Posted on 03-16-2020 06:11 AM
I apologize as I am very new to the area of MDM.
We are deploying iPads and iPhones to our employees, but while setting up the config profiles, I can't find a way to restrict which apple ID's are used. When checking the settings menu, I would like to remove or deactivate the ability to sign into icloud because these are for business use. Is there a way to make this happen or is there a way to force it to only accept managed AppleID's?
Thank you in advance!
Posted on 03-16-2020 01:26 PM
@dgadd, have a look in Jamf Pro under Devices > Configuration Profiles > New button > Restrictions payload > iOS tab > Functionality tab > Allow modifying account settings (supervised only). This prevents adding/modifying most any account you can associate to an iOS device including iCloud, email, calendar, contacts, etc.
You'll also find more granular iCloud options here. What specifically do you hope to block by managing sign-ins to iCloud?
Posted on 03-18-2020 06:08 AM
Thanks for the response! That option seemed like it made the most sense, but I wan't sure what it would encompass.
Realistically, I want to be sure that employee don't have the ability to personalize them, or use them as personal devices. I have to make sure they cannot access the app store and download apps, that is a big issue we have run into in the past.
Posted on 03-18-2020 08:26 AM
If a account is logged in on the device they will lost the ability to remove it when you set this restriction. It will also affect the password & accounts settings.
Posted on 03-19-2020 02:28 PM
@zamo We use the passwords and accounts settings when setting up the exchange mailbox. Would this disable the mailbox from bringing in user data?
Posted on 03-20-2020 01:20 AM
No. When it's set up everthing works as expected but you were enable to do any changes to these accounts on the device itself. If you set up exchange accounts with a configuration profile you can do any changes whether the account restriction is set or not.
It's a bit hard for me to explain it in english so I hope you can understand what I am trying to say here^^
Posted on 03-20-2020 05:50 AM
Oh, that helps. Thank you. I'm going to make some changes today to play around with it on our test devices.
Thanks again
Posted on 10-14-2020 10:00 AM
I am finding this does not work on Shared ipads. We are trying to find a solution that only allows users to use Guest account, which wipes at signout. I have completely restricted everything iCloud, and it seems to allow a Apple ID login. JAMF Pro 10.25.0 and iOS 14.01
Posted on 10-15-2020 11:35 PM
@mhegge The devices have to be supervised to use this restriction.
If you want to reset the devices, the jamf reset app maybe something for you. I didn't test it myself but, just read about it. You have to use it with the jamf setup app to work correctly.
Posted on 10-16-2020 10:05 AM
@zamo We use Jamf reset for Library checkout iPads. But that is an operation performed by library staff. We cannot rely on students to utilize JAMF Reset consistently. It would be a data security risk.
Posted on 10-16-2020 10:07 AM
I have found out that if users try to use an Apple ID, it states it can only accept managed Apple IDs, so we may be able to work around it. We currently are not using managed apple IDs (only a few test accounts).
Posted on 11-04-2021 12:05 PM
Do you know how you had the profiles set up to enforce that? I'm looking to set up devices so they only allow managed Apple IDs
Posted on 05-07-2021 10:45 AM
I wish this was a restriction we could use on Macs instead of just iOS. We are trying to use Apple Classroom on macs however many students have logged out of their managed Apple ID and just are using a personal one instead.
Gabe Shackney
Princeton Public Schools
Posted on 10-21-2021 10:20 AM
I am not seeing this anymore: Configuration Profiles > New button > Restrictions payload > iOS tab > Functionality tab > Allow modifying account settings (supervised only).
Posted on 10-28-2021 03:01 AM
They changed the layout, few versions ago. It looks like this on my side:
I am using jamf Pro 10.32.2
Posted on 05-09-2023 08:10 AM
Is there a way to back up the iPhone / iPad to iCloud even if we restrict the end user from logging out of their work-managed account?