Training profiles can be set using MDM

Apple Mobile Device Management Protocol Link on page 44 below

Third-party enterprise applications require provisioning profiles to run them. You can use MDM to deliver up-to-date versions of these profiles so that users do not have to manually install these profiles, replace profiles as they expire, and so on. To do this, deliver training profiles via MDM instead of distributing them through the corporate web portal or bundled with the application.

Does this mean that I have to remove or untie the embedded .mobileprovision from the application before installing?

Or does that mean

Installing a provisioning profile through an MDM server separately before installing the application?

If the answer is the first, how can I remove the built-in .mobileprovision without violating the application. If the answer is second, is the application subsequently updated, starting the profile set by the MDM server?

+4
source share
1 answer

Second. The MDM server installs provisioning profiles on the device before installing the application. This is usually part of the “device setup” using MDM.

Installing or updating the application after this point will be done through MDM, so everything will remain complicated.

Updated training profiles are laid out on MDM (developer / administrator), then the MDM application on the user device notifies the user of the update. They press the refresh button, and new profiles are downloaded and installed.

EDIT 3/12/14: Apple introduced the Device Registration Program (DEP), which now allows you to install “without touch” MDM provisioning profiles, configure controls, and silently install applications without ever taking the device out of the box. The system is based on:

  • A company account buys all devices (Apple maintains a list of serial numbers belonging to the company / account).
  • Apple says MDM has permission to make changes.
  • The company associates MDM with Apple.
  • Now MDM sends requests to Apple, which sends requests to the device.

This will allow us to only connect the devices that we bought. There are ways to “switch” ownership of devices / serial numbers that they did not all buy in the same account.

+2
source

All Articles