Configuration – UEM Authority https://guides.uemauthority.com Learn. Test. Deploy Thu, 20 Jan 2022 16:22:32 +0000 en-GB hourly 1 https://wordpress.org/?v=6.5.3 https://guides.uemauthority.com/wp-content/uploads/2021/11/cropped-UEM_Authority_Logo_favicon-32x32.png Configuration – UEM Authority https://guides.uemauthority.com 32 32 214635633 Create an iOS Native Mail Profile https://guides.uemauthority.com/knowledge-base/create-an-ios-native-mail-profile/?utm_source=rss&utm_medium=rss&utm_campaign=create-an-ios-native-mail-profile https://guides.uemauthority.com/knowledge-base/create-an-ios-native-mail-profile/#respond Wed, 19 Jan 2022 16:53:20 +0000 http://guides.uemauthority.com/?post_type=ht_kb&p=954 In this guide, we create an iOS Email Profile which will be used to pre-provision the iOS native mail app with our test user account UPN and security type.

Create an iOS Email Profile

Note – The email profile uses the native or built-in email app on the device, and allows users to connect to their work email. This profile will not apply settings for Outlook mobile app.

From the home dashboard, navigate to Devices > Configuration Profiles.

Select the ‘Create Profile’ button.

Select ‘iOS/iPadOS’ as the platform.

Select ‘Email’ as the Profile Type and then select ‘Create’.

Set a Name and Description.
**Example**
Name: iOS – Email Profile
Description: Email profile for iOS devices.

Select ‘Next’

For the purposes of this training course, the following example email profile settings will be set:
**Example**
Exchange ActiveSync account settings

  • Email server: outlook.office365.com
  • Account name: Work Email
  • Username attribute from AAD: User Principal Name
  • Email address attribute from AAD: Primary SMTP Address
  • Authentication method: Username and password
  • SSL: Enable

Exchange ActiveSync profile configuration

  • Exchange data to sync: All data

Select ‘Next’.

Under Assignments, select ‘Add Groups’.

In this example, the ‘Corporate Devices’ group will be selected.

Select ‘Select’ to add your Azure AD Group.

Select ‘Next’ and then ‘Create’.

Once created, you will see the email profile appear in the list ready for use.

See in Action

Note – Device prompts and their wording may change and present slightly different between iOS versions.

Once the email profile has been successfully installed, the device will automatically prompt the user to complete Exchange ActiveSync authentication by asking for a password.

After authentication is complete, within the settings app under Mail > Accounts, we can see our account listed. Drilling down further into detail by selecting the email profile, we can validate the details match the Endpoint Manager deployed email profile.

Moving over to the native mail app, a test email has been received successfully.

Within the Endpoint Manager portal, we can validate the email profile has been successfully installed on the device by navigating to Devices > All Devices.

Selecting the device entry, under Device Configuration on the left side menu, we can see the email profile we created successfully installed.

]]>
https://guides.uemauthority.com/knowledge-base/create-an-ios-native-mail-profile/feed/ 0 954
Create an iOS Configuration Profile https://guides.uemauthority.com/knowledge-base/create-an-ios-configuration-profile/?utm_source=rss&utm_medium=rss&utm_campaign=create-an-ios-configuration-profile https://guides.uemauthority.com/knowledge-base/create-an-ios-configuration-profile/#respond Wed, 19 Jan 2022 16:09:42 +0000 http://guides.uemauthority.com/?post_type=ht_kb&p=950 In this guide, we create an iOS Configuration Profile using the Restrictions profile type in order to define baseline security and device password requirements.

Create an iOS Configuration Profile

Note – Apple iOS/iPadOS supervised mode gives administrators more options when managing Apple devices, making it useful for corporate-owned devices deployed at scale. For example, you can restrict AirDrop or prevent users from changing the name of the device. For a list of settings that require supervised mode, see iOS device restriction settings in Intune.

From the home dashboard, navigate to Devices > Configuration Profiles.

Select the ‘Create Profile’ button.

Select ‘iOS/iPadOS’ as the platform.

Select ‘Device Restrictions’ as the Profile Type and then select ‘Create’.

Set a Name and Description.
**Example**
Name: iOS – Device Restrictions Profile
Description: Device Restrictions profile for iOS devices.

Select ‘Next’

For the purposes of this training course, the following example baseline configuration profile settings will be tailored to an Unsupervised device:
**Example**
App Store, Doc Viewing, Gaming

  • Treat AirDrop as an unmanaged destination: Yes

Cloud and Storage

  • Force encrypted backup: Yes

Password

  • Require password: Yes
  • Block simple passwords: Yes
  • Required password type: Numeric
  • Number of non-alphanumeric characters in password: 1
  • Minimum password length: 6
  • Maximum minutes after screen lock before the password is required: Immediately
  • Maximum minutes of inactivity until screen locks: 5 minutes

Show or Hide Apps

  • Type of apps list: Hidden apps
  • Apps list: (Microsoft kindly provide a list of known Apple native app bundle ID’s)
    • App bundle ID: com.apple.gamecenter
    • App Name: Game Center

Wireless

  • Block data roaming: Yes

Select ‘Next’.

Under Assignments, select ‘Add Groups’.

In this example, the ‘Corporate Devices’ group will be selected.

Select ‘Select’ to add your Azure AD Group.

Select ‘Next’ and then ‘Create’.

Once created, you will see the configuration profile appear in the list ready for use.

See in Action

Installed configuration can be validated on the device by the user. Observing our enrolled device with the setting app, under General > Device Management > Management Profile, we can see “2 Restrictions” and “Password Policy” listed in the Contains list.

Selecting Restrictions, we can further validate device restriction settings match the Endpoint Manager deployed configuration profile we created.

Drilling down into more detail by selecting the password policy, again, we can validate the password policy being enforced on the device matches the Endpoint Manager deployed configuration profile.

Within the Endpoint Manager portal, we can validate the configuration profile has been successfully installed on the device by navigating to Devices > All Devices.

Selecting the device entry, under Device Configuration on the left side menu, we can see the configuration profile we created successfully installed.

]]>
https://guides.uemauthority.com/knowledge-base/create-an-ios-configuration-profile/feed/ 0 950