hobby: Sailing, Gaming, Basketball, Calligraphy, Mycology, Astronomy, Juggling

Introduction: My name is Rev. Leonie Wyman, I am a colorful, tasty, splendid, fair, witty, gorgeous, splendid person who loves writing and wants to share my knowledge and understanding with you.