Posted on 04-06-2023 09:05 AM
(Jamf Pro 10.41) This is the first I've had to manage any mobile device as the company usually puts them in InTune. But these users need more gradual control as the'll be using the phones mostly as cameras. But they're not going to be exclusively just using the camera app so can't use single-app mode. But there's no need for almost any of the built-in apps like Activity, Books, TV, Calendar, Health, Mail, Music, News, Podcasts, Reminders, Wallet.
I can find previous questions about this from before Apple allowed the removal of built-in apps - the technique then was to hide (old) or rearrange (older). But I'm looking at ideally removing, or hiding if that's all I can do.
I've tested trying to manage Podcasts, and set it to be managed if already installed. But the log says it can't be installed because it's already installed (duh. yeah). It doesn't even show up in Apps as managed or unmanaged - just failed. And I created a profile to restrict that list of apps (Some apps not allowed), but they still allow me to open them when I launch them (policy confirmed installed). Huh?
Posted on 04-06-2023 12:22 PM
I also don't manage iOS devices with JAMF but if I remember correctly you can hide built in apps. You would use a restrictions payload and set which apps they are allowed to use. It should remove all apps not allowed from the springboard.
Posted on 04-17-2023 11:42 AM
@cwaldrip The way to do it is to use the Apps Sub Category of Restrictions in a Configuration Profile. If you scroll to the bottom, you can either list apps to remove, or only access specific apps.
Either way, the following link will probably make your life a lot easier. It is the Bundle IDs for native apps installed on Apple Devices.
Posted on 04-17-2023 12:04 PM
Posted on 04-17-2023 11:53 AM
I think that my biggest problem is that many of the mobile devices are BYOB, and not "Supervised". So I'm working to get them enrolled in our ABM account now.
04-17-2023 11:56 AM - edited 04-17-2023 11:57 AM
The software restriction payload does not work on BYOD devices. They are personally owned and apple rightfully does not feel an organization has any right to restrict applications on a personally device.
However, I do feel apple needs a better way to identify an organizationally owned device than the only current option which is MDM enrollment with Automated Device Enrollment. Or wiping the device with a supervision flag on the OS using Apple Configurator as that is very hands on.
Posted on 04-17-2023 11:59 AM
Except in this case they aren't personal devices. They were just bought through a 3rd party resellers and thus were never enrolled in ABM. facepalm...