MDM Flash Flashcards
(50 cards)
Where are MDM configuration profiles located on iPhone/iPad?
Settings > General > VPN & Device Management
Where are MDM configuration profiles located on Mac?
System Settings > General > Device Management
What file extension do configuration profiles use?
.mobileconfig (XML files)
What are the three types of MDM enrollment?
User Enrollment, Device Enrollment, Automated Device Enrollment
Which enrollment type provides the most management capabilities?
Automated Device Enrollment (devices are both managed and supervised)
What’s the difference between Enrollment Profile and Configuration Profile?
Enrollment Profile: Contains identity certificates to associate device with MDM. Configuration Profile: Contains payloads for settings/restrictions
How long can MDM defer software updates on supervised devices?
1-90 days for supervised devices
Which Setup Assistant pane CANNOT be skipped on devices in Apple Business Manager?
Remote Management pane
What happens when MDM skips a Setup Assistant pane?
Device uses more privacy-preserving default settings
Which devices can be set up without user interaction via Ethernet?
Mac and Apple TV
What’s required for macOS 13+ Setup Assistant on Apple Business Manager devices?
Internet connection
Do Rapid Security Responses follow MDM software update deferrals?
No, they don’t follow deferral rules and can be managed separately
What happens when a user unenrolls a personal device from MDM?
All managed apps and their data may be removed (depends on MDM admin settings)
Which Apple devices have built-in MDM framework support?
iPhone, iPad, Mac, Apple Watch, Apple Vision Pro, Apple TV
What are the two types of configuration profiles?
Device profiles (affect entire device) and User profiles (specific users)
What’s the most secure EAP protocol for enterprise Wi-Fi via MDM?
EAP-TLS (uses digital certificates for authentication)
What are examples of MDM payload types?
Wi-Fi networks, passcode policies, FileVault settings, printer configurations, software update restrictions
What are the three main MDM capabilities?
Update software/device settings, monitor compliance with policies, remotely wipe or lock devices
Does the presence of a configuration profile always mean MDM management?
No, you must check specifically for an MDM enrollment profile
What’s needed to reenroll a device that was unenrolled from MDM?
IT administrator assistance is typically required
What are available EAP protocols for enterprise Wi-Fi in MDM?
EAP-TLS, EAP-TTLS, EAP-PEAP, EAP-FAST, EAP-MSCHAPv2
What can MDM control regarding automatic updates?
Download control (user choice/off/on) and Installation control (user choice/off/on)
What’s the recommended cadence options for iOS/iPadOS updates via MDM?
iOS 17 only, iOS 18 only, or user choice
What can MDM enforce regarding software updates?
Set deadline for required updates regardless of configured deferrals