Ios Deployment Reference Kkapple Inc
Total Page:16
File Type:pdf, Size:1020Kb
iOS Deployment Reference K Apple Inc. The Bluetooth® word mark and logos are registered © 2014 Apple Inc. All rights reserved. trademarks owned by Bluetooth SIG, Inc. and any use of such marks by Apple Inc. is under licence. Apple, the Apple logo, AirDrop, AirPlay, Apple TV, Bonjour, FaceTime, iBooks, iMessage, iPad, iPhone, iPod, iPod touch, IOS is a trademark or registered trademark of Cisco in the U.S. iTunes, Keychain, Mac, MacBook Air, OS X, Passbook, Safari, Siri, and other countries and is used under licence. Spotlight and Xcode are trademarks of Apple Inc., registered in the US and other countries. Other company and product names mentioned herein may be trademarks of their respective companies. AirPrint, iPad Air, iPad mini and Touch ID are trademarks of Apple Inc. Mention of third-party products is for informational purposes only and constitutes neither an endorsement nor AppleCare, iCloud, iTunes Store and iTunes U are service marks a recommendation. Apple assumes no responsibility with of Apple Inc., registered in the U.S. and other countries. regard to the performance or use of these products. All understandings, agreements, or warranties, if any, take place App Store and iBooks Store are service marks of Apple Inc. directly between the vendors and the prospective users. The Apple logo is a trademark of Apple Inc., registered in Every effort has been made to ensure that the information in the U.S. and other countries. Use of the “keyboard” Apple this document is accurate. Apple is not responsible for printing logo (Option-Shift-K) for commercial purposes without the or clerical errors. prior written consent of Apple may constitute trademark infringement and unfair competition in violation of federal and B019-00051/2014-09-09 state laws. Contents 6 Chapter 1: iOS Deployment Reference 6 Introduction 8 Chapter 2: Deployment models 8 Overview 8 Education deployment models 8 Overview 9 Institution-owned one-to-one 11 Student-owned 12 Shared use 14 Enterprise deployment models 14 Overview 14 personalised device (BYOD) 16 personalised device (corporate-owned) 18 Non-personalised device (shared) 21 Chapter 3: Infrastructure and integration 21 Overview 21 Wi-Fi 22 Bonjour 22 AirPlay 24 Digital certificates 25 Single Sign-On (SSO) 26 Standards-based services 26 Microsoft Exchange 29 Virtual private networks (VPN) 29 Overview 29 Supported protocols and authentication methods 29 SSL VPN clients 30 VPN setup guidelines 32 Per App VPN 33 VPN On Demand 33 Overview 33 Stages 33 Rules and actions 34 Backwards compatibility 35 Always-on VPN 35 Overview 35 Deployment models 36 Always-on VPN configuration profile 37 Always-on VPN payload 3 39 Chapter 4: Internet services 39 Overview 39 Apple ID 40 Find My iPhone and Activation Lock 40 iCloud 41 iCloud Backup 41 iCloud Keychain 41 iMessage 41 FaceTime 42 Siri 42 Apple ID for Students 43 Chapter 5: Security 43 Overview 43 Device and data security 46 Network security 47 App security 49 Chapter 6: Configuration and management 49 Overview 49 Setup Assistant and activation 50 Configuration profiles 50 Mobile device management (MDM) 50 Overview 51 Enrol 51 Configure 51 Accounts 52 Queries 52 Management tasks 52 Managed apps 54 Managed books 54 Managed domains 54 Profile Manager 55 Supervise devices 55 Device Enrolment Programme 56 Apple Configurator 57 Chapter 7: App and book distribution 57 Overview 57 Volume Purchase Programme (VPP) 57 Overview 58 Enrol in the Volume Purchase Programme 58 Purchase apps and books in volume 58 Managed distribution 59 Distribute redemption codes 59 Custom B2B apps 60 In-house apps 61 In-house books 61 Deploy apps and books 61 Overview 61 Install apps and books using MDM Contents 4 62 Install apps with Apple Configurator 62 Caching Server 64 Chapter 8: Planning for support 64 Overview 64 AppleCare Help Desk Support 64 AppleCare OS Support 64 AppleCare for iOS device users 65 iOS Direct Service Program 66 Chapter 9: Appendices 66 iOS restrictions 69 Wi-Fi infrastructure 72 Install in-house apps wirelessly Contents 5 iOS Deployment Reference 1 Introduction This reference guide is for IT administrators who want to support iOS devices on their networks. It provides information about deploying and supporting iPad, iPhone and iPod touch in a large- scale organisation such as an enterprise or education organisation. It explains how iOS devices provide integration with your existing infrastructure, comprehensive security, powerful tools for deployment, and methods to distribute apps and books to your employees or students. This guide is divided into the following sections: Deployment models There are several possible ways to deploy iOS devices in your organisation. Regardless of the deployment model you choose, it’s helpful to consider the steps you’ll need to take to ensure that your deployment goes as smoothly as possible. While this guide encompasses all aspects of an iOS deployment, businesses and educational institutions may go about their deployments differently. Infrastructure and integration iOS devices have built-in support for a wide range of network infrastructures. In this section, you’ll learn about iOS-supported technologies and best practices for integrating with Microsoft Exchange, Wi-Fi, VPN and other standard services. Internet services Apple has built a robust set of services to help users get the most out of their devices. These services include iMessage, FaceTime, Siri, iCloud, iCloud Backup and iCloud Keychain. Details about how to setup and manage Apple IDs used to access these services is also covered in this section. Security iOS is designed to securely access corporate services and protect important data. iOS provides strong encryption for data in transmission, proven authentication methods for access to corporate services, and hardware encryption for all data stored on iOS devices. Read this section for an overview about the security-related features of iOS. Configuration and management iOS supports advanced tools and technologies to ensure that iOS devices are easily set up, configured to meet your requirements, and managed with ease in a large-scale environment. This section describes the different tools available for deployment, including an overview of mobile device management (MDM) and the Device Enrolment Programme. 6 App and book distribution There are a number of ways to deploy apps and content throughout your organisation. Programmes from Apple, including the Volume Purchase Programme and the iOS Developer Enterprise Program, let your organisation buy, build and deploy apps and books for your internal users. Use this section to get an in-depth understanding of these programmes and how to deploy apps and books purchased or built for internal use. Planning for support Apple provides a variety of programmes and support options for iOS users. Before deploying devices, find out what’s available for your organisation and plan for any support you’ll need. The following appendices provide technical details and requirements: iOS restrictions Describes the restrictions you can use to configure iOS devices to meet your security, passcode and other requirements. Wi-Fi infrastructure Describes the Wi-Fi standards that iOS supports and considerations for planning a large-scale Wi-Fi network. Install in-house apps wirelessly Describes how to distribute your in-house apps using your own web-based portal. Additional resources • www.apple.com/uk/education/it • www.apple.com/ipad/business/it • www.apple.com/iphone/business/it Chapter 1 iOS Deployment Reference 7 Deployment models 2 Overview Think first about how you’ll distribute and set up devices. There are several options, from pre- configuration to employee or student self-service setup. Explore the possibilities before you get started. The tools and process you use to deploy will also be determined by your particular deployment model. • In education, there are typically three deployment models for iOS devices: Institution-owned one-to-one, Student-owned and Shared use. Although most institutions have a preferred model, you may encounter multiple models within your institution. • In enterprise, there are several possible ways to deploy iOS devices in your organisation. Whether you choose to deploy company-owned devices, share devices among employees or institute a “bring your own device” (BYOD) policy, it’s helpful to consider the steps you’ll need to take to ensure that your deployment goes as smoothly as possible. After the deployment models are identified, your team can explore Apple’s deployment and management capabilities in detail. These tools and programmes are covered extensively within this resource and should be reviewed with the key stakeholders within your organisation. Education deployment models Overview iPad brings an amazing set of tools to the classroom. Choosing the right strategies and tools can help transform the education experience for teachers, students and other users. Whether your educational institution deploys iOS devices to a single classroom or across all years, there are many options to easily deploy and manage devices and content. Deployment models In educational institutions there are three common deployment models for iOS devices: • Institution-owned one-to-one • Student-owned • Shared use While most institutions have a preferred model, you may encounter multiple models within your institution. The following are a few examples of how these models would be applied in a typical education institution: • A school may plan and deploy an institution-owned one-to-one model for all years. • A large education authority may first deploy an institution-owned one-to-one model at a single school, and then roll out identical models for the whole authority. 8 • A primary school may deploy both an institution-owned one-to-one model for years 3-6 and a shared use model up to year 2. • In higher education, it is common to see the student-owned model at the campus or multi-campus levels. Exploring these models in more detail will help you identify the best deployment model for your unique environment.