Hi,
I have been using Meraki MDM for a while at our workplace. All is good. We are expanding the use of it to personal devices (BYOD). It has been noticed that the MDM Management Profile requests the following rights on iOS...
Some of these rights seem excessive, particularly 1, 2, 9 & 13. Understandably, users with personal devices are hesitant to allow the profile.
Is it possible to edit this list? Or change what rights the management profile requires? Is there a bare minimum list of rights required for the management to operate correctly?
The profile is only installing iOS mail settings. We are not using the agent app.
Thanks in advance.
Solved! Go to Solution.
Under Systems Manager > General (under the “Configure” heading) > Access Rights (you have to scroll down a bit to see it) you can restrict some of the SM capabilities. I believe these are per network rules, maybe create another SM network (aka “site”) for BYOD devices and apply these restrictions?
@Miyo360 wrote:Hi,
I have been using Meraki MDM for a while at our workplace. All is good. We are expanding the use of it to personal devices (BYOD). It has been noticed that the MDM Management Profile requests the following rights on iOS...
- Erase all data and settings
- Lock device and remove passcode
- List configuration profiles
- Add/remove configuration profiles
- List provisioning profiles
- Add/remove provisioning profiles
- List device information
- List network information
- List installed applications
- List restriction information
- List security information
- Apply settings
- Install and remove applications and data
Some of these rights seem excessive, particularly 1, 2, 9 & 13. Understandably, users with personal devices are hesitant to allow the profile.
Is it possible to edit this list? Or change what rights the management profile requires? Is there a bare minimum list of rights required for the management to operate correctly?
The profile is only installing iOS mail settings. We are not using the agent app.
Thanks in advance.
Under Systems Manager > General (under the “Configure” heading) > Access Rights (you have to scroll down a bit to see it) you can restrict some of the SM capabilities. I believe these are per network rules, maybe create another SM network (aka “site”) for BYOD devices and apply these restrictions?
@Miyo360 wrote:Hi,
I have been using Meraki MDM for a while at our workplace. All is good. We are expanding the use of it to personal devices (BYOD). It has been noticed that the MDM Management Profile requests the following rights on iOS...
- Erase all data and settings
- Lock device and remove passcode
- List configuration profiles
- Add/remove configuration profiles
- List provisioning profiles
- Add/remove provisioning profiles
- List device information
- List network information
- List installed applications
- List restriction information
- List security information
- Apply settings
- Install and remove applications and data
Some of these rights seem excessive, particularly 1, 2, 9 & 13. Understandably, users with personal devices are hesitant to allow the profile.
Is it possible to edit this list? Or change what rights the management profile requires? Is there a bare minimum list of rights required for the management to operate correctly?
The profile is only installing iOS mail settings. We are not using the agent app.
Thanks in advance.
Thanks very much. This was helpful. I created a new network and looked at the options you suggested. I set the following...
I then added a device and checked the permission list and the differences are
Thanks again for your help.