You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Can Apple Configurator prevent removal of the management profile?

Hi,


I am looking for a YES/NO answer for this question, but so far my research is just a disaster and I hope the community can help me out.


We are tying to configure Ipad's for a school and our goal is to prevent the students from removing the "mobile device management profile" via UI (Settings/Genral). Unfortunately DEP is out of option for us, so we can only use Apple Configurator, In our tests we were not able to prevent the deletion of the "managementprofile" from the UI. See below "Remove Management" section is always there.


User uploaded file


I believe that this is not possible but on the other hand when I do some research I can find some blogs and articles mentioning that this is somehow possible via apple configurator! (example: http://paulciano.org/2014/03/controlling-ios-devices-with-apple-configurator/).


I would really appreciate If someone can shed a light on this.

thanks,

iPad Air, iOS 9.0.2

Posted on Oct 10, 2015 2:13 PM

Reply
8 replies

Sep 21, 2016 7:30 PM in response to jbhnrh

jbhnrh wrote:


There are now two ways profiles cant be removed:


1. The profile was CREATED by Apple Configuator and is password protected

2. The profile is LINKED to a MDM profile that is ENROLLED with DEP.


Neither of these can be removed. If it is a MDM profile but is not enrolled with DEP then the profile will ALWAYS be removable, and that is by design. Apple believes end users should have the OPT-OUT option, unless the devices is enrolled in DEP.


How do you know this?! Where in the world is this actually stated in the documentation? Why doesn't the stupid Server software throw an error and warn you that it's not going to work as intended, if the "MDM profile" (whatever that is) is not enrolled in DEP?


I don't understand. The documentation clearly says that as long as the iOS device is "supervised" then it should be fine. Well, my device is supervised; I set it up to be supervised in the Configurator. Then the Configurator downloads the profile from the server onto the device during the "Preparation" phase. So why can we still erase the **** profile off the device?


This is so frustrating. Why can't Apple do their dang jobs and write adequate documentation for this stuff? If that's going to be their policy then why don't they just say so, so that people don't waste entire days of their lives trying to make it work and diligently following the directions, to no avail? It's so stupid!

Oct 31, 2017 5:20 PM in response to yuan yuo

In Apple Configurator, go to File > New Profile. Under General, there is an option for Security. Click the pop-up menu and choose the option you want for removal: "With Authorization" or "Never." If you choose "With Authorization" a field is added for you to enter a password. Type carefully because there is no field for confirming the password.


Note: The profile must be installed by Apple Configurator for the removal restriction to stay in effect. If you import the profile into a third-party MDM and then push it out to the iPad, the profile becomes part of that MDM's management profiles and removing the management will remove the profile. Installing it with Configurator keeps it separate from the MDM. Unfortunately, that also means remote removal will not be possible.

Oct 10, 2015 3:46 PM in response to tunagezer

We were never able to prevent certain profiles from being removed. I can't remember exactly how they were configured, unfortunately, but when we had iPads in the hands of students, the management profile contained the credentials for the student wireless network. Removing the profile would remove internet access from the device, rendering it pretty useless at school.


Is the management profile being created outside of Apple Configurator and being imported in?


~Lyssa

Oct 11, 2015 12:26 AM in response to Lyssa

thanks Lyssa, yes indeed we use "Microsoft Intune" to create the management profile and import it in to Appple Configurator, there are not many options in Intune console just a bunch of checkboxes during the creation of the profile file. So I am wondering if this is a limitation of Intune or are other MDM's having the same issue due to a limitation of Apple.


Lots of confusing information in the web, actually all I am looking for is a "yes it is possible" or "no it is not", depending on the answer we will build our strategy.


thanks,

Oct 15, 2015 8:06 AM in response to Lyssa

There are now two ways profiles cant be removed:


1. The profile was CREATED by Apple Configuator and is password protected

2. The profile is LINKED to a MDM profile that is ENROLLED with DEP.


Neither of these can be removed. If it is a MDM profile but is not enrolled with DEP then the profile will ALWAYS be removable, and that is by design. Apple believes end users should have the OPT-OUT option, unless the devices is enrolled in DEP.

Can Apple Configurator prevent removal of the management profile?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.