Jump to:navigation, search
Wiki












































Managing iOS profiles with the Apple TV type in the Mobile Security Portal

Last adaptation to the version: 2.15(03.2026)

New:
notempty
This article refers to a Beta version
Access: portal.securepoint.cloud  Mobile Security iOS/iPadOS Profile




Preamble

In a profile permissions, restrictions, password requirements, email settings and security settings are configured.
Several users or user groups (roles) can be assigned to a profile.
Several devices or device groups (devices designated by tags) can be assigned to a profile.

notempty
For a large number of devices and users it is recommended to map the assignment via groups.
  • Device registration is directly tied to a profile
  • A profile must be created first' (and configured) before a device can be registered

In Android Enterprise profiles, numerous security-relevant settings can be made, e.g.

  • Disable Kamara
  • Disable microphone
  • Disable USB file transfer
  • Disable outgoing calls
  • Disable Bluetooth
  • Disable contact sharing
  • Disable tethering
  • Disable sms
  • Enable network only with VPN
  • and much more.
notempty
Android Enterprise Profiles are used immediately and do not need to be published!
  • Outdated Android profiles behave fundamentally different than Android Enterprise Profiles (EMM)
  • It is no longer possible to assign a profile to a role, user or tag

Overview of profile management

In the profile overview new profiles can be created, existing ones can be edited and deleted. The view of the profiles can be displayed in the list or tile view. You can also view details of existing profiles, update the list of profiles, and publish profiles.
Overview of profile management iOS
Overview of profile management Android

General Options

Search Filters on profile tiles that contain the search text
 Sort
Clicking this button opens a menu where you can sort the tiles according to specific criteria
 Sort
Clicking this button opens a menu where you can sort the tiles according to specific criteria
Name
Sorts the tiles by profile name
Priority
Sorts the tiles according to the priority of the profile
Ascending
Sorts the tiles in ascending or descending order according to the selected criterion
 Add profile Creates a new profile. The settings in the profile vary depending on the operating system.
 Import profile Existing profiles that were previously exported from the Securepoint Mobile Security Portal can be imported here
 Hide generated profiles Hides the generated profiles
Show details Show / hide details: For a large number of profiles, it can be useful to hide the most important details for clarity.
/ List view / Grid view Switch between lists and grid view
Refresh Refreshes the display

Profile tile

Profile-Options
The button at the top right of each profile tile provides the following options:
 Edit Editing the settings (see below)
  Copy Copying the profile to the clipboard
  Export Exporting the settings
  Delete The profile is deleted
notempty
New as of: 2.5
Android profiles that have at least one assigned device cannot be deleted.
Details displayed in the profile tile:
 Updated Changes have been made to the profile that have not yet been published!
 Partially installed Not all sub profiles were able to be installed
Profile information
  Type Profile type (see below)
  Roles Roles
  Users User
 Devices Devices
  tags Tags
  Parts Listing of the sub-profiles that make up the complete Mobile Security Profile.

Copy & paste of profiles

Click on the logo of the profile tile to mark one or more profiles In the general options, another field now appears under the filter mask:
Action for selected items Please choose Execute the selected action with Ok
Copy Copies one or more selected profiles to the clipboard
Delete Deletes one or more selected profiles
notempty
New as of: 2.5
Android profiles that have at least one assigned device cannot be deleted.
  Paste Inserts a copy of a profile from the clipboard
This also works from one tenant / customer to another as long as they are assigned to the same reseller account   AnyIdeas GmbH



Configuration iOS profile AppleTV




General

General

 Add profile

Caption Value Description
General menu item
Type Device profile Standard device profile
Shared iPad Profile that allows different users for one iPad
  • Only for devices with iPadOS
  • Apple TV profiles Profile with limited settings options. Additional settings for Apple TV
    User Enrollmant profile Profile owned by the user on which managed apps of the company can be installed
    Name Name Profile name
    Priority 5 The higher the number, the higher the priority. This is only used if a device is assigned to multiple profiles.
    Roles Add roles Click-Box: The profile will be assigned to all devices of all users with these roles
    Users Add users The profile will be assigned to all devices from these users
    Devices Add devices The profile will be assigned to these devices
    Tags Add tags The profile will be assigned to all devices with these tags
    Comment Comment Comment



    Close Closes the tab without applying changes
     Save Applies the changes / new creation, saves and closes the tab

    Restrictions

    Restrictions




    Caption Value Description
    Allow automatic unlocking    When deactivated   , the automatic unlocking is disabled
    Kon­troll­zen­trum im Sperr­bild­schirm zu­las­sen    Wenn aktiviert    ermöglicht es den Zugriff auf das Kontrollzentrum direkt vom Sperrbildschirm

    Dies erleichtert Schnellaktionen (WLAN, Taschenlampe), kann aber unerwünschte Änderungen ohne Anmeldung ermöglichen

    Mit­tei­lungs­an­sicht im Sperr­bild­schirm er­lau­ben    Wenn aktiviert    ermöglicht es die Anzeige vergangener Mitteilungen auf dem Sperrbildschirm

    Dies verbessert die Sichtbarkeit wichtiger Informationen, erhöht jedoch das Risiko, dass sensible Inhalte von Dritten eingesehen werden

    Heu­te-An­sicht im Sperr­bild­schirm zu­las­sen    When deactivated   , today's lock screen view will be disabled
    Force encrypted backups    When activated   , encrypted backups are enforced
    Ad-Tracking be­schrän­ken    When activated   , ad tracking will be restricted
    Find My De­vice er­lau­ben    Wenn aktiviert    wird Find My Device in der Find My App zugelassen
    Find My Fri­ends er­lau­ben    Wenn aktiviert    wird Find My Friends in der Find My App zugelassen
    Allow trusting enterprise apps    When deactivated   , Enterprise apps are not trusted
    Bild­schirm­fo­tos und Bild­schirm­auf­nah­men zu­las­sen    Wenn aktiviert    erlaubt es dem Benutzer das Erstellen von Bildschirmfotos und Bildschirmaufnahmen
    Wal­let-Mit­tei­lun­gen bei ge­sperr­tem Bild­schirm    When deactivated   , wallet notifications will not be shown on the lock screen
    E-Mail-Da­ten­schutz zu­las­sen    When activated   , Apple's Mail Privacy Protection (AMPP) is activated
    Ent­sper­ren mit Touch- & Face-ID zu­las­sen    When deactivated   , Touch ID/Face ID is not allowed to unlock the device
    Än­de­rung von Touch- & Face-ID zu­las­sen    When deactivated   , the user is not permitted to change the Touch ID/Face ID
    Sen­den von Dia­gno­se­da­ten zu­las­sen    When deactivated   , diagnostic and usage data is not sent to Apple
    Än­dern der Dia­gno­se­ein­stel­lun­gen zu­las­sen    When deactivated   , the user is not permitted to change the diagnostic settings
    Allow network access for files    When deactivated   , the connection to network drives is prevented in the file app
    Än­de­rung der Blue­tooth-Ein­stel­lun­gen zu­las­sen    When deactivated   , changes to the Bluetooth settings are not permitted
    Än­de­rung der mo­bi­len Da­ten­nut­zung für Apps zu­las­sen    When deactivated   , the mobile data uses for app settings cannot be changed
    Ak­zep­tie­ren nicht ver­trau­ens­wür­di­ger TLS-Zer­ti­fi­ka­te zu­las­sen    When deactivated   , the user is not allowed to accept untrusted certificates in TLS
    Hand­off zu­las­sen    When deactivated   , handoff is deactivated. Handoff allows you to continue an activity started on an iOS-device on another device.
    iCloud-Fo­tos zu­las­sen    When deactivated   , the use of the iCloud Photo Library on the device is not permitted
    iCloud-Back­up zu­las­sen    When deactivated   , the backup with the iCloud is not permitted
    Au­to­ma­ti­sches Syn­chro­ni­sie­ren bei Roa­ming zu­las­sen    When deactivated   , automatic synchronisation is deactivated during roaming
    Back­up von En­ter­pri­se-Bü­chern zu­las­sen    When deactivated   , Enterprise books are not saved
    Syn­chro­ni­sa­ti­on von No­ti­zen/Mar­kie­run­gen in En­ter­pri­se-Bü­chern zu­las­sen    When deactivated   , Enterprise books and highlights are not synchronised
    In-App-Käu­fe zu­las­sen    When deactivated    no in-app purchases can be made
    Mul­ti­play­er-Ga­ming zu­las­sen    When deactivated   , multiplayer gaming is not allowed
    iTu­nes Pass­wort für alle Käu­fe an­for­dern    When activated   , the user's iTunes password is required for all purchases
    Siri zu­las­sen    When deactivated   , Siri is not allowed
    Siri bei ge­sperr­tem Bild­schirm zu­las­sen    When deactivated   , Siri is not allowed while the device is locked
    Siri Zu­griff auf be­nut­zer­ge­ne­rier­te In­hal­te zu­las­sen    When deactivated   , it prevents Siri from querying requests with user-generated content
    Dik­tier­funk­ti­on zu­las­sen    When deactivated   , dictations are not allowed
    On-De­vice Dik­tier­funk­ti­on    When deactivated   , the QuickPath keyboard is disabled
    Force translation on the device only    When activated   , the device does not connect to Siri servers for translation purposes
    Allow QuickPath keyboard    When deactivated   , the QuickPath keyboard is disabled
    Content & Entertainment
    Content & Entertainment
    Ap­ple Mu­sic zu­las­sen    When deactivated   , Apple Music will be disabled in the Music app
    iTu­nes Ra­dio zu­las­sen    When deactivated   , iTunes Radio will be disabled in the Music app
    News-App zu­las­sen    When deactivated    no news can be used
    App-Al­ters­frei­ga­be fest­le­gen Alle Apps erlauben Legt die höchste erlaubte App-Altersfreigabe fest
    Auswahlmöglichkeiten App-Altersfreigaben festlegen anzeigen
    hide
    Klicken für dauerhafte Anzeige
    Alle Apps erlauben 17+ 12+ 9+ 4+ Nichts erlauben
    Film-Al­ters­frei­ga­be fest­le­gen Alle Filme Legt die höchste erlaubte Film-Altersfreigabe fest (FSK)
    Auswahlmöglichkeiten Film-Altersfreigaben festlegen anzeigen
    hide
    Klicken für dauerhafte Anzeige
    Alle Filme FSK 18 FSK 16 FSK 12 FSK 6 FSK 0 Keine Filme
    TV-Al­ters­frei­ga­be fest­le­gen Alle TV-Sendungen Legt die höchste erlaubte TV-Altersfreigabe fest
    Auswahlmöglichkeiten TV-Altersfreigaben festlegen anzeigen
    hide
    Klicken für dauerhafte Anzeige
    Alle TV-Sendungen Ab 18 Jahren Ab 16 Jahren Ab 12 Jahren Ab 6 Jahren Ab 0 Jahren Keine TV-Sendungen
    Coo­kies in Sa­fa­ri zu­las­sen Nur von aktueller Webseite (iOS 8) oder besuchten Seiten (pre-iOS 8) Möglichkeiten zur Einstellung der Cookie Akzeptanz in Safari
    Auswahlmöglichkeiten Cookies in Safari akzeptiert anzeigen
    hide
    Klicken für dauerhafte Anzeige
    Nur von aktueller Webseite (iOS 8) oder besuchten Seiten (pre-iOS 8) Never Webseiten die ich besucht habe Always
    Ja­va­Script zu­las­sen    When deactivated   , JavaScript is not allowed in Safari
    Pop-ups zu­las­sen    When deactivated   , pop-ups are not allowed in Safari
    Enable fraud warning    When activated   , the fraud warning in Safari is activated
    System & Sonstiges
    System & Sonstiges
    Allow OTAPKI updates    When deactivated   , OTAPKI updates are disabled
    Tem­po­rä­re Sit­zun­gen (Ge­teil­tes iPad) zu­las­sen    When deactivated   , the temporary session of the shared device is disabled
    Air­Play-Kopp­lungs­pass­wort (aus­ge­hend) er­zwin­gen    When activated   , all devices receiving AirPlay requests from this device will be forced to use a pairing password
    Än­de­rung des Ge­rä­te­na­mens zu­las­sen    When deactivated   , the device name cannot be changed
    Allow voice dialing while device is locked    When deactivated   , no voice dialling is allowed, even if the device is locked
    Force Apple Watch wrist detection    When activated   , Apple Watch wrist detection is enforced
    Allow pairing with Apple Watch    When deactivated   , pairing with Apple Watch is not permitted
    In­ter­net­er­geb­nis­se in Spot­light zu­las­sen    When deactivated   , search results from the web will not be shown in Spotlight
    Per­so­na­li­sier­te Wer­bung zu­las­sen    When deactivated   , restricts Apple's personalized advertising. Available in iOS 14 and later
    Ka­me­ra­nut­zung zu­las­sen    When deactivated   , the user is not allowed to use the camera
    Än­de­rung der Mit­tei­lungs­ein­stel­lun­gen zu­las­sen    Wenn aktiviert    ermöglicht es das Ändern der Mitteilungseinstellungen
    Ver­wal­te­ten Apps das Schrei­ben in nicht ver­wal­te­te Kon­tak­te zu­las­sen    When deactivated   , writing unmanaged contacts will be disabled
    Nicht ver­wal­te­ten Apps das Le­sen ver­wal­te­ter Kon­tak­te zu­las­sen    When deactivated   , unmanaged apps cannot access contacts of managed accounts and that managed apps do not save contacts in the local Contacts app
    iCloud-Syn­chro­ni­sie­rung für ver­wal­te­te Apps zu­las­sen    When deactivated   , iCloud synchronisation is deactivated for managed apps
    Öff­nen aus nicht ver­wal­te­ten Quel­len in ver­wal­te­ten Apps zu­las­sen    When deactivated   , iCloud synchronisation is deactivated for managed apps
    Öff­nen aus ver­wal­te­ten Quel­len in nicht ver­wal­te­ten Apps zu­las­sen    When deactivated   , iCloud synchronisation is deactivated for managed apps
    Ver­wal­te­te Zwi­schen­ab­la­ge    When activated   , the copy and paste feature follows the "Allow open from managed to unmanaged" and "Allow open from unmanaged to managed" constraints.
    Treat AirDrop as unmanaged destination    When activated   , it prevents protected (managed) data from leaving the device without authorisation via Airdrop



    Restrictions for supervised devices
    Restrictions for supervised devices




    Restriction Explanation
    App Nutzung & Installation
    App-Nut­zung ein­schrän­ken Allow all apps Alle Apps erlauben, Blocklist oder Allowlist
    Auswahlmöglichkeiten App-Nutzung einschränken einblenden
    hide
    Klicken für dauerhafte Anzeige
    Allow all apps Do not allow certain apps Allow only certain apps

    Weitere Konfigurationen bei Optionsauswahl Bestimmte Apps nicht erlauben einblenden
    Weitere Konfigurationen bei Optionsauswahl Nur bestimmte Apps erlauben einblenden

    Blocked apps Choose application Blocked apps
     Add system apps If the selection is limited to Allowed apps, all system apps can be added to the click box.
    The system apps can then be removed individually.
    Erlaubte Apps Choose application Allowed apps
     Add system apps If the selection is limited to Allowed apps, all system apps can be added to the click box.
    The system apps can then be removed individually.
    Ein­zel-App-Mo­dus: Er­laub­te Apps Choose application Allowed apps in single app mode
    Ent­fer­nen von Apps zu­las­sen    Allows the user to remove apps
    App-In­stal­la­ti­on via Con­fi­gu­ra­tor/iTu­nes zu­las­sen    Allow only a connected Mac host to install applications
    Allow automatic app downloads    Allows automatic app downloads
    App-In­stal­la­ti­on aus dem App Store zu­las­sen    Allow the user to install applications
    App Clips zu­las­sen    When this option is disabled, a user cannot add app clips and remove existing app clips on the device. Available in iOS 14.0 and later.
    Allow AirDrop    If set to false, AirDrop will be disabled
    Allow AirPrint    If set to false, AirPrint will be disabled
    Allow saving AirPrint credentials    If set to false, the storage of AirPrint credentials is disabled
    Allow AirPrint iBeacon detection    If set to false, AirPrint iBeacon detection will be disabled
    Ver­trau­ens­wür­di­ges TLS für Air­Print er­for­dern    If set to true, AirPrint enforces the trusted TLS request
    Allow change of mobile tariff    If set to false, the change of the mobile tariff will be disabled
    Allow iCloud keychain synchronization    If set to false, cloud keychain synchronization is disabled
    Allow private iCloud relay    If set to disabled, iCloud Private Relay will be disabled
    Allow eSIM changes    If set to false, the eSIM change will be disabled
    Zu­griff der Da­tei­en-App auf USB-Lauf­wer­ke zu­las­sen    If set to false, access to the files USB drive is disabled
    Allow host pairing    Allow host pairing
    notempty
    If pairing is switched off, the end device can no longer be connected to a computer via USB Please ensure that the end device always has a functioning Internet connection even without pairing
    Allow NFC    If set to false, NFC will be disabled
    Än­de­rung der Hot­spot-Ein­stel­lun­gen zu­las­sen    If set to false, the change of the personal hotspot will be disabled
    Allow VPN creation    If set to false, VPN creation will be disabled
    Kon­fi­gu­ra­ti­on von Ge­rä­ten in der Nähe zu­las­sen    Wenn aktiviert    wird die Aufforderung zur Konfiguration von neuen Geräten in der Nähe bei Annäherung aktiviert

    Dies beschleunigt Rollouts/Übertragungen, kann aber ungewollte Konto-/Einstellungsübernahmen aus nicht verwalteten Geräten ermöglichen

    Teilen von Daten
    Au­to­ma­ti­sches Aus­fül­len von Pass­wör­tern zu­las­sen    If set to false, the auto-completion of the password will be disabled
    Au­then­ti­fi­zie­rung vor au­to­ma­ti­schem Aus­fül­len er­zwin­gen    If set to true, authentication is enforced before autofilling
    Pass­wort­an­fra­gen an Ge­rä­te in der Nähe zu­las­sen    If set to false, password proximity requests are disabled
    Tei­len von Pass­wör­tern zu­las­sen    If set to false, password sharing will be disabled
    Än­de­rung von Ac­counts zu­las­sen    If inactive, account modification will be disabled.
    notempty
    This option prevents, for example, the creation of another Apple account, which could then be used to install additional apps.

    notempty
    iOS can only activate this restriction for all accounts. This also means that changing a password for an Exchange account is no longer possible.
    Än­de­rung an Find My Fri­ends zu­las­sen    If set to false, the modification will be disabled for find my friends
    Media & Entertainment
    Allow Podcasts    If set to false, podcasts will be disabled
    An­stö­ßi­ge In­hal­te zu­las­sen    Allows the user to access explicit content. When activated, the SafeSearch function is switched off by Safari.
    iMes­sa­ge zu­las­sen    Allow use of iMessage
    Ap­ple Books Store er­lau­ben    Supervised only. If disabled, iBookstore will be disabled
    Ero­tik in Ap­ple Books zu­las­sen    Supervised only. If disabled, the user will not be able to download media from the iBookstore marked as erotica
    iTu­nes Store zu­las­sen    When enabled    the iTunes Music Store is activated
    Sa­fa­ri zu­las­sen    Allows the user to use Safari
    Game Cen­ter zu­las­sen    Allow Game Center
    Hin­zu­fü­gen von Game Cen­ter-Freun­den zu­las­sen    Allow the user to add friends to the Game Center
    FaceTime zulassen    Allow Game Center
    Siri-Ob­szö­ni­tä­ten­fil­ter ak­ti­vie­ren    Enables Siri profanity filter
    Au­to­ma­ti­sches Aus­fül­len in Sa­fa­ri zu­las­sen    Wenn aktiviert    wird das automatische Ausfüllen in Safari aktiviert
    Allow modifying wallpaper    Allow changing the background image
    Ge­teil­te Al­ben zu­las­sen    Allow changing the background image
    System- und Gerätesteuerung
    Allow removal of system apps    If set to false, the removal of system apps is disabled
    Star­ten in den Wie­der­her­stel­lungs­mo­dus von nicht ge­kop­pel­ten Ge­rä­ten zu­las­sen    If set to false, unpaired external booting for recovery is disabled
    Allow restricted USB mode    If set to false, the restricted USB mode will be disabled
    Force automatic date and time    If set to true, the date and time are automatically enforced
    WLAN er­zwin­gen    If set to true, WLAN is forced only on allowed networks
    Bei­tritt nur zu WLAN-Netz­wer­ken aus Pro­fi­len    If set to true, WLAN is forced only on allowed networks
    Än­dern des Ge­rä­te­codes zu­las­sen    Allow changing the passcode
    In­stal­la­ti­on von Kon­fi­gu­ra­ti­ons­pro­fi­len durch Be­nut­zer zu­las­sen    If set to false, the user is prohibited from installing configuration profiles and certificates interactively
    Zu­rück­set­zen auf Werks­ein­stel­lun­gen zu­las­sen    If disabled, the user cannot select the "Clear all content and settings" option in Settings > General > Reset
    Än­dern der Bild­schirm­zeit-Ein­stel­lun­gen zu­las­sen    Allow configuration restrictions
    iCloud-Do­ku­men­ten­syn­chro­ni­sa­ti­on zu­las­sen    Allow document synchronization with iCloud
    Ver­zö­ger­te Soft­ware­up­dates er­zwin­gen    When active, user visibility of software updates is delayed.
    Ver­zö­ge­rung für Soft­ware­up­dates (in Ta­gen) 30 With this restriction, the administrator can specify by how many days a software or app update is delayed on the device. With this restriction, the user will not see a software update until the specified number of days after the software update release date.
    Vor­schlä­ge ak­ti­vie­ren    Allow predictive keyboard.
    Tas­ta­tur­kurz­be­feh­le ak­ti­vie­ren    Allow keyboard shortcuts.
    Auto-Kor­rek­tur ak­ti­vie­ren    Allow autocorrect.
    Recht­schreib­prü­fung ak­ti­vie­ren    Allow correction help.
    "Nach­schla­gen" ak­ti­vie­ren    Allow correction help.
    TVOS exklusiv
    Au­to­ma­ti­schen Ru­he­zu­stand ak­ti­vie­ren    If set to false, the hibernation of the device is disabled
    Au­to­ma­ti­schen Bild­schirm­scho­ner ak­ti­vie­ren    Wenn aktiviert    wird der automatische Bildschirmschoner aktiviert
    Kop­peln mit Re­mo­te App ak­ti­vie­ren    Wenn aktiviert    erlaubt es das Koppeln von Apple TV mit der Remote App oder dem Widget im Kontrollzentrum



    Close Closes the tab without applying changes
     Save Applies the changes / new creation, saves and closes the tab





    Apps

    Apps
    Profile created from portal version 1.31 onwards
    notempty
    Profile created from portal version 1.31 onwards
    notempty
    New as of 1.31
    Managing apps and web clips via profiles is outdated and no longer available. Reassigning applications to devices is now done via the menu item  Mobile Security iOS/iPadOS Apps .
    Further information can be found in the Wiki article on iOS apps
    Apps & Web clips
    Profile created before portal version 1.31
    notempty
    Profile created before portal version 1.31
    notempty
    This function is deprecated. In profiles before version 1.31, apps can be removed but not newly added. Reassigning applications to devices is now handled via the menu item  Mobile Security iOS/iPadOS Apps in the side menu. This also allows for later uninstallation of the application.
    Further information can be found in the Wiki article on iOS apps
    Caption Value Description
    Apps & Web clips
    Apps
    Securepoint VPN Client The created apps can only be deleted.
    New apps cannot be added,
    Apps are added and removed from an iOS profile via the portal page  Apps
    Web clips Securepoint Wiki [Label: SP Wiki] (https://wiki.securepoint.de) The created Web clips can only be deleted.
    New Web clips cannot be added,
    Web clips are added and removed from an iOS profile via the portal page  Apps


    App-Lock (Kiosk mode)
    App-Lock (Kiosk mode)

    The app lock activates the guided mode which limits the device to a single app. In this state - also called kiosk mode - you can control which app functions are available.
    Activate configuration   

    Show restrictions
    Hide restrictions





    1. 2. 3.
    Abb.1 Abb.2 Abb.3
    Abbildungen
    Caption Value Description
    Bundle ID Enter ID The bundle ID of the application
    notempty
    Entering an unknown bundle ID can cause problems
    Options
    Disable Touch Input    If true, the touch screen is disabled
    Disable Auto-Rotation    If active, device rotation detection is disabled
    Dis­able Vol­ume But­tons    When active, the volume keys are disabled
    Dis­able Ringer (Mute) Switch    When active, the ringtone switch is disabled
    Dis­able Sleep/Wake But­ton    When active, the sleep / wake button is disabled
    Dis­able Auto-Lock    If active, the device is not automatically set to sleep mode after an idle period
    Accessibility
    Force En­able VoiceOver    If active, voice over is enabled
    En­able Zoom    When active, zoom is enabled
    En­able In­vert­ed Col­ors    If active, invert colors is enabled
    En­able As­sis­tive­Touch    When active, AssistiveTouch is enabled
    Force En­able Speak Se­lec­tion    Wenn aktiv    wird die Aktivierung der Vorlese-Funktion erzwungen
    Force En­able Mono Au­dio    When active, mono audio is enabled
    Force En­able Voice Con­trol    If active, the language selection is enabled.
    User Enabled Options
    Al­low VoiceOver    If active, VoiceOver customization is allowed
    Al­low Zoom    If active, the zoom setting is allowed
    Al­low In­vert­ed Col­ors    If active, the colors invert setting is allowed
    Al­low As­sis­tive­Touch    If active, AssistiveTouch customization is allowed
    Al­low Voice Con­trol    Wenn aktiv    wird die Benutzersteuerung für Sprachsteuerung zugelassen



    Close Closes the tab without applying changes
     Save Applies the changes / new creation, saves and closes the tab




    Home screen layout

    Home screen layout


    Caption Value Description
    Menu item Home Screen Layout: Select template
    Enable home screen layout    After activation, changes can be made to the home screen layout
    Select type Use a predefined layout Uses an already existing home screen layout
    Create an individual home screen layout Creates a profile specific layout
    Select layout
    Only for Use predefined layout
    Test layout Displays a selection of predefined layouts under  Home screen layouts.

    Only for Create an individual home screen layout:
    Menu item Home Screen Layout: Profile-specific layout
    Type Application Applications from the Apple Appstore'
    System application Provides a list of Apple system applications on the device as a selection
    Web clip Provides a list of apps created as Web clips as a selection
    Folder Adds a folder.
    Apps can then be moved into it via drag'n drop.
    Once the maximum number of apps that can be added to a page is reached, the folder can be configured by clicking the gear icon in the upper left corner and adding another page with +.
    Choose app
    Only for the type Application and System application
    Choose app
    • For System apps, an app can be selected from the drop-down menu
    • For Applications at least 2 characters must be entered to perform a search in the app store
    Web clip
    Only for the type Web clip
    Choose a web clip List of Web Clips
    Name
    Only for the type Folder
    Name Name of the folder on the home screen
    Add Adds the selected element to the last page of the home screen
    The elements can be subsequently moved to other areas
    Add all system applications
    Only for the type System application
    Adds the selected element to the last page of the home screen
    The elements can be subsequently moved to other areas
    Add all apps
    Only for the type Application
    Adds all apps from the   Apps menu or apps with  VPP licenses to the last page of the homescreen
    The elements can be subsequently moved to other areas



    Close Closes the tab without applying changes
     Save Applies the changes / new creation, saves and closes the tab






    Networks

    Networks

    In this section, access profiles for WiFi networks can be configured and pushed to the device.

    Network configuration
    Caption Value Description
    Network configurations
    Network configurations  Add configuration Network configuration
    Name Name Name of the configuration
    Type WiFi Configuration type (WiFi predefined)
    Wifi
    SSID SSID The SSID of the network
    Security Security level of the network key
    None No security
    WEP-PSK Insecure
    WPA-PSK Secure
    Password Password Password of the account for the server
    Hidden SSID    When activated   , the network's SSID is hidden
    Autoconnect    When activated   , the device automatically connects to the network
    Deactivate MAC randomisation    When activated   , the devices always identify themselves with the same MAC address in a network. Cannot be changed by the user.
    This function also displays a data protection warning in the settings that the network has limited data protection.
    This value is only locked if the profile is installed via an MDM.
    If the value is set with the Apple Configurator, for example, it can be changed by the user.
    EAP-Client / WPA2 Enterprise
    Use EAP Client    When activated   , the EAP client, the WPA2 Enterprise, can be used
    Available options for the EAP type EAP-AKA. Additional options will be available for other EAP types
    EAP Types Select EAP Types The EAP type is selected. Several types can be selected.
    The choices are:
    Payload Certificate Anchor UUID
        The certificate that is handed to the server by the client as authentication when logging on to the WLAN.
    Apple: An array of the UUID of a certificate payload to trust for authentication

    notempty
    New as of: 2.7
    The user certificate $user_cert$ can be used
    System Mode Credentials Source     The server for the system mode credentials
    Use Open Directory credentials    When activated    logging in through Open Directory is possible
    Allow two-factor authentication    When activated   , two-factor authentication is possible
    Trusted certificates
        The certificates that are to be trusted are entered.
    These certificates must first be stored in the  Mobile Security  Certificate
    notempty
    New as of: 2.7
    The user certificate $user_cert$ can be used
    Trusted server names     The names of the servers that are to be trusted are entered
    Provision PAC    When activated    PAC will be provided
    Provision anonymously
    Displayed when Provision PAC is activated.
       When activated    PAC will be provided anonymously
    Use existing PAC    When activated    existing PAC will be used
    One time user password    If activated   , the user will be prompted to enter the password each time they connect
    Outer Identity     A name that hides the user's true name
    Max. TLS Version 1.2
    default
    The maximum TLS version is selected.
    The choice is:
    • 1.0
    • 1.1
    • 1.2
    Min. TLS Version 1.0
    default
    The minimum TLS version is selected.
    The choice is:
    • 1.0
    • 1.1
    • 1.2
    Username     Username of the account for the server
    Password     Password of the account for the server
    EAP SIM Number Of RANDs 3
    default
    The number of EAP SIMs of the RANDs is selected
    One time user password    If activated   , the user will be prompted to enter the password each time they connect
    Username     Username of the account for the server
    Password     Password of the account for the server
    One time user password    If activated   , the user will be prompted to enter the password each time they connect
    Outer Identity     A name that hides the user's true name
    Max. TLS Version 1.2
    default
    The maximum TLS version is selected.
    The choice is:
    • 1.0
    • 1.1
    • 1.2
    Min. TLS Version 1.0
    default
    The minimum TLS version is selected.
    The choice is:
    • 1.0
    • 1.1
    • 1.2
    Username     Username of the account for the server
    Password     Password of the account for the server
    Max. TLS Version 1.2
    default
    The maximum TLS version is selected.
    The choice is:
    • 1.0
    • 1.1
    • 1.2
    Min. TLS Version 1.0
    default
    The minimum TLS version is selected.
    The choice is:
    • 1.0
    • 1.1
    • 1.2
    One time user password    If activated   , the user will be prompted to enter the password each time they connect
    Outer Identity     A name that hides the user's true name
    Max. TLS Version 1.2
    default
    The maximum TLS version is selected.
    The choice is:
    • 1.0
    • 1.1
    • 1.2
    Min. TLS Version 1.0
    default
    The minimum TLS version is selected.
    The choice is:
    • 1.0
    • 1.1
    • 1.2
    TTLS Inner Authentication MSCHAPv2
    default
    The inner authentication of TTLS is selected.
    The choices are:
    • PAP
    • EAP
    • CHAP
    • MSCHAP
    • MSCHAPv2
    Username     Username of the account for the server
    Password     Password of the account for the server
    Global HTTP proxy
    A Global HTTP proxy can be configured, for example, if devices are permanently on the same network and a local proxy is to be used on the device.
    Especially recommended for devices that only have an MDM license. These can then use, for example, the protection functions of a Securepoint UTM with web filter, etc.
    Global HTTP proxy configuration
    Use global HTTP proxy    When activated    the global HTTP proxy is used
    Type Manual
    Automatic
    For a manual proxy type, the profile contains the proxy server address, including the port, and optionally a user name and password. For an auto proxy type, you can enter a PAC URL.
    Allow captive login   
    Username Username The username used to authenticate to the proxy server
    Password Password The password used for authentication to the proxy server
    Server Server The network address of the proxy server
    Server port 8080 The port used to connect to the proxy server



    Close Closes the tab without applying changes
     Save Applies the changes / new creation, saves and closes the tab





    Certificates

    Certificates

    Certificates are required, for example, to retrieve emails from an Exchange server with https or to confirm the authenticity of self-signed apps.

    Caption Values Description
    Certificates
    Activate certificates    After activation   , certificates can be added
    Certificates
    Select certificates Selection of certificates, Base-64-encoded X.509 or PKCS#12, imported in the  Mobile Security  Certificate menu.
    Further information can be found in the Wiki article Certificates.
    notempty
    New as of: 2.7
    The user certificate $user_cert$ can be used



    Close Closes the tab without applying changes
     Save Applies the changes / new creation, saves and closes the tab































    Apple TV

    Apple TV
    Conference room display
    Caption Value Description
    Apple TV menu item
    Activate conference room display    When enabled   , the conference room display mode locks the Apple TV in this mode to prevent other types of usage
    Message Type message The custom message displayed on the screen in the conference room display mode

    TV-remote
    Caption Value Description
    Activate TV-remote    Activating    enables the remote configuration of the Apple TV
    Allowed remotes  Add remote Add remotes
    Remote devices ID MAC address Either the MAC address of a device is entered, or a configured device is selected from the drop-down menu
    Allowed TVs  Add TV Add TVs
    Name Name of the TV The name of the TV
    TV ID MAC address Either the MAC address of a device is entered, or a configured device is selected from the drop-down menu

    AirPlay-Security
    Caption Value Description
    Activate AirPlay-Security    When    is enabled, the AirPlay security settings are activated
    Access type
    Any The access policy for AirPlay:
    Allows connections both via Ethernet/WiFi and Apple Wireless Direct Link
    WiFi only Allows connections only from devices on the same Ethernet/WiFi network as Apple TV
    Security level
    Passcode once The AirPlay security policy:
    Requires a screen passcode for the first connection from a device. Subsequent connections from the same device are not prompted
    Always passcode Requires a screen passcode for each AirPlay connection
    Password Requires a passphrase as specified in the password key



    Close Closes the tab without applying changes
     Save Applies the changes / new creation, saves and closes the tab