- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unable to apply group policy on mobile phone due to MAC randomization
Hello Everyone.
I am trying to apply group policies in meraki . I have applied policies to Laptops/Desktop after fixing the Wireless IP address . But in case of mobile phones, I am facing issue. As every time, mobile phones are changing their MAC and IP address even if I have fixed their IP and MAC randomization is set to "Phone MAC' or "Private MAC".
Their MAC address is fixed only for that particular SSID for which I have fixed the MAC, but as the user connects to another SSID, it automatically changes to "Randomized MAC" and it bypasses all group policies.
Even "Description" which I set for that mobile device, changes to default name due to which it is difficult to track the device even with Name, MAC and IP.
Someone , kindly suggest me the best idea that how to fix any identity of mobile device on Meraki so that I can apply the group policies on mobile devices .
Is there any solution to fix the mobile device identity and won't changes if user connects to any SSID ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are the devices company owned or personal devices? If company owned I would suggest managing them using an MDM if you are not already which will allow you to disable MAC randomisation.
If they are private devices you will need to look for an alternative solution that might involve and SSID specifically for phones.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Users are having private devices.
Is there any possible way which can help to fix these private device identities on meraki ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Rohit_Rana both Android and IOS devices now choose a random virtual MAC address for each new wireless network that they connect to. They do retain the same random address for reconnections to the same network, but not between networks. This can be disabled by the user, either for the whole device, or for a specific wireless network, but the only way to force this is to install an MDM solution on the device. It is not a Meraki issue, but a deliberate design from the mobile device vendors to reduce device tracking.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The best solution here is to MDM the devices.
You can also apply the group policy on the SSID based on the device type which might be helpful
https://documentation.meraki.com/MR/Group_Policies_and_Block_Lists/Applying_Policies_by_Device_Type
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Brash ,
Thanks !
I think this can be the best solution to map the users for particular SSID wise, and we can provide access to that SSID only to them.
