# Recommended Standard Teacher MDM Profile

#   


This guide provides a recommended baseline configuration for **teacher and staff Apple devices** managed through **Mosyle MDM**. The goal is to create a balanced standard that protects school data, reduces classroom distractions, and keeps devices consistent without overly limiting teachers from doing their work.

<div id="bkmrk-recommended-profile-" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><div style="background: #eef6fb; border-left: 5px solid #1f4e79; padding: 14px; margin: 20px 0;">**Recommended Profile Name:**  
`Staff / Teacher – Standard Security & Classroom Use`</div></div>## Purpose

This profile should be applied to school-owned teacher and staff devices such as MacBooks, iPads, and other Apple devices assigned to employees. This profile should be less restrictive than a student device profile, but more controlled than a personal unmanaged device.

<div id="bkmrk-protect-school-data-" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;">- Protect school data
- Reduce security risks
- Limit classroom distractions
- Keep device settings consistent
- Allow teachers to use approved instructional tools

</div>## Recommended Mosyle Profile Naming Examples

```
Staff - macOS - Teacher Baseline
Staff - iPadOS - Teacher Baseline
Staff - Standard Restrictions
Staff - Security Baseline
Staff - Web Filtering
```

## Recommended Baseline Settings

### 1. USB Storage / External Drives

<div id="bkmrk-recommendation%3A-rest" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><div style="background: #fff8e5; border-left: 5px solid #d89b00; padding: 14px; margin: 15px 0;">**Recommendation:** Restrict USB storage where possible, or allow only by documented exception.</div><table style="width: 100%; border-collapse: collapse; margin: 15px 0;"><thead><tr style="background: #1f4e79; color: #fff;"><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Setting</th><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Recommendation</th></tr></thead><tbody><tr><td style="padding: 10px; border: 1px solid #ccc;">USB storage access</td><td style="padding: 10px; border: 1px solid #ccc;">Allow only if needed</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Unknown USB accessories</td><td style="padding: 10px; border: 1px solid #ccc;">Restrict when device is locked</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">External drive writing</td><td style="padding: 10px; border: 1px solid #ccc;">Restrict where possible</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">External drive reading</td><td style="padding: 10px; border: 1px solid #ccc;">Allow only for approved workflows</td></tr></tbody></table>

</div>USB drives are one of the easiest ways for school data to leave a device. They can also introduce malware or create data-loss concerns. Teachers may have legitimate reasons to use external storage, but the standard should be to use approved cloud storage instead whenever possible.

**Suggested policy language:**

> Teachers should avoid using personal USB drives for school data. Approved school cloud storage should be used whenever possible to reduce the risk of data loss, malware, or unauthorized transfer of sensitive information.

### 2. Siri

<div id="bkmrk-recommendation%3A-disa" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><div style="background: #fff8e5; border-left: 5px solid #d89b00; padding: 14px; margin: 15px 0;">**Recommendation:** Disable Siri on school-owned teacher devices unless there is an accessibility need.</div><table style="width: 100%; border-collapse: collapse; margin: 15px 0;"><thead><tr style="background: #1f4e79; color: #fff;"><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Setting</th><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Recommendation</th></tr></thead><tbody><tr><td style="padding: 10px; border: 1px solid #ccc;">Siri</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Siri while locked</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Dictation</td><td style="padding: 10px; border: 1px solid #ccc;">Allowed only if needed for accessibility</td></tr></tbody></table>

</div>Siri is usually not required for classroom instruction or staff productivity. Disabling Siri reduces privacy concerns, prevents accidental voice activation, and removes unnecessary lock-screen access.

### 3. AirDrop

<div id="bkmrk-recommendation%3A-disa-1" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><div style="background: #fbeeee; border-left: 5px solid #b00020; padding: 14px; margin: 15px 0;">**Recommendation:** Disable AirDrop by default. Allow only by exception for approved instructional use.</div><table style="width: 100%; border-collapse: collapse; margin: 15px 0;"><thead><tr style="background: #1f4e79; color: #fff;"><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Setting</th><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Recommendation</th></tr></thead><tbody><tr><td style="padding: 10px; border: 1px solid #ccc;">AirDrop</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled by default</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">AirDrop from Everyone</td><td style="padding: 10px; border: 1px solid #ccc;">Not allowed</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Password sharing through AirDrop</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr></tbody></table>

</div>AirDrop can be useful, but in a school setting it can also be abused for distractions, inappropriate file sharing, or accidental exposure of sensitive information.

**Possible exception groups:**

<div id="bkmrk-art-teachers-media-t" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;">- Art teachers
- Media teachers
- STEM teachers
- Yearbook staff
- Technology staff

</div>### 4. Apple ID and iCloud

<div id="bkmrk-recommendation%3A-rest-1" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><div style="background: #fbeeee; border-left: 5px solid #b00020; padding: 14px; margin: 15px 0;">**Recommendation:** Restrict personal Apple ID use on school-owned devices.</div><table style="width: 100%; border-collapse: collapse; margin: 15px 0;"><thead><tr style="background: #1f4e79; color: #fff;"><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Setting</th><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Recommendation</th></tr></thead><tbody><tr><td style="padding: 10px; border: 1px solid #ccc;">Personal Apple ID</td><td style="padding: 10px; border: 1px solid #ccc;">Not allowed on school-owned devices</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Managed Apple ID</td><td style="padding: 10px; border: 1px solid #ccc;">Preferred</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">iCloud Drive</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled unless approved</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">iCloud Photos</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">iCloud Keychain</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr></tbody></table>

</div>School-owned devices should not become tied to personal Apple IDs. This can create problems with Activation Lock, app ownership, data ownership, privacy, and long-term device support.

### 5. App Store and App Installation

<div id="bkmrk-recommendation%3A-apps" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><div style="background: #eef6fb; border-left: 5px solid #1f4e79; padding: 14px; margin: 15px 0;">**Recommendation:** Apps should be deployed through Mosyle using Apple School Manager Apps and Books.</div><table style="width: 100%; border-collapse: collapse; margin: 15px 0;"><thead><tr style="background: #1f4e79; color: #fff;"><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Setting</th><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Recommendation</th></tr></thead><tbody><tr><td style="padding: 10px; border: 1px solid #ccc;">App Store</td><td style="padding: 10px; border: 1px solid #ccc;">Restricted</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">User app installation</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled or limited</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Managed apps</td><td style="padding: 10px; border: 1px solid #ccc;">Required method</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Removing managed apps</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr></tbody></table>

</div>### 6. Classroom Distraction Controls

<div id="bkmrk-feature-recommendati" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><table style="width: 100%; border-collapse: collapse; margin: 15px 0;"><thead><tr style="background: #1f4e79; color: #fff;"><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Feature</th><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Recommendation</th></tr></thead><tbody><tr><td style="padding: 10px; border: 1px solid #ccc;">Game Center</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Messages</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled unless approved</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">FaceTime</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled unless approved</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Camera</td><td style="padding: 10px; border: 1px solid #ccc;">Allowed</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Microphone</td><td style="padding: 10px; border: 1px solid #ccc;">Allowed</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Screen Recording</td><td style="padding: 10px; border: 1px solid #ccc;">Allowed for teachers</td></tr></tbody></table>

</div>Teachers should have access to instructional tools such as the camera, microphone, screen recording, printing, and approved classroom applications. Consumer features that do not support instruction should be limited.

### 7. Privacy and Security

<div id="bkmrk-recommendation%3A-enfo" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><div style="background: #eaf7ea; border-left: 5px solid #2e7d32; padding: 14px; margin: 15px 0;">**Recommendation:** Enforce security settings on all school-owned teacher devices.</div><table style="width: 100%; border-collapse: collapse; margin: 15px 0;"><thead><tr style="background: #1f4e79; color: #fff;"><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Security Item</th><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Recommendation</th></tr></thead><tbody><tr><td style="padding: 10px; border: 1px solid #ccc;">Password / Passcode</td><td style="padding: 10px; border: 1px solid #ccc;">Required</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Auto-lock</td><td style="padding: 10px; border: 1px solid #ccc;">Required</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">FileVault on macOS</td><td style="padding: 10px; border: 1px solid #ccc;">Enabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Firewall on macOS</td><td style="padding: 10px; border: 1px solid #ccc;">Enabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Gatekeeper</td><td style="padding: 10px; border: 1px solid #ccc;">Enabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Local admin rights</td><td style="padding: 10px; border: 1px solid #ccc;">Standard user preferred</td></tr></tbody></table>

</div>### 8. Web Filtering and Content Protection

Teacher devices should still have web filtering enabled, but the teacher policy should be less restrictive than the student policy. Teachers may need access to broader educational content, research tools, media, and administrative websites.

<div id="bkmrk-category-recommendat" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><table style="width: 100%; border-collapse: collapse; margin: 15px 0;"><thead><tr style="background: #1f4e79; color: #fff;"><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Category</th><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Recommendation</th></tr></thead><tbody><tr><td style="padding: 10px; border: 1px solid #ccc;">Adult content</td><td style="padding: 10px; border: 1px solid #ccc;">Blocked</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Malware / phishing</td><td style="padding: 10px; border: 1px solid #ccc;">Blocked</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Risky categories</td><td style="padding: 10px; border: 1px solid #ccc;">Blocked</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">YouTube</td><td style="padding: 10px; border: 1px solid #ccc;">Allowed with staff-level filtering</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Social media</td><td style="padding: 10px; border: 1px solid #ccc;">Allow or limit based on school policy</td></tr></tbody></table>

</div>## Suggested Mosyle Profile Structure

Instead of placing every setting into one large profile, it is better to split the configuration into smaller Mosyle profiles. This makes troubleshooting easier and allows IT to update one area without affecting everything else.

### Recommended Profiles

<div id="bkmrk-profile-name-purpose" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><table style="width: 100%; border-collapse: collapse; margin: 15px 0;"><thead><tr style="background: #1f4e79; color: #fff;"><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Profile Name</th><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Purpose</th></tr></thead><tbody><tr><td style="padding: 10px; border: 1px solid #ccc;">**Staff - Restrictions**</td><td style="padding: 10px; border: 1px solid #ccc;">AirDrop, Siri, Game Center, App Store, iCloud, sharing controls</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">**Staff - Security**</td><td style="padding: 10px; border: 1px solid #ccc;">Password, FileVault, firewall, auto-lock, Gatekeeper</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">**Staff - Wi-Fi**</td><td style="padding: 10px; border: 1px solid #ccc;">School Wi-Fi, certificates, auto-join settings</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">**Staff - Apps**</td><td style="padding: 10px; border: 1px solid #ccc;">Required apps, classroom tools, security agents, print clients</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">**Staff - Web Filtering**</td><td style="padding: 10px; border: 1px solid #ccc;">Staff-level filtering policy, malware protection, content protection</td></tr></tbody></table>

</div>## Recommended Final Standard

<div id="bkmrk-category-recommended" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;"><table style="width: 100%; border-collapse: collapse; margin: 15px 0;"><thead><tr style="background: #1f4e79; color: #fff;"><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Category</th><th style="padding: 10px; border: 1px solid #ccc; text-align: left;">Recommended Setting</th></tr></thead><tbody><tr><td style="padding: 10px; border: 1px solid #ccc;">USB storage</td><td style="padding: 10px; border: 1px solid #ccc;">Restricted / exception only</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Siri</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Siri while locked</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">AirDrop</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Personal Apple ID</td><td style="padding: 10px; border: 1px solid #ccc;">Not allowed</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">iCloud Photos</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">iCloud Keychain</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">App installs</td><td style="padding: 10px; border: 1px solid #ccc;">Mosyle-managed only</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Game Center</td><td style="padding: 10px; border: 1px solid #ccc;">Disabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Camera</td><td style="padding: 10px; border: 1px solid #ccc;">Allowed</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Microphone</td><td style="padding: 10px; border: 1px solid #ccc;">Allowed</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Screen Recording</td><td style="padding: 10px; border: 1px solid #ccc;">Allowed for teachers</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Printing</td><td style="padding: 10px; border: 1px solid #ccc;">Allowed</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">FileVault</td><td style="padding: 10px; border: 1px solid #ccc;">Enabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Firewall</td><td style="padding: 10px; border: 1px solid #ccc;">Enabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Password / Passcode</td><td style="padding: 10px; border: 1px solid #ccc;">Required</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Auto-lock</td><td style="padding: 10px; border: 1px solid #ccc;">Required</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Web filtering</td><td style="padding: 10px; border: 1px solid #ccc;">Enabled</td></tr><tr><td style="padding: 10px; border: 1px solid #ccc;">Admin rights</td><td style="padding: 10px; border: 1px solid #ccc;">Standard user preferred</td></tr></tbody></table>

</div>## Recommended Exception Process

Some teachers may need exceptions based on their role or instructional workflow. Exceptions should be intentional, approved, and documented.

### Example Exceptions

<div id="bkmrk-art-teacher-needs-ai" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;">- Art teacher needs AirDrop for media workflow
- STEM teacher needs USB storage for robotics equipment
- Music teacher needs external audio devices
- Media teacher needs camera, microphone, and screen recording access
- Administrator needs broader website access

</div>### Exception Documentation Should Include

<div id="bkmrk-user-or-group-name-d" style="font-family: Arial, sans-serif; line-height: 1.6; color: #222;">- User or group name
- Device serial number
- Requested exception
- Business or instructional reason
- Approval person
- Review date

</div>