Apple pie or top management’s iPhone management mechanisms

5 min


Apple device management has its own filling specificity. For example, it is impossible to develop an application that would control a device. Control functions are available only for iOS itself. You cannot prevent a user from disconnecting from control. After supervise, you cannot restore data from a backup. And so on.

Under the cut, we will tell you how the management of iOS is arranged and what corporate services Apple is lacking in Russia.

How does iOS control work?

When a company uses more than a dozen mobile devices, administrators lose the desire to configure them manually – install applications, configure Wi-Fi, mail, VPN, etc. In this case, mobility management systems help, one of which we have been producing for ten years. Therefore, we will continue to share our practical, sometimes bitter experience in managing corporate devices.

The main specificity of iOS devices is their owners. As a rule, these people are busy, demanding, versed in everything, but not always technically trained. In short, top managers. Do these features complicate the process of managing iOS devices?

Except for the little things, such as “I won’t give the device more than once to the wrong hands,” “everyone is to blame, except me,” “encouragement is the absence of punishment,” then they do not complicate.

Another feature of iOS devices is the mechanisms for managing IOS devices offered by Apple:

  1. A configuration profile must be installed on the device, which defines the parameters for connecting to the management server. The profile can be installed using a browser, mail, mobile app, or MacBook.

  2. When the profile is installed, the device is registered with the management server. In this case, the device informs the server of a token by which the server can contact the device via APNS (Apple Push Notification Service).

  3. When the management server needs to deliver a command to a device, it notifies the device using APNS.

  4. Having received a notification, the device contacts the server for a command, executes it and reports the result to the server.

The management server must implement Apple’s management protocol and send management command notifications via APNS. Without notifications and APNS, this scheme does not work. An iOS device won’t come for commands by itself. This is not a lordly business. Companies, as a rule, are not happy with the need to provide corporate servers with access to external Internet resources. But in the case of managing iOS devices, there is no alternative. In this case, you need to open the HTTPS and DNS ports of the entire subnet 17.0.0.0/8.

Despite the fact that you cannot manage iOS devices using the application, we and other developers of mobility management systems still have mobile clients for iOS.

With the help of our client application, the user will be able to register in SafePhone and install corporate applications from the server of his company without the App Store.
For example, a self-written EDF client or personalized BI reporting for managers.

The SafePhone client also monitors for signs of jailbreak. When jailbroken in iOS, the sandboxes of various applications no longer protect their private data.
After a jailbreak, applications may appear in the system that have full access to files on the device. Therefore, it is important to automatically delete corporate applications and their data from iOS devices if a jailbreak is detected.

Another management client can be used to collect information about the location of devices. In SafePhone, you can set up working hours for individual departments and employees. The survey of the coordinates of the devices will be carried out strictly according to this schedule.

What are the limitations?

You cannot change the technology for managing iOS devices, so the following restrictions must be taken into account.

The user can disconnect the iOS device from control at any time, and the control server may not know about it. Apple requires the user to be able to independently delete the configuration profile that specifies the settings for connecting iOS to the management server. When deleting a profile, the device sends a disconnect message to the server once. If at this moment the device does not have access to the Internet, the message will not reach the control server.

From the company’s point of view, disconnecting an iOS device from management is usually not a big problem, because it removes all corporate applications and settings from the device. Anything that the company does not want to lose or disclose will be removed along with the ability to manage.

The next block of restrictions is related to the supervised operating mode of iOS. This is a special mode in which more commands and control policies are available. At the same time, as new versions of iOS are released, existing commands and policies begin to require supervised mode.
Therefore, we recommend switching all corporate iOS devices to this mode.
But there is a nuance.

To put an iOS device in supervised mode, you need to connect it with a cable to the MacBook and reflash it using the Apple Configurator 2. If the flashing is performed before the device is handed over to the user, there will be no further problems. But if the company has decided to put corporate devices in supervised mode after giving them to users, there will be no problems.

In supervised mode, you cannot restore data from a backup that was made before this mode was enabled. This is the key problem. Starting with putting the device into supervised mode, the history of its backups begins anew. If the backup contains data that the user needs to work, he will lose access to them. Therefore, it is important to put iOS devices in supervised mode as early as possible. And first of all, the devices of the tops …

What is missing in Russia?

The key corporate service Apple Business Manager is still not available in Russia. We hope that after the “pre-installed” Russian applications on iOS devices, his turn will come.

Apple Business Manager lets you manage your devices from the first start-up. If a company and its devices are registered in Business Manager, then the settings for connecting devices to the corporate management server are communicated to devices immediately upon activation. These devices are activated immediately in supervised mode and it can be made so that the user cannot delete the control settings, i.e. devices will always be under control.

The second major feature of Apple Business is the ability to purchase business apps. Currently, Russian companies cannot centrally purchase applications from the App Store.
If users need paid applications for work, usually the users themselves buy them, and then the spender-employer returns the money with sadness in his eyes.
With the advent of Apple Business Manager, Russian companies will be able to buy software for iOS in a civilized manner, and then use management systems to distribute purchased licenses to corporate devices.

Some Russian companies already use Apple Business Manager, but for this they use their foreign offices. A foreign representative office can register in Apple Business Manager and add to it all corporate iOS devices, including Russian ones. Setting up a European branch for access to Business Manager is probably overkill.
But if it has already been created, connect your devices through it.

Still have questions?

If you still have questions about the use of iOS devices in your company, write to us at sales@niisokb.ru or leave a comment on the article.

We will be grateful to you and will definitely answer.


0 Comments

Leave a Reply