Moslye Education

Mosyle MSP Training program for MSP Exam

Getting Started

Getting Started

What's needed before you get started

Welcome to the Mosyle Education Certification! Before getting started it's recommended that you have access to the following items so you can apply the skills and knowledge while learning to ensure full understanding.

Throughout the Mosyle Education Certification we'll be walking through a number of settings that can be managed using Mosyle MDM and how they are configured. It is recommended to have access to your Mosyle Education account, and test devices available to apply various configurations to the devices, which may include erasing the device. Please be sure the devices used while completing the certification are test devices that won't be impacted if they are erased.

Getting Started

Network Requirements

In order for devices to successfully communicate with Mosyle and Apple, the following domains and ports will need to be released. Mosyle utilizes dynamic load balancing, therefore we do not have a specific IP range as servers can be added or removed at any time. It's recommended to release the Mosyle wildcard in the network to ensure all Mosyle domains and subdomains are allowed.

Required Mosyle domains:

Required domains for the Mosyle CDN:

Required Ports:

Service Name Port Protocol
Web Service (http) 80 TCP
Web Service (https) 443 TCP
Push Notification 2195, 2196, and 2197 TCP
Mosyle macOS Agent Push Notification 3000 TCP
MDM Enroll 1640 TCP
APNs 5223 TCP
Internet Control (Web Filter) 3180 TCP
Apple Classroom 3284 and 3285 TCP/UDP

Required Apple domains:

Be sure to release the entire IP range for Apple: 17.0.0.0/8, as well as all ports used by Apple software products which can be found here: https://support.apple.com/en-us/HT202944

It's also recommend to release all hosts and ports used for Apple products on Enterprise networks, which can be found here: https://support.apple.com/en-us/HT210060

Getting Started

Hardware and Software Requirements

To ensure the best experience, it's recommended to keep devices updated to the latest OS version as some features have specific operating system requirements.

However, the following devices can be enrolled in Mosyle:

NOTE: The Mosyle Education macOS agent is officially tested and supported on the two latest versions of macOS. It can be installed on macOS versions prior to this, however, the functionality of the agent on macOS versions earlier than the previous two is unknown.

Intro to Mosyle Education

Intro to Mosyle Education

Navigating the Interface

Mosyle Education is organized into 7 tabs which can be accessed using the bottom menu bar within the platform:

NOTE: The Security and DNS Filtering tabs are available only for Mosyle OneK12 subscriptions.

Dashboard

The Dashboard for each account can be customized to show the school or district logo in the upper left corner. Any MDM Alerts for iOS/iPadOS, macOS, or tvOS will be available directly in the dashboard. Clicking on any of the alerts will bring additional details showing which devices are impacted.

The number of licenses available, as well as the number of enrolled devices per OS platform will be displayed in the upper middle, with quick access to your favorite Management profiles directly underneath. Clicking any of the favorited profiles will result in being redirected to the Management profile in order to view any details or make any necessary edits or adjustments.

On the right side of the dashboard, the metrics for the security of your devices will be displayed, such as the Device Scout score of your enrolled devices and any infections found by Detection & Removal. Clicking either of these options will redirect you to the appropriate area within the Security tab.

Directly below the security metrics will be access to any/all support tickets submitted and show the status of the ticket. Click any of the ticket titles to bring up the ticket thread, or click the button to Go to Support to navigate to the Support tab.

In the upper right hand corner, you'll see the name of the user currently logged into the Mosyle web panel as well as the time remaining in the session. Clicking Settings will bring up account settings such as the timezone, date and time formatting, two-factor authentication, and the option to change the password. To logout, click Logout.

My School

The My School tab includes all information relevant to your school or district. Within this tab, you can:

Management

The Management tab is where all device information and configuration can be found. Here you can:

The Management tab is separated based on OS so only relevant profiles and commands are available based on which OS is being managed. To navigate between the different OS platforms, click the dropdown menu in the top left.

Security

The Security tab provides access to configure and manage Device Scout, Detection & Removal, and Admin On-Demand.

DNS Filtering

The DNS Filtering tab provides access to configure and manage DNS Filtering configurations.

Class Manager

The Class Manager provides access to Class Management tools for teachers.

Support

The Support tab provides access to all content available in the Help Center as well as direct access to the Mosyle Support Team via tickets.

Intro to Mosyle Education

Account organization and profile assignments

Mosyle is organized so that the management and configurations of devices is as intuitive as possible, allowing you to assign configurations based on the user who is using the device, the grade level or class the assigned user is associated with, or the shared device group or dynamic device group the device belongs to.

By importing user data, all users are organized just as they are in your directory service - including grade levels, courses, and classes. This data can then be used for device assignment, as well as profile and configuration assignment.

In Mosyle, all device management and configurations start with the creation of “management profiles”. When creating the management profile, you can define the necessary configurations and settings and then assign the profile to any users, grade levels, classes, devices, shared device groups, dynamic device groups, etc. as needed. This way devices will automatically receive the configuration when the user is assigned to the device, or the device is assigned to a shared or dynamic device group.

Use the dropdown to navigate between the Device Enrollment and User Enrollment to target devices based on the enrollment method used.

device-enrollment.png

Intro to Mosyle Education

Supported features and Apple integrations

Mosyle fully supports integrating with Apple School Manager for device management and enrollment (MDM server tokens), and Apps and Books management (Apps and Books content tokens). Support for multiple tokens is also available.

On iOS and iPadOS devices, Mosyle utilizes the full Apple MDM Protocol for management functionality. You can choose to deploy the Mosyle Manager application to obtain additional information, such as bluetooth status, WiFi SSID, location information, and allow messages/notifications to be sent. The Mosyle Manager application is not required in order for Mosyle to manage iPhone and iPad devices.

If you decide to deploy the Mosyle Manager application to the iOS/iPadOS devices, you can obtain the free licenses in Apple School Manager and configure the Automatic Installation profile under the Management tab > Install App.

graph.png

On macOS devices, Mosyle fully supports Apple's MDM Protocol while also utilizing our Mosyle MDM agent to provide additional management functionality that may not be currently available through MDM Protocol. The agent is not required in order for Mosyle to manage Mac computers via MDM Protocol.

The Mosyle agent is automatically installed alongside the Mosyle Manager application on macOS devices enrolled via Device Enrollment or Automated Device Enrollment. You can request to reinstall the agent on devices at any time by clicking the option to “Resend Manager agent”. The agent is required for the following management options and features:

Additional features and functionality supported by Mosyle's agent can be added in the future.

NOTE: The Mosyle Education macOS agent is officially tested and supported on the two latest versions of macOS. It can be installed on macOS versions prior to this, however, the functionality of the agent on macOS versions earlier than the previous two is unknown.

Intro to Mosyle Education

Mosyle Manager app & Self-Service

The Mosyle Self-Service is available for devices enrolled via Device Enrollment. Self-Service can be accessed using the Mosyle Manager app on iOS/iPadOS devices and through the Manager.app on macOS devices. Self-Service provides Administrators with the ability to allow end users to request the installation of apps, web clips, profiles, and more.

manager-app.png

iOS/iPadOS

The Mosyle Manager application is not automatically installed on iOS/iPadOS devices. By default, devices enrolled will receive a Mosyle web clip so users can access Self-Service. If the Mosyle Manager App Installation profile is configured and the app deployed to devices, the web clip will be removed.

To configure the automatic installation of the Mosyle Manager app, first obtain licenses for the app in Apple School Manager. Once licenses are available and the Apps and Books token is integrated, go to Management > Install App (iOS/iPadOS) > Click Edit Configuration for the Mosyle Manager App Automatic Installation profile. Choose the Apps and Books token to use for licensing and assign the configuration to users/devices. Click Save.

automatic-installation.png

macOS

The Manager.app is automatically installed on macOS devices enrolled using Automated Device Enrollment and Device Enrollment. If needed, it can be reinstalled on devices using the command in Management > Devices > Devices Overview > Resend Manager agent.

resend.png

Intro to Mosyle Education

Configuring Account Preferences

Account wide preferences can be configured under My School > Preferences. Options available include:

Intro to Mosyle Education

Subscription Models


Mosyle Education has three subscription options - Free, Premium, and OneK12. More information about subscription options can be found here: https://school.mosyle.com/pricing

Planning your Deployment

Planning your Deployment

Introduction

The basis for any deployment includes the following:

The following sections provide information on what can be accomplished using Mosyle for your deployment to help with the discussion and decision-making for the questions above.

Planning your Deployment

Enrollment Methods

When planning your deployment, you need to consider how the devices will be enrolled. When possible, it's always recommended to erase devices and enroll them fresh into the MDM using Automated Device Enrollment. If it's not possible, you can use any other enrollment method.

Most deployments utilize Automated Device Enrollment or some combination of Automated Device Enrollment and Device Enrollment.

Automated Device Enrollment

Mosyle supports Automated Device Enrollment which provides the ability to enroll devices over-the-air by syncing an enrollment profile with Apple servers. Using Automated Device Enrollment, users can easily complete enrollment by erasing the device and then going through the Setup Assistant. After connecting the device to a network connection, it will retrieve the enrollment profile from Apple servers and complete the enrollment. With Automated Device Enrollment, devices can be handed directly to users so they can complete the enrollment to accomplish a zero-touch deployment.

Enrolling with Automated Device Enrollment locks the MDM enrollment profile on the device so that it cannot be manually removed by the user.

NOTES:

Device Enrollment

If erasing devices is not possible, you can still enroll them using Device Enrollment. For iPhone and iPad devices, you can complete enrollment using Apple Configurator 2 or by entering the Safari enrollment URL. For Mac computers, you can complete enrollment by entering the Safari enrollment URL and manually installing the MDM enrollment profile. Users will need Admin rights to complete the installation of the MDM enrollment profile.

This method of enrollment requires a more hands-on approach to ensure users are properly installing the MDM profile. Keep in mind, the MDM enrollment profile cannot be locked on the device and can be manually removed when using this method of enrollment.

User Enrollment

Users can complete User Enrollment by logging in to the device or specified URL with their Managed Apple ID. User Enrollment is beneficial in environments where students or teachers bring their own devices and need access to school or district resources, such as apps or books.

User Enrollment requires users to be registered in Mosyle with their school/district Managed Apple ID.

Planning your Deployment

Authentication & Assignment Options

As mentioned, Mosyle is organized to make management and the configuration of devices as intuitive as possible, allowing you to assign configurations based on the user who is using the device, the grade level or class the assigned user is associated with, or the shared device group or dynamic device group the device belongs to.

Since configurations can be assigned to specific users, it's important users are assigned or associated with the specific device, or devices, they use. Assignment of devices can be fully automated so that students or teachers simply authenticate with their school credentials and Mosyle will automatically pair them with the device. In order to do this, users must be imported into Mosyle.

An ideal zero-touch deployment flow would include users imported into Mosyle and devices enrolled using Automated Device Enrollment, along with prompting users for authentication during the enrollment in order to complete the device assignment. From there, management profiles and applications that are assigned to the user will automatically be deployed upon device enrollment. This enrollment example is dependent on the user completing the device enrollment.

If the IT team or a provisioning service will be enrolling devices, user authentication during enrollment may not be ideal. Instead, device assignment can be completed by students or teachers authenticating in the Mosyle Manager app on iOS/iPadOS or via a login event on macOS, either through the native macOS login window or Mosyle Auth.

Planning your Deployment

Integrations

Mosyle supports integration with Apple School Manager and Active Directory to import students, teachers, staff, grade levels, and classes. If the school data is not available in ASM or Active Directory, it can be created manually within the web panel, or in bulk using the Spreadsheet import or API integration.

When importing users, it's important to ensure the correct email address and user ID is imported in Mosyle. If app and book deployment using user-based license assignment will be used, or User Enrollment will be used, it's important to also import the user's Managed Apple ID.

Planning your Deployment

Management Profiles and Configurations

Any and all configurations and profiles created and assigned to the device will be applied immediately upon enrollment. Configurations and profiles assigned to the user, grade level, course/class, or shared device group will be applied once the device is assigned to the user or shared device group.

This allows you to build out all management configurations needed so that once devices are enrolled and assigned, they will be provisioned and protected as expected and ready for use.

Setting up a Mosyle account

Setting up a Mosyle account

Apple Integrations

When renewing the Push Certificate, be sure to confirm the Push Certificate ID in Apple's Push Portal to make sure it matches the topic UDID shown in the Mosyle interface. If it's not possible to renew the original Push Certificate, the devices will need to be re-enrolled in Mosyle.

push.png

NOTE: For the security of customer accounts, MSPs do not have access to the Push Certificate area when accessing the account from the Mosyle Partner Portal.

Resources


Apple School Manager (ASM)


To enroll devices using Automated Device Enrollment, an MDM server for Mosyle must be created in ASM and the MDM server token must be integrated into Mosyle.

Complete the steps below to integrate your Apple School Manager account with Mosyle:

  1. Go to My School > Apple Basic Setup
  2. Click Apple School Manager
  3. Click “Add new account” and follow the on-screen instructions

Once the Mosyle MDM server is created in Apple School Manager you can assign devices to the Mosyle MDM within Apple School Manager. For more information about assigning devices to an MDM server in Apple School Manager, check Apple's documentation.

Additional MDM server tokens can be integrated in Mosyle from Apple School Manager using the steps above.

To restrict access to the Apple School Manager token to make changes, update, or renew the token, click the integration under My School > Apple Basic Setup > Apple School Manager, and uncheck the box for “All current and future locations”. Select only the locations to have access to the integration. Location Leaders not assigned to the specified locations will not have access to the token.

After integrating the token from Apple School Manager into Mosyle, you can click it at anytime to view the following information:

Syncing data from Apple School Manager

The Apple School Manager integration provides the opportunity to sync students and teachers, along with any class roster data that has been imported to Apple School Manager directly into Mosyle. After integrating the MDM server token into Mosyle, go to My School > Apple School Manager > Click “Sync Hierarchy”. Within this screen you can edit any sync preferences or manually pull fresh data and start the import.

Enrolling devices from Apple School Manager

To view devices assigned to the Mosyle MDM server from ASM, and the status of the enrollment profile, go to My School > Apple Basic Setup > Enrollment > Automated Device Enrollment > View devices. The status of each device is displayed and is color-coded for quick and easy status identification. Mosyle will automatically sync with Apple servers every 2-3 hours to update this information. If you have recently assigned devices to Mosyle and need to configure them immediately, click Update to request a sync.

In order for the device to successfully enroll in the Mosyle MDM using Automated Device Enrollment, the enrollment profile must be synced with Apple servers. When devices are erased and connect to WiFi, or the Terminal command is used on macOS, they will reach out to Apple's cloud configuration servers to retrieve any enrollment information. So long as the Automated Device Enrollment profile is synced with Apple server's the device should proceed through Remote Management during the setup.

If you run into any issues during the enrollment process, please check the Help Center and/or get in touch with our Support Team via tickets.

Apple Apps and Books


In order to install apps or books on devices using licenses purchased in Apple School Manager, the Apps and Books content token must be integrated in Mosyle.

Complete the steps below to integrate your Apple School Manager account with Mosyle:

  1. Go to Management > Applications
  2. Click Apple Apps and Books (VPP)
  3. Click “Add account” and follow the on-screen instructions

Once the Apps and Books content token is integrated into Mosyle, app and book licenses will be available for distribution. Additional Apps and Books tokens can be integrated in Mosyle from Apple School Manager using the steps above.

IMPORTANT: The Apps and Books content token from Apple School Manager should only be integrated in one MDM solution at a time to prevent licensing conflicts. Even if the token shows unclaimed or revoked from another solution, it's recommended to fully delete it to avoid conflicts.

To restrict access to the Apps and Books token to install apps, or make changes to the token, click “Edit” for the integration under Management > Applications > Apple Apps and Books (VPP), and uncheck the box for “All current and future locations”. Select only the locations to have access to the integration. Location Leaders not assigned to the specified location(s) will not have access to the token. Licenses for apps and/or books from the token will be unable to be assigned to users or devices not associated with the specified location(s).

To manage teacher access to the licenses available in the Apps and Books token, you can check or uncheck the box “Allow teachers to use the licenses from this account to install applications from the "Study Apps" list when starting a class. All licenses will be assigned using the method "device based"”. With this option checked, teachers will be able to select apps available on the Apps and Books token to include in their list of Study Apps in the Mosyle Class Manager.

After integrating the content token from Apple School Manager into Mosyle, you can click “Edit” at anytime to view the following information:

Clicking the token integration will display more information regarding the apps and books purchased along with the licensing information, such as how many licenses used versus how many licenses available.

The Invites tab will show a list of users to whom invites have been sent and are either pending acceptance or have been accepted. Invites are required in order to utilize user-based assignment of app or book licenses. When sending invites, you have the option to email the invite to the user so that it can be accepted with their consumer Apple ID so that licenses can be assigned; or you can automatically invite users via their Managed Apple ID that was created in the same Apple School Manager account as the Apps and Books token. Invites can be downloaded, resent, or revoked by selecting the checkbox of the invite and clicking the corresponding icon.

Licenses will be assigned to the Apple ID that is used to accept the invite. Therefore, it is critical that invites are accepted with the same Apple ID logged in on the device to ensure the content downloads. If the invite is accepted with a different Apple ID than what is logged in on the device, the app or book will not download.

NOTE: Books can only be assigned via user-based license assignment and licenses cannot be revoked.

Token Integration


After the MDM server token or Apps and Books token is integrated into Mosyle, it will need to be renewed annually. It is not necessary for the same user to renew the token each year.

If the user who integrated the token changes their password in ASM, their role/permissions change, or is deleted, the token will be invalidated and a new token will need to be integrated. Additionally, for security purposes, any time a new token is downloaded from ASM, the previous token will be revoked.

Setting up a Mosyle account

Other Integrations

Purpose


Mosyle is organized so the management of devices is as intuitive as possible, allowing you to assign configurations based on the user who is using the device and/or the location, grade level, or class the user is associated with. Since configurations can be assigned to specific users and/or their association with a grade level or class, or to a specific group of shared devices, it's important users are assigned or associated with the specific device or devices they use and/or devices are assigned to the appropriate shared device group. Assignment of devices can be fully automated so that users simply authenticate with their school or district credentials and Mosyle will automatically pair the user with the device. In order to do this, users must be imported into Mosyle.

You can quickly import users, locations, grade levels, and courses/classes from Apple School Manager using the ASM integration. If your data has not been imported into Apple School Manager, you can use Active Directory, the Mosyle API, a Spreadsheet import, or create any hierarchical data manually if needed.

Once the school or district data is imported into Mosyle and devices are assigned to their corresponding user, you can effectively scope configurations based on the specific user needs. For example:

Resources


Configuring Apple School Manager Integration


Location, Grade Levels, Courses/Classes, and Users can be imported into Mosyle from Apple School Manager. Apple School Manager provides multiple methods for importing the school or district data, including from a Student Information System (SIS) directly into ASM, using an SFTP upload, or importing users from Google Workspace or Microsoft Azure AD

When importing data from ASM into Mosyle, in order for a user to be properly assigned to a location, grade level, and user type (Student or Teacher), they must be associated with a Class. Currently, ASM does not provide information regarding a user's type or location. In order to correctly import users as Students or Teachers and assign them to the appropriate location and grade level within Mosyle, the user's association with a Class is used to infer the user type and location. If users are not assigned to a Class, they will not be imported unless the option to “Import Users without a Location” is selected in the Sync Parameters.

Complete the steps below to import data into Mosyle from Apple School Manager:

  1. If the MDM server has already been created in Apple School Manager, skip this step and go to step 2. Otherwise, go to My School > Apple Basic Setup > Apple School Manager > Add new account. Follow the on-screen instructions to complete the integration.
  2. After the integration is complete, click Sync Hierarchy under the Apple School Manager token
  3. Click "Edit Sync Preferences" to configure the following settings:
    • Sync automatically: configure the time of day the daily automatic sync will run
    • Only add new data and do not edit existing data
    • User ID (Identifier): Choose what to use for the user's ID when syncing data from ASM. Choices include Person Number, Person ID, Managed Apple ID Prefix, SIS username, Email address, Managed Apple ID.
    • E-mail: Choose what to use for the user's email address when syncing data from ASM. Choices include the same e-mail address registered in ASM, the Managed Apple ID, or the Managed Apple ID without the subdomain. Students are not required to have an email address registered in Mosyle, click the checkbox “Do not import email attribute for students” if you do not wish to have the student email addresses imported into Mosyle.
    • User without Location: This option exists due to Mosyle being unable to import users unless a class is assigned. Select this option if you have users without a class that need to be imported into Mosyle. The users will be imported without any grade level or location assigned.
    • Class Period Name: Choose what to use for the name of the class when syncing data from ASM. Choices include Class ID, Class Number, Name, or Display Name.
    • Locations to Sync: Check the box next to all locations to be synced from ASM. Locations not selected will not be imported.

Once the integration is completely set up, you can click Pull fresh data to preview the data to be imported into Mosyle. If needed, make any necessary changes under “Edit Sync Preferences” and Pull fresh data again. When all data in the preview looks correct, click Start Integration to begin importing the data.

Mosyle identifies users via the user ID and/or the email address. In the event a user's information needs to be updated, make the changes as needed in Apple School Manager or in the Sync Parameters, making sure at least one of the identifiers remain the same. Pull fresh data and complete the integration to update the user.

Configuring Active Directory Integration


Complete the steps below to add an Active Directory integration and import users, grade levels, and/or class periods into Mosyle Education:

  1. Go to My School > Integrations > + Activate New Integration
  2. Select Active Directory
  3. After Activating the integration, click “Add new profile” > Active Directory LDAP

When configuring the Active Directory integration three tabs will be available, two of which need to be configured to successfully import users and user groups: Setup and Synchronization. The Setup tab is where the Active Directory server information will be added. Be sure to release the IPs listed in the interface so that Mosyle is able to establish a connection. Mosyle only supports secure connections (LDAPS or LDAP over TLS).

The Synchronization tab is where mapping and configurations will be made to import users, grade levels, and/or class periods. In this area you can specify the following sync options:

When completing the mapping, filter the users, grade levels, and/or class periods by specific filters or attributes so that only the users and groups you wish to import are imported into Mosyle.

Once the integration is completely set up, you can click the integration name to request a fresh data sync and import users.

Configure the Authentication tab to allow users to authenticate in Mosyle with their Active Directory credentials. Check the box to indicate “Use the AD to validate user and password” and enter the attribute that is used to authenticate. Be sure to test the integration to make sure all is authenticating as expected.

NOTE: AD FS and General OAuth are available for user authentication purposes only. Users, grade levels, and class periods cannot be imported using these integrations.

If you need any assistance with the Active Directory integration, visit the Help Center for more information or submit a Support Ticket.

Configuring Spreadsheet and Mosyle API Integrations


If your school or district doesn't have Apple School Manager or Active Directory, users, grade levels, and classes can be imported using a Spreadsheet or the Mosyle API Integration.

Complete the steps below to add an integration and import users and user groups in Mosyle Education:

  1. Go to My School > Integrations > + Activate New Integration
  2. Choose from: Mosyle API Integration or Spreadsheet Importing
  3. After Activating the integration, toggle on the API Integration or Download the templates for the Spreadsheet integration.

Mosyle API Integration

After toggling on the API Integration, you can choose to restrict the access to specific IPs or leave it open by editing the Access Method.

To create users via the API, you'll make requests to the /users endpoint. To create classes via the API, you'll make requests to the /classes endpoint. Additional documentation, as well as a sample json that is compatible with Postman and Insomnia, is available in the Mosyle interface.

Spreadsheet Integration

Users, grade levels, locations, and courses/classes can be imported directly into Mosyle from a CSV or XLSX Spreadsheet. After downloading the template for the Spreadsheet integration, fill it out and upload the file to Mosyle. Be sure to not delete any headers or sheets (even if empty).

Enrollment

Enrollment

What is MDM enrollment

In order for a device to be managed by Mosyle MDM, it first needs to be enrolled. The enrollment process involves the download and installation of an enrollment profile, either automatically or manually, which will establish secure communication between the device and the Mosyle MDM server. Once the enrollment profile is installed on the device, it is considered managed by the MDM and can receive profiles and commands.

The MDM enrollment profile can be viewed on a device at any time.

After a device is enrolled, the Mosyle MDM maintains communication using the Apple Push Notification service (APNs). Any time a command is generated or a profile is requested to be installed or removed, the MDM sends a push notification to the device via APNs to instruct the device to contact the MDM server. The device then contacts the MDM server to retrieve and act upon the command.

apn.png

Enrollment

Mosyle MDM Enrollment options


Mosyle supports enrollment of devices using Automated Device Enrollment, Device Enrollment, and User Enrollment. Navigate to My School > Apple Basic Setup > Enrollment to view the options available.

The top middle dropdown menu will allow you to choose between iOS/iPadOS, macOS, and tvOS to access specific enrollment information for each OS.

The options listed under Device Enrollment include Automated Device Enrollment, Apple Configurator 2 (iOS/iPadOS and tvOS) and Manual enroll via Safari (URL). Enrollment using one of these methods is recommended for devices owned by the school or district. Click each tile to view more information or configure specific enrollment settings.

User enrollment is available for user owned iOS/iPadOS and macOS devices. Click the user enrollment tile to configure specific settings.

Enrollment

Automated Device Enrollment

What is Automated Device Enrollment


Automated Device Enrollment provides an automated approach to enrolling devices owned by the school or district the moment they are unboxed. In order to enroll using Automated Device Enrollment, devices must exist in an Apple School Manager account and be assigned to the Mosyle MDM server. Devices purchased from Apple or an Apple Authorized Reseller or carrier can be automatically added to the Apple School Manager account. Other devices can be manually added to Apple School Manager using Apple Configurator 2 (certain restrictions apply). Click here for more information on manually adding devices to Apple School Manager.

Devices assigned to the Mosyle MDM server from Apple School Manager can be assigned to an Automated Device Enrollment profile created in Mosyle to be synced with Apple's Cloud Configuration servers. Doing this will ensure devices automatically download the enrollment profile when the devices are powered on for the first time, or erased and the OS reinstalled, and connected to the network. Different settings can be configured in the Automated Device Enrollment profile to dictate the Setup Assistant steps that will be presented when enrolling devices.

In addition to the benefit of over-the-air hands off deployment and enrollment of devices, enrolling devices using Automated Device Enrollment provides:

During Automated Device Enrollment, devices will attempt to retrieve/download the cloud configuration profile that is synced with Apple servers. In order to successfully retrieve the profile and complete enrollment it's critical the network allows for proper communication, including access to all Mosyle and Apple domains. Click here for information on which hosts and ports are required for Apple products.

enroll.png

Enrolling devices using Automated Device Enrollment


The first steps to enrolling devices into Mosyle using Automated Device Enrollment include:

  1. Integrating the Apple School Manager account with Mosyle
  2. Assigning devices in Apple School Manager to the Mosyle MDM Server
  3. Creating and syncing an Automated Enrollment profile

Steps 1 and 2 have been reviewed in previous lessons. In the next sections we'll review the many configuration options available in the Mosyle Automated Device Enrollment profile.

All Mosyle accounts include a Default enrollment profile which has basic enrollment settings configured. All devices assigned to the Mosyle MDM server will be assigned to the Default profile unless they are manually assigned to a different enrollment profile. Modify the Default profile at any time to meet the needs of the school or district.

View devices assigned to the Mosyle MDM server and their current status by going to My School > Apple Basic Setup > Enrollment > Automated Device Enrollment > View devices. The following statuses are retrieved from Apple servers and will be listed for each device:

Each status is color-coded to assist with quick identification. If needed, the devices and their current status can be exported from this screen using the “Download devices” option at the bottom of the list.

Update the list of devices and their status by clicking the “Update” button in this screen.

Tip: It's recommended to work within your Mosyle Education account while going through this section to configure the Automated Device Enrollment profiles to meet your school or district's needs.



Automated Device Enrollment configurations for iOS/iPadOS


Use the Automated Device Enrollment profile(s) to specify how the devices will behave after they're unboxed, or after Erasing all Content and Settings. Multiple enrollment profiles can be created if needed.

To start, go to My School > Apple Basic Setup > Enrollment > Automated Device Enrollment. Choose the iOS/iPadOS platform from the dropdown menu at the top. Click the Default profile to make any changes or adjustments, or create a new profile by clicking “New profile”. The Automated Device Enrollment profiles are separated into different sections. Each is addressed below.

Profile Name

Enter a name for the enrollment profile. Only Mosyle Administrators will see this information, so feel free to use a name that will help organize and identify the enrollment settings configured.

The default enrollment profile will be named the same as the Mosyle account. You can update the name at any time by clicking the profile and editing this field.

Check the options you want to activate on the device

Each new enrollment profile created in Mosyle will automatically have the default settings configured. Feel free to check any new options or uncheck options as needed.

Supervision Identity

The Supervision Identity is required in order to pair a device with a computer when the restriction “Do not allow host pairing” is applied. When the restriction is applied, devices will not be able to connect or pair with computers. By installing the Supervision Identity on the Mac, you grant permission for the device to pair with the computer. Devices will only be able to pair with computers that have the Supervision Identity certificate installed.

The options that can be configured in Mosyle include:

In most cases when pairing is required, a command from Mosyle MDM can be sent to the device to remove the restriction profile and allow host pairing. If the device loses network connectivity and is unable to receive commands from the MDM to remove the restriction profile, the Supervision Identity is useful to allow pairing access.

Devices will be used in which model?

If you choose to enroll devices to limbo and they are assigned after the enrollment, if the device is ever wiped it will automatically re-enroll in Mosyle and will automatically be reassigned to the user. If you do not want this to happen, please check the option to Return devices to assignment model selected above after wipe.

Select the location responsible for the devices

Here you can choose which of the locations in Mosyle the device should be assigned after it is enrolled. If the device will be assigned 1:1 to a user or to a Shared Device Group, the device will assume the location of the user or shared group.

Customize Setup Assistant (Available only for iOS 13+)

The options available allow you to customize the end user experience during the enrollment process. Include items such as a welcome message, an End User License Agreement Screen, and/or authentication. Each option is described in more detail below. As items are added, they can be rearranged by dragging and dropping the tile in any order desired.

*When using the options in the Custom Setup Assistant to complete device assignment (Mosyle User Authentication and Single Sign-On Authentication), be sure the Device Assignment options configured in your account are correct. To confirm, go to My School > Users > Device Assignment > User Authentication Assignment. Be sure the option under the heading 'Assignment through SSO Authentication during Automated Device Enrollment' is configured with the selection Auto-assign the device to the Authenticated user during the SSO Sign In.

Select the iOS/iPadOS devices that will receive this profile

Choose the device serial numbers to receive the enrollment profile. Assign all devices or specific devices to the enrollment profiles as needed to meet the needs of your school or district.

By default, devices that are erased and re-enrolled in Mosyle will automatically keep the user assignment. Therefore, if you wish to always enroll devices as freshly unassigned devices check the box for “Enroll devices as unassigned devices”.

Select the options that will not be presented to the user in Setup Assistant

Check any of the Setup Assistant steps you wish to skip during the enrollment. Uncheck any steps you wish to present to the user during the enrollment. Anything skipped during the enrollment can always be configured at a later time through the device Settings unless it is configured to be restricted.

Phone & Email Support (optional)

These fields are optional. If information is entered here it will be displayed on the Remote Management screen during the enrollment as the School/District Support Email and Phone Number.

Rename devices after enrollment

Automatically rename devices during the enrollment flow using device or user variables. If users are authenticating during the enrollment and completing the device assignment, any available 1:1 variables can be used for the renaming. If prompting users to enter Tag or Asset Tag information with the Custom Setup Assistant, use the corresponding variables to rename the devices.

After configuring the Automated Device Enrollment profile for iOS/iPadOS devices, click Save. View the device list to ensure the devices show a “Profile Associated” (Enrollment > Automated Device Enrollment > View Devices). Once the devices show a “Profile Associated” they are ready to be enrolled.

iOS and iPadOS devices will prompt the enrollment process in one of two ways:



Automated Device Enrollment configurations for macOS


Use the Automated Device Enrollment profile(s) to specify how the devices will behave after they're unboxed, or after erasing and reinstalling the macOS. Multiple enrollment profiles can be created if needed.

To start, go to My School > Apple Basic Setup > Enrollment > Automated Device Enrollment. Choose the macOS platform from the dropdown menu at the top. Click the Default profile to make any changes or adjustments, or create a new profile by clicking “New profile”. The Automated Device Enrollment profiles are separated into different sections. Each is addressed below.

Profile Name

Enter a name for the enrollment profile. Only Mosyle Administrators will see this information, so feel free to use a name that will help organize and identify the enrollment settings configured.

The default enrollment profile will be named the same as the Mosyle account. You can update the name at any time by clicking the profile and editing this field.

Check the options you want to activate on the device

The following options are the same as the iOS/iPadOS configuration. Please see “Automated Device Enrollment configurations for iOS/iPadOS” for additional information.

Each new enrollment profile created in Mosyle will automatically have the default settings configured. Feel free to check any new options or uncheck options as needed.

Customize Setup Assistant (Available only for macOS 10.15+)

The options available in the Custom Setup Assistant for macOS are the same as the options for iOS/iPadOS, allowing the possibility to provide a consistent enrollment experience across all devices in the fleet. Please see “Automated Device Enrollment configurations for iOS/iPadOS” for additional information.

If using the Auto-Advance enrollment options, it's recommended to skip as many Setup Assistant steps as possible to fully leverage the Auto-Advance enrollment process.

Select the Macs that will receive this profile

Choose the device serial numbers to receive the enrollment profile. Assign all devices or specific devices to the enrollment profiles as needed to meet your organization needs.

Select the options that will not be presented to the user in Setup Assistant

Check any of the Setup Assistant steps you wish to skip during the enrollment. Uncheck any steps you wish to present to the user during the enrollment. Anything skipped during the enrollment can always be configured at a later time through the device System Settings unless it is configured to be restricted.

Account Configuration

Define whether or not the user will be prompted to create a local user account during the Setup Assistant, and/or configure a local administrator account on the Mac using the options below.

To prompt the creation of a local user account on the Mac during the Setup Assistant, check the box for “Prompt user to create an account”. After checking the box, you'll have additional option available:

If you plan to use Mosyle Auth 2 to create user accounts, or users will be logging in using a network/mobile account or another account created outside of Setup Assistant, uncheck the box for “Prompt user to create an account”. In doing so, after downloading and installing the enrollment profile it will boot to the Login Window without requiring the user to manually create a local user account.

Since the Mac requires at least one Admin account during setup, when skipping the manual creation of a local user account you'll be required to create a managed administrator account using the option “Create additional local admin during Setup Assistant”. When creating the managed administrator account:

Phone & Email Support (optional)

These fields are optional. If information is entered here it will be displayed on the Remote Management screen during the enrollment as the School/District Support Email and Phone Number.

Rename devices after enrollment

Automatically rename devices during the enrollment flow using device or user variables. If users are authenticating during the enrollment and completing the device assignment, any available 1:1 variables can be used for the renaming. If prompting users to enter Tag or Asset Tag information with the Custom Setup Assistant, use the corresponding variables to rename the devices.

After configuring the Automated Device Enrollment profile for macOS devices, click Save. View the device list to ensure the devices show a “Profile Associated” (Enrollment > Automated Device Enrollment > View Devices). Once the devices show a “Profile Associated” they are ready to be enrolled.

macOS devices can be enrolled in the following ways:



Automated Device Enrollment configurations for tvOS


Use the Automated Device Enrollment profile(s) to specify how the devices will behave after they're unboxed, or after Erasing all Content and Settings on the Apple TV. Multiple enrollment profiles can be created if needed.

To start, go to My School > Apple Basic Setup > Enrollment > Automated Device Enrollment. Choose the tvOS platform from the dropdown menu at the top. Click the Default profile to make any changes or adjustments, or create a new profile by clicking “New profile”. The Automated Device Enrollment profiles are separated into different sections. Each is addressed below.

Profile Name

Enter a name for the enrollment profile. Only Mosyle Administrators will see this information, so feel free to use a name that will help organize and identify the enrollment settings configured.

The default enrollment profile will be named the same as the Mosyle account. You can update the name at any time by clicking the profile and editing this field.

Check the options you want to activate on the device

Devices will be used in which model?

Apple TVs can only be enrolled as Limbo devices.

Select the location responsible for the devices

Here you can choose which of the locations in Mosyle the device should be assigned after it is enrolled.

Select the Apple TVs that will receive this profile

Choose the device serial numbers to receive the enrollment profile. Assign all devices or specific devices to the enrollment profiles as needed to meet the needs of your school/district.

Select the options that will not be presented to the user in Setup Assistant

Check any of the Setup Assistant steps you wish to skip during the enrollment. Uncheck any steps you wish to present to the user during the enrollment. Anything skipped during the enrollment can always be configured at a later time through the device Settings unless it is configured to be restricted.

If using the Auto-Advance enrollment options, it's recommended to skip as many Setup Assistant steps as possible to fully leverage the Auto-Advance enrollment process.

Phone & Email Support (optional)

These fields are optional. If information is entered here it will be displayed on the Remote Management screen during the enrollment as the School/District Support Email and Phone Number.

Rename devices after enrollment

Automatically rename devices during the enrollment flow using device variables.

After configuring the Automated Device Enrollment profile for tvOS devices, click Save. View the device list to ensure the devices show a “Profile Associated” (Enrollment > Automated Device Enrollment > View Devices). Once the devices show a “Profile Associated” they are ready to be enrolled.

Apple TVs can be enrolled in the following ways:



After enrollment


Once devices are enrolled in the Mosyle account, they can be fully managed by all available and compatible configuration profiles and commands. Enrolled devices can be found under the Management tab > Devices Overview. Click the device name to bring up the Device Info window.

Enrollment

Device Enrollment

What is Device Enrollment


Device enrollment is available for devices that are not purchased from Apple or an Authorized Reseller or carrier and therefore are not eligible for Automated Device Enrollment. Device enrollment allows the device to be manually enrolled in the MDM using Apple Configurator 2 or by entering the enrollment URL into Safari.

Enrolling iOS/iPadOS and tvOS devices using device enrollment does not guarantee device supervision unless they are enrolled using Apple Configurator 2 and supervision is applied. Devices enrolled using device enrollment will not have the ability to lock the MDM enrollment profile, allowing end users to remove the profile at any time from the device Settings or System Settings.

During device enrollment, devices will attempt to retrieve/download the enrollment profile and the user will need to manually approve and install the profile installation. In order to successfully retrieve the profile and complete enrollment it’s critical the network allows for proper communication, including access to all Mosyle and Apple domains. Click here for information on which hosts and ports are required for Apple products.

 



 

Enrolling devices using Apple Configurator 2


To enroll iOS, iPadOS, or tvOS devices using Apple Configurator 2, the enrollment URL will need to be added to Apple Configurator 2 during the “Prepare” workflow. The enrollment URL can be found in Mosyle under My School > Apple Basic Setup > Enrollment > Apple Configurator 2.

Within the Mosyle interface a step-by-step tutorial is provided to walk through the enrollment using Apple Configurator 2. It's important to enable Supervision to get the most out of the management features and functionality available.

apple-configurator-2.png

Notes:



 

Device Enrollment using the Safari URL


To enroll iOS, iPadOS, or macOS devices manually, the enrollment URL can be entered into the Safari browser to download the MDM enrollment profile. When enrolling devices using the Safari URL, they can be enrolled as general, unassigned devices, or enrolled and assigned to a specific user. Depending on the enrollment preference, the enrollment URL can be found in Mosyle in a few areas:

Once the profile is downloaded, users will be prompted to install the enrollment profile under the device Settings or System Settings. To install the enrollment profile on Mac computers, the user must have Admin rights.

Notes:

Additional manual enrollment settings can also be configured under My School > Apple Basic Setup > Enrollment > Manual enroll via Safari (URL). The options available include:

Once devices are enrolled in the Mosyle account, they can be found under the Management tab > Devices Overview. Click the device name to bring up the Device Info window.

Enrollment

User Enrollment

What is User Enrollment


User Enrollment is available for devices that are not owned by the school or district, rather are personally owned devices. User Enrollment requires Managed Apple IDs to establish a user identity on the device.

With User Enrollment, organization data is separate from user data and the MDM can only access and manage certain aspects of the device. For more information about User Enrollment, visit Apple's documentation.

 

Resources




Enrolling devices using User Enrollment


To enroll iOS, iPadOS, or macOS devices using User Enrollment, the device must support User Enrollment, the user must have a Managed Apple ID, and the user must be registered, with the Managed Apple ID, in Mosyle under My School > Users.

When enrolling via User Enrollment, users will enter the enrollment URL into the Safari web browser and authenticate with their Managed Apple IDs to download and install the enrollment profile. Once the enrollment profile is installed, the Mosyle MDM will be able to communicate with and manage the device. Once enrolled, users will see the Managed Apple ID account configured in Settings > Passwords & Accounts on iOS/iPadOS devices and in System Settings on macOS devices.

To obtain the User Enrollment URL and configure additional options, go to My School > Apple Basic Setup > Enrollment > Click “Configure User Enrollment”.

Within the User Enrollment configuration area, choose the settings to best meet the needs of your school or district. To allow User Enrollment, check the box to Allow User Enrollment (BYOD).

User Enrollment screen

Customize the screen user's will see when enrolling via User Enrollment. Choose between using the Standard screen, a Personalized screen, or use your own HTML code.

URL for User Enrollment

Customize the URL user's will enter into Safari when enrolling via User Enrollment. Choose between using the Standard URL, a Premium URL, or a Custom URL.

Install Self-Service app after enroll

Choose whether or not the Mosyle Manager application will be installed on devices enrolled via User Enrollment.

Users allowed to complete User Enrollment

Allow or restrict the use of User Enrollment to specific users in the school or district.

 



Enrolling devices using Account-driven User Enrollment


Account-driven User Enrollment can be used for devices running iOS/iPadOS 15 or later. This method of User Enrollment still requires the user to have a Managed Apple ID, and the user must be registered, with the Managed Apple ID, in Mosyle under My School > Users.

When enrolling via Account-driven User Enrollment, users will go to the device Settings > General > VPN & Device Management > Click “Sign in to work or school account” > Authenticate with school/district credentials. After authenticating, the enrollment profile is downloaded and can be installed. Once the enrollment profile is installed, the Mosyle MDM will be able to communicate with and manage the device.

To enable Account-driven User Enrollment and additional options, go to My School > Apple Basic Setup > Enrollment > Under the iOS/iPadOS enrollment options, click “Configure User Enrollment”.

Using the dropdown menu at the top, select Account-driven User Enrollment and check the box to Allow Account-driven User Enrollment.

User Enrollment screen

Customize the screen user's will see when enrolling via User Enrollment. Choose between using the Standard screen, a Personalized screen, or use your own HTML code.

Well-known host

This is where the user will authenticate with school/district credentials to download the enrollment profile. Mosyle provides the option to use a Mosyle well-known endpoint and to define the unique identifier to authenticate in order to retrieve the enrollment profile. Schools/Districts can also host the well-known endpoint at their domain to which end users must authenticate.

Required App for MDM

Starting with iOS/iPadOS 15.1 and later, schools can require an application to be installed via the MDM on User Enrolled devices without first prompting for end user approval. Use this area to select a required application, such as a custom application, VPN or web filtering application.

Install Self-Service app after enroll

Choose whether or not the Mosyle Manager application will be installed on devices enrolled via User Enrollment.

Users allowed to complete User Enrollment

Allow or restrict the use of User Enrollment to specific users in the school or district.

Once devices are enrolled in the Mosyle account, they can be found under the Management tab > Devices Overview > User Enrollment tab. Click the device name to bring up the Device Info window.

Users can manually remove the MDM enrollment profile at any time through the device Settings or System Settings. In doing so, the device will be removed from the Mosyle interface.

 




 

 

Users & Hierarchy

Users & Hierarchy

Users & Hierarchy

Purpose


As mentioned previously, importing users, grade levels, and/or classes allows for devices to be assigned to their corresponding users and for configurations and profiles to be customized based on the device user. While importing users, grade levels, and/or classes is not required, we've found it facilitates ease of device management for Administrators.

Use the Apple School Manager or Active Directory integrations to import user data into Mosyle. Additional options such as a Spreadsheet import or use of the Mosyle API integration are also available.

Once User data is imported into Mosyle, it can be found under My School > Users. Locations, Grade Levels, Courses, and Shared Device Groups can be found under My School > Hierarchy.

Resources


Locations, Grade Levels, Courses, and Shared Device Groups


All management profiles are assigned based on the Hierarchy configured in Mosyle, starting with Locations. Using this Hierarchy, you can assign management profiles as broadly as you would like (ex: All current & future devices) or as granularly as you would like (ex: A specific student device from a specific location). Additionally, Mosyle Admin users can be created that only have access to specific locations; and, access to Apple School Manager, Apps and Books, and Active Directory integrations can be configured based on Locations to ensure devices, users, and content remains organized as needed.

Hierarchy

Locations can be created manually, imported using a spreadsheet, imported from Apple School Manager or Active Directory. Once Locations have been created, you will be able to assign access for integrations such as Apps and Books token and Apple School Manager based on the locations. You are also presented with the option to create Location assigned Administrators. Additionally, you'll be able to view any profiles assigned to each location as needed.

Grade Levels can be created manually, imported using a spreadsheet, or imported from Apple School Manager or Active Directory. After creating Grade Levels, you'll be able to view what grades are assigned to various locations within your account, the students assigned, and any grade level based profiles.

Courses and Classes can be created manually, imported using a spreadsheet, or imported from Apple School Manager or Active Directory. Assigning students to classes will allow teachers to take advantage of the Mosyle Class Manager, as well as automatically configure the teacher devices with admin-created classes for the Apple Classroom app.

Shared Device Groups can be created manually or imported using a spreadsheet. Assigning devices to a shared device group is a way of organizing devices into static groupings in Mosyle.

Profile Assignment

Management profile assignment always begins with the Location, from here you can filter by grade levels, classes, shared carts/groups, and individual users. Assignments in Mosyle can be completed in the following way:

Academic Year


The Academic Year tool was designed to help Administrators clean and update data imported from Apple School Manager or Active Directory for the new school year. Using the Academic Year tool, student data will be updated to reflect new grade levels and courses/classes while automatically updating all Management profiles assigned and installed.

To access and update data for the new school year, follow the steps below:

  1. Make sure all data (including courses/classes) is updated in ASM and/or AD
  2. Go to My School > Hierarchy
  3. Click Academic Year
  4. Click Start and choose the integration
  5. Follow the onscreen prompts
  6. Once the data is synced, a preview of any/all changes will be displayed
  7. If all looks ok, click Start Integration

The Academic Year area also provides tools to clean up data in your Mosyle account, including:

User Types & Permissions


There are multiple types of users available in Mosyle Education and can be viewed and accessed under My School > Users:

Students and Staff can be imported using one of the methods mentioned earlier and do not have access to the Mosyle MDM web panel. Teachers can also be imported using the methods mentioned, but will have access to only the Class Manager portion of the Mosyle MDM web panel. For security purposes, Location Leaders and Leaders are required to be manually created.

When creating Leaders, you can choose the type of Leader account to be created, either a Location Leader or Leader. Location Leaders will only be able to manage the users and device groups that are assigned to their location and will have limited visibility to the rest of the school or district users and devices.

Under the Advanced Options area, additional settings can be configured for the Leader user accounts:

User Roles and Permissions can be updated at any time as needed by clicking a specific Administrator > Advanced Options > Click “Select” under Limit User Permissions > Edit for the role to be edited. Choose and update the permissions and click Save. Save the Administrator. Once saved, the permissions will be updated for any other Administrators/Leaders with that same role.

User Security Settings


Administrator users can login to Mosyle MDM via the Mosyle web panel and teachers can login to the Mosyle Class Manager at https://myschool.mosyle.com. By default, each session is limited to 15 minutes unless selecting the “Keep me logged in” option. If the “Keep me logged in” option is not checked when accessing the account, users will be logged out after 15 minutes. When clicking the “Keep me logged in” option, the session duration will depend on what is configured in the Admin Authentication Policies under My School > Preferences > Other Settings > Admin Authentication Policy.

By default, students and staff are not required to have a password and will be automatically logged in to the Mosyle Manager application when the device is assigned. If the school or district would like to enforce students and staff to have a password when logging into the Mosyle Manager application, use the Single Sign-On configuration for the iOS/iPadOS and/or macOS application under My School > Preferences > Single Sign-On.

Admin Authentication Policy


Access to the Mosyle MDM web panel should be handled with caution, and access should be provided on a need-only basis. In addition to providing access to only those who absolutely need access, Authentication policies can be configured to ensure extra security of the account.

To configure these policies, go to My School > Preferences > Other Settings > Admin Authentication Policy.

admin-authentication-policy.png

Password Policies

The password policies allow you to configure specifications on how the password should be handled when logging into the Mosyle web panel with an Administrator account. Options include how frequently the password should be changed, character requirements, and how many unique passwords must exist before one can be reused.

If Single Sign-On is configured to authenticate with the Identity Provider credentials when logging into the web panel, the Password Policies configured will be ignored as it is expected the Identity Provider configurations to supersede the configurations in Mosyle.

Authentication Policies

The authentication policies allow you to configure specifications regarding account and authentication access. Options include configuring the maximum session time, how many authentication attempts are allowed before login is blocked, time delay before a user can attempt to login again after so many failed attempts, and allow access from only specific IPs.

Within this area restrictions can be applied so that Administrator accounts can only be created for users with emails of a specific domain, and two factor authentication can be enforced for all Administrator accounts.

User Photos


If desired, user photos can be uploaded to the Mosyle MDM or students can be permitted to add their own photos. These photos will show within the Mosyle Manager application and in the Admin web panel.

To upload User Photos or configure it so students can add their own photos, go to My School > Users > Users Photos.

user.png

Users & Hierarchy

Device Assignment & User Authentication

Purpose


When enrolling devices into Mosyle Education, there are three models of assignment to choose from:

In order to scope configurations and profiles based on users or device groups, the Users and/or Shared Device Groups will need to be registered in Mosyle and devices will need to be assigned to their corresponding user or group. Device Assignment can be accomplished in multiple different ways using Mosyle MDM.

The ideal workflow when using Mosyle MDM is to automate the device assignment as much as possible to promote a hands-off deployment.

When a device isn't assigned to a specific user or shared device group, it is displayed as a “Limbo” device in Mosyle. Limbo devices can be configured by assigning configurations and profiles to all current and future devices and/or Limbo devices, rather than the user or shared device group.

Notes:

Assigning Devices to Users


Configure Device Assignment Settings by going to My School > Users > Device Assignment. Here you can choose from the following:

Devices can also be assigned to users manually at any time within the Mosyle MDM web console by viewing the Device Information or User Information.

User Authentication Assignment

By default, when a user authenticates on a device, the device will be assigned to the user and remove the assignment of any other device of the same OS from the user. Administrators can modify or adjust this behavior within the User Authentication Assignment settings under My School > Users > Device Assignment.

The User Authentication Assignment settings offers three main options:

Devices assigned to Shared Device Groups will never automatically be converted to 1:1 devices. When a user authenticates on a Shared Device, it will remain shared but will reflect the current user logged in so that any/all profiles assigned to the user can be applied.

Assignment Methods

Methods for assigning devices to end users via authentication include the following:

In most cases, user authentication with their school or district Single Sign-On credentials is the preferred method due to the user familiarity with the credentials and ability to automate the assignment flow. Three frequently used methods for assigning devices to users are described below.

 

 

Completing Device Assignment during Automated Device Enrollment (iOS/iPadOS & macOS)


The Custom Setup Assistant is available within the Automated Device Enrollment profile which allows Administrators to prompt users during the enrollment to authenticate with either their Mosyle access code or their Single Sign-On credentials (Google, Azure, AD FS, or Active Directory). My School > Apple Basic Setup > Enrollment > Automated Device Enrollment > Customize Setup Assistant > Mosyle User Authentication or Single Sign-On Authentication. This option is available for both iOS/iPadOS and macOS devices allowing the enrollment flow to be consistent across all devices.

Configuring this option, users will be prompted to authenticate during the Automated Device Enrollment which will complete the device assignment. In order to complete the device assignment, the users must be imported and registered in Mosyle with the email address used to authenticate. This method of authentication and device assignment brings multiple benefits:

sign-in.png

 

 

Completing Device Assignment using the Mosyle Manager app (iOS/iPadOS & macOS)


If the enrollment will be completed by the IT department, or use of the Custom Setup Assistant is not possible within the school or district, user authentication through the Mosyle application can complete the device assignment. With this method, the device will be enrolled and remain in limbo until a user logs in to the Mosyle Manager app to complete the device assignment.

By default, the Mosyle Manager application accepts login using the user's Mosyle access code, User ID, or email address. Admin users and Teachers will be required to enter their Mosyle password. Students and Staff users aren't required to have a password unless Single Sign-On authentication is configured.

Administrators can configure the Mosyle Manager application to accept login using Single Sign-On credentials such as Google, Azure, AD FS, or Active Directory by configuring the Single Sign-On profile under My School > Preferences > Single Sign-On > Login on Mosyle iOS app and/or Login on Mosyle macOS app.

login.png

Completing Device Assignment during macOS login


On Mac computers, device assignment can be completed based on the user logging in on the device.

Mac user account login

When users login on the Mac, so long as the account name matches the User ID in Mosyle the device will be assigned to the user upon logging in on the Mac.

This assignment option can be used for devices that have been enrolled via Automated Device Enrollment or manually. When enrolled via Automated Device Enrollment, the user can be prompted to create the local user account with their User ID during the Setup Assistant and upon logging in, the device will be assigned to the user. If using the Terminal command to enroll via Automated Device Enrollment or manually enrolling a device, when logging in with an account on the Mac be sure the account name matches a User ID in Mosyle to complete the device assignment.

account-login.png

Mosyle Auth

Users logging into the Mac using Mosyle Auth will automatically complete the device assignment (depending on Device Assignment settings). This assignment option is useful for devices enrolled via Automated Device Enrollment where the local user account creation during the Setup Assistant is skipped. This way, the device will go through the enrollment and launch the Mosyle Auth login window. Upon logging in, the device will be assigned to the user.

auth.png

Multiple Device Assignment


The default device assignment behavior in Mosyle follows a 1-to-1 model, therefore if the user logs in and/or is assigned to another device, they will be unassigned from the first device. However, we understand in some scenarios users may have more than 1 device assigned. Using the options and workflows listed below will ensure a previously assigned device will not be unassigned when the user authenticates on another device to complete the assignment.

The workflow used to assign multiple devices will depend on the planned deployment flow. A maximum of 10 devices per OS platform can be assigned to each user, in other words, up to 10 iOS/iPadOS and 10 macOS devices can be assigned to each user.

 

 

Assigning Devices to Shared Device Groups


A Shared Device Group is a way of organizing devices into static groupings in Mosyle. After creating a Shared Device Group, you can assign profiles to all devices in the group or by selecting individual devices when needed.

If you need to create a group where devices will be entering or leaving the group based on some specific criteria, it's recommended to use Dynamic Device Groups found under the Management tab.

Assigning devices to a Shared Device Group can be completed using a few different methods in Mosyle. The method used will depend on the planned deployment flow. Methods for assigning devices to Shared Device Groups are similar to those used for 1:1 devices and are listed below.

Completing Assignment during Automated Device Enrollment

If you are enrolling devices using Automated Device Enrollment, you can complete the assignment during the enrollment using:

group-code.png

Completing Assignment using the Mosyle Manager app

End-users can complete the device assignment by entering the Shared Device Group access code or scanning the QR code in the Mosyle application. In this scenario, devices will first be enrolled into Limbo. Once enrolled, users will launch the Mosyle app and scan the QR code, or enter the 6 digit access code for the Shared Device Group to complete the assignment.

Completing Assignment in the Mosyle Web Console

Mosyle Administrator users can complete the device assignment by logging into the Mosyle console and using:

shared-cart.png

 

 

 

Devices in Limbo


Devices in Limbo are devices that are not assigned to a User or a Shared Device Group. Devices in Limbo can be associated with all locations in the account, or specified to belong to only one location.

To configure Limbo devices to be assigned to all locations, go to My School > Preferences > Other Settings > General Preferences > Check the box "Limbo devices belong to all locations". Click Save.

To configure Limbo devices to be assigned to a specific location, you can specify the location in the Automated Device Enrollment profile, or modify the locations by going to Management > Devices Overview > Bulk by Import > Download the template for Update Location. Fill out the template and upload.

Devices can be changed to Limbo devices using the following methods:

Once a device is in Limbo, it can be assigned to any user or Shared Device Group as needed.

Apple Shared iPad devices cannot be changed to Limbo without erasing and re-enrolling.

 

 

Inventory Management

Inventory Management

Devices Overview

Overview


Devices enrolled in the Mosyle account are listed under Management > Devices Overview for their respective platform. Change platforms by clicking the dropdown menu in the top left under Manage OS to choose between iOS/iPadOS, macOS, and tvOS.

Navigate between the list of devices enrolled via Device Enrollment or User Enrollment using the tabs along the top. Filter the list using the Filter options along the top, or enter search criteria to find a specific device or devices. The information provided by the filters is also designed to be sorted with a simple click of a column name or edited with a click of the search.

Along the top menu are commands that can be sent to devices including Update Info, Update OS, Update Apps, Rename Devices, and many others. The commands will be sent to selected devices immediately after clicking. Many of the commands are also available in the Single Shot profile to be scheduled as needed.

In the top right, the Personalize button allows each Admin to personalize the data displayed on the Devices Overview screen when they login and access. This allows the ability to display data relevant to the school or district.

Administrators can use the Bulk by Import feature to upload a spreadsheet to change Device Names, Tags, Asset Tags, and the Lock Screen Message for multiple devices at once

 


 

Device Information


Clicking a device name will bring up device specific detailed information in the Device Information view. The menu in the Device Information view provides access to many of the same commands offered in the Devices Overview area. Information regarding the specific device is available within each of the tabs.

iOS/iPadOS Device Information

The Device Information for iOS/iPadOS devices includes seven tabs: Info, Security Info, Apps, Books, Commands, Profiles, Occurrences.

The Info tab provides information regarding the device hardware and the OS. Key pieces of information in this area include:

The Security Info tab provides information regarding the status of Activation Lock, Find My, and if a passcode is present on the device. If User-Initiated Activation Lock is allowed, the Activation Lock bypass code can be found in this tab. This information is updated every 24 hours as part of the full Update Information. If you wish to update sooner, click the “Send Update Info” button within the tab.

The Apps tab provides information regarding the apps assigned and installed on the device. Likewise, the Books tab provides information regarding any media assigned and installed on the device. The apps and books information is updated every 24 hours as part of the full Update Information. If you wish to update sooner, click the “Send Update Info” button within the tab.

Apps

The Apps tab is organized into four sections: Installed, Profiles, Study Apps, and VPP Licenses.

Books

The Books tab is organized into three sections: Installed, Profiles, and VPP Licenses.

The Commands tab will show a list of any pending or failed commands for the individual device. By default, the Mosyle MDM will attempt to resend any pending or failed commands every 15 minutes. However, a push can be manually sent as well to call the device to the MDM server to retrieve any pending/failed commands. If needed, the commands can be cleared from this area as well. Note: Devices locked with a passcode will not accept commands to change any configuration/settings on the device while locked. Unlock the device in order for the commands to go through.

The Profiles tab lists any and all profiles assigned to the device and the current installation status. The profile installation status is updated any time a profile is sent to the device to be installed, and every 24 hours as part of the full Update Information. If you wish to update sooner, click the “Send Update Info” button within the tab. Potential statuses are listed below:

The Occurrences tab provides information regarding any profiles that may be installed that are no longer assigned, or any profiles that are assigned but are not installed. It is typical for this tab to be empty.

macOS Device Information

The Device Information for macOS devices includes six tabs: Info, Security Info, Apps, Commands, Profiles, Occurrences.

The Info tab provides information regarding the device hardware and the OS. The information is similar to that received by iOS/iPadOS devices. Information obtained by Mosyle is retrieved via Apple's MDM Protocol commands as well as through the Mosyle MDM agent. The “Last Update Info” date and time will reflect the date and time of the last info retrieved via Apple's MDM Protocol. Device Information command is sent automatically every hour to update the status of the data on the first tab. The full Update Info consists of many commands to gather data for all tabs in the Device Information view, and is automatically sent every 24 hours. Request an Update Info at any time to refresh the information in the tabs.

The Security Info tab provides information regarding the status of Activation Lock, Firewall, FileVault, Bootstrap Token, and includes the DEP Admin Password. If User-Initiated Activation Lock is allowed, the Activation Lock bypass code can be found in this tab. This information is updated every 24 hours as part of the full Update Information. If you wish to update sooner, click the “Send Update Info” button within the tab.

The Apps tab provides information regarding the apps assigned and installed on the device. The list of apps is updated every 24 hours as part of the full Update Information. If you wish to update sooner, click the “Send Update Info” button within the tab. The tab is organized into four sections similar to the iOS/iPadOS Device Information. The App Profiles list will include Install App profiles using Apps and Books and Mosyle Catalog, as well as apps pushed using the Install PKG profile.
*Note: Installation status for apps installed using the Install PKG profile relies on the correct bundle identifier for the app being defined during the PKG creation. If the wrong bundle ID is used, the installation status will be incorrect.

Similar to iOS/iPadOS devices, the Commands tab lists any pending or failed commands for the individual device.

The Profiles tab lists any and all profiles assigned to the device and the current installation status. The profile installation status is updated any time a profile is sent to the device to be installed, and every 24 hours as part of the full Update Information. If you wish to update sooner, click the “Send Update Info” button within the tab. The tab is organized into two sections:

The Occurrences tab provides information regarding any profiles that may be installed that are no longer assigned, or any profiles that are assigned but are not installed. It is typical for this tab to be empty.

tvOS Device Information

The Device Information for tvOS devices includes six tabs: Info, Security Info, Apps, Commands, Profiles, Occurrences. Each tab is similar to the tabs available for the iOS/iPadOS devices. The Device Information command is sent automatically every hour to update the status of the data on the first tab. The full Update Info consists of many commands to gather data for all tabs in the Device Information view, and is automatically sent every 24 hours. Request updated information at any time by clicking Update Info.

Inventory Management

Shared Device Groups

Overview


Shared Device Groups are a useful way to organize devices into static groupings in Mosyle. Profiles and other configurations can be assigned to Shared Device Groups so that all devices in the group will receive the same profiles and/or apps. Any new devices added to the group will also receive the configurations.

 

Creating a Shared Device Group


Shared Device Groups can be created within Mosyle under My School > Hierarchy > Shared Device Groups > Create new Shared Device Group.

When creating a Shared Device Group, add the group name and configure the settings as described below:

 

Shared Device Group for Apple Shared iPad devices


When creating a Shared Device Group for Apple Shared iPad devices, the following preferences can also be configured:

Devices enrolled as Apple Shared iPad devices will be temporarily assigned to the user logging in with the Managed Apple ID registered in Mosyle. Profiles and configurations can be applied to the entire device, or scoped to individual users so they are only applied when that specific user logs in.

When using temporary or guest sessions, only the profiles and configurations applied to the device will be applied.

If the number of resident users or quota size needs to be updated after the device is enrolled, it can be done under Management > Devices Overview or Device Info > More dropdown menu: Change Shared Config. The following options are available:

 

 

Assigning Devices to Shared Device Groups


As previously reviewed, devices can be assigned to Shared Device Groups during Automated Device Enrollment or after enrollment by editing the Shared Device Group or from the Device Info window.

Shared Device Groups can be created in bulk using a Spreadsheet under My School > Integrations > Spreadsheet.

 

 

Move Devices Between Shared Device Groups


Devices can be moved between Shared Device Groups of the same type. For example, devices in a Shared Device Group for Mosyle Shared devices can be moved between other Shared Device Groups with Mosyle Shared devices. Devices that are configured as Apple Shared iPad devices cannot be moved to Shared Device Groups that are configured with Mosyle Shared devices.

To change devices from Apple Shared iPad devices to Mosyle Shared, they will need to be wiped and re-enrolled. Similarly, to change from Mosyle Shared to Apple Shared iPad, the Automated Device Enrollment profile will need to be updated and the device will need to be wiped and re-enrolled.

Inventory Management

Dynamic Device Groups

Overview


Dynamic Device Groups are a useful way to organize groups of devices based on certain criteria. The criteria can be static values, information that can dynamically change, or some combination of the two. Profiles and other configurations can be assigned to Dynamic Device Groups so that all devices in the group will receive the same profiles and/or apps. Any new devices added to the group, either manually or based on criteria will also receive the configurations.

 

 

Creating a Dynamic Device Group


Dynamic Device Groups can be created within Mosyle under Management > Device Groups > Add new Dynamic Device Group.

When creating a Device Group, add the group name and choose the criteria to determine which devices will be dynamically added and removed from the group. When finished click Save.

After saving a group, the Device Group Information shows the devices in the group as well as multiple features:

The list of devices in the Device Group will be listed similar to the devices listed in Devices Overview, providing multiple commands as well as options for exporting data.

dynamic-device-group.png

To delete a Device Group, click “Edit Criteria” and scroll to the bottom. Click “Delete” in the bottom right.

 

 

 

Dynamic Device Group Criteria


Device Groups can be created using a variety of criteria. Criteria available includes both static information such as specific device serial numbers or models, and dynamic information such as OS version or app installation status.

When using criteria to populate devices into the Device Group, the Assigned to specific Location(s) and Last Update Info criterion is required. The Assigned to specific Location(s) indicates which devices should be added to the group based on the locations in which the devices are assigned. If devices are enrolled in Limbo, be sure to consider their location assignment. The Last Update Info indicates which devices should be added to the group based on the last time they updated information with the MDM. Other criteria are optional and added under Your Criteria. The drop-down menu features four types of criteria:

After adding criteria, request a status update from devices by selecting Send an Update Info to All Devices, and then click Save. This ensures the correct devices are added to the group.

Multiple criteria can be used with logical operators AND and OR. Each criteria also has its own logical operators that are relevant to the rule configured, such as: “is”, “is not”, “like”, “is equal to”, “is not equal to”, “is greater than”, “is greater than or equal to”, “is less than”, “is less than or equal to”, “contains”, and “does not contain”. Criteria can be moved and rearranged into any order, or removed, in order to meet the needs of the school or district. Custom command responses can also be used for Dynamic Device Group criteria for macOS devices.

Dynamic Device Groups can be updated at any time by manually refreshing the group under Management > Device Groups > Click the group > Refresh, or configure to automatically update. To automatically update Device Groups every 24 hours between 3am and 4am local time, check the box for “Update list automatically”.

Note: To use Custom Attributes and Custom Commands for Device Group criteria, the Mosyle Manager app must be installed on the Macs.

 

Use Case


Dynamic Device Groups can be used for a variety of purposes when managing devices. One example includes targeting specific devices that need OS updates. Using the criteria for “OS Update” is “Available”, devices that are reporting available OS updates will automatically be populated to the group. The Single Shot profile can then be assigned to the Device Group to initiate the OS updates based on the defined schedule. Once configured, the OS update routine is then automated based on the Device Group criteria and its assignment to the Single Shot profile.

 

Inventory Management

Basic Inventory Reports

Overview


Mosyle provides an extensive amount of data for devices enrolled in the MDM. Data can be exported from multiple areas within the product. Exports with minimal information are typically downloaded immediately, exports with larger amounts of data will be generated and available under My School > Preferences > Reports. The download link is for single use only.

 

 

Exporting User Data


User data can be exported by going to My School > Users > Select all users to be exported > Click the download icon and choose from the available options. The spreadsheet will include the user's name, user ID, personalized access code, personalized enrollment URL, email address, Managed Apple ID, user type, serial number of the assigned device, and any user groups the user is assigned.

 

 

Exporting Action Logs


Actions taken within the account by Administrators can be exported by going to My School > Preferences > Action Logs > Export. The spreadsheet will include the action, details, user name, action date, and IP from which the account was accessed and the action taken.

action-logs.png

 

 

Exporting Device Data


The list of devices enrolled can be viewed at any time by going to Management > Devices Overview. From this area, Administrators can request the export of the following information:

device-data.png

This information can also be exported for individual Dynamic Device Groups under Management > Device Groups > Select the Device Group from the dropdown menu > Export Info.

device-groups.png

 

 

Exporting Commands Activity Log


In the event a large number of commands are pending, it's helpful to export the command activity for a holistic view of the type of commands pending and if there are any trends to which devices have pending commands. To export, go to Management > Commands Activity Log > Click either the Pending or Failed tab > Export.

commands-activity-log.png

 

 

 

 

Exporting Alerts


Export a list of devices identified by specific Alert criteria under Management > Alerts > Export Alerts.

alerts.png

 

 

 

 

Exporting App Data


App data can be exported from within the App Center under the Management tab > Applications. Select the apps you wish to export and click “Export apps” in the menu. Information such as the app name and details, as well as the device serial number the app is installed will be included in the spreadsheet.

app-data.png

 

 

 

Exporting Security Information


When utilizing Mosyle's Device Scout, Detection & Removal 2, and Admin On-Demand, Administrators have the ability to export device details relevant to each feature as well as the corresponding Logs. Export the devices and their security details by clicking the Devices menu option under the Security feature heading. Click the button in the upper right showing the number of devices that match the applied filters. Logs can be exported under the Logs tab.

 

 

 

Exporting DNS Filtering Logs


When using Mosyle's DNS Filtering, Administrators can export logs of requests as needed. To export, first filter the logs based on specific criteria such as a certain URL, start and end date, specific device, or by status (allow/deny). After applying the filters, click Export in the upper right corner.

Inventory Management

Alerts

Overview


Mosyle Alerts provide Administrators important information regarding device status in the environment. In the Dashboard, default Alerts created by Mosyle are categorized by device type (iOS / iPadOS, macOS, tvOS) along with the number of affected devices.

dashboard-alerts.png

Viewing Alerts


To view all default alerts, or create custom alerts, go to Management > Alerts.

Alerts are grouped into four tabs based on alert types, 1:1 users, Devices in Shared Device Groups, and devices in Limbo. Types refers to the kind of alerts, such as devices with OS updates available or full storage. The remaining three tabs refer to the assignment model of the affected devices.

Click each of the alerts to open a pop-up window with more information or click View History for historical analysis based on users and devices. If it's a custom alert, a unique icon and name can be entered to identify it. All alerts are automatically refreshed every 30 minutes.

 

 

Adding Custom Alerts


Add custom alerts specific to the school environment by going to Management > Alerts > Add Custom Alert. By design, custom alerts work similar to Dynamic Device Groups. The Location and Last Update Info criteria is required. Other criteria are optional and can be added under Your Criteria. Multiple criteria can be used with logical operators AND and OR. Each criteria also has its own logical operators that are relevant to the rule configured. The drop-down menu features four types of criteria:

After adding criteria, request a status update from devices by selecting Send an Update Info to All Devices, and then click Save. This ensures the correct devices are added to the alerts.

For example, if we are interested in the Battery Health of the devices in our fleet, a Custom Command can be used for criteria to retrieve the battery health information (Add Custom Alert > Add New Alert > New Custom Command). After entering the Custom Command, the expected response to add devices to the alert can be entered. In this example, we want to be alerted for devices with failed battery health so our expected response to the command is “Battery Health Failed”. The Custom Command will run on every Device Info to retrieve the current status of the device so it can be added or removed from the alert as needed.

criteria.png

Note: To use Custom Attributes and Custom Commands for alert criteria, the Mosyle Manager app must be installed.

 

 

 

Configuring Email Alerts


Alerts can be configured to be sent via email by going to Management > Alerts > Alerts via Email > Config. Toggle on the email alerts, choose what alerts to receive emails about and how frequently, and then save. The frequency is once a day, every new alert, or none. Emails are sent only to the administrator who has configured them.

In case a report of the alerts is needed, click Export Alerts at the bottom of the page, select the alerts, and then click Export Info. The report will be available under My School > Preferences > Reports.

 

 

 

DNS Filtering Alerts


Alerts specific to DNS Filtering can also be configured so that selected Administrators receive emailed alerts regarding browser activity. To configure the DNS Filtering alerts, go to DNS Filtering > Click the profile > Select the Alerts tab > Add New Alerts.

Name the Alert and choose an icon. Enter the specific domains or filter you wish to be alerted. Choose the frequency in which to receive emails and select the Administrators to receive the email alerts.

image.png

 

 

 

App deployment and management

App deployment and management

App Installation w/ Apple Apps and Books

Overview


Remotely installing and updating apps is a critical task when managing devices. For this reason, Mosyle supports the installation of apps using managed distribution to devices and/or users. The Install App profile under the Management tab provides the ability to install, reinstall, update, and configure apps in bulk.

Once Install App profiles are created in the account, Administrators can search and filter the profiles based on the profile name and/or category.

As a reminder, the Mosyle Manager application is available for devices enrolled via Automated Device Enrollment and Device Enrollment and provides Administrators with the ability to allow users to complete the installation of apps, web clips, profiles, and more.

To automatically install the Mosyle Manager app so users can access Self-Service on iOS/iPadOS devices, first obtain licenses for the app in Apple School Manager. Once licenses are available and the Apps and Books token is integrated, go to Management > Install App (iOS/iPadOS) > Click Edit Configuration for the Mosyle Manager App Installation profile. Choose the Apps and Books token to use for licensing and click Save.

automatic-installation.png

 

 

The Manager.app along with the Mosyle agent is automatically installed on macOS devices enrolled using Automated Device Enrollment and Device Enrollment. If needed, it can be reinstalled on devices using the command in Management > Devices Overview > Resend Manager agent.

resend.png

 

 

 

Installation Source & License Assignment


To install apps, go to Management > Install App.

Install App profiles can be created to install a single app or groups of apps, to multiple groupings of users and devices. When creating a new configuration profile, name the profile and select the installation source which indicates the source of the app license. For apps available in the App Store, including free apps, it's recommended to obtain licenses using Apple School Manager so they can be deployed using the Apple Apps and Books (VPP) token as the installation source. Similarly, to deploy Custom Apps available in a school or district's Apple School Manager account, choose Apple Apps and Books (VPP) token as the installation source.

*Choosing the App Store as the installation source for iOS or iPadOS devices will result in users being prompted to enter a personal/consumer Apple ID in order to download/install the assigned applications.

After selecting the installation source as Apple Apps and Books (VPP), choose the method in which the license for the app will be assigned. Choosing a device-based license assignment (recommended) will assign the app license to the device serial number, allowing the installation process to be silent to the end user, requiring no user interaction.

Tip: When enrolling via User Enrollment, user-based license assignment is required. This type of license assignment will assign the app license to the user's Apple ID and requires users to be registered in Mosyle with a valid Managed Apple ID and an invite to be associated with the user (Management > Applications > Apple Apps and Books > Invites). The same Apple ID that is associated with the invite must be logged in on the device.

Next, choose the app or apps to be installed and select the users, devices, and/or device groups to assign the profile to in the Profile Assignment area.

image.png

 

 

 

Installation Options


Additional options can be configured when creating an Install App profile in Mosyle. These additional options provide Administrators the ability to control whether apps are automatically installed, available in Self-Service, updated automatically, and/or removed when the assignment is removed.

 

Managing App Updates


The Install App profile can be configured to automatically update apps. Mosyle regularly scans the App Store for updated versions of apps. If an updated version is detected, commands to update the apps can be sent automatically. There are multiple options regarding app updates to choose from:

Requests to update apps can also be pushed from the App Center, Devices Overview/Device Information, or using the Single Shot profile. The Single Shot profile provides the ability to configure a schedule for when the commands for app updates will be sent.

Notes:

 

Managing the Removal of Apps


The Install App profile can be configured to automatically remove applications no longer assigned to iOS/iPadOS devices in the profile. Choose between the following options:

Managed apps can also be removed from devices under Devices Overview and in the App Center. If the apps are not yet managed by the MDM, the user will be prompted to enter their Apple ID and password to first confirm management of the app before the app can be removed by the MDM.

 

 

Managed App Configuration (iOS/iPadOS)


App Configuration is supported by devices running iOS 7 or later and is available in the Install App profile, allowing you to send custom configurations supported by the app developers to applications. Some examples include configuring a specific license or key code for an application. Hover an app in the profile to show the 'C' button in the bottom corner and then click on it to open the App Configuration window. Check the box for “Prepare and Apply an AppConfig PLIST”. If the app's software developer has provided keys and values for the configuration, or an XML file, paste the contents starting with and ending with . When finished, click Confirm.

app-configuration.png

 

 

Installation Flow & Status


Once an Install App profile is created and assigned to users/devices, the View Details area will display the installation status of the apps. There are multiple steps to the installation process for apps, starting with the license assignment. Because of this, it's important to understand the flow in which apps are installed on devices via the MDM.

Before commands to install an application are sent to the device, the MDM first assigns the app license to the device. Once the app license assignment is confirmed to be successful, the MDM generates and sends the command to install the app to the device. The device then validates the app license with Apple servers and proceeds to fetch the app file from the App Store or from a local network caching server. The diagram below gives a broad overview of this flow.

flow.png

Note: This flow is specific for installing apps using device-based license assignment.

The View Details area of the Install App profile provides insight into the status of the app installation process. The app installation status will display if the command is pending or failed, any errors occurred, the app is downloading/installing, installed, outdated, removed, or available in Self-Service.

status.png

Important Notes:

Visit Apple's documentation regarding Content Distribution with MDM for more information.

 

App deployment and management

Enterprise App Installation

Overview


Mosyle supports the installation of proprietary in-house apps on iOS and iPadOS devices through the Install Enterprise profile. The installation of Enterprise apps requires self-hosting, or hosting via Mosyle's CDN, as well as the management of provisioning profiles and distribution certificates.

Reminder: Custom Apps available to organizations within their Apple School Manager account can be deployed using the Install App profile and choosing the Apple Apps and Books (VPP) token as the installation source.

 

 

Adding Enterprise Apps


To install proprietary in-house apps on iOS and iPadOS devices, go to Management > Install Enterprise.

Before creating the Install Enterprise profile, the .ipa file must be hosted and publicly accessible, requiring no user interaction to download. Once hosted, click the Enterprise Apps tab > Add new Enterprise App and enter the .ipa file URL. After entering the URL, Mosyle will automatically retrieve the app name, bundle identifier, and version information. An app icon can be uploaded to the Mosyle console for easy identification of the app within the console and Self-Service.

adding.png

Mosyle provides its own private cloud hosting solution that allows you to host packages directly in the MDM. If the account has access to the Mosyle CDN, simply upload the .ipa file under the Enterprise apps tab to create the app.

 

 

Creating Install Enterprise app profile


After Enterprise Apps are created in Mosyle, click the Profiles tab > Add new profile. Name the profile and select any of the Enterprise apps available in the account to be installed on the devices.

Similar to the Install App profile, options are available for auto-installation, whether the app will be available in Self-Service, as well as uninstall, reinstall, and update behavior.

 

Updating Enterprise Apps


To deploy updates to Enterprise apps, the .ipa file URL for the updated version will need to be added to Mosyle. Once added, the Install Enterprise profile will need to be updated to include the new version. The old version can be deleted from Mosyle under Management > Install Enterprise > Enterprise Apps, click on the previous version of the app and then click Delete in the bottom-right corner of the profile (optional).

After the new version is added to the profile, if the profile is configured to update apps automatically, upon saving the profile commands will be generated to install and update the app on the devices.

Note: Mosyle uses version comparison to determine if an app is outdated. Be sure the value of any new app versions are greater than the current version.

 

Managing the Removal of Enterprise Apps


Enterprise apps can be automatically uninstalled when the Install Enterprise profile is edited using the Advanced Options in the profile.

Managed Enterprise apps can also be removed from devices via Devices Overview and the App Center.

 

Installation Status


Once an Install Enterprise profile is created and assigned to users/devices, the View Details area will display the installation status of the app.

App deployment and management

Mosyle Catalog App Installation

Overview


Mosyle Catalog provides the ability to install, update, and manage third party applications that are not available in the Mac App Store, without having to manually download and host PKG or DMG files. Installing apps using Mosyle Catalog can also automatically install any additional permissions needed for the app, such as Privacy Permissions, System Extensions, or Kernel Extensions.

Whenever available, the Universal version of the application will be installed through the Mosyle Catalog. If a Universal version of the app is not available, the appropriate version of the app will be installed on compatible devices - Apple silicon versions of the app will be installed on Apple silicon devices, and Intel versions of the app will be installed on Intel devices. If only the Intel version of the app is available by the app developer, then the Intel version of the app will be installed on devices. In this scenario, it's recommended that Rosetta 2 is installed on Apple silicon devices.

Apps added to the Mosyle Catalog are based on customer requests. All apps offered in the Mosyle app catalog are owned, distributed, and maintained by each respective software developer. When sending installation commands, Mosyle uses direct download links provided by each respective software developer, thus all packages are offered as-is, without warranty, and the functionality, compatibility, and/or availability of each package cannot be guaranteed by Mosyle. Any licensing or rights to the third party software packages is not offered by Mosyle.

The installation of apps using the Mosyle Catalog requires the Mosyle Manager app to be installed on the Macs. Installation of apps using the Mosyle Catalog is not supported on User Enrolled devices.

 

Creating Install App profile using Mosyle Catalog


To install macOS apps using the Mosyle Catalog, go to Management > Install App > Add new Profile > Choose the installation source “Mosyle Catalog”.

To view the list of applications available in Mosyle Catalog, click the “+ Add Application” button. Within this area, all applications available to be installed are listed along with any permissions required. To view the permissions required for the app, click the link “View permissions for this app”. If you prefer to manually manage the permissions by creating the required management profiles, uncheck the box for “Automatically grant permissions required”.

permissions.png

Choose the app or apps to be installed and select the users, grade levels, devices, and/or groups to assign the profile to in the Profile Assignment area.

apps.png

 

 

Installation Options


Similar to installing apps from Apple Apps and Books, additional options can be configured when creating an Install App profile in Mosyle.

Administrators can control whether apps are automatically installed or available in Self-Service. If choosing the option to “Do not install all apps after saving the profile”, it's recommended to use the option to “Show the apps in Self-Service” so that users can manually request the installation of the apps as needed.

If the option is selected to “Install all apps after saving the profile”, apps will be immediately installed after enrollment if the device is assigned to a User, Grade Level, Course/Class Period, Shared Device Group, or Dynamic Device Group that is assigned to the Install App profile. Administrators can also choose whether apps that have been manually removed should be automatically reinstalled under “Show advanced options”.

 

Updating Apps in Mosyle Catalog


The Install App profile with Mosyle Catalog can be configured to automatically update apps without having to manually update and host the PKG and DMG. Mosyle scans for updated versions of the apps every 24 hours. If an updated version is detected, commands to update the apps can be sent automatically. There are multiple options regarding app updates to choose from:

Requests to update apps can also be pushed from Device Information, by clicking the paper airplane option to install/update the app, or requested using Self-Service.

 

Managing the Removal of Mosyle Catalog Apps


Mosyle Catalog apps can be automatically uninstalled when the Install App profile is edited using the Advanced Options in the profile. To configure the profile so that applications are automatically removed when they are no longer assigned to devices in the profile use one of the following options:

 

Installation Status


Once an Install App profile is created and assigned to users/devices, the View Details area will display the installation status of the app.

 

 

App deployment and management

Install PKG

Overview


Mosyle supports the installation of applications not available in the App Store on macOS devices through the Install PKG profile. The installation of these apps require the PKG, DMG, or ZIP file to be hosted so that they are publicly accessible and directly downloadable without redirection and/or user interaction. They can be self-hosted on a local server (such as SMB), third party CDN, or hosted using Mosyle's CDN.

Despite only specifying “PKG” in the profile name, Mosyle supports the deployment of apps from PKGs, DMGs, and/or ZIP files. The PKG must be a flat PKG. It's recommended each PKG only contain a single application.

 

Adding PKGs


To install PKGs on macOS devices, go to Management > Install PKG.

Before creating the Install PKG profile, the PKG, DMG, or ZIP file used to install the application must be created, hosted, and publicly accessible, requiring no user interaction to download. Many app developers provide a PKG, DMG, or ZIP file that can be hosted and used to remotely deploy the app to multiple devices. If the file is not provided, you can generate the PKG for the app using the Mosyle Manager app (PKGs tab > Add new package > Generate .PKG with Mosyle Manager).

After generating or obtaining the PKG file, it must be hosted so that devices can access and retrieve the file to complete the installation. Mosyle provides its own private cloud hosting solution that allows you to host packages directly in the MDM. If the account has access to the Mosyle CDN, upload the PKG, DMG, or ZIP file under the CDN tab to host.

Once hosted, click the PKGs tab > Add new package > Already have a .PKG.

adding.png

Choose from the following options to configure the app information, which is used to track installation status and if the app is outdated or not:

When editing or manually entering the app information for the PKG, the following fields are available:

Once all app information has been entered, click Save.

 

Creating Install PKG profile


After the PKGs are created in Mosyle, click the Profiles tab > Add new profile. Name the profile and select any of the PKGs available in the account to be installed on the devices.

If the app is signed and it is being installed on User Enrolled devices, check the box to “Install with Apple Protocol”. This will use the MDM protocol command to install the PKG rather than using the Mosyle agent. Keep in mind, PKGs installed using MDM protocol must contain a single, signed application installed into /Applications. If the app is being installed on devices enrolled using Automated Device Enrollment or Device Enrollment, it's recommended to leave this option unchecked.

Options are available for auto-installation, delayed installation, and whether the app will be available in Self-Service.

 

Managing Updates with Install PKG


To deploy updates to apps installed via Install PKG, a new PKG must be created and hosted with the new app version and added to Mosyle. Be sure to update the version field when adding the updated PKG. Once added, the Install PKG profile will need to be updated to select the new/updated version. The old version can be deleted from Mosyle under Management > Install PKG > PKGs, click on the previous version of the app and then click Delete in the bottom-right corner of the profile (optional).

After the new version is added to the profile, if the profile is configured to update apps automatically, upon saving the profile commands will be generated to install and update the app on the devices.

Note: Mosyle uses version comparison to determine if an app is outdated. Be sure the value of any new app versions are greater than the current version.

 

Managing the Removal of Apps


Some apps installed using the Install PKG profile on devices running macOS Big Sur or later can be considered "managed" and therefore, can be removed using an MDM command. In order for an enterprise app (PKG) to be considered a managed app on macOS, it has to meet certain criteria:

If the app is managed, it can be removed through Device Info under the Apps tab. If the app is not a managed app, or the device is not running macOS Big Sur or later, you can remove the app from the Mac using the uninstaller provided by the app developer, or a custom command such as: rm -rf /Applications/PATH_TO_APP.app

 

Custom Configuration of PKGs


Applications that require specific configurations, such as a registration code or license key, can be installed on devices using the Install PKG profile. When creating the PKG in Mosyle, enter the configurations necessary as a pre- or post-install script so that they are applied either before or after the installation of the app. Check the app developer documentation for more information on any configuration specifications.

custom-config.png

If preferred, the installation of applications with specific configurations can also be done using the Custom Commands.

 

Installation Status


Once an Install PKG profile is created and assigned to users/devices, the View Details area will display the installation status of the app. The verification that the app has been installed relies on the bundle ID entered when creating the PKG in Mosyle. If the bundle ID for the app is incorrect, the installation status will remain as “Installing” or “Removed” due to Mosyle being unable to match the bundle ID of the PKG with a bundle ID of an app installed on the device.

 

App deployment and management

App Center

Overview


The App Center itemizes all apps installed on managed devices based on platform (iOS / iPadOS, macOS, tvOS). It includes detailed information about an app's name, bundle identifier, category, status, how many devices it's installed on, and if it's managed (iOS / iPadOS).To access the App Center, go to Management > Applications > App Center.

Filter the apps by clicking Add Filter at the top of the screen. Filter the list using the Filter options along the top, or enter search criteria to find a specific device or app. The information provided by the filters is also designed to be sorted with a simple click of a column name or edited with a click of the search.

Commands available along the toolbar of the App Center include:

Notes: Manage Apps supports macOS devices running 11 or later. In order for an enterprise app to be manageable on macOS, it has to meet certain criteria: it must not contain any nested packages, it must contain only a single signed app, and it must be installed in /Applications.

 

 

Additional Information


Within the App Center you can see the Install app or Install PKG profiles the app is assigned to as well as the installation status of the app. Use the Filters to search for apps installed or not installed through profiles, installation source, managed status, and more.

Click the “View” link under the Profiles column to view the Install app or Install PKG profile associated with the app.

Click the “View” link under the Installed column to view the installation status of the app or PKG. The installation status should reflect the same information that is presented in the “View Details” area of the Install App profile.

app-center.png

 

 

Management Profiles & Device Configuration

Management Profiles & Device Configuration

Management profiles

Overview


The Management Tab in the Mosyle Web Panel is organized by OS platform and provides Administrators a variety of Management profiles which can be customized to automate the application of policies and restrictions to fit the needs of each school or district. Some profiles have specific requirements such as supervision or a certain OS version. Requirements will be listed within the profile.

 

Activating and Deactivating Management Profiles


The list of Management profiles can be found in the menu on the left and are organized in alphabetical order, with the exception of Install App and Install Enterprise/PKG. Each account, upon first setup, is equipped with a standard set of commonly used Management profiles. Additional Management profiles are available and can be activated by clicking “+ Activate New Profile Type”. Enter keywords to search for a specific profile, or click the link to read more about the Management profile.

activating.png

If the school or district does not have a need for a specific Management profile, select the profile from the menu on the left and click “Deactivate”. Only Management profiles that aren't in use and don't have any configuration profiles can be deactivated.

deactivating.png

 

 

Favorite Management Profiles


Frequently used Management profiles can be marked as a “Favorite” so that they appear at the top of the list, and on the Dashboard under the Profiles. To add a profile as a favorite, click the ⭐ icon. The favorite profiles are customizable for each Admin user.

favorite.png

 

 

Profile Scopes


Apple Shared iPad devices and macOS devices support both system and user scope configurations. By default, profiles install at the system scope unless it is not supported. However, profiles can be installed at the system scope or user scope based on the needs of the school or district. Choose one from the Profile Scope menu at the bottom of a profile.

profile-scope.png

System Scope

Profiles installed at the system scope apply the configured preferences at the system level, affecting all user accounts on the device and show under System Settings > Privacy & Security > Profiles > Device Profiles. Typically, settings configured via Management profiles are enforced on the device and cannot be manually changed.

User Scope

Profiles installed at the user scope apply the configured preferences only for the specific user accounts who are assigned and eligible for user scope profiles. User accounts are eligible for user scope profiles in the following scenarios:

When assigning profiles via the user scope, be sure to assign the profile to users rather than to devices. Profiles installed at the user scope on macOS devices show under System Settings > Privacy & Security > Profiles > User Profiles.

Notes:

 

 

 

Scheduling Profiles


Management profiles such as restrictions and allowed/blocked apps, provide options for scheduling their automatic installation and removal. This is useful in a variety of environments, some examples listed below:

For profiles that support time based scheduling, there is an option to apply the profile “Fulltime (24x7)” or “Schedule choosing a time profile”.

schedule.png

Applying the profile full time will install the profile and enforce the settings until it is unassigned or removed. In the case of an App Lock or Kiosk Mode profile, Administrators have the option to install the profile only once or to resend the profile every 24 hours. When selecting the option to resend every 24 hours, the profile will install and be configured to automatically remove from the device after 24 hours. Mosyle will simultaneously send a command to reinstall the profile. This option for the 24 hour expiration is provided as a potential failsafe for devices in the event they lose network connectivity so that the profile will automatically be removed locally, releasing the device from the App Lock so it can be reconnected.

In a scenario where the profile is not resent every 24 hours, if the device loses network connectivity, the command from Mosyle to remove the App Lock will be unable to go through. If this happens, the device will need to be connected to ethernet, paired with a computer, or erased in order to remove the App Lock and regain access to the device.

resend.png

When scheduling the profile using a time schedule, click Select to create a new time profile or choose an existing time profile to define when the configuration will be installed and removed.

schedule-time.png

To choose an existing time profile click on the time profile; click “Edit” to edit an existing time profile. To create a new time profile click “New time profile”. Enter a name for the time profile, choose the time zone, and choose whether to restrict access or not, click Save. On the next screen, enter the start time in which the management profile will be sent, and an end time to designate when Mosyle will send a profile removal command. Select the days the schedule will be applied and click Add time. When finished, click the back arrow in the upper left corner and then select the time profile to apply it to the management profile.

profile-time.png

 

 

Installation Options in Profiles


Some profiles include additional installation options within the profile to control when the profile is pushed to the devices. The options include:

 

Using Variables in Profiles


Many profiles support the use of variables to automate the inclusion of user or device information in profile fields, saving administrators time. Variables pass user information based on the data contained within each user's profile under the Organization tab. Check the link within the profiles to view the available variables. Check the box to indicate the profile is using variables to ensure the payload is properly configured.

variables.png

 

 

Compliance Status


After a Management profile is created and saved, the profile Compliance Status will be displayed and accessible under the “View Details” link for the profile. Devices with the profile installed will be listed, along with devices where the profile is pending to install, either because the device is turned off or offline, or devices with the profile removed. At any time a Push can be sent to call devices to the MDM server to retrieve the command to install the profile.

Profiles showing a compliance status as “Not compatible” will occur if the device does not meet compatibility requirements of the profile, or if the profile contains variables and Mosyle is unable to fill the variables. For example, a profile using user variables such as User ID or Email, but the device is not assigned to a specific user. In this scenario, the variables are unable to be filled, therefore the profile will be listed as “Not compatible”.

 

 

Management Profiles & Device Configuration

Commands Activity Log

Overview


The Commands Activity Log provides an overview of all pending and failed commands. Filter commands, send a push to the devices, or clear specific commands with a few clicks. To access the Commands Activity Log, go to Management > Devices > Commands Activity Log.

commands-activity.png

 

Pending Commands and Failed Commands


The Pending Commands tab shows commands that have not been delivered to or acknowledged by devices. The Failed Commands tab shows commands received by devices but failed or received some other error. Ten commands are shown per page with information about the type of command, the scope, the device's name, the device's serial number, the date of the command, and the last time the device communicated with the MDM.

Administrators can filter the commands by serial number and then narrow their search by time frame, including today's date, this week, this month or all-time, or by type of command. After filtering the commands, click Send a Push to Devices to communicate with the devices and resend pending and failed commands.

If the commands remain pending or failed, troubleshoot your local network for firewalls or proxies, or get in touch with the Mosyle Support team for assistance. Click Export to request a CSV file of the current pending or failed commands. Review the export for any trends, such as a common last connection date for devices, or repeat devices in the list of pending commands. This data can assist with isolating communication issues with devices.

Notes: If a device's last connection was prior to the command date, it's possible the device is no longer communicating with the MDM. First, check to make sure the MDM profile is still installed on the device, then select the device and send an Update Info command from Management > Devices Overview.

 

Clear Commands


The Clear Commands tab lists all commands available for clearance. Filter the commands by date, devices, pending or failed. Select the commands from the list and click Submit to clear them.

Commands that have been cleared will not be automatically resent to devices. If a command is cleared, it will need to be manually regenerated to be sent to the device.

If a historical analysis is needed of cleared commands, click View Cleaning History. A pop-up will show who, when, and how many commands were cleared. To restore commands sent in the last two days, click Restore.

 

 

Management Profiles & Device Configuration

Managing OS Updates

Overview


Mosyle encourages administrators to update devices to the latest OS version available when possible. Both major and minor, or incremental, updates can be managed, downloaded, installed, and/or deferred using Mosyle. The OS update process is a two-step process:

  1. The OS update is first downloaded on the device
  2. The OS update is then installed on the device

Devices must be online, supervised, charged, meet the minimum OS requirement, have sufficient storage available, and a battery percentage of at least 50 percent when receiving the OS update command.

Devices cannot downgrade to an older version than their existing version and must be compatible with the version selected. If incompatible, the command will not be sent. Only copies of operating system versions that are actively being signed by Apple can be installed on devices.

 

Software Delay


The MDM is unable to block or prevent OS updates, however the Software Delay profile allows Administrators to defer OS updates and upgrades. Using the Software Delay profile, Administrators can configure devices so that OS updates are not visible to end users up to 90 days from the release date. Delaying software updates provides time to test the latest release and ensure all apps and systems work as expected before updating the fleet.

The Software Delay settings will not prevent the MDM from pushing OS updates to devices or querying available OS updates.

To create a Software Delay profile, go to Management > Click the Software Delay profile. Choose from the options available.

Delaying iOS/iPadOS Updates

On iOS/iPadOS devices, you can delay the software updates from being visible to end users for up to 90 days.

delaying.png

Delaying macOS Updates

On macOS devices, you can delay major or minor software updates, and/or App updates, from being visible to end users for up to 90 days.

The options available when delaying macOS software updates include:

delaying-options.png

 

 

Software Update Settings


Software Update settings include which OS will show available to end users on iOS and iPadOS devices when more than one is available, automatic security updates (iOS/iPadOS 16+), and background OS update behavior on Mac computers.

To create a Software Update profile, go to Management > Click the Software Update profile. Choose from the options available.

The Software Update profile does not push OS updates. To send commands to update the OS on devices, use Devices Overview or Single Shot.

iOS/iPadOS Software Update Settings

Recommendation Cadence (iOS/iPadOS 14.5+ and tvOS 15+): The software updates that will be visible when more than one is available.

Automatic Security Updates (iOS/iPadOS 16+): Configure the automatic security update settings on the device.

software-update-ios.png

macOS Software Update Settings

The Software Update profile configures the advanced options on macOS devices in System Settings > General > Software Update > . If the profile is installed, the options will be grayed out for users.

Once configured, native OS protocols will control when the macOS device is updated. This is similar to configuring these settings natively on the device but without allowing the end-user to change it afterwards.

Available options for macOS devices:

More information about each of the options above can be found in Apple's Change Software Update preferences on Mac documentation.

software-update-macos.png

 

 

Deploying iOS & iPadOS Updates


Devices will report the latest available OS updates to the MDM via the AvailableOSUpdate query. Any additional OS updates available are identified using Apple Software Update Servers and the software update ID for the device. Updates that have expired, or are no longer signed by Apple, cannot be pushed from the MDM.

Devices running iOS 10.2 or earlier, must be supervised and enrolled through Automated Device Enrollment in order for the MDM to push OS updates to the device. Devices running iOS 10.3 or later just need to be supervised.

If an iOS/iPadOS device has a passcode, the user will need to authorize the update by entering their passcode, allowing them to defer the update a limited number of times. After the user reaches the limit, the system will prompt to update every time the device returns to the home screen.

Update through Devices Overview

Update the operating system (OS) on iOS, iPadOS and tvOS devices in Management > Devices Overview. The toolbar shows the command based on the platform selected, such as Update iOS or Update tvOS, and offers multiple options for updates:

After selecting the command, select the OS version to install. Check the status of the update in Management > Devices Overview > Click on the device's name to bring up Device Info > Operating System Version.

update-ios.png

Update through Single Shot Profile

Update the operating system (OS) on iOS, iPadOS and tvOS devices in Management > Management Profiles > + Activate New Profile > Single Shot. The Single Shot profile provides the ability to send the commands to update the OS at a time that is convenient for users, such as outside of school hours. Since the OS update is performed in two steps, it's recommended to configure two Single Shot profiles:

Choose when the commands will be sent - when saving the profile and based on a schedule, only when saving the profile, or based on schedule only. The option “when saving the profile” includes when the profile is saved and when the device is enrolled or assigned to the profile. When scheduling the commands, it\’s recommended to schedule at a time that will not impact device use.

 

 

Deploying macOS Updates


Devices will report the latest available OS updates to the MDM via the AvailableOSUpdate query. Updates that have expired, or are no longer signed by Apple, cannot be pushed from the MDM.

Devices running earlier versions than macOS 11 must be supervised and enrolled through Automated Device Enrollment. Devices running macOS 11 or later, only supervision is required. Mac computers with Apple silicon must have a bootstrap token to allow the MDM to push and install software updates.

Update through Devices Overview

Update macOS on devices in Management > Devices Overview > More dropdown menu > Update macOS. The command downloads and/or installs the version available to devices.

The list of available macOS versions across the fleet will be displayed in the pop-up window, where administrators select the version to update the devices. If the device is not compatible with the version selected, or the version selected is lower than the macOS version running on the Mac, the command is not generated. Administrators can send or schedule the command. If scheduled, the command will be available for users to run from the Self-Service application after the days-long delay expires.

update-macos.png

Available Commands

The Priority dictates the priority of the OS update. If set as “Low” the standard behavior will occur. If set as “High”, the macOS will interpret the command as if the user requested it manually on the Mac.

Update through Single Shot Profile

Update macOS on devices in Management > Single Shot. The Single Shot profile provides the ability to send the commands to update the OS at a time that is convenient for users, such as outside of school hours. Since the OS update is performed in two steps, it's recommended to configure two Single Shot profiles similar to the iOS/iPadOS updates.

Choose when the commands will be sent - when saving the profile and based on a schedule, only when saving the profile, or based on schedule only.

 

 

Automating OS Updates


Automate OS updates for devices in your school or district using a combination of Device Groups and two Single Shot profiles. Doing this will ensure the devices download and install any updates as soon as they are available. To do this, follow the steps below.

  1. Create a Dynamic Device Group to identify devices that have available updates using the criteria: "OS Update" is "Available".

    The Device Group will update daily and automatically add any devices that are reporting a software update is available. As soon as the devices are updated, they will no longer meet the criteria for the Device Group and will be removed from the group and no longer receive the commands to download/install software updates until a new software update is available.

  2. Create a Single Shot profile to Download the OS Update on devices that are identified as having a software update available. Using the dropdown menu for Action choose "Update iOS/ tvOS/macOS" and select the option "Download the software update without installing" along with the "Latest version available".

    Execute the command based on the schedule only and choose a day/time outside of school hours to avoid any interruption in use. You can schedule to run as often as you'd like or as needed. Assign the Single Shot profile to the Dynamic Device Group created earlier. As devices are added to the Device Group, the command to download the OS update will be sent based on the defined schedule.

  3. Create a Single Shot profile to Install the OS Update on devices that have been identified as having a software update available and received the command to download the OS update. Using the dropdown menu for Action choose "Update iOS/tvOS/macOS" and select the option "Install an already downloaded software update" and the "Latest version available".

    Execute the command based on the schedule only and choose a day/time outside of school hours to avoid any interruption in use. Be sure to schedule for days/times after the command to download the OS update was sent. You can schedule to run as often as you'd like or as needed. Assign the profile to the Dynamic Device Group created earlier. As devices are added to the Device Group, the command to install the OS update will be sent based on the defined schedule.

Additional Options

Considering OS updates can take some time, additional notifications and configurations can be used to alert users that the OS update is required. Some examples are included below:

A combination of these additional options along with the Single Shot profile to enforce the OS update has proven successful to keep devices up to date.

 

 

 

Management Profiles & Device Configuration

Device Restrictions & Passcode Policies

Device Restrictions


The Restrictions profile configures restrictions on iOS, iPadOS, macOS, and tvOS devices. Features may vary based on the type and OS version of the device, and some may require supervision.

To create a Restrictions profile go to Management > Restrictions. Select the restrictions to be applied, and choose the Application time (Full time or according to a time profile). Assign the profile to users and/or devices and click Save.

If multiple Restriction profiles are installed on a device, the OS will combine all settings for the most restrictive configuration.

 

 

Common iOS/iPadOS Restrictions


Below is a list of common restrictions applied to iOS/iPadOS devices:

 

Common macOS Restrictions


The macOS Restriction profile is organized into six categories/tabs. Use the option 'Do not configure the options on this tab' in the Restrictions profile to ensure any settings or restrictions within the tab are not applied and the default or manual configuration that's present on the macOS devices will remain unchanged. This feature is important in prevention of accidental deployment of configurations and impact of devices assigned to the profile.

The tabs are organized with their corresponding restrictions. After making any changes to a Restriction profile and reinstalling the profile on devices, the Mac may require a reboot for the new restriction configurations to be applied.

macOS Restrictions Tabs

 

Passcode Policies


The Passcode Policies profile configures passcode criteria on iOS, iPadOS and macOS devices. It supports the system scope and user scopes on macOS devices. If user scope is chosen, please assign only users to the profile. If existing passcodes do not meet the policy standards, users will be prompted to reset their password.

The Passcode Policy profile does not create or set passcodes and is not compatible with Apple Shared iPad devices. To set the PasscodeLockGracePeriod on Apple Shared iPad devices, configure the Apple Shared iPad Shared Device Group settings.

To create a Passcode Policy, go to Management > Passcode Policies.

Features include:

Additional Considerations

 

Removing a passcode on iOS/iPadOS devices


If the passcode is forgotten on an iOS/iPadOS device, it's important to keep the device connected to the network and not restart the device. The device will remain auto-joined to the network as long as it has not been restarted or powered off. As long as the device remains connected it can receive the Remove Lock Passcode command from Mosyle to remove the passcode, Touch ID, and/or Face ID.

To remove the passcode from an iOS/iPadOS device go to Management > Devices Overview > Select the device > More dropdown menu: Remove Lock Passcode.

If the command is sent and the device is connected to the internet, it will remove the passcode and allow the device to be unlocked with the Home button. If the Passcode Policies profile is installed on the device to force a password, it will prompt the user to set a new passcode.

 

Managing User Accounts on macOS


Administrators can manage User Accounts on Mac computers that are supervised and enrolled in Mosyle.

To access these options, go to Management > Devices Overview > Click on a device's name to bring up the Device Information window > More dropdown: Manage Users. Here you can either change the user's password or unlock the user account after too many failed password attempts.

In order to change a user's password, Administrator credentials for an admin user with a Secure Token is required. The new password must meet password policies, including the Passcode Policies profile or active rules in Security. If FileVault is turned on, the disk must be unlocked for the device to acknowledge the commands. The device must be online at the login window in order for the commands to go through to change the user's password or unlock the device.

If the user's password is unable to be changed through Mosyle, the password can be changed using the Reset Password Assistant in recoveryOS. To reset an account's password, follow the instructions under the heading "Use the Reset Password assistant" in the Apple Support article.

Changing the ADE Admin Password

When creating the Administrator account using the Automated Device Enrollment profile, a password needed to be defined. This password can be changed by sending the Set Admin password in Devices Overview, or using the Single Shot profile to Change the Randomized DEP Admin Password.

 

Management Profiles & Device Configuration

Managing WiFi Connectivity

WiFi Authentication


The WiFi Authentication profile configures networks for devices to join. To create a WiFi Authentication profile, go to Management > WiFi Authentication. Name the profile, enter the network SSID, choose the Security Type, and enter the password to join the network. Assign the profile to users/devices and click Save.

It's important the Security type and password are correct in the profile so that the device can successfully join the network.

MAC Address Randomization (iOS/iPadOS)

Starting with iOS and iPadOS 14, devices use a unique MAC address, or network address, when connecting to each network. This is a security and privacy enhancement to prevent network administrators from tracking devices, especially in the public sphere. In a school or district, this enhancement may conflict with network protocol that filters devices based on their MAC address. If your environment is impacted, please turn off MAC Address Randomization by checking the box in the profile.

When disabling MAC Address Randomization, it is on a per-SSID basis and will result in a privacy warning being displayed in the Settings app indicating the network has reduced privacy.

Lock WiFi (iOS/iPadOS)

The Lock WiFi configures iOS and iPadOS devices to only connect to managed networks that have been configured on devices using a WiFi Authentication profile.

To create a Lock WiFi profile, go to Management > WiFi Authentication > Click the Lock WiFi tab. Name the profile and choose an Application time.

Mosyle automatically installs a backup WiFi Authentication profile on enrolled devices so that in the event a Lock WiFi configuration is applied, and the device is unable to join the managed network, a temporary SSID can be configured to allow the device to connect. To view the credentials for the backup WiFi Authentication profile, a Mosyle Administrator can click View Details for the profile then click the link “Too late? Here's how to fix this problem”.

wifi.png

 

 

 

Multi-Cert Profile


The Multi-Cert Profile configures network settings that use certificates to authenticate to the network by combining related WiFi, VPN, SCEP, or AD Certificate payloads. It supports installations at the system scope and the user scope. If user scope is chosen, please assign only users to the profile.

To create a Multi-Cert Profile:

  1. Click on Management > Multi-Cert Profile
  2. Click “Add New Profile”
  3. Name the profile and click + Add Profile
  4. Click the payload
  5. Configure as needed and Save
  6. Save
  7. Assign the profile to users/devices
  8. Save

The WiFi Authentication profile and Multi-Cert profiles will be reinstalled each time they are saved. To avoid this behavior, it's recommended to select 'Do not reinstall the profile during assignment/login'.

Management Profiles & Device Configuration

Kernel Extensions, System Extensions, Privacy Preferences

Overview


Applications deployed to macOS devices may require the configuration of Kernel Extensions, System Extensions or Privacy Preferences. This can be remotely configured through Mosyle so the user isn't prompted to allow any additional items upon the installation of the application.

 

Kernel Extensions


The Kernel Extensions profile allows signed kernel extensions to load from a list of developer Team Identifiers or a list of Team Identifiers mapped to application Bundle Identifiers. Map Team Identifiers to Bundle Identifiers to allow specific Bundle Identifiers to load. Enter only the developer Team Identifier to allow all Bundle Identifiers.

Be sure to reference an application's software documentation if system extensions have replaced kernel extensions, or if both are needed. Mac computers running macOS 11 or later require user approval or manual intervention to load kernel extensions, unless it is a Mac computer with Apple silicon and Bootstrap Token is allowed for authentication. Check Apple's documentation for more information on kernel extensions and management of legacy extensions.

To create a Kernel Extensions Profile

kernel-extension.png

 

 

System Extensions


The System Extensions profile loads system extensions on devices running macOS 10.15 or later. System extensions run in the user space and replace Kernel extensions. As developers transition applications to use System Extensions instead of Kernel Extensions, apps may require the combination of Kernel Extensions profile in addition to the System Extensions profile in the meantime. Check the developer documentation to confirm the use of either Kernel or System Extensions. Reference Apple's documentation for more information about system extensions.

To create a System Extensions Profile

  1. Click Management > System Extensions
  2. Click “Add New Profile” and name the profile
  3. Choose how to allow the extensions: Allow all system extensions from specific Team IDs; allow specific system extensions from specific Team IDs; allow specific system extensions
  4. Enter the Team ID and Bundle ID
  5. Assign the profile to users and/or devices
  6. Save

system-extension.png

 

 

Privacy Preferences


The Privacy profile configures privacy permissions for applications. It's installed at the system level, meaning configurations will not be visible to the logged-in user in System Settings > Privacy & Security.

Apple's MDM protocol does not provide MDM solutions access to remotely grant certain privacy permissions such as Camera, Microphone, Screen Sharing/Capture, Location Services, and Listen Events (Input Monitoring). For microphone and camera, these permissions may be approved by a Standard local account. By default, Screen Capture and Listen Events require Admin credentials. For devices running macOS 11+, you can create the Privacy profile with the option "Allow Standard User to Set (macOS 11 and later)" for these two permissions.

To create a Privacy Profile

  1. Click Management > Click Security & Privacy > Privacy tab
  2. Click “Add New Profile” and name the profile
  3. Configure as needed
  4. Assign the profile to users and/or devices
  5. Save

Some features in Mosyle require the agent to have certain Privacy Permissions. Check the box “Install the Privacy Preferences Policy Control settings for the Mosyle Manager app to allow access to all necessary files and application data.”

Management Profiles & Device Configuration

Securing Devices

Overview


In the event a device belonging to the school or district is lost or stolen, there are remote management methods to lock the device, secure data stored, and/or prevent further use of the device.

Available options via the MDM include:

IMPORTANT NOTE: Mosyle will retain the Activation Lock bypass codes, FileVault Personal Recovery Key, and Lock PIN for the duration of time the device remains in the Mosyle system. If the device is removed from the MDM, the data will be removed from all Mosyle systems and cannot be recovered. Before removing devices from the Mosyle MDM, please be sure to take note of any codes, keys, or passwords that may be needed in the future.

 

 

Lost Mode (iOS/iPadOS)


To enable Lost Mode on a device, go to Management > Devices Overview > Select any/all devices to enable Lost Mode. From the More dropdown menu, choose “Activate Lost Mode”. Enter the desired message to be displayed on the device screen when it is locked (required), as well as a phone number or footnote (optional). In order for Lost Mode to be enabled on the device, it must have a valid network connection so it can receive the command from the MDM.

When Lost Mode is enabled, a banner will be presented under the Security Info tab in Device Information for the iPhone or iPad.

lost-mode.png

After turning on Lost Mode, the device will be locked. To play a sound or request the device location, click the More dropdown menu and choose: Request Location or Play Sound.

location-or-sound.png

Enabling Lost Mode will not prevent someone from erasing the device. If erased and the device is part of Apple School Manager and assigned to Mosyle, it will automatically re-enroll in the MDM after connecting to a network and will re-apply Lost Mode. If the device is not part of Apple School Manager, or is not assigned to the Mosyle MDM server, it can be erased and the user will be able to proceed with normal setup.

To disable Lost Mode, go to Management > Devices Overview > Select any/all devices to turn off Lost Mode. From the More dropdown menu, choose “Disable Lost Mode”. Again, devices will need a valid network connection to receive the command to release Lost Mode.

 

 

Activation Lock


Activation Lock is a built-in security mechanism on iOS, iPadOS, and macOS devices which prevents users from being able to activate and set up a device without knowing the Apple ID credentials that enabled Activation Lock. If Activation Lock is enabled and the device is erased, the user will be presented with a screen requesting the Apple ID credentials used to enable Activation Lock in order to proceed with setup. The device will be locked and unusable until Activation Lock is released or unlocked.

Activation Lock can be managed on devices owned by the school or district, and exist in Apple School Manager. Devices can be locked with Activation Lock in two forms:

Note: A T2 chip or Apple silicon is required on macOS devices for Activation Lock.

User-initiated Activation Lock

By default, devices enrolled in Mosyle MDM using Automated Device Enrollment will be blocked from User-initiated Activation Lock being enabled, in other words users enabling Activation Lock with their personal Apple ID. If the school or district prefers users to have access to enabling Activation Lock, check the box to “Allow User-initiated Activation Lock” in the Automated Device Enrollment profile.

Upon enrollment, Mosyle requests an Activation Lock bypass code from the device. This code can be used to unlock a device which has been Activation Locked by a user. Please note, Mosyle MDM is unable to manage or unlock Activation Lock if it was enabled prior to enrolling in the MDM.

If devices have already been enrolled and you wish to either allow or block User-initiated Activation Lock:

If a device is User-Initiated Activation Locked after being enrolled in the Mosyle MDM, it can be turned off using one of the methods below:

MDM-initiated Activation Lock

The MDM can enable MDM-initiated Activation Lock on any enrolled device that was enrolled via Automated Device Enrollment and is part of the school or district's Apple School Manager account. When enabling Activation Lock, the device is not required to have a network connection as the Activation Lock request is simply an API call between the Mosyle servers and Apple servers.

To enable Activation Lock, go to Management > Devices Overview > Click a device name to bring up Device Info > More dropdown menu: Enable MDM-Initiated Activation Lock.

If a device is MDM-Initiated Activation Locked, it can be turned off using one of the methods below:

Activation Lock Bypass Code

Each device will have two Activation Lock Bypass Codes. One code is to bypass User-Initiated Activation Lock, the other is to bypass MDM-initiated Activation Lock (if MDM Activation Lock was enabled). Be sure to use the appropriate Activation Lock Bypass Code depending on how Activation Lock was enabled. To view the Bypass Codes, go to Management > Devices Overview > Click on a device's name to bring up Device Info > Click Security Info tab.

If Activation Lock is unable to be removed, the device will need to be taken to an Apple Store with proof of purchase in order to be unlocked.

activation-lock.png

 

 

FileVault (macOS)


The Security profile in Mosyle will enforce the enablement of FileVault. Find the profile by going to Management > Security & Privacy > Security tab > Add new profile. The FileVault settings are available under the FileVault tab.

To enforce and require FileVault, check the box for “Require FileVault”. Choose whether to use an Institutional Recovery Key, Personal Recovery Key, or both. Institutional Recovery Keys are not supported on Mac computers with Apple silicon, so it's recommended to use Personal Recovery Keys.

personal-recovery.png

When using Personal Recovery Keys, it's recommended to escrow the key to the MDM so it's available as needed. To escrow the key, check the box “Escrow Personal Recovery Key”. Enter location information for the key and choose whether or not to show the end user the recovery key locally on the Mac when FileVault is enabled.

escrow.png

Last, choose when to prompt the user to enable FileVault. Select “Defer enabling until logout” to prompt users to enable FileVault when logging out, check the box “Ask at login” to prompt users to enable FileVault when logging in. Set the maximum number of times the user can skip the prompt to enable FileVault before being forced.

prompt-enable.png

Secure Token & Bootstrap Token

Users can only enable FileVault if they have a secure token. Starting with macOS 11, the first user created on the Mac with a plain text password is granted the initial secure token.

Users granted a secure token on macOS 11 and later:

Because the password for the additional admin account created during Automated Device Enrollment is set using a password hash, the admin account created during Automated Device Enrollment is typically not the first user to be granted a secure token. In order for the admin account created during Automated Device Enrollment to be granted a secure token, the bootstrap token must be generated and escrowed. The bootstrap token is generated and escrowed to Mosyle only after a user with a secure token logs in for the first time. Once the bootstrap token is generated and escrowed, any other user who logs in on the Mac will receive a secure token (macOS 11 and later). This means, in order for the admin account created during Automated Device Enrollment to be granted a secure token, the user account will need to login on the Mac.

Mac computers with Apple silicon, enrolled via Automated Device Enrollment, require the bootstrap token to authorize the installation of kernel extensions and software updates via the MDM. Additionally, the bootstrap token is used to authorize the Erase All Content and Settings (EACS) command on Mac computers with the T2 security chip or Apple silicon running macOS 12.0.1 or later. Mac computers with Apple silicon that are manually enrolled will need to update the Security settings in Recovery mode so the MDM can install kernel extensions, software updates, and authorize EACS.

To allow the bootstrap token, configure your Automated Device Enrollment profile to “Allow Bootstrap Token” by going to:

  1. My School > Apple Basic Setup
  2. Enrollment > Automated Device Enrollment
  3. Click the enrollment profile
  4. Check the box to “Allow Bootstrap Token” and save
  5. After the device is enrolled and a user with a secure token logs in, the bootstrap token will be created and escrowed in Mosyle.

Apple silicon devices that have already been enrolled via Automated Device Enrollment, but were not enrolled with the option to “Allow Bootstrap Token” can be sent a command after the enrollment to allow bootstrap token. To do this, follow the steps below:

  1. Management > Devices > Devices Overview
  2. Select the device(s) > More dropdown menu: MDM Options
  3. Choose the option “Allow bootstrap Token”
  4. After the command goes through, a user with a secure token will need to login to generate and escrow the bootstrap token. Once generated and escrowed, all other users logging in on the Mac will receive a secure token (macOS 11 and later).

Check out Apple's documentation for more information on FileVault, Secure token, and Bootstrap Tokens.

Rotating the Recovery Key

For security reasons, you may need or want to rotate the personal recovery key. You can do this in intervals of 30, 60, 90, or 120 days using the Single Shot profile under the Management tab.

  1. Go to Management > Single Shot
  2. Choose the action "Rotate FileVault key"
  3. Select to rotate the personal recovery key or the institutional recovery key and enter the required information
  4. Choose the interval for the rotation: 30, 60, 90, or 120 days
  5. Assign the profile to users/devices

To rotate the institutional recovery key, you must enter the username and password for an Admin user on the Mac that has a secure token and upload the new institutional recovery key. To rotate the personal recovery key, you must enter the username and password for an Admin user on the Mac that has a secure token or select the option to use the current recovery key if it is escrowed in Mosyle.

Managing devices that are already encrypted

Devices that are already encrypted can be managed so that the personal recovery is escrowed in Mosyle. Some scenarios that administrators may find the need to do this include:

Below are options and workflows that can be used to migrate encryption management:

  1. Decrypt the Macs, enroll in Mosyle and then install the Security profile to enforce FileVault encryption and escrow the recovery key in Mosyle.
  2. If you know the username and password for an Admin user on the Mac with a secure token, once the Security payload from Mosyle is installed, you can configure the Single Shot profile to rotate the recovery key. After it's rotated, it will be escrowed in Mosyle.

If you need assistance with escrowing the personal recovery key, please contact the Mosyle Support Team.

 

 

Firmware Password (macOS)


The Firmware Password profile sets a password on the firmware of Intel-based devices running macOS 10.13 or later. A firmware password prevents users who don't have the password from starting up all disks other than the designated startup disk and blocks most startup key combinations.

To add a firmware password to a Mac, go to Management > Click the Firmware Password profile > Enter the new password. If the devices already have a firmware password and it needs to be changed, select “The devices already have a firmware password” and enter the old password. To remove the firmware password, leave the new password field blank and enter the current password.

Mac computers with Apple silicon do not support firmware passwords. Mosyle is unable to remove or change a firmware password if the current password is forgotten. In a scenario where the firmware password is unknown, please contact Apple.

 

 

Recovery Lock Password (macOS)


The Recovery Lock profile sets a Recovery Mode password on Apple silicon devices running macOS 11.5 or later. A Recovery Lock password prevents users who don't have the password from booting Apple silicon devices into Recovery Mode. Recovery Lock passwords are removed when a device is erased or removed from the MDM.

To add a recovery lock password to a Mac, go to Management > Click the Recovery Lock Password profile > Enter the new password. If the devices already have a recovery lock password and it needs to be changed, select “The devices already have a recovery lock password” and enter the old password. To remove the recovery lock password, leave the new password field blank and enter the current password.

 

Lock Device (macOS)


Lock a device with a 6-digit PIN so it cannot be accessed until the correct 6-digit PIN is entered. To send the command to lock the Mac, go to Management > Devices Overview > More dropdown menu: Lock Device. Enter the 6-digit PIN.

lock-device.png

The last 10 Lock PIN codes are available under Management > Devices Overview > Click on the device's name > Has Lock PIN Code? > Click here to see the last Lock PIN Code. If the PIN is entered incorrectly too many times and shows the Mac is “Disabled”, please contact Apple support to unlock the devices.

Reminder: If the device has been sent a command to lock the device with the Lock PIN code and is then removed from Mosyle MDM, the PIN code sent will no longer be able to be retrieved from Mosyle systems if it is forgotten.

 

 

Using Dynamic Device Groups


Check device security status using Dynamic Device Group criteria. Criteria listed below can help identify devices that are not meeting security requirements of the school or district and need to be addressed, or assist in identifying devices that have potentially been lost or stolen:

Management Profiles & Device Configuration

Erasing Devices

Overview


The ability to send remote commands to erase devices is critical when managing a fleet of devices. Devices typically need to be erased to prepare for a new user, when reselling devices, if the device has been misplaced, or many other reasons. Mosyle provides the ability to remotely erase devices when needed.

 

Erasing iOS/iPadOS Devices


Erasing an iOS/iPadOS device using the command from Mosyle, will erase all data on the device. If the device is associated with your Apple School Manager account and has an Automated Device Enrollment profile assigned to it, once the device reboots and Wifi is connected the device will automatically re-enroll into Mosyle.

To send the erase command to an iOS/iPadOS device

  1. Go to Management > Devices Overview
  2. Select any device(s) > More dropdown menu: Erase device

The erase command can be sent for individual devices via the Device Information window or can be sent on a schedule using the Single shot profile.

Additional Options:

Erasing macOS Devices


Erasing a Mac computer with an Intel processor using the command from Mosyle will erase all data, volumes, containers, and partitions, including the recovery partition. In order to reinstall the macOS on the device, you will need to use Internet Recovery. When sending the command from Mosyle you will be required to enter a 6-digit PIN which will need to be entered on the device before it is erased. If a Firmware Password exists, it will first need to be removed in order to erase the Mac.

When erasing a Mac running macOS 12.0.1 or later with T2 Security Chip or Apple silicon, the device will Erase all Content and Settings (EACS) unless the command fails. In the event the command to Erase all Content and Settings fails, the defined 'Obliteration behavior' will be used.
The options available for the Obliteration behavior include:

To send the erase command to a macOS device

The erase command can be sent for individual devices via the Device Information window or can be sent on a schedule using the Single shot profile.

 

 

 

Setting up devices for a new user


To set up a device for a new user, you can simply change the device assignment by first unassigning the device and then assigning it to the new user, or you can erase the device, re-enroll and assign it to the new user. Whenever possible, it's recommended to first erase the device before distributing to a new user.

 

 

Device Refresh or Selling Devices


When refreshing or replacing devices, the old devices will need to be erased. Send the erase command from Mosyle to ensure all data is removed.

Be sure to unassign the device from the Mosyle MDM server in ASM and remove the devices from Mosyle in order to free up a license for a new device. To remove a device from Mosyle, go to Management > Devices Overview > Click a device name to bring up the Device Information window > More dropdown menu: Remove device/Remove MDM.

When selling devices, it's recommended to release devices from ASM indicating the school or district no longer owns the device. Click here for more information about releasing devices.

Classroom Tools

Classroom Tools

Configuring Class Manager

Overview


Mosyle's Class Manager offers teachers a specialized tool to ensure students are focused on learning by providing a core set of functionalities for classroom tasks. It also empowers teachers to disable or allow the camera, enable Bluetooth, verify devices are compliant with teacher defined policies, and ensure that Apple Classroom is automatically configured to be used in conjunction. Class Manager works across any network so it's a great tool to use with Apple Classroom when students are face to face or standalone when they are in remote learning.

 

Configuring Classes


The Mosyle Class Manager will automatically populate classes and rosters that are created in or imported into Mosyle. Apple School Manager (ASM) can provide an automated way of creating and updating courses and rosters using integration with your Student Information System (SIS)Google WorkspaceMicrosoft Azure AD, or by SFTP upload.

If you are not leveraging Apple School Manager, you can download the spreadsheet templates in Mosyle to populate your user information under My School > Integrations > Spreadsheet.

The option to create Classes/Courses manually within the MDM is also available. To do so, navigate to My School > Hierarchy > Courses > + Add New Course, and then give it a name. Once the Course is created, associated classes can be configured.

 

 

 

Accessing Class Manager


Teachers and Administrators can access Class Manager from the Mosyle Manager app or by logging in to the Mosyle Web Panel. Administrators will be able to view and access all classes configured in Mosyle, teachers will be able to view and access only the classes they are assigned. To start a class, click the name of the Class in the Class Manager tab.

accessing-class-manager.png

After selecting a class, the Class Manager Features are organized into the following sections:

class-manager.png

Classroom Tools

Class Manager Features

Class Feed


Each class features a Class Feed which is a message forum for the teacher and students in the class. Administrators, Teachers, and students can post messages within the Class Feed in the Mosyle Class Manager for others to see. Only messages containing text can be sent.

Deleting Messages

Teachers can delete individual messages within the Class Feed as needed.

Enable or Disable Class Feed

Posting in the Class Feed can be enabled or disabled for student devices by the Mosyle Admin under My School > Preferences > Other Settings > General Preferences > Check or Uncheck "Allow students to post in the Class Feed". When this option is unchecked, students are unable to post in the Class Feed but can still view messages posted by Teachers or Administrators. The setting configured will apply to the entire account and all students/classes.

 

Starting a Class & Class Preferences


To access the features of Mosyle Class Manager, the teacher will need to first select the class. After selecting the class, the teacher can navigate between managing iOS/iPadOS devices or macOS devices using the dropdown menu at the top.

start-class.png

Students assigned to the class are listed on the right side. Any students that are absent should be selected so that commands initiated during the class session will not be sent to the student device. Since Class Manager commands are delivered over the network and do not require students to be within proximity of the teacher device, if a student is not present in class, their device will still be affected by commands if they are not marked "Absent".

The middle section allows teachers to define their Start Class Preferences, or preferences that will be applied immediately upon starting the class.

Prepare the Classroom App

Toggle on the option to ensure the Education Configuration profile is installed on all devices when starting the class. The Education Configuration profile is necessary to configure MDM-synced classes in Apple Classroom. If the Mosyle Administrator has configured settings to prevent the installation of the Education Configuration profile, it will not be installed, even if toggled on.

Administrators can configure the settings for the Education Configuration profile under:

Hide apps not listed on Study Apps

Toggle on the option to immediately hide or block all applications installed on student devices that are not listed in the Study Apps list after clicking “Start Class”. On iOS and iPadOS devices, apps not selected in Study Apps will be hidden. On macOS devices, apps not selected in Study Apps will be unable to launch.

Apply my Study Sites

Toggle on the option to immediately block websites that are not specified in the Study Sites list after clicking “Start Class”. Study Sites utilizes a global proxy to only allow the sites listed. Since devices can only have one global proxy profile installed at a time, any other global proxy configured in the Web Filter management profile will be removed to install the configuration for Study Sites. When the class is over, the global proxy configured in the Web Filter management profile will be reinstalled.

If a specific global proxy is required on devices at all times, or if a DNS Proxy Extension is being utilized, its recommended Administrators remove the option for teachers to use Study Sites under My School > Preferences > Other Settings > iOS/iPadOS and macOS > Check the box "Do not allow teachers to use "Study Sites"" > Save.

Mute all apps (iOS & iPadOS only)

Toggle on the option to immediately mute application sounds after clicking "Start Class". This feature will also block app notifications.

Enable Bluetooth

Toggle on the option to immediately enable Bluetooth on devices after clicking "Start Class". On iOS and iPadOS devices, Bluetooth will be forced on and cannot be turned off. While enforced, students will be unable to pair new devices. On macOS devices, Bluetooth will be turned on.

Class Duration

Set the duration of the class to ensure student devices are automatically released from any restrictions at the end of class. Use the slider tool to set the duration of the class (in minutes). If necessary, the duration of the class can be increased by clicking “+10 min”, or the class can be ended before the expected time by clicking “End Class”.

Start Class

Click Start Class to apply any configured preferences. Students will be notified the class has begun. When the class has concluded, end the class by clicking "End Class" or use the toggle to turn the class "Off".

If starting a class where students are not assigned 1:1 to devices, teachers will be prompted to select a "Shared Device Group" to be used. Only Shared Device Groups in the same location as the teacher/class will be available. The location for the Shared Device Group can be modified under My School > Hierarchy > Shared Device Groups > Select the group > Edit.

After selecting the Shared Device Group, teachers can choose to automatically assign students to devices or allow students to self-assign by choosing their name/photo from the class roster data.

 

Class View


Once a class is started, teachers can view information regarding student devices during the class. Options and features available per OS are listed below.

iOS /iPadOS Class View

ios-view.png

macOS Class View

macos-view.png

Notes:

 

 

Study Apps


The Study Apps feature allows teachers to create a list of allowed apps for each class, allowing customization of app access based on the unique characteristics of each group of students. The Study Apps configuration will be applied to all students in the class.

study-apps.png

When Study Apps is enabled, only the apps available in the list will be accessible. On iOS and iPadOS devices, apps not listed will be hidden. On macOS devices, apps not listed will not launch.

Notes:

Access the Study Apps List

To access the list of Study apps, navigate to the Mosyle Class Manager > Select the class > Click Study Apps from the menu on the left side of the screen.

Add or Remove Apps in the Study Apps List

To add applications to the list of Study Apps, click the “Add application(s) to the list” button at the bottom of the screen. Teachers can search for applications available in the Apps and Books token, the App Store, or by searching a list of Native Apps. The availability of each list is dependent on the access permitted by the school's Mosyle Manager Admin, see additional information below.

After finding and selecting the application to add to the list of Study Apps, click the check mark in the upper right corner. Icons for any and all applications selected will be displayed in the list.

Turn on and Apply Study Apps

Once the list of Study Apps is created it can be turned on and applied to the student devices in the class. If there are no apps listed in Study Apps, all apps will be hidden on the devices with the exception of the Mosyle Manager and Settings app.

Apply the Study Apps list to classes after they have been started by toggling on the Study Apps option in the menu. Toggle off at any time to remove Study Apps.

Availability of Apps in Study Apps List

Administrators can configure the Mosyle account so that teachers are only able to select apps from the App Store, Apps and Books token, or both when creating a Study Apps list.

 

Study Sites


The Study Sites feature allows teachers to create a list of allowed websites for each class, allowing customization of website access based on the unique characteristics of each group of students. The Study Sites configuration will be applied to all students in the class.

When Study Sites is enabled, only the websites configured in the list will be accessible. Port 3180 is required for the use of Study Sites.

study-sites.png

Notes:

Access the Study Sites List

To access the list of Study Sites, navigate to the Mosyle Class Manager > Select the class > Click Study Sites from the menu on the left side of the screen.

Add or Remove Apps in the Study Sites List

To create the list of Study Sites, select the class where the Study Sites will apply, then click Study Sites from the menu on the left side of the screen.

Websites added to the list of Study Sites will be available to students in the Mosyle Manager app under “My Web Clips”. Clicking the link will navigate the students to the specified website.

Turn on and Apply Study Sites

Once the list of Study Sites is created it can be turned on and applied to the student devices in the class. If there are no websites listed in Study Sites, all websites will be blocked on the devices with the exception of Mosyle and Apple domains when Study Sites is turned on.

Apply the Study Sites list to classes after they have been started by toggling on the Study Sites option in the menu. Toggle off at any time to remove Study Sites.

 

Heads Up


The Heads Up feature allows teachers to quickly disable/lock student devices to gain attention during a lesson or explanation. The Heads Up configuration will be applied to all students in the class when it is turned on.

heads-up.png

Access Heads Up Configuration

To access the Heads Up configuration, navigate to the Mosyle Class Manager > Select the class > Click Heads Up! from the menu on the left side of the screen.

Customize the Heads Up Configuration

To customize the message in Heads Up, select the “Heads Up” option from the menu on the left. Next, click the text on the blackboard and type in the message to be displayed on student devices.

Turn on and Apply Heads Up

Heads Up can only be applied after a class has been started by toggling on Heads Up from the menu on the left side of the screen or by navigating to Heads Up and then clicking “Apply Heads Up”.

Heads Up can be turned off using one of the following methods:

 

 

Safe Test


The Safe Test feature allows teachers to quickly lock student devices into a specific website, preventing students from navigating to other online resources or browsing the Internet. The Safe Test configuration will be applied to all students in the class when it is turned on.

safe-test.png

Access Safe Test Configuration

To access the Safe Test configuration, navigate to the Mosyle Class Manager > Select the class > Click Safe Test from the menu on the left side of the screen.

Update the Safe Test Configuration

To update the website in Safe Test, select the “Safe Test” option from the menu on the left. Next, click the field to enter the URL for the website that student devices will be locked into.

Turn on and Apply Safe Test

Safe Test can only be applied after a class has been started. Once the class has been started, click Safe Test from the menu on the left side of the screen. Enter the Locked URL or select the last locked URL and choose the duration for Safe Test. When finished, click Apply Safe Test.

Safe Test can be turned off using one of the following methods:

View History

In addition to applying the Safe Test feature, you can view the history of websites entered in Safe Test as well as the date and time they were applied by clicking “View History”.

 

 

App Lock


The App Lock feature allows teachers to quickly lock student devices into a specific app, preventing students from navigating to other resources or applications. The App Lock configuration will be applied to all students in the class when it is turned on.

app-lock.png

Access App Lock Configuration

To access the App Lock configuration, navigate to the Mosyle Class Manager > Select the class > Click App Lock from the menu on the left side of the screen.

Update the App Lock Configuration

To update the app selected in App Lock, select the “App Lock” option from the menu on the left. By default, all apps selected in Study Apps will be displayed in a list to provide the option for a quick selection. If the teacher would like to lock student devices into a different app, click Find App.

Turn on and Apply App Lock

App Lock can only be applied after a class has been started. Once the class has been started, click App Lock from the menu on the left side of the screen. Select the app and choose the duration for App Lock. When finished, click Apply App Lock.

App Lock can be turned off using one of the following methods:

 

Quick Poll


The Quick Poll feature allows teachers to quickly survey students to receive feedback and/or instantly view the level of student understanding. The Quick Poll configuration will be applied to all students in the class when it is turned on.

quick-poll.png

Access Quick Poll

To access Quick Poll, navigate to the Mosyle Class Manager > Select the class > Click Quick Poll from the menu on the left side of the screen.

Create a Quick Poll

To create a Quick Poll, select the “Quick Poll” option from the menu on the left. Enter the question that will be presented to students and choose whether the response should be a Short Answer or Multiple Choice. If Multiple Choice, enter the available options. If additional multiple choice options are needed, click the button “Add more options”.

Turn on and Apply Quick Poll

Quick Poll can only be applied after a class has been started. Once the class has been started, click Quick Poll from the menu on the left side of the screen. Enter the question, select the response type, and choose the duration for the Quick Poll. When finished, click Apply Quick Poll.

After the Quick Poll is applied, student devices will be locked into the Mosyle Manager application until they provide a response to the Quick Poll or until the class ends. Teachers will be directed to a screen that will show students responses in real-time.

Quick Poll can be turned off using one of the following methods:

View History

In addition to applying the Quick Poll feature, you can view the history of polls delivered, the date and time in which they were delivered, as well as student responses by clicking “View History”.

 

Class Manager Settings


Teachers can access Settings for each class by going to Class Manager > Select a class > Settings from the menu on the left. Some available options that can be configured include:

Class Nickname

Personalize the name of the class. The class will be displayed with the nickname in the Class Manager app and in the Apple Classroom app.

Share Management

Share Management of the class with other teachers for a specified duration. Choose to provide access for the day or until the next day.

Request Apps

Mosyle Administrators can allow teachers to request applications to be deployed to their student devices under My School > Preferences > Other Settings > iOS/iPadOS > Check or Uncheck the box "Allow teachers to send app requests to administrators". When finished, click Save.

Teachers can request applications by going to Class Manager > Select the class > Click Request Apps from the menu on the left side of the Manage iOS/iPadOS screen. Search for apps from the App Store to add to the request. After selecting the apps to add, choose the class(es) the apps should be deployed. When finished, click Save.

Administrators will receive the request in the Alerts area of the Mosyle Web Panel. Configure to receive the Alert by email under Management > Alerts > Click Config for Alerts via email.

Classroom Tools

Apple Classroom app

Overview


Apple Classroom is an app available for teachers to assist with the management of supported iPad and Mac devices. Click here for more information about Classroom.

Requirements

Requirements may vary depending on the type of classes configured in the Apple Classroom app. Please visit the following Apple User Guides for additional information:

 

Installing the Classroom App


Before teachers can use and access the Classroom app it must be installed on the devices. Mosyle Administrators can deploy the app to devices using device based licensing via the Install App profile. When using MDM-synced classes, only teacher devices need the Classroom app. To install the app, follow the steps below:

  1. Obtain licenses for the Classroom app in Apple School Manager
  2. Make sure the licenses are synced in Mosyle under Management > Applications > Apple Apps and Books > Click the token > Update
  3. Create the Install App profile under Management > Install app
  4. Choose the Apps and Books token as the installation source, select the app and choose users/devices to assign the profile
  5. Click Save

 

Configuring the Classroom App


Currently there are three methods for syncing classes to the Apple Classroom app: MDM-synced classes, classes synced with Apple School Manager, and unmanaged classes. For MDM-synced classes, the Education Configuration profile is required on devices. The Education Configuration profile will automatically be installed on 1:1 devices assigned to students or teachers with classes assigned and on Apple Shared iPad devices after a user logs in with their Managed Apple ID.

When using classes synced with Apple School Manager and unmanaged classes, the Education Configuration profile should not be installed as it could create a conflict. The automatic installation of the Education Configuration profile can be turned off using one of the methods below:

Using any of the methods above to turn off the automatic installation of the Education Configuration profile will trigger removal commands for the profile on any devices that currently have it installed.

 

Reinstalling the Education Configuration profile


If needed, the Education Configuration profile can be reinstalled on the devices using one of the methods below:

Note: If any of the options to not automatically install the educational profile are selected, no commands will be generated.

 

Apple Classroom for User Enrolled Devices


Per Apple's MDM protocol, devices enrolled using User Enrollment cannot receive the Education Configuration profile to set up MDM-synced classes. In this case, teachers can make use of unmanaged classes which can be configured manually on the devices. Click here for more information about unmanaged classes in Apple Classroom.

 

Restrictions Available to Facilitate the use of Apple Classroom


Restrictions are available for supervised devices enrolled in the MDM to force certain permissions for the Apple Classroom app. Below are the available restrictions for each OS platform.

iOS & iPadOS Restrictions

The following restrictions are available for supervised iPad devices under Management > Restrictions.

macOS Restrictions

The following restrictions are available for supervised Mac devices under Management > Restrictions > Functionality tab.

Mosyle OneK12 features

Mosyle OneK12 features

Mosyle Auth 2

Overview


Mosyle Auth 2 for macOS allows end users to login to the Mac with their organization credentials. Configure Mosyle Auth 2 so that users login on the Mac with their Google Workspace, Microsoft Azure AD, Active Directory (LDAP or AD FS), or On-Premise Active Directory credentials, and keep the passwords synced between the Mac local user account and SSO.

Users must exist in Mosyle in order to login on the Mac via Mosyle Auth. When using Google or Microsoft Azure AD, the user's email address registered in Mosyle must match the email address registered in the Identity Service. When using Active Directory (LDAP, AD FS, or OnPrem), the user ID registered in Mosyle must match the authentication query used when authenticating with LDAP/ADFS.

If enrolling devices via Automated Device Enrollment, configure the Automated Device Enrollment profile with the following settings: check the box to 'Allow Bootstrap Token (macOS 10.15+)', uncheck the box to 'Prompt user to create an account' so the local user account creation during the Setup Assistant will be skipped, and check the box to 'Create additional local admin during Setup Assistant'.

When users login through Mosyle Auth 2, a user account on the Mac will be created. All Mosyle Auth 2 user accounts are created as Mobile accounts to leverage the possibility of User Scope profiles and ensure the secure token is passed to each user if the Bootstrap Token is allowed. To skip all user account creation prompts, such as Data & Privacy, Apple ID, Touch ID, Siri, etc., configure the Login Window profile.

Mosyle Auth 2 supports the use of 2FA, including the 2FA with Security Keys. On macOS 13+, due to USB Restricted Mode, the Security Keys for 2FA will not be allowed unless the restriction to disable USB Restricted Mode is installed, or a user has first logged in to allow access to the Security Key.

To access Mosyle Auth 2, go to Management > Mosyle Auth 2.

 

Creating a Mosyle Auth 2 Profile


To create a Mosyle Auth 2 profile, go to Management > Mosyle Auth 2 > Add new profile. Profiles can be assigned to individual users or devices, as well as grade levels, classes, device groups, or any other assignment option.

Choose the identity provider and then select the usage model. Every Mosyle Auth 2 profile will include the following configuration options:

 

Configuring Mosyle Auth 2 for 1:1 devices


If devices are used solely by one, individual user it's recommended to use the 1:1 usage model with Mosyle Auth 2. This configuration ensures only the user assigned to the device will be able to authenticate and login to the Mac.

The device assignment will be completed when the user logs in via Mosyle Auth 2 based on the Device Assignment settings under My School > Users > Device Assignment > User Authentication Assignment. Be sure the option under the heading 'Assignment through Mosyle Auth' is configured with the following selection: Only auto-assign devices not already assigned to a user. Once the device is assigned to the user, no other user will be able to authenticate to login and access the Mac until it is unassigned.

When using Mosyle Auth in a 1:1 usage model, Administrators can define how the account will be created on the Mac. Mosyle will automatically determine if the device is considered a “New device” or a “Device already in use” based on any pre-existing user accounts on the Mac. Once a user authenticates via Mosyle Auth 2 on a brand new device and the user account is created on the Mac, it will then be recognized as a “Device already in use”.

In all scenarios, Administrators have the ability to define the Local Password sync behavior. By default, Mosyle Auth will automatically compare the password used to authenticate during login with the saved password on the Mac. If the two passwords do not match, the user will be prompted to enter the password for the user account on the Mac, which is typically the previous IdP password, in order to update and sync the passwords. In the event users do not logout and login frequently, Administrators can define how often a user will be prompted to sync their password:

pass-sync.png

If a user updates or changes their IdP password, it is best practice to sync the password prior to logging out of the Mac. Users can do this by clicking the Mosyle Auth sync icon in the menu bar.

pass-sync-icon.png

New Devices

The new device workflow is typically an unboxed device that goes through Setup Assistant, and is configured with Mosyle Auth. The device will skip all prompts and land at the Mosyle Auth login window. The user logs in with their organization credentials such as Google, Azure, etc., their account is automatically created on the Mac (formatted as defined by the Mosyle Admin) and the device automatically assigned to the user. Moving forward, only that user is authorized to authenticate and login on that Mac.

In the Mosyle Auth profile, choose how to create the user account on the Mac when the user logs in:

account-creation.png

Devices already in use

For devices already in use, such as devices that are already set up and have been in use, it's understood that user accounts already exist on the device. Therefore, it is undesirable for Mosyle Auth to create a new user account on the Mac. In order to avoid the creation of a new user account on the Mac, configure the “Devices already in use” tab.

Choose whether or not Mosyle Auth should be enforced for all accounts on the device, or only for specific accounts.

devices-already-in-use.png

 

Configuring Mosyle Auth 2 for Shared devices


The shared usage model for Mosyle Auth 2 is designed for environments where a single Mac is not assigned to a specific user and may be used by multiple users throughout the day. When using this model, any user registered in Mosyle will be permitted to login on the device with their Single Sign-On credentials. Upon logging in, a Standard user account will be created using the User ID for the user in Mosyle.

It is typical to assign this type of Mosyle Auth 2 usage to devices enrolled in Shared Device Groups.

 

Removing Mosyle Auth 2


If you choose to remove Mosyle Auth from your devices, the login window will revert to the native macOS login window and users can login to their local user account on the Mac by entering their user account name and password (most likely the same password as their SSO password). The local user account on the Mac will not be removed if Mosyle Auth is removed. Therefore, all user data will remain and the user can access by logging in locally with their credentials.

Mosyle OneK12 features

Mosyle CDN

Overview


Mosyle offers a CDN solution that supports the PKG, DMG, ZIP, and IPA file types of up to 8 GB and is included in the Mosyle OneK12 subscription plan.

To Upload Packages to Mosyle's CDN

  1. Click Management > Install PKG > Click the CDN tab
  2. Click “Upload” > Choose a File
  3. Select the file > Click Choose for Upload
  4. Monitor the progress bar for the upload status

upload.png

 

Using the CDN Variable


When hosting packages on the Mosyle CDN, the URL of each package is replaced with a Variable (ID). In order to continue deploying the packages using Custom Commands or other management profiles, replace any previous URLs with the PKG Variable ID to ensure expected behavior.

Finding a PKG Variable

  1. Click Management > Install PKG
  2. Click the CDN tab > Click the PKG name
  3. Copy the value in the Variable field (%MosyleCDNFile:00ac0f0a-c00b-0e00-aaec-0f000cd0bca0%)
  4. Navigate to a profile that includes the URL and replace the URL with the Variable

finding.png

Adding a PKG Variable to the Custom Commands Profile

  1. Click Management > Custom Commands
  2. Click an existing profile's name or create a new profile
  3. Select 'Enable Variables for this profile' > Click the link 'Click here to view available variables'
  4. Click on View Mosyle CDN Variables > Copy the value in Variable
  5. Exit the pop-up
  6. Click the text box in Code > Delete the package's URL > Paste the package's Variable
  7. Click on the blue checkmark
  8. Save

adding.png

Mosyle OneK12 features

Device Scout

Overview


Device Scout checks devices against a repository of recommended security controls or any custom controls to reflect security requirements needed for a school or district environment. The repository of rules for compliance are established by recommendations from many recognized cybersecurity agencies and are mapped to CIS and NIST frameworks, as well as a set of proprietary rules. Select any/all rules to apply to the devices and ensure they are in compliance. Enable auto-remediation so that non-compliant devices are automatically corrected to be in compliance with the specific security control.

For Mac computers, the agent is leveraged for compliance scans. Therefore, the Mosyle Manager app must be installed.

Click the Security tab and expand the Device Scout menu option in the left menu bar. Device Scout is organized into four sections:

Overview

The Overview pane provides a quick summarized view of your device compliance status. You can view the following in this area:

Device Scout Score: The score is calculated based on the security controls applied and device compliance status. The higher the score, the more secure your devices are.

Based on your Security Controls (macOS): Use the dropdown menus to view the top controls or top devices that are compliant or not compliant.

Top Rules among All Schools (macOS): A list of the top rules activated across all Mosyle companies.

Evolution over Time / You vs All Schools: View the compliance average or max active rules over a period of time for your school and other Mosyle schools.

What changed?: View any recent changes in the compliance status.

device-scout.png

Security Controls

View a list or grid of all active Security Controls. To change views, use the dropdown on the right side of the screen to choose between “Grid View” or “List View”.

Each control will show the rule name, associated security benchmarks, the percentage of devices in compliance, as well as if remediation is turned on or not. Favorite any controls to make sure they show at the top of the list by clicking the star icon in the rule box. To refresh and update the controls to show the latest compliance status, click the refresh button within the rule. Device compliance status is checked every hour.

Using the filter, choose to view the rules based on: show only favorites, by security baselines, if remediation is available or unavailable, or if remediation is enabled or not enabled.

Search for specific Security Controls using keywords and sort based on the control name or compliance percentage.

Click + New Control at any time to add additional Security Controls. When adding controls, choose to use controls from Mosyle's Repository or by creating your own custom Security Control.

Use the Bulk Assignment or Bulk Remove buttons to assign controls to devices in bulk, or remove compliance checks for controls in bulk.

Devices that are not in compliance with the controls assigned will automatically be grouped into a “Security Group”, categorized by each control. Use these Security Groups when assigning management profiles as needed.

rules.png

Devices

View a list of devices assigned to security controls and their corresponding compliance status. Clicking on a device tile will bring up a detailed list of the security controls assigned, which are compliant, and give you the ability to automatically remediate controls not in compliance. Click the link to open a new tab to view additional device info.

Filter the list of devices by: serial number, device name, asset tag, deviceUDID, Wifi MAC Address, Ethernet MAC Address, user assigned, grade levels, and more.

Sort the list of devices by the device name or compliance percentage.

After filtering and sorting devices as needed, export a spreadsheet of the devices and security controls by clicking the button in the upper right corner that indicates X devices match filters. The spreadsheet will include a list of devices (device name and serial number) and all assigned controls along with the compliance status.

Logs

View logs to see detailed info for when a device became compliant or lost the compliance status. In addition to the compliance status, the control name, date/time stamp, device name and serial number are listed. The logs provide detailed reports containing necessary information for any potential internal and external audits.

To export a list of devices and the compliance status, go to the Security tab and click the Devices menu option under Device Scout. Filter the devices as needed and click the Export button in the upper right to export in a CSV or XLSX file format.

 

 

Configuring Controls


When first accessing the Device Scout Overview area under the Security tab, a list of controls available from the Mosyle repository will be displayed that can be activated. Select any controls to scan for compliance and assign the devices. When finished, click Start.

To add more controls to be checked for compliance, go to the Security tab > Device Scout > Security Controls > + New Control. Choose a rule from the Mosyle Repository or create your own custom control.

new-control.png

After checking the box for the rule, click the button to “Enable Tracking”. Select the users and/or devices to assign the control to and click “Enable”.

control-repository.png

Once controls are enabled, they'll be listed in the Security Controls area. Click any of the controls to view detailed information about the control, change assignments, and/or turn on auto-remediation.

 

 

Configuring Custom Controls


To configure a custom control, go to the Security tab > Device Scout > Security Controls > + New Control. Choose “Create a New Security Control”.

Name the control, choose an icon, add tags and/or framework mapping or reference. Enter the code that should be run on devices to check for compliance. Be sure to include specific output that can be used to define devices in compliance or not. Define what should be considered compliant under “Results for Compliance”, anything that doesn't meet the definition will be considered not in compliance. Add the assignment and save.

To remediate the custom control, go to the Management tab and use any of the Management profiles, including Custom Commands, to create the profile or configuration to remediate the control. When assigning the profile for remediation, assign it to the automatically created Security Group for devices not in compliance with the control.

 

 

Compliance Checks


Devices are checked for compliance during every device info update. The device info update is automatically requested every hour, so long as the device remains online and reachable. If the device is not online, the update of device info along with any compliance checks will be pending. Once the device is back online, the commands will go through and the compliance status as well as the device info will update. For Mac computers, the compliance checks rely on the Mosyle Manager app being installed on the Mac.

If a device has not responded to a compliance status check in over 5 days, the compliance will change to “Not compliant” until the device checks back in to confirm it's current status.

 

 

Auto-Remediation


Auto-remediation is completed using a combination of management profiles and/or customized commands created by our Developers. When auto-remediation is turned off, or the security configurations are unassigned, the remediations installed via profiles will be removed from the device and the security control will no longer be enforced. Any other remediations that were not applied via profiles, rather were processed using customized commands, will no longer be executed. Turning off auto-remediation does not revert any settings.

If auto-remediation is turned on, it's recommended to not duplicate any controls or policy configuration through Management profiles to avoid any unexpected side effects. For example, if passcode controls are configured in Device Scout with auto-remediation enabled, it's not recommended to also push a Passcode Policy payload.

 

 

Mosyle OneK12 features

Detection & Removal

Overview


Detection & Removal is a client based solution that leverages Apple's Endpoint Security Framework to constantly monitor a set of different events that could potentially represent the introduction of a new malware on a macOS device. Once these events are identified, they are scanned against a multi-source signature database that combines the local XProtect Yara rules present on each device, a database of different well-known macOS malware and a proprietary database created and maintained by our Security Research team. When Detection and Removal is assigned to devices, the MosyleSecurity agent will automatically be installed.

Scans are typically done using an On-access strategy, which means that events immediately trigger scans as they happen for real-time protection, such as when a new file is downloaded from the internet or email. A weekly full-scan is also available in order to allow recently introduced definitions to be used to scan the system regardless of the occurrence of triggering events. All the routines are performed locally for privacy protection and no file is synced with Mosyle servers.

Click the Security tab and expand the Detection & Removal 2 menu option in the left menu bar. Detection & Removal is organized into four sections:

Detection & Removal 2 is supported on macOS 10.15 and later.

Overview

The Overview pane provides a quick summarized view of your device status. You can view the following in this area:

overview.png

Devices

View a list of devices assigned to Detection & Removal and their corresponding scan status, date and type of last scan, last definition updates, and if there are any files in quarantine. Clicking a device serial number will open the device info window.

The device status is determined based on the last scan. If the last scan was “Healthy” it shows “Healthy”. If the last scan detected any infected files (whether or not they were automatically removed), it shows the device “Infected”. If infected files are removed after the last scan, run the scan again to update the status. A status of “Not defined” indicates a scan hasn't run yet.

Different scan types available:

Use the menu options to complete a full scan, update definitions, and/or manage quarantine files.

menu-options.png

Filter the list of devices by: serial number, device name, asset tag, deviceUDID, Wifi MAC Address, Ethernet MAC Address, local hostname, hostname, current console user, last SSID, user logged in, and more.

filter.png

Sort the list of devices by the device name, files in quarantine, last definition update, last scan date, last scan type, serial number, status, tags, or compliance percentage.

sort.png

After filtering and sorting devices as needed, export a spreadsheet of the devices and scanned status by clicking the button in the upper right corner that indicates X devices match filters. The spreadsheet will include all information found in the interface.

export.png

Quarantine

View the list of files in quarantine, including the type of threat, file path, and date and time the file was quarantined. The device name and serial number is also listed. Click the serial number to view the Device Info window.

If needed, quarantine files can be deleted from this area or restored. If a file from quarantine is restored on a device, the file will no longer be flagged as a threat on that particular device.

Sort and filter data to view specific information. Export data as needed with the export option.

quarantine.png

Settings

Configure the Detection & Removal settings, including the time and day of the weekly full scan, if device-based AI and behavior detection should be used, behavior for quarantined files, any manual definitions to be included, alerts, file bypass and mute paths.

settings.png

Logs

View logs to see detailed info for when a device was scanned and if any infected files or threats were found. In addition to the scanned status, the event type, details regarding the file, date/time stamp, device name and serial number are listed. To export the logs, click “Export” in the upper right corner.

logs.png

 

 

 

 

Configuring Detection & Removal


To configure Detection and Removal go to Security > Detection & Removal 2 > Settings > Add new profile.

Enter the name of the profile and configure the following tabs:

After configuring the options available for Detection & Removal, assign the profile to users and/or devices.

Mosyle will automatically install the Detection & Removal engine, along with any System Extensions and Privacy Preferences required.

 

 

What to Expect


When an infection is detected, Administrators will see the infections in the Logs and in the device status view under Devices. End users will be alerted via a native macOS Notification as well as see an alert in the Manager application.

macOS Notification

macos-notification.png

Manager app

manager-app.png

 

 

 

Mosyle OneK12 features

Admin On-Demand

Overview


Admin On-Demand provides a quick, easy way for Mosyle Administrators to convert Admin user accounts on the Mac to Standard users, while also allowing user accounts on the Mac to request temporary user account escalation to complete any tasks that require Admin access.

Admin On-Demand is organized into four menu items: Overview, Devices, Settings, and Logs.

Overview

The Overview pane provides a quick summarized view of your user account status on devices. You can view the following in this area:

overview.png

Devices

The Devices tab will show all devices assigned to the Admin On-Demand configuration and the current user type logged in on the device - either Admin or Standard.

Use Filters available to filter and sort devices to show only those of interest. If needed, the data can be exported at any time using the button in the upper right “X devices match filters”.

Click a device tile to bring up additional details about the device and user. See any logs or actions taken on the device, export the data, or convert the user to Admin or Standard user.

devices.png

Settings

Configure the Admin On-Demand settings, including the conversion behavior, request settings, and/or customize the notification text for end users.

settings.png

Logs

View logs to see detailed info for when a user requested Admin access, when it was granted and removed, the justification for the access, and any corresponding logs. The date & time stamp, device name and serial number are also listed. To export the logs, click “Export” in the upper right corner. To export individual device action logs, click “View” under the Active Log column and click “Export”.

logs.png

 

 

Configuring Admin On-Demand


To configure Admin On-Demand

  1. Go to Security
  2. Admin On-Demand
  3. Click Settings > Add new profile
  4. Configure the settings in the three available tabs: Convert Current Admin, Request Settings, and Notification Pop-Up

Convert Current Admin

The Convert Current Admin settings will convert the current logged in Admin user to a Standard user. This option will not convert the additional Admin account created during Automated Device Enrollment (DEP Admin), however it will convert any other logged in Admin users if enrolled manually.

Using the dropdown menu, choose from the following:

Request Settings

The Request Settings tab allows configuration of whether or not users will have access to Admin On-Demand in the Manager application to request temporary Admin access. There are two options available:

When users have the option to temporarily escalate their privileges to Admin, they can request the escalation in the Manager application and because they have access to perform such escalation, it will be granted automatically to the end user. The following options are available to configure for this escalation period:

Notification Pop-Up

Customize the pop-up message users will see before their user account is escalated to have Admin privileges.

 

 

 

What to Expect


When users have access to Admin On-Demand, they can request the user privilege escalation from the Manager application.

request.png

After requesting Admin access, users will receive a notification indicating the account has been converted.

account-converted.png

At the end of the approved time period, the end user will receive a notification that their account has been converted back to Standard user access.

account-converted-back.png

Actions taken during the user privilege escalation can be viewed in the Admin On-Demand Logs.

Mosyle OneK12 features

DNS Filtering

Overview


DNS Filtering provides Administrators an easy way to filter network traffic to ensure users are accessing approved sites. It is organized in 7 tabs: Overview, Settings, Filtering, Security, Allowed/Blocked, Alerts, and Logs.

DNS Filtering profiles and configurations can be assigned to individual users and groups, or to all devices. Complete assignment based on what is needed for the school or district environment. Profiles can be quickly toggled ON and OFF using the toggle in the left menu.

When the DNS Filtering is assigned to a user/device, the necessary configuration profiles (DNS Settings and DNS Proxy Extension) will be automatically installed. Mosyle's DNS Filtering requires iOS/iPadOS 14+ and macOS 11+.

The Mosyle DNS Filtering requires specific domains and ports. Please see the help center article titled “Domains and Ports for DNS Filtering” for more information.

Overview

The Overview tab provides query data on the devices assigned to the individual profile. View the total number of queries, number of blocked queries, global traffic, number of queries per day, and filter by the list of top domains resolved and/or blocked.

overview.png

Settings

The Settings tab can be configured to specify Privacy & Logging settings, settings for macOS and iOS management, and any DNS Bypass rules. Assign the profile to the users/devices to be filtered. When using the DNS Filtering, it's strongly recommended not to apply any other content filtering solutions or profiles to avoid conflicts.

settings.png

Filtering

The Filtering tab can be configured to apply a Standard set of filters to filter network traffic. Custom filters can be created and applied.

filtering.png

Security

Configure the Security tab to block domains based on malicious activity, domain age, or hosting country.

security.png

Allowed/Blocked

Customize specific domains that should be always allowed or always blocked, despite their categorization. Add domains that require custom resolution.

allowed-blocked.png

Alerts

Configure alerts so that Administrators are notified when users attempt to access a domain or site that is not allowed.

alerts.png

Logs

View logs to see any blocked and/or allowed sites. The logs provide the device identifier, serial number, URL visited, the action (blocked/allowed), the reason for the block based on URL categorization, the IP address, and date & time stamp.

Click the gear icon to add the URL as an always blocked domain, always allowed domain, report as wrong classification, or set to exclude the domain in the logs.

The logs can be filtered by specific URLs, dates, devices, or by status (allow/block). Once filtered, the results can be exported.

logs.png

 

 

 

Configuring DNS Filtering


To configure DNS Filtering

  1. Go to DNS Filtering
  2. Click + Create New Profile
  3. Name the profile and select the users/devices the filtering will be assigned to
  4. Configure the following tabs: Settings, Filtering, Security, Allowed/Blocked, and Alerts

Settings

The following options can be configured in the Settings tab. When finished, click Save.

Filtering

Toggle ON any of the Standard filters to be blocked. If any additional filters need to be applied, create a custom filter by clicking “Create new filter”. Choose the site categories to be blocked. If needed, enter a URL in the URL checker to check the site categorization.

If desired, toggle on the options to enforce Safe Search and/or YouTube restricted mode. When finished, click Save.

Security

Toggle ON any of the options to block domains based on malicious activity, domain age, or hosting country. To add a hosting country click the button “Select / Edit Countries”. When finished, click Save.

Allowed/Blocked

Domains added in the Allowed list will always be allowed, even if they are configured to be blocked due to site categorization. Domains added in the Blocked list will always be blocked, even if their site categorization is not blocked.

If a domain requires custom resolution, such as an internal resource, enter the domain in the Allowed list and check the box for “Customize resolution” and enter the IP address.

Alerts

Configure to receive email alerts if users attempt to access a restricted domain, or attempt to access a site that is blocked due to its categorization. Choose how long devices will remain in the alerts until they are removed if there are no additional occurrences.

Email Preferences can be configured to receive a daily report, receive an email for every alert, or not receive email alerts. Choose the Administrators to receive the alert emails. When finished, click Save.

 

 

 

 

Best Practices

Best Practices

Recommended Standard Teacher MDM Profile


This guide provides a recommended baseline configuration for teacher and staff Apple devices managed through Mosyle MDM. The goal is to create a balanced standard that protects school data, reduces classroom distractions, and keeps devices consistent without overly limiting teachers from doing their work.

Purpose

This profile should be applied to school-owned teacher and staff devices such as MacBooks, iPads, and other Apple devices assigned to employees. This profile should be less restrictive than a student device profile, but more controlled than a personal unmanaged device.

Staff - macOS - Teacher Baseline
Staff - iPadOS - Teacher Baseline
Staff - Standard Restrictions
Staff - Security Baseline
Staff - Web Filtering

1. USB Storage / External Drives

Recommendation: Restrict USB storage where possible, or allow only by documented exception.
Setting Recommendation
USB storage access Allow only if needed
Unknown USB accessories Restrict when device is locked
External drive writing Restrict where possible
External drive reading Allow only for approved workflows

USB drives are one of the easiest ways for school data to leave a device. They can also introduce malware or create data-loss concerns. Teachers may have legitimate reasons to use external storage, but the standard should be to use approved cloud storage instead whenever possible.

Suggested policy language:

Teachers should avoid using personal USB drives for school data. Approved school cloud storage should be used whenever possible to reduce the risk of data loss, malware, or unauthorized transfer of sensitive information.

2. Siri

Recommendation: Disable Siri on school-owned teacher devices unless there is an accessibility need.
Setting Recommendation
Siri Disabled
Siri while locked Disabled
Dictation Allowed only if needed for accessibility

Siri is usually not required for classroom instruction or staff productivity. Disabling Siri reduces privacy concerns, prevents accidental voice activation, and removes unnecessary lock-screen access.

3. AirDrop

Recommendation: Disable AirDrop by default. Allow only by exception for approved instructional use.
Setting Recommendation
AirDrop Disabled by default
AirDrop from Everyone Not allowed
Password sharing through AirDrop Disabled

AirDrop can be useful, but in a school setting it can also be abused for distractions, inappropriate file sharing, or accidental exposure of sensitive information.

Possible exception groups:

4. Apple ID and iCloud

Recommendation: Restrict personal Apple ID use on school-owned devices.
Setting Recommendation
Personal Apple ID Not allowed on school-owned devices
Managed Apple ID Preferred
iCloud Drive Disabled unless approved
iCloud Photos Disabled
iCloud Keychain Disabled

School-owned devices should not become tied to personal Apple IDs. This can create problems with Activation Lock, app ownership, data ownership, privacy, and long-term device support.

5. App Store and App Installation

Recommendation: Apps should be deployed through Mosyle using Apple School Manager Apps and Books.
Setting Recommendation
App Store Restricted
User app installation Disabled or limited
Managed apps Required method
Removing managed apps Disabled

6. Classroom Distraction Controls

Feature Recommendation
Game Center Disabled
Messages Disabled unless approved
FaceTime Disabled unless approved
Camera Allowed
Microphone Allowed
Screen Recording Allowed for teachers

Teachers should have access to instructional tools such as the camera, microphone, screen recording, printing, and approved classroom applications. Consumer features that do not support instruction should be limited.

7. Privacy and Security

Recommendation: Enforce security settings on all school-owned teacher devices.
Security Item Recommendation
Password / Passcode Required
Auto-lock Required
FileVault on macOS Enabled
Firewall on macOS Enabled
Gatekeeper Enabled
Local admin rights Standard user preferred

8. Web Filtering and Content Protection

Teacher devices should still have web filtering enabled, but the teacher policy should be less restrictive than the student policy. Teachers may need access to broader educational content, research tools, media, and administrative websites.

Category Recommendation
Adult content Blocked
Malware / phishing Blocked
Risky categories Blocked
YouTube Allowed with staff-level filtering
Social media Allow or limit based on school policy

Suggested Mosyle Profile Structure

Instead of placing every setting into one large profile, it is better to split the configuration into smaller Mosyle profiles. This makes troubleshooting easier and allows IT to update one area without affecting everything else.

Profile Name Purpose
Staff - Restrictions AirDrop, Siri, Game Center, App Store, iCloud, sharing controls
Staff - Security Password, FileVault, firewall, auto-lock, Gatekeeper
Staff - Wi-Fi School Wi-Fi, certificates, auto-join settings
Staff - Apps Required apps, classroom tools, security agents, print clients
Staff - Web Filtering Staff-level filtering policy, malware protection, content protection

Some teachers may need exceptions based on their role or instructional workflow. Exceptions should be intentional, approved, and documented.

Example Exceptions

Exception Documentation Should Include

Best Practices

Recommended Standard Student MDM Profile


This guide provides a recommended baseline configuration for student Apple devices managed through Mosyle MDM. Student devices should be configured with stronger restrictions than teacher or staff devices because they are used in a classroom environment, may be shared or assigned to minors, and must support school safety, security, and compliance requirements.

Purpose

This profile should be applied to school-owned student iPads, MacBooks, and other Apple devices. The goal is to keep the device focused on learning, reduce distractions, protect students, prevent unauthorized changes, and maintain consistent device behavior across the school.

Students - iPadOS - Standard Restrictions
Students - macOS - Standard Restrictions
Students - Security Baseline
Students - Web Filtering
Students - App Controls
Students - Shared Device Restrictions

1. USB Storage / External Drives

Recommendation: Block USB storage and external drives for students unless there is a documented instructional exception.
Setting Recommendation
USB storage access Blocked
External drives Blocked unless approved
Unknown USB accessories Restricted
File transfer to removable media Not allowed

Students should not be able to copy school files, screenshots, assignments, or sensitive information to removable storage without approval. External storage also increases the risk of malware, inappropriate files, and data loss.

2. Siri and Dictation

Recommendation: Disable Siri and restrict Dictation unless required for accessibility.
Setting Recommendation
Siri Disabled
Siri while locked Disabled
Siri Suggestions Disabled
Dictation Disabled unless required for accessibility

Siri is not normally required for student learning devices and can create privacy concerns, classroom distractions, or unintended lock-screen access.

3. AirDrop

Recommendation: Disable AirDrop for all student devices.
Setting Recommendation
AirDrop Disabled
AirDrop receiving from Everyone Not allowed
Password sharing through AirDrop Disabled

AirDrop should be disabled for students because it can be used for inappropriate file sharing, classroom disruption, bullying, image sharing, or bypassing normal communication controls.

4. Apple ID and iCloud

Recommendation: Block personal Apple ID use and limit iCloud services.
Setting Recommendation
Personal Apple ID Blocked
Managed Apple ID Allowed if school-managed
iCloud Drive Disabled unless required
iCloud Photos Disabled
iCloud Keychain Disabled
iCloud Backup Disabled unless school-approved

Student devices should not be tied to personal Apple IDs. Personal accounts can create privacy issues, app ownership problems, Activation Lock concerns, and support issues when the device needs to be reassigned.

5. App Store and App Installation

Recommendation: Students should not install apps directly. Apps should be deployed through Mosyle.
Setting Recommendation
App Store Disabled or restricted
Install apps Not allowed by students
Remove apps Not allowed for managed apps
In-app purchases Disabled
Untrusted enterprise apps Blocked

Required apps should be assigned through Mosyle and Apple School Manager Apps and Books. This keeps app licensing, installation, updates, and removal under school control.

6. Classroom Distraction Controls

Recommendation: Disable non-instructional features that create distractions or safety concerns.
Feature Recommendation
Game Center Disabled
Messages Disabled unless required
FaceTime Disabled unless required
Music / Apple Music Disabled or restricted
Podcasts Disabled or restricted
News Disabled or restricted
Screen recording Restricted unless needed for instruction

7. Camera, Microphone, and Screen Recording

Recommendation: Allow only when instructionally needed.
Feature Recommendation
Camera Allowed if needed for instruction
Microphone Allowed if needed for instruction
Screen recording Restricted unless approved
Screenshots Restrict if supported and appropriate

For many classrooms, the camera and microphone may be required for projects, testing, accessibility, video assignments, and teacher-approved activities. These should not be blocked globally unless the school has a specific reason.

8. Web Filtering and Content Protection

Recommendation: Student web filtering should be required on all student devices.
Category Recommendation
Adult content Blocked
Malware / phishing Blocked
Proxy / VPN bypass sites Blocked
Gambling Blocked
Violence / weapons Blocked according to school policy
Social media Blocked or limited by grade level
YouTube Restricted or education-filtered
AI tools Controlled by school policy

Student filtering should apply both on-campus and off-campus when possible. Students should not be able to bypass filtering by using VPN apps, proxy sites, alternative browsers, private relay services, or unauthorized DNS settings.

9. Browser and Search Settings

Setting Recommendation
Safari Allowed only with filtering
Private Browsing Disabled where possible
Browser extensions Restricted
SafeSearch Enforced
YouTube Restricted Mode Enforced where applicable

10. VPN, DNS, and Network Changes

Recommendation: Students should not be allowed to install VPNs, modify DNS, or bypass network controls.
Setting Recommendation
VPN apps Blocked unless school-managed
DNS changes Restricted
Proxy configuration Restricted
Private Relay Disabled

11. Privacy and Security

Recommendation: Enforce security settings on all student devices.
Security Item Recommendation
Password / Passcode Required based on grade level and device type
Auto-lock Required
FileVault on macOS Enabled for assigned MacBooks
Firewall on macOS Enabled
Gatekeeper Enabled
Local admin rights Not allowed

12. Account and Settings Restrictions

Setting Recommendation
Account changes Restricted
Erase all content and settings Blocked
Device name changes Restricted
Wallpaper changes Optional: restrict for shared devices
Bluetooth changes Restricted if not needed
MDM profile removal Blocked

Suggested Mosyle Profile Structure

Student settings should be split into multiple Mosyle profiles instead of one large profile. This makes management, troubleshooting, and grade-level customization much easier.

Profile Name Purpose
Students - Restrictions AirDrop, Siri, App Store, iCloud, Game Center, account changes, device changes
Students - Security Passcode, auto-lock, FileVault, firewall, Gatekeeper, profile removal protection
Students - Wi-Fi Student Wi-Fi, certificates, auto-join, network restrictions
Students - Apps Required apps, blocked apps, approved learning tools, app removal restrictions
Students - Web Filtering CIPA-aligned filtering, malware protection, category restrictions, bypass prevention
Students - Testing Mode Assessment restrictions, app lock, browser lock, testing-specific controls

Not all students need the same level of restriction. The school may want to separate student profiles by grade band.

Grade Level Recommended Approach
K–2 Most restrictive; only required apps; very limited settings access
3–5 Highly restricted; allow only approved learning apps and websites
6–8 Restricted with some flexibility for projects, research, and classroom tools
9–12 Controlled but more flexible; still block bypass tools, unmanaged apps, and risky content

Student exceptions should be limited and documented. Exceptions should normally be tied to a class, grade level, accessibility requirement, testing requirement, or approved instructional activity.

Example Exceptions

Exception Documentation Should Include