MDM Primer-02
TweetFollow Us on Twitter

MDM Primer-02

Mobile Device Management (MDM) Primer
Fall, 2011

(continued)

Configuration Profiles

Configuration profiles are lists of settings that IT departments use to quickly set up iOS devices. These profiles may be setup to configure end users' devices to access Microsoft Exchange servers, the corporate VPN tunnel, Wi-Fi networks and corporate resources. Configuration profiles also give IT the ability to lock the settings.

Configuration profiles can be created with the iPhone Configuration Utility (iPCU), a free application for Mac OS X (10.6.x and 10.7.x) and Windows (XP, Vista and 7).


Figure 4 - iPCU Configuration Profiles

What are configuration profiles?

A configuration profile is an XML file that can be used to distribute configuration information to iOS devices. IT administrators will use these configuration profiles to configure specific, single or multiple, settings for iOS devices. Each configuration profile contains one or more "payloads,” which detail out all of the settings that one can possibly set on an iOS device, which include:

  • Passcode - requirement of passcode, simple vs. complex passcode
  • Restrictions - locking down Safari, YouTube, iTunes, installation of apps, deletion of apps, allowed content
  • Wi-Fi - networks SSID's and passwords (any standard 802.11x wireless network)
  • VPN - Cisco IPSec, L2TP, PPTP, SSL VPN
  • Email - Standards-based email, contacts, and calendars (IMAP, POP, CardDAV and CalDAV)
  • Exchange ActiveSync - supporting Exchange Server 2003, 2007 and 2010
  • LDAP - directory service settings
  • CalDAV - calendar service settings for shared calendars
  • CardDAV - group address book
  • Subscribed Calendars - read only access to shared calendars
  • Web clips - URL's to a specific website, shortcut
  • Credentials - PKCS1 and PKCS12 certificates to install on the device
  • SCEP - Simple Certificate Enrollment Protocol allows the device to obtain certificates from a certificate authority
  • Mobile Device Management - configures the device so that its configuration is managed over the air by an MDM server
  • Advanced - Cellular network settings (APN)

Best Practices for Protecting Configuration Profiles

Administrators should sign and/or encrypt a configuration profile to prevent it from being altered or viewed. You can also protect a configuration profile by locking it with a passcode so that an end user can't remove it.


Figure 5 - Setting Security

Signing and encryption

The data on a configuration profile can contain sensitive information such as account information and passwords. iPCU allows three options for exporting out the profiles you have built and protect your data.

A signed profile may only be replaced by another profile with the same Identifier and signed by the same copy of iPCU. iPCU may be used to both encrypt and sign configuration profiles, locking them down to a specific device and preventing others from changing or viewing the settings of the profile.

Security on profiles is available as follows, upon Export:

  • None - Creates a plain text .mobileconfig file that can be installed on any device. Data is not encrypted and may be viewed in any text editor. There is no security in place.
  • Sign configuration profile (good security) - Creates a signed .mobileconfig file that can be installed on any device, provided the profile hasn't been altered. After installation, the profile can be updated only by another profile with the same Identifier and signed by the same copy of iPCU.
 The profile is signed with the public key associated with a device's identity certificate. This public key can be obtained by connection through USB to a computer running iPCU or using over-the-air enrollment.
  • Create and sign encrypted configuration profile for each selected device (best security) - Signs the profile so it cannot be altered, encrypts all the contents so the profile cannot be viewed in a text editor, and can be installed only on specific devices that appear in the Devices list. Separate .mobileconfig files are created for each of the devices you select from the Devices list. In most cases, this is the best option to select and offers the highest amount of security.

Locking Profiles

A profile may also be distributed that's locked to a device so that after it's installed, it can be removed only by wiping the device of all data (full reset) or, by entering a passcode. Locking a configuration profile is recommended to prevent end users from deleting it from a device. The following three choices are available for locking:

  • Always - The end user may remove the profile at any time.
  • With Authorization - Password is set, and needed, for removal of profile.
  • Never - Profile may only be updated with a new version, but not be removed.

Installing configuration profiles

Profiles can be installed via one of several methods:


Figure 6 - Hard-wired USB Connections

  • USB - for smaller installations, this is a viable way of getting payloads onto your mobile devices. As the quantity goes up, the benefits to this method go down and it becomes much more work. This process is, typically, done by IT directly. The USB method is meant for low-quantity deployments, such as 50 or less devices.


    Figure 7 - Wireless Connections

  • Wirelessly - Profiles can be distributed wirelessly via email, website and over the air. When an end user downloads the profile from the web or opens it as an attachment in Mail, the device recognizes the .mobileconfig extension as a profile and begins installation when the user taps Install. If a passcode has been set on the device, the user will be prompted to enter in their credentials.
  • Email - Distribution of profiles via email. The end user receives the email message on the iOS device and then taps on the attachment to install the profile. This process does require the end user to accept and install.
  • Website - Distribution of profiles via a corporate website require the user to follow a specific link to download a profile. The end users can navigate to the web page on their device and then download the profile onto it. This process does require the end user to accept and install.
  • Over the air - IT can use a secure enrollment and configuration process enabled by the Simple Certificate Enrollment Protocol (SCEP) to distribute encrypted configuration profiles over the air. SCEP does require some infrastructure to be setup, but makes the process much easier for IT departments to manage in the long run.

Did you know that the fastest way to get a handle on MDM is through MacTech's seminar series?
MacTech InDepth: Mobile Device Management will do a deep dive on MDM in one day. December 7, 2011 San Francisco, CA. Learn the issues, talk to vendors, be able to make a plan. Save $200 with early bird registration or find out more about the event.

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

How to become the ultimate robot warrior...
Chrono Strike is a delightfully immersive beat ‘em up with a sense of humor (any game with a good Sims reference gets points in my book). [Read more] | Read more »
Tips and tricks to get a higher score in...
Snow Roll is a devilish endless runner very much in the vein of Flappy Bird. It revels in its dastardly level of difficulty, and doesn’t really care how angry you get at it as it knows you’ll keep coming back for more. [Read more] | Read more »
How to win big in Slots Deluxe
Cheating while gambling is illegal and morally wrong, and in some parts of the world it leads to men with names like Vinnie "Six Knuckles" Manchenzo beating you to a pulp in a dark alley. [Read more] | Read more »
How to take over the world in Dictator 2
Running a country isn't easy - especially when you're a dictator who wants to take over the world and crush everyone in your path while you do it. [Read more] | Read more »
Tips and tricks to get a higher score in...
Tank.iois - you guessed it! - another multiplayer arena battler likeAgar.io and Slither.io. It does differentiate itself by putting you in a tiny tank though, so it's not exactly the same. To help you get that all-important high score, we've got a... | Read more »
How to unlock characters in One Tap Tenn...
As the title suggests, One Tap Tennis requires only a single tap to play its particular brand of tennis, and rewards you with a ton of unlockable characters if you perform well. Fortunately for you, we at 148Apps have got a few tips and tricks to... | Read more »
Grab it now: Game Craft’s Legend of War...
The real time strategy game is now available for you to sink your teeth into, through the App Store and Google Play. Combining elements of skill, strategy and empire building, Legend of War is a real gamers’ game. [Read more] | Read more »
Skateboard Party 3 ft. Greg Lutzka (Gam...
Skateboard Party 3 ft. Greg Lutzka 1.0 Device: iOS Universal Category: Games Price: $1.99, Version: 1.0 (iTunes) Description: Skateboard Party is back! This third edition of the popular sports franchise features professional skater... | Read more »
Cubious (Games)
Cubious 1.0 Device: iOS Universal Category: Games Price: $.99, Version: 1.0 (iTunes) Description: Cubious – How smart are you? How high is your IQube? Solve the impossible puzzles to find out, and help a lost little cube find his... | Read more »
Goat Simulator Waste of Space (Games)
Goat Simulator Waste of Space 1.1 Device: iOS Universal Category: Games Price: $4.99, Version: 1.1 (iTunes) Description: ** IMPORTANT - SUPPORTED DEVICESiPhone 4S, iPad 2, iPod Touch 5 or better.** | Read more »

Price Scanner via MacPrices.net

Enterprise Workers Pick Technology Over Perks...
New Adobe study shows surprising attitudes about office jobs and where the future of work is heading. Adobe has released survey findings revealing that a surprising 70 percent of U.S. office workers... Read more
Memorial Day Weekend Sale: $50-$100 off 11-in...
B&H Photo has 13″ and 11″ MacBook Airs with 256GB SSDs on sale for $50-$100 off MSRP. Shipping is free, and B&H charges NY sales tax only: - 11″ 1.6GHz/256GB MacBook Air: $999 $100 off MSRP... Read more
Memorial Day Weekend Sales: Apple MacBook Pro...
B&H Photo has 13″ and 15″ Retina MacBook Pros on sale for up to $210 off MSRP. Shipping is free, and B&H charges NY tax only: - 15″ 2.2GHz Retina MacBook Pro: $1799 $200 off MSRP - 15″ 2.5GHz... Read more
Memorial Day Weekend Sales: Apple iMacs and M...
Take up to $150 off the price of a new iMac or Mac mini at the following Apple resellers this Memorial Day weekend: iMacs: B&H Photo has 21″ and 27″ iMacs on sale for up to $150 off MSRP... Read more
Apple refurbished Retina MacBook Pros availab...
Apple has Certified Refurbished 2015 13″ and 15″ Retina MacBook Pros available for up to $380 off the cost of new models. An Apple one-year warranty is included with each model, and shipping is free... Read more
Apple refurbished 11-inch MacBook Airs availa...
Apple has Certified Refurbished 11″ MacBook Airs (the latest models), available for up to $170 off the cost of new models. An Apple one-year warranty is included with each MacBook, and shipping is... Read more
Goal Zero and OtterBox Partner to Expand iPh...
Goal Zero, specialists in portable power, have announced a partnership with OtterBox, brand smartphone case protection, to offer the Slide and Slide Plus Batteries as modules compatible with the new... Read more
15-inch Retina MacBook Pros on sale for up to...
B&H Photo has 15″ Retina MacBook Pros on sale for up to $210 off MSRP. Shipping is free, and B&H charges NY tax only: - 15″ 2.2GHz Retina MacBook Pro: $1799 $200 off MSRP - 15″ 2.5GHz Retina... Read more
Clearance 2015 13-inch MacBook Airs available...
B&H Photo has clearance 2015 13″ MacBook Airs available for $250 off original MSRP. Shipping is free, and B&H charges NY sales tax only: - 13″ 1.6GHz/4GB/128GB MacBook Air (MJVE2LL/A): $799... Read more
Apple refurbished Apple TVs available for up...
Apple has Certified Refurbished 32GB and 64GB Apple TVs available for up to $30 off the cost of new models. Apple’s standard one-year warranty is included with each model, and shipping is free: -... Read more

Jobs Board

*Apple* Solutions Consultant - APPLE (United...
Job Summary As an Apple Solutions Consultant, you'll be the link between our future customers and our products. You'll showcase your entrepreneurial spirit as you Read more
*Apple* Project Engineer - Smart Source Inc...
SmartSource is in need of an Apple Project Engineer for a 12 month contract opportunity in Pittsburg, PA. Role: Apple Project Engineer Location: Pittsburg, PA Read more
Automotive Sales Consultant - Apple Ford Linc...
…you. The best candidates are smart, technologically savvy and are customer focused. Apple Ford Lincoln Apple Valley is different, because: $30,000 annual salary Read more
Service Assistant - *Apple* Chevrolet *App...
Apple Automotive is one of the fastest growing dealer...and it shows. Consider making the switch to the Apple Automotive Group today! At Apple Automotive, we Read more
Editor, *Apple* News - APPLE (United States...
Job Summary The Apple News team is looking for a passionate and knowledgeable editor with experience covering entertainment/pop culture and experience running social Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.