Hi @soomeGUy! I'm late to this thread, but I think the steps below will help. Unchecking the restriction "Allow App Removal " under Restrictions> ios restrictions (supervised) will lock all apps on the device - which doesn't sound like what you want. Instead, I might make all managed apps set to auto-install, so even if a user deletes them, they will be reinstalled by SM. Using VPP device assignment will also set this up to install silently (the user can't block or deny this). Here's more on that - https://documentation.meraki.com/SM/Apps_and_Software/Using_Apple%E2%80%99s_Volume_Purchase_Program_(VPP)_with_Systems_Manager With regard to your question about geofencing and location services - at this time Apple does not provide the ability to force location services, except through Lost Mode. In your case, I might actually use IP override to gather location info for your devices, and set a geofencing policy that is active when devices are off/outside of your network. That would work even if location services have been disabled by the user. Another option would be to use time-based tags, instead of location based tags. Do you want the device to operate different when your users are offsite - or do you simply want to know when they are offsite? https://documentation.meraki.com/SM/Monitoring_and_Reporting/How_Systems_Manager_Approximates_the_Location_of_a_Managed_Device
... View more