VSA 10 MDM: Apple MDM profiles
NAVIGATION Administration > Configuration > Profiles > New Profile > Apple MDM Applications (Device Configuration) profile type
NAVIGATION Administration > Configuration > Profiles > New Profile > Apple MDM Restrictions (Device Configuration) profile type
NAVIGATION Administration > Configuration > Profiles > New Profile > Apple MDM Networking (Device Configuration) profile type
NAVIGATION Administration > Configuration > Profiles > New Profile > Apple MDM Security (Device Configuration) profile type
NAVIGATION Administration > Configuration > Profiles > New Profile > Apple MDM System Configuration (Device Configuration) profile type
NAVIGATION Administration > Configuration > Policies
SECURITY Administrator
Using any of the Apple MDM types of Device Configuration profiles, you have the ability to automate the setup of mobile device user accounts, networking settings, security policies, and hardware, operating system, and application restrictions from the moment the device is enrolled. This powerful feature eliminates the need for administrators to manually onboard every MDM endpoint in your environment, saving you time and ensuring that all devices are configured consistently.
To learn how to enroll a device in MDM, refer to VSA 10 MDM: enrollment.
For a comprehensive overview of how profiles and policies work in VSA 10, refer to Policies overview.
Overview
With MDM profiles, you can create predefined setup templates for supported Apple devices and associate them with management policies. When VSA 10 detects a client that meets the criteria of one or more of the associated policy rules, it will automatically apply the corresponding profile to the device via the Apple Push Notification Service.
Supported hardware
The following devices support management via MDM profiles:
Notebooks | Desktops | Mobile | Other |
---|---|---|---|
MacBook Air, Macbook Pro | iMac, Mac mini, Mac Studio, Mac Pro | iPad, iPhone | Apple Watch, Apple TV |
Capabilities
MDM profiles support the following applications and system settings:
Category | Description | Applications and settings |
---|---|---|
Networking | Manage network configuration, including WiFi, Ethernet, and VPNs. |
WiFi, Ethernet, cellular, firewall, DNS, proxy, VPN, AirPlay, AirPrint |
Security | Control sensitive security-related device settings. |
Authentication, certificates, parental controls, encryption, passcodes |
Restrictions | Manage hardware, operating system, and application restrictions. |
Bluetooth, camera, Game Center App Store, lock screen, user creation, startup, authentication |
System Configuration | Enable or disable interface elements, manage login behavior, control system updates. |
Login behavior, user experience, preferences, software catalog |
Applications | Deploy apps to devices automatically, automate app updates, and track installation and update statuses for managed apps. | App deployment, updates, and update status |
Apple MDM Profile Configuration Settings
The Apple MDM Applications profile allows you to provision, install, and update software from the Apple App Store through VSA 10 on iOS, iPadOS, and macOS devices. Applications added to this profile will be installed and kept up to date on targeted devices.
NOTE Devices are checked for uninstalled/out of date apps on a 24 hour cycle, so if a user uninstalls and app manually it will be reinstalled within a day.
NOTE This profile will work with non-supervised devices.
To configure this profile, follow the instructions below depending on which configuration you want to apply:
- Select App Store from the menu on the left.
- Click Add Application in the upper right.
- Use the drop-down for App Store Country to select the country the targeted devices reside.
- Type in the Application field to search the App Store. Click to select the application you wish to configure.
- For the selected application, check or uncheck the necessary boxes to choose which of the following settings you want applied:
- Update the application to the latest version automatically: Checking this option will keep the app up to date on targeted devices.
- Delete the app when the device is unenrolled from MDM: Checking this option will force the application to be removed from the any targeted devices if they are unenrolled from MDM.
- Prevent the backup of app data: Checking this option will omit the app and app data from being backed up when a phone is backed up with a service such as iCloud
- Click Add to add the app configuration to the profile.
-
Repeat this process for all apps you want to add to the profile, and then click Create to save the profile.
- Select Apps and Books from the menu on the left.
- Click Add Application in the upper right.
- Use the Connector dropdown to select your connector. Refer to Connectors if one needs to be configured.
- Select one of the applications from the Application dropdown.
- Enter in the application configuration settings in the Configuration field. Refer to the application vendor's documentation for directions on configuring these settings in the proper format.
- For the selected application, check or uncheck the necessary boxes to choose which of the following settings you want applied:
- Update the application to the latest version automatically: Checking this option will keep the app up to date on targeted devices.
- Delete the app when the device is unenrolled from MDM: Checking this option will force the application to be removed from the any targeted devices if they are unenrolled from MDM.
- Prevent the backup of app data: Checking this option will omit the app and app data from being backed up when a phone is backed up with a service such as iCloud
- Click Add to add the app configuration to the profile.
-
Repeat this process for all applications you want to add to the profile, and then click Create to save the profile.
The Apple MDM Restrictions profile allows you to allow or restrict functions on iOS, iPadOS, and macOS devices.
To configure this profile:
-
Select which items you wish to be allowed or restricted by clicking the sliders. Items that will only work on supervised devices will have an eye icon next to their label.
NOTE To learn more about restrictions settings, click the Learn more link at the top of the configuration.
-
Once finished configuring the profile, click Create in order to save your changes and create the profile.
The Apple MDM Networking profile allows you to configure network settings for the different types of network interfaces that macOS, iOS, and iPadOS can connect to.
For each interface, you can configure various settings based on the interface type. For example, the below image is from the 802.1X: First Active Ethernet configuration.
NOTE There is a Learn more link at the top of each section that links back to Apple developer documentation on the device management profile for that interface.
To configure this profile:
-
Using the search bar or scrolling through the list manually, select which section you wish to configure using the list on the left.
-
Click Add Configuration in the upper right.
-
Configure the section as desired.
-
Repeat the process if you want to add more sections to the profile.
-
Once finished configuring the profile, click Create in order to save your changes and create the profile.
NOTE You can have multiple network interface configurations in one profile.
The Apple MDM Security profile allows you to configure security settings and certificates for macOS, iOS and iPadOS devices.
For example, this profile allows you to configure, among other things:
- Passcode requirements
- Guest Account availability
- Active Directory Certificate settings
- Parental Controls
NOTE There is a Learn more link at the top of each section that links back to Apple developer documentation on the device management profile for that configuration.
To configure this profile:
- Using the search bar or scrolling through the list manually, select which section you wish to configure using the list on the left.
- Click Add Configuration in the upper right.
- Configure the section as desired.
- Repeat the process if you want to add more sections to the profile.
- Once finished configuring the profile, click Create in order to save your changes and create the profile.
NOTE You can have multiple security configurations in one profile.
The Apple MDM System Configuration profile allows you to configure system settings for MacOS, iOS and iPadOS devices.
For example, this profile allows you to configure, among other things:
- Accessibility settings
- Associated Domains
- Time Machine settings
- Web Content Filters
NOTE There is a Learn more link at the top of each section that links back to Apple developer documentation on the device management profile for that configuration.
To configure this profile:
- Using the search bar or scrolling through the list manually, select which section you wish to configure using the list on the left
- Click Add Configuration in the upper right.
- Configure the section as desired.
- Repeat the process if you want to add more sections to the profile.
- Click Create to safe the configuration and create the profile.
NOTE You can have multiple system configurations in one profile.
How to...
To create an MDM profile, complete the following steps:
- In your VSA instance, navigate to Administration > Configuration > Profiles.
- The Profiles page will load. At the top of the Folders list, click All Profiles.
- In the Profiles pane, click New Profile.
- The Create New Profile page will load.
- In the Details section, enter a name and a brief description for the profile
- In the Policy Type section, make the following selections:
- Policy Type: Device Configuration
- Configuration Type: Any Apple MDM configuration type
- Click Next.
- Select a configuration section from the Not Configured Sections list. Then, click Add Configuration.
- You'll notice that the selected configuration moves into the Configured Sections list. Complete all applicable fields.
- To add additional configuration sections, click Add Configuration. To remove a section, click the Remove link next to its name.
- When you've finished customizing the profile, click Create.
NOTE For more details on how to configure different Apple MDM profile types, refer to Apple MDM Profile Configuration Settings.
Next, you'll need to create a policy that defines the devices to which you'd like to automatically apply your configuration. Complete the following steps:
- Navigate to Configuration > Policies. Create a new policy or edit an existing policy.
- Click Assign Profile.
- Locate the profile you'd like to use. Select it by clicking the radio button next to its name.
- Click Assign.
- VSA 10 will begin enforcing the selected profile immediately. You can view it in effect at Configuration > Policies.