Been playing with tvOS 10.2 and Apple TV Gen4 and JAMF PRO 9.98, here is something I have come across.
First I'll share the current out of box workflow.
Connect to DHCP ethernet
Prestage ATV4gen
Initial ATV Config (scoped to Prestage) adds WiFi, just to be sure and safe.
Manual changes to JSS record for device name, building, & asset tag
Initial Config units are smarted into Ready for Airplay Restrictions group
Airplay Restrictions Config (scoped to Airplay Restrictions Group) has tvOS restrictions checked for: Require passcode on first AirPlay pairing Allow keyboard continuation
Airplay Restrictions Config Also contains setting for Conference Room Display, showing the variables: $BUILDINGNAME, $DEVICENAME, and $SERIALNUMBER
In this Airplay Restrictions Config there is an exclusion group, a static list that can be edited at any time, allowing the ATV to lose the Airplay config and return to normal usage for whatever local changes are needed, etc. Remove the ATV from the list, it returns to normal and resets the variables shown in the conference display. (A good idea when it goes bonkers.)
So, what is the issue you ask.
Well, if you engage Airplay Permissions in Global Settings or via a config with Airplay Permissions, you can only target an ATV with a list of devices that can connect to it. Once connected or aligned to the ATV a device will always be able to connect to it and never prompted for a code until the ATV is restored or wiped.
If permissions are not set in Global nor via a config, the connected device is prompted once for a code and will always be able to connect to it and never prompted for a codeuntil the ATV is restored or wiped.
This is an issue in schools, where students will connect once and always have the ability to connect. Having the security of being in the room to see the airplay code is highly convenient way to control student access to ATV, for obvious reasons.
What my take away for the moment is that Airplay Permissions or restrictions may not always work in educational settings, sans conference rooms or restricted access ATVs. Perhaps, it is worth a trial to see how an ATV aligned to a teacher only is able to use Apple Classroom to route traffic from a controlled student device.
Curious what others have found or experienced, please share your feedback.
Thanks.
