Maas360 and Ios
Total Page:16
File Type:pdf, Size:1020Kb
MaaS360 and iOS A comprehensive guide to Apple iOS Management Table of Contents Introduction Prerequisites Basics and Terminology Integrating MaaS360 with Apple’s Deployment Programs Deployment Settings Enrollment: Manual Enrollment Enrollment: Streamlined Apple Configurator Device View Policy App Management Frequently Asked Questions "Apple’s unified management framework in iOS gives you the best of both worlds: IT is able to configure, manage, and secure devices and control the corporate data flowing through them, while at the same time users are empowered to do great work with the devices they love to use.” -Apple Business “Managing Devices and Corporate Data on iOS” Guide IBM Security / © 2019 IBM Corporation 3 Types of iOS Management “Supervision gives your organization more control iOS supports 3 “styles” of management that will over the iOS, iPadOS, and tvOS devices you own, determine the MDM capabilities on the device. allowing restrictions such as disabling AirDrop or Apple Music, or placing the device in Single App Standard – an out-of-the-box device with no additional Mode. It also provides additional device configurations. Would be enrolled over-the-air via a Safari configurations and features, so you can do things URL or the MaaS360 agent. like silently install apps and filter web usage via a global proxy, to ensure that users’ web traffic stays Supervised – Supervision unlocks the full management within the organization’s guidelines. capabilities available on iOS. Can be automated via the Apple streamlined enrollment program or enabled manually By default, iOS, iPadOS, and tvOS devices are not via Apple configurator. Supervision of an existing device supervised. You can, however, set up devices as always requires a factory restore. supervised prior to activation (before Setup Assistant first appears on a new or fully erased User Enrollment – new on iOS 13. Creates a user profile device)…” with limited device management capabilities. Coming to MaaS360 mid-2020. -Apple Business Manager User Guide IBM Security / © 2019 IBM Corporation 4 IBM MaaS360 and iOS Prerequisites IBM Security / © 2019 IBM Corporation 5 Prerequisites To manage iOS devices, Apple requires an Apple Push Notification service (APNs) certificate. MaaS360 has a wizard to walk you through the process of obtaining this certificate. • Safari, Chrome and Firefox web browsers are recommended for this straightforward process, which usually takes less than 5 minutes to complete. • Detailed step by instructions are available here. • It is strongly recommended that an Apple ID registered to the organization be used, and not an ID belonging to an individual. If a personal Apple ID is used, and the person leaves (rendering it inaccessible), a replacement Apple ID will be required, which can result in devices losing communication with MaaS360, resulting in a manual re-enrollment scenario. The setup and annual renewal of an APNs certificate is an Apple requirement, which is performed via the MaaS360 console. There are no end user steps required when a certificate is renewed. IBM Security / © 2019 IBM Corporation 6 IBM MaaS360 and iOS Getting Started: Basics and Terminology IBM Security / © 2019 IBM Corporation 7 What is Apple Business Manager? What is Apple School Manager? “Apple Business Manager is a simple, web-based Apple School Manager is a simple, web-based portal for IT administrators to deploy iPhone, portal for IT administrators to deploy iPhone, iPad, iPod touch, Apple TV, and Mac computers all iPad, iPod touch, Apple TV, and Mac computers all from one place. When used with your mobile device from one place. When used with your mobile device management (MDM) solution, you can configure management (MDM) solution, you can configure device settings and buy and distribute apps” device settings and buy and distribute apps” -Apple Business Manager User Guide -Apple School Manager User Guide IBM Security / © 2019 IBM Corporation 8 For organizations that will be utilizing Apple School Manager, or Apple Business Manager, enrollment is required: Apple School Manager or Apple Business Manager and work with reseller(s) to ensure devices (existing, or new orders going forward), are flagged as eligible for enrollment Apple Support Resources for Apple Support Resources for Apple Business Manager Apple School Manager Sign in to Apple Business Manager Sign in to Apple School Manager Apple Business Manager Getting Apple School Manager User Guide Started Guide Education Deployment Guide Apple Business Manager User Guide IBM Security / © 2019 IBM Corporation 9 IBM MaaS360 & iOS Key terminology Other terms iOS devices can be enrolled in MaaS360 manually, – Supervised/supervision A – Apple Configurator (AC)/Apple deeper level of management Configurator 2 (AC2) Software converted to supervised status using Apple Configurator for organizationally owned available on macOS devices that 2 software, or supervised over-the-air using Apple’s devices that provides allows for an iOS device to be additional functionality supervised by tethering to the streamlined enrollment programs. The method by which computer. Also allows for a device is enrolled is largely determined by ownership, conversion to ABM supervised where devices procured by the organization are eligible – Apple Business Manager for future over the air (ABM) and Apple School management for enrollment with supervision, and devices that are Manager (ASM) Apple’s personally owned by an end user are enrolled manually streamlined enrollment – Profile A management profile is without supervision. programs that facilitates the piece installed on a device over the air enrollment of either interactive or silently organizationally owned (depending on management devices style), to deliver policy payloads and configurations. The profile is what manages the device – Volume Purchase Program through MaaS360 (VPP) Part of Apple’s deployment programs that – Device Enrollment Program allows administrators to (DEP) & Apple for Education procure licenses for free or Legacy names for Apple’s paid applications from the deployment programs, often iTunes App Store, and used interchangeably with ABM deploy via MaaS360 and ASM IBM Security / © 2019 IBM Corporation 10 Outlined here are Apple Business/School Apple Configurator 2 Manual Enrollment Manager Supervision Supervision some of the key Devices are owned by the end differentiators Devices owned by the Devices owned by the user or cannot be supervised between ABM/ASM Business or Educational Business or Educational for some reason supervised, AC2 Institution Institution, but are not added to ABM/ASM – End user must interact with supervised, and – Profile is installed over the the device to install the manually enrolled iOS air by integrating MaaS360 – Admin must have access to profile during enrollment. devices. with ABM/ASM portal macOS device to install They can remove profile at AC2 app any time. – Provisions devices from start up to force enrollment – Devices must be tethered – Provides more user automatically and create a physically to macOS device focused settings for streamlined enrollment management, in order to experience – Devices must be wiped to protect privacy and prevent factory settings if already in too much control from – Admin must create an use being granted over a Apple account and work consumer device. with reseller to add devices – Allows for supervision of to Apple portal prior to devices that may not be – If devices are truly enrolling eligible for ABM/ASM organizationally owned, there are fewer policy – Devices must be wiped to – Provides ability to convert options available, which factory settings if already devices on iOS 11+ to ABM may prevent a business or activated account, for over the air educational institution from management going forward gaining the level of – Profile can be locked so management they are that user cannot remove looking for IBM Security / © 2019 IBM Corporation management 11 Apple Volume Purchase Program The Apple Volume Purchase Program (VPP) is part of Apple’s deployment programs. It is accessible within the ABM or ASM portal. It provides additional benefits for supervised General Benefits Supervised Benefits devices but can be – Allows administrators to – Deploy and install apps leveraged on non- purchase bulk licenses for silently with no end-user supervised devices as paid public applications, to interaction well. Instructions for avoid end user prompt for integrating Apple VPP with payment. – Device-based licensing MaaS360 can be found means public applications here. – Syncs via token in the can be installed without an MaaS360 portal, so license Apple ID configured on the quantities are kept up to device. date. – Silently “take over” user – Apps can be automatically install apps to make them imported into the MaaS360 managed. app catalog via VPP token, once licenses are obtained IBM Security / © 2019 IBM Corporation in ABM/ASM portal. 12 Deployment Profile The deployment profile for streamlined enrollment needs to be assigned to devices prior to activation (or wipe, in the case of a device that was previously in use). This profile handles the supervision of the device (all devices on 13+ will be supervised automatically, regardless of options selected), along with requiring enrollment, locking the profile, and skipping any startup items that the admin may not want to present to the end user. For complete instructions on creating and managing profiles, view the Apple DEP Setup Guide .in our Security Learning Academy IBM Security /