You can block and whitelist apps with that respective restrictions profile. If you want only managed apps (apps you will be able to remove from Dashboard) on the device, you will need to add those and scope them to either auto-install or have the user install in the Meraki MDM Self Service Portal. On devices that call for restrictions regarding content, I prefer not to go the route of disabling the app store. I instead scope out a whitelist profile and have a policy notify me of membership change if a user installs a "blacklisted app". I basically have a restrictions profile setup that is tripped and installed by that policy and the device becomes unusable until the user (a) removes the app and waits until and apps refresh takes place for restrictions to be taken off or (b) sees me, and I take the restrictions off by temporarily excluding them from profiles, deleting the app and re-installing the correct configs. Seems to be working in my environment. Unfortunately, I can't limit all apps, but people using a VPN to get around corp filters is an issue. Jared
... View more