Able to remove profile without the need for a password

I'm currently running into an issue with Mobile Device Management in Lion Server with remotely managing the new 30 unit iPad cart our school just purchased.


I'm able to attached the iPad's to the MDM server and the profile applies just fine. But I'm able to easily REMOVE the profile(s) from the iPad without the need for a password, even though I've configured one.


Three profiles get applied. 1) The organization profile 2nd) The Remote Management profile 3rd) the iPad specific settings I've set.


The 3rd profile has a password set so that removal requires me entering the password. But I'm able to remove profile 1 and 2 WITHOUT the need for a password and then profile 3 automatically removes along with it.


Has anyone else run into this issue? According to Apple Care, this is by design. Maybe it is, but it seems like a HUGE design flaw in my opinion.

iPad 2, iOS 5.1, Lion Server - Mobile Device Manager

Posted on May 2, 2012 8:49 AM

Reply
24 replies

May 2, 2012 10:00 AM in response to gyrhead

gyrhead...


Maybe I'm doing something wrong. In the Profile Manager on the server, I've set the following:


Under Devices -> iPad 01 (name of iPad unit ) -> Profile -> Edit -> Settings for iPad 01 -> General -> Security WITH Authorization and I've set a password


Under Device Group -> iPad Cart ( Name of Group ) -> Porfile -> Edit -> Settings for iPad Cart -> General -> Security WITH Authorization and I've set a password


Under User -> My User Name -> Profile -> Edit -> Settings for My User Name -> General -> Security WITH Authorization and I've set a password


I then goto http://<myservername.tld>/mydevices -> Profiles -> Trust Profile for <My Organization> -> Install... It then installs the certificate


I then go back to http://<myservername.tld>/mydevices -> Devices -> and I click Enroll -> it now enrolls the device


When I goto General -> Profile, I see three certicates:


- Trust relationship for My Organization

- Remote Management

- iPad Cart Settings


iPad Cart Settings requires me to enter a password to remove it. But removing the Trust Relationship or Remote Management does NOT. And after removing Remote Management, iPad Cart Settings are automatically removed as well, without needing the password I set.


What am I doing wrong?

May 2, 2012 11:12 AM in response to Hermits

Unfortunately you are not doing anything wrong, even with the high end MDM providers such as Airwatch there is not a way to password protect the primary trust certificate to prevent its removal. Once the upper level certificate is removed the rest go with it.

This is an Apple issue, driven by the philosophy that the end user should have ultimate privacy and control. In your case you will have to go in and manually enable restrictions if you want to ensure that controllable settings can't be changed if the profiles are removed. You may also be able to make it so the iPad can't connect to the network if its profiles have been deleted, this might deter students from deleting them.

May 2, 2012 11:35 AM in response to gyrhead

I'll take a look at this gyrhead... While knowing if a device was removed from the MDM is good, I need to prevent it all together.


The I.T. Department at my school is small. If even one iPad per class peroid was removed from the MDM, it would be extremely troublesome for us.


If even they made it where the Settings app was password protected, in order to access it, that would help greatly!

May 2, 2012 11:50 AM in response to Hermits

We have an IT department of 1 (yours truly). Over 600 mobile devices (ipads and laptops) to manage. I feel your pain. I looked at Airwatch and the rep said the end user could delete the profile and the Airwatch MDM agent app unless I went on each iPad and manually enabled restrictions with deleting apps disabled. I may end up doing this just to save time in the long run.

May 2, 2012 11:58 AM in response to gyrhead

So if I understand you correctly, you can prevent MDM removal using AirWatch by setting restrictions on the iPad that they cant delete apps?


If the answer to this is yes, you might have just found my solution! 🙂 I dont see where restricting users from being able to delete apps will be a problem at all. Infact, it might be an additional plus! 🙂

May 2, 2012 12:17 PM in response to Hermits

Airwatch has an MDM agent app ( see it in itunes) that works with their console. Some MDM solutions don't use an agent app, just a profile. You should definitely verify and see a demo or trial - this is just based on a question I asked when viewing an Airwatch webinar. I always go in and manually enable restrictions in environments like the middle school to prevent adding and deleting apps. I am probably going to go ahead with Airwatch as soon as budget conditions allow. They have a free trial.

http://www.air-watch.com/solutions/apple-ios

May 10, 2012 4:37 AM in response to gyrhead

gyrhead...


I just wanted to update this thread. After spending some time looking into AirWatch, it doesn't look like its a solution for what we've been discussing here. Unfortunately, there doesn't appear to be ANY solution to this problem. Not until Apple decides to either allow 3rd party solutions to be implamented, or implaments it themselves, will there be a solution to it.


I dont want to make it sound like AirWatch is not a good product. From my research, they appear to be a very good solution... Just not a solution to this particular problem.

May 14, 2012 11:04 AM in response to gyrhead

I've ran into these same issues myself. I'm currently using Meraki to manage our 450+ iPads now, but may be transitioning to Microsoft System Center 2012 once we finish planning and roll out that monster. MDM is supposed to be a decent part of the package.


Just chiming in though because you're not alone in this struggle. What I also found extermely annoying is that I can disable App installs through the MDM which would save teachers time since their students wouldn't install crap (read: games) on the devices, but at the same time I found that it would not even let me sync "install" the Apps which made it a no-go for us.

May 14, 2012 11:14 AM in response to cryohazard

Cryohazard...


Thanks for the solidarity 🙂


I'm currently running SCCM 2007... I wasn't aware that SCCM 2012 was going to have a MDM built into it 🙂


Unfortunately, I dont expect that even if SCCM 2012 will have MDM, that will solve this issue. It appears that its not a problem that 3rd party developers have slacked on adding, but that Apple refuses to allow it to happen. So long as that's the case, I dont see anything changing anytime soon.

Jan 9, 2013 8:26 AM in response to Hermits

I wanted to chime in with everyone, we have at this time about 1,600 iPads deployed for 7th-12th. We currently have the Casper Suite from Jamf Software, and we have the same issue. The students can simply remove the MDM profile and this removes all the restrictions we have in place. To make things worse, if a student sync's their iPad with their PC it removed the profiles as well.

Jan 9, 2013 8:36 AM in response to WaylandNetAdmin

I also found that as teachers were trying to save themselves time they did backup/restores which removed MDM profiles. Which caused more work for them in the end because I then asked them to re-register with the MDM. Whether they did that or not I don't know. I don't have the time or energy to verify that they've done that.


I also found the naming of devices very problematic. I had named all devices based on barcode (since the barcode is covered once you put a case on) and they have sinced named them "UserName iPad 1", "UserName iPad 2", etc. That means nothing to me people! My brain works in barcodes.


I cautioned against going with Casper in the beginning because I wanted to test a free product first to see if it would meet my needs. While it's disappointing that the paid services can also be easily removed, it's nice that you chimed in and I can show this post to the powers-that-be when they ask to ramp this program up or look at buying Casper.


If you read this reply, would you be able to let me know if Casper does push-install of Apps or if it does push-suggestions? What I mean is does it install without user interaction or does the user still have to agree to install and then type in Apple ID password?

Feb 14, 2013 1:15 AM in response to Hermits

Hi, I thought I'd put my two cents in as well. We have about 40 iPads set up for student use and we use profile manager on an OSX Server, I have come up against all the restrictions that you're discussing and the only solution we have found is that there is no solution...Yet. It's up to apple to change the spec of the xml profiles so that they include additional features.


Because it's an apple limitation all MDM solutions are basically exactly the same, however there do seem to be a few small differences like Meraki's ability to alert you of profile deletion, and also the ability of a lot of 3rd party MDM's to support other platforms like Windows and Android.


In our IT department we're currently upgrading SCCM to 2012 sp1 so that we can use the mdm features and although I don't know much about it yet we're looking at Windows Intune to give us the cloud based interface and tie it all in together with our existing network.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Able to remove profile without the need for a password

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.