Apple modifies enrollment procedure for devices running iOS 12 and above

Apple modifies enrollment procedure for devices running iOS 12 and above

The first step to manage devices using Mobile Device Manager Plus (MDM), is to enroll them into the MDM server. The simplest way to enroll devices is either using Self Enrollment or sending enrollment invites to users. Both of these enrollment methods involve an enrollment profile to be installed on the devices.

Till iOS 12, this enrollment profile is automatically installed on devices once the enrollment request is authenticated by the user. While this simplifies the enrollment process, the automatic installation of untrusted profiles gives hackers an opportunity to push malware disguised as profiles into devices.

With iOS 12, the users now have to manually install the profile, giving them a chance to review the details of the profile being installed by MDM. Upon authentication, the downloaded profile will be listed in  Settings . The user can initiate and complete the installation by entering the device passcode. 




A point to remember is that this new workflow is not applicable if devices are enrolled using Apple Configurator and Apple Business Manager, since the profiles installed in these cases are already verified by Apple.

In case you face any trouble while enrolling devices, please contact our Support team for further assistance.
                New to ADManager Plus?

                  New to ADSelfService Plus?