MDM Flash Flashcards

(50 cards)

1
Q

Where are MDM configuration profiles located on iPhone/iPad?

A

Settings > General > VPN & Device Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Where are MDM configuration profiles located on Mac?

A

System Settings > General > Device Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What file extension do configuration profiles use?

A

.mobileconfig (XML files)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the three types of MDM enrollment?

A

User Enrollment, Device Enrollment, Automated Device Enrollment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which enrollment type provides the most management capabilities?

A

Automated Device Enrollment (devices are both managed and supervised)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What’s the difference between Enrollment Profile and Configuration Profile?

A

Enrollment Profile: Contains identity certificates to associate device with MDM. Configuration Profile: Contains payloads for settings/restrictions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How long can MDM defer software updates on supervised devices?

A

1-90 days for supervised devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which Setup Assistant pane CANNOT be skipped on devices in Apple Business Manager?

A

Remote Management pane

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What happens when MDM skips a Setup Assistant pane?

A

Device uses more privacy-preserving default settings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which devices can be set up without user interaction via Ethernet?

A

Mac and Apple TV

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What’s required for macOS 13+ Setup Assistant on Apple Business Manager devices?

A

Internet connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Do Rapid Security Responses follow MDM software update deferrals?

A

No, they don’t follow deferral rules and can be managed separately

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What happens when a user unenrolls a personal device from MDM?

A

All managed apps and their data may be removed (depends on MDM admin settings)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which Apple devices have built-in MDM framework support?

A

iPhone, iPad, Mac, Apple Watch, Apple Vision Pro, Apple TV

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the two types of configuration profiles?

A

Device profiles (affect entire device) and User profiles (specific users)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What’s the most secure EAP protocol for enterprise Wi-Fi via MDM?

A

EAP-TLS (uses digital certificates for authentication)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What are examples of MDM payload types?

A

Wi-Fi networks, passcode policies, FileVault settings, printer configurations, software update restrictions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the three main MDM capabilities?

A

Update software/device settings, monitor compliance with policies, remotely wipe or lock devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Does the presence of a configuration profile always mean MDM management?

A

No, you must check specifically for an MDM enrollment profile

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What’s needed to reenroll a device that was unenrolled from MDM?

A

IT administrator assistance is typically required

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What are available EAP protocols for enterprise Wi-Fi in MDM?

A

EAP-TLS, EAP-TTLS, EAP-PEAP, EAP-FAST, EAP-MSCHAPv2

22
Q

What can MDM control regarding automatic updates?

A

Download control (user choice/off/on) and Installation control (user choice/off/on)

23
Q

What’s the recommended cadence options for iOS/iPadOS updates via MDM?

A

iOS 17 only, iOS 18 only, or user choice

24
Q

What can MDM enforce regarding software updates?

A

Set deadline for required updates regardless of configured deferrals

25
What happens when you remove a configuration profile?
Removes all associated settings, apps, and data
26
What's supervision in MDM context?
Organization-owned devices with enhanced management control beyond standard managed devices
27
What can Apple Configurator do for MDM?
Back up and restore multiple devices, deploy apps/settings/configurations, create blueprints for deployment
28
What's a blueprint in Apple Configurator?
Combination of settings, apps, profiles, and identity information for device deployment
29
Can Apple Configurator restore backups between different device types?
No, supervised device backups can only be restored to other supervised devices
30
What administrative roles can work with Managed Apple Accounts?
Administrator, Site Manager, People Manager, Device Enrollment Manager, Content Manager, Instructor, Staff, Student
31
What happens to organizational data encryption keys when a personal device unenrolls from MDM?
Separate encryption keys are destroyed during MDM unenrollment, ensuring organizational data becomes inaccessible. This cryptographic separation protects against data leakage after unenrollment.
32
What are the key management differences between User Enrollment and Automated Device Enrollment?
User Enrollment: Limited to work apps/data, user retains control. Automated Device Enrollment: Full device control, supervised status, can skip Setup Assistant screens, comprehensive restrictions.
33
If MDM sets a 60-day software update deferral but then enforces an update with a deadline, which takes precedence?
The enforcement deadline overrides deferrals. MDM can set deadlines for required updates regardless of configured deferrals, allowing urgent security patches while maintaining normal update management.
34
What operational challenge does certificate expiration create in EAP-TLS Wi-Fi deployments via MDM?
Expired certificates break Wi-Fi authentication. Organizations must track expiration dates, coordinate certificate renewal, and update MDM payloads to maintain network access.
35
Can supervision status be transferred between devices using Apple Configurator backups?
No, supervision status cannot be transferred via backups. Supervision is determined by enrollment method (Automated Device Enrollment) and Apple Business Manager registration, not backup data.
36
Why does skipping Setup Assistant panes result in privacy-preserving defaults rather than leaving settings unconfigured?
Apple's security-by-default design ensures that when organizations skip user choice screens, the system automatically selects the most privacy-protective option to prevent security gaps.
37
Why don't Rapid Security Responses follow normal MDM deferral rules?
RSRs address critical security vulnerabilities requiring immediate patching. They bypass deferrals to ensure critical security patches deploy rapidly regardless of normal update policies.
38
What's the functional relationship between Enrollment Profiles and Configuration Profiles?
Enrollment Profiles establish the trust relationship (certificates, MDM server association). Configuration Profiles use that trust to deploy settings. Enrollment Profile authenticates the device to receive Configuration Profiles.
39
Why do iPhone/iPad have single software deferral settings while Mac has separate controls?
iOS/iPadOS has simpler update categories. macOS has complex update types (OS updates, upgrades, Safari, XProtect, system files) requiring granular control for enterprise environments.
40
What are the advantages of using blueprints in Apple Configurator versus individual profile deployment?
Blueprints ensure consistent deployments, reduce configuration errors, provide standardized security policies, and enable faster deployment. Individual profiles offer more device-specific customization flexibility.
41
Why can only Mac and Apple TV achieve zero-touch deployment via Ethernet?
Mac and Apple TV support pre-boot network capabilities and can download/apply configurations without user interaction. iPhone/iPad require user interaction for initial network setup and trust establishment.
42
Why is EAP-TLS considered the most secure EAP method for enterprise Wi-Fi?
EAP-TLS uses mutual certificate authentication (both client and server verify identity) and is immune to password attacks. Other methods like PEAP and TTLS rely on passwords which can be compromised.
43
Why might a configuration profile be present on a device that isn't actively MDM managed?
Configuration profiles can be manually installed, remain after unenrollment, or be inactive. Active MDM requires an MDM enrollment profile with valid certificates and active server communication.
44
What security benefit do different administrative roles provide in Apple Business Manager?
Role separation (Administrator, Site Manager, People Manager, etc.) implements least privilege access. Each role has specific permissions, preventing single points of failure and reducing security risks.
45
What's the difference between device-level and user-level configuration profiles?
Device profiles affect all users and persist through user changes, ensuring consistent policies. User profiles are user-specific and may not apply when different users access the device.
46
What protects organizational data when personal devices unenroll from MDM?
Managed apps and data use separate encryption keys that are destroyed during unenrollment. This ensures organizational data becomes permanently inaccessible after unenrollment.
47
Why does Apple require internet connectivity for Setup Assistant on Apple Business Manager devices with macOS 13+?
Internet connectivity enables device identity verification with Apple servers, certificate validation, and secure enrollment profile download to prevent unauthorized device enrollment.
48
How does MDM compliance monitoring differ from configuration deployment?
Compliance monitoring requires two-way communication - not just pushing settings but actively checking device state, comparing against policies, and reporting violations in real-time.
49
What additional capabilities does device supervision provide beyond standard MDM management?
Supervision enables Setup Assistant control, enhanced restrictions, and deeper system access through Apple's supervision framework. These require special privileges only granted to supervised devices.
50
What advantage does having built-in MDM frameworks across all Apple devices provide?
Universal MDM frameworks enable consistent management policies across device types, simplified administration tools, and unified security models, reducing complexity while improving security.