Systems Manager / BYOD policy

MikeH
New here

Systems Manager / BYOD policy

Hello all,

 

Looking for some help please.

 

We intended to place some mobile restrictions on such as .. no camera..etc.,

 

However, when I test the device will enrol, that's all good and I can allow each SSID to access each policy, I think.

 

My question is, when the BYOD disconnects from Company WIfi how do I restore all the functions to the phone?

 

Thanks

7 Replies 7
PhilipDAth
Kind of a big deal
Kind of a big deal

It sounds like what you want is actually a geo-fencing policy.

https://documentation.meraki.com/SM/Tags_and_Policies/Geofencing_with_Managed_Devices

 

Then apply your policies based on the dynamic tags of the policy be compliant (or non-compliant).

 

You might also might to define some IP based locations under the "General" tab, "Network Location". Assign the public IP address for you site to your address.

Screenshot from 2018-04-04 01-23-01.png

jared_f
Kind of a big deal

I did know you can scope to IP also, thanks @PhilipDAth - I will have to take a look.

Find this helpful? Click the kudos button. Thanks!

Thanks all!

 

I am missing something here with SM? Is it not the propose of SM to control the BYOD when its connected to say the Meraki Access point network and then when the user is done the BYOD goes back to the way the user likes it? 

 

jared_f
Kind of a big deal

I don’t have any Meraki APs so I can’t really comment. But, in order for SM to control the device the user has to be enrolled. Maybe sentry enrollment is something you are looking for?

Find this helpful? Click the kudos button. Thanks!
PhilipDAth
Kind of a big deal
Kind of a big deal


@MikeHwrote:

Thanks all!

 

I am missing something here with SM? Is it not the propose of SM to control the BYOD when its connected to say the Meraki Access point network and then when the user is done the BYOD goes back to the way the user likes it? 

 


I don't think you can do this @MikeH.

PhilipDAth
Kind of a big deal
Kind of a big deal

When you use the IP scoping @jared_f it causes the devices location to update quickly, rather than having to wait for a GPS update.  If the devices is in BYOD mode you could be waiting a long time to get a GPS update.

jared_f
Kind of a big deal

Would time-based tags also work? The only problem with geofencing is that it sometimes takes restrictions 2+ hours to sync off. Maybe scoping to a time based + geofencing tag would keep it synced.

Find this helpful? Click the kudos button. Thanks!
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels