iPad Private Wifi (MAC) Address

mstydel
Contributor

Found out today that some students have the "Private Wi-Fi Address" option enabled in the settings for their appropriate SSID.  We don't want this setting enabled on any of our iPads so we have it disabled in all of our wifi SSID config profiles.  I had one this morning that I was able to enable and disable it, I tried restarting but no change, also tried removing and adding that SSID's config profile but no change, I could still enable or disable.  All of our devices are running ~16.6 or newer, probably around half have gone to iOS 17.  I'm guessing it defaulted to off rather than on like an unmanaged SSID would normally due to the profile disabling it, some just found that they could enable it for whatever reason and have.

7 REPLIES 7

JesseC1006
New Contributor II

Resurrecting an old post on ya.  LOL. Are you still having this issue?  We seem to be experiencing it here in my district as well, despite the Config Profile that has it set to be turned off.

We can't easily identify the iPads on our Cisco's when this option is enabled.  Just wish the setting would stick.

mstydel
Contributor

We have found in our environment that the option to enable private MAC is there no matter what, but having it disabled in the wifi config profile will have it disabled on the iPad until it is turned on.  In our DHCP we have private MAC wildcards blocked so if students turn it on they can't get an IP, or they don't get a renewal for the one they have.

JesseC1006
New Contributor II

It's so weird because on my test iPad here at my desk.  I can't turn Private on or off.  It's set to off of course.  But we are seeing students being able to turn them back on.  And both of these iPads fall under the same configs in JAMF.  It's getting annoying.  LOL

I guess I shouldn't say they don't all have the option, I think some do and some don't, but all are off by default with the config profile. It is only on if they have the option and turn it on themselves. We have to remember if we manually put a different SSID on it for some reason that we have to go in right away and turn it off as it defaults to on and the device won't get an IP until we do so. But we rarely manually put students on other SSID's anymore as they can see the password now.

JesseC1006
New Contributor II

So on my test iPad the option was off.  Wouldn't allow me to do anything to it.  The moment I connected to a different SSID the option was re-enabled and I could turn it on or off as much as I wanted.  I'd say that's a pretty decent bug if you ask me.

I know why our students are on then.  In the summer time we have an open SSID so we can run updates on the iPads so they are ready for when the kids come back.  That's how it's getting enabled again.  Hmmmm.....

mstydel
Contributor

Nothing really surprises me anymore with Apple and bugs.  My iPhone has had some of the same bugs for years that never get fixed.  The whole "iOS 16 makes iPads 5th-7th gen randomly stop communicating with MDM" bug left a bad taste in my mouth with Apple.  The solution of "it's fixed in iOS 17 so just update them" wasn't a real great solution when iOS 17 didn't come out for another 2 months and wasn't compatible with all of our 5th gen iPads that became basically useless after having iOS 16 on them.  Usually we keep iPads a year or two beyond the end of their updates so we can use them where we HAVE to but guess we won't be doing that with the 5th gens.

JesseC1006
New Contributor II

I agree with what's been going on with all of the bugs and stuff still lingering around.  We weren't happy with that same crap either.  LOL. We have almost 4k iPads and we took the entire summer (Last year) to whip them all and get them communicating again.  I thought JAMF was supposed to give us less work at IT people.  It's a full time job just for our iPads alone.

Much appreciated for the info on the SSID's though.  I was certainly puzzled for quite some time with that one.  I might reach out to JAMF in the future.