Configurations & Accounts



Configurations allow an administrator to set up accounts, services, and other functionalities on devices. Some configurations can be shared between device groups, some are linked to just one device group, and others are created as accounts for individual devices.

Available Profiles


SimpleMDM supports many configurations, including:

Configuration Name Allows you to define...
Accessibility settings that would typically be found under System Settings > Accessibility on macOS.
App Restrictions an app allow list or block list to hide undesired apps from iOS. Requires supervision.
AirPlay Destination an available destination to stream audio and video to.
AirPrint Printer an AirPrint-compatible printer for devices to utilize.
APN an Access Point Name. This is also called a Cellular payload. Sometimes used in advanced deployments.
CalDAV a WebDAV or CalDAV calendar account.
CardDAV a WebDAV or CardDAV contacts account.
Certificates deploy custom certificates to devices.
Email an Exchange, IMAP, or POP-based email account.
Extensible Single Sign On Kerberos settings to configure SSO for apps and websites via Kerberos.
Extensible Single Sign On settings to configure SSO for apps and websites for identity providers that support the extension.
FileVault requirements around using Filevault full disk encryption. Also supports escrowing and rotating personal recovery keys.
Firewall Firewall settings on macOS devices.
Firmware Password Firmware password settings and saves password to SimpleMDM.
Gatekeeper Policy settings for Gatekeeper (as found under System Settings > Privacy & Security on macOS).
Global HTTP Proxy an HTTP proxy that all web traffic on the device will be forced to pass through. Requires supervision.
Google Account a Google account to use for email, contacts, and calendaring.
Home Screen Layout an icon and folder layout on the iOS home screen and dock. Requires supervision.
Kernel Extension Policy approvals for specific kernel extensions on macOS.
LDAP an LDAP account, typically used to populate Contacts in iOS.
Login and Background Item Management settings for Login Items (as found under System Settings > Login Items on macOS).
Loginwindow controls for the login window screen on macOS.
Notification Settings notification preferences for applications.
Passcode Policy complexity requirements for passcodes on iOS and macOS, as well as screen lock settings.
Printing configurations for printers on macOS.
Privacy Preferences accessibility permissions for specific applications on macOS.
Recovery Lock Password settings to enable a Recovery Lock password on macOS.
Restriction a list of iOS functionalities that should be disabled.
Single App Lock an app that is forced to run at all times on a device. Requires supervision.
Single Sign-On Account a Kerberos account to be used to sign into websites and apps.
Software Update Policy for iOS settings to automatically download/install iOS and tvOS updates. Requires supervision.
Software Update Policy for macOS settings to configure Software Update preferences and automatically download/install macOS updates.
Subscribed Calendar a calendar subscription. These appear in the device's calendar list.
System Extensions Policy settings to allow specific System Extensions to automatically load on macOS.
VPN a VPN account, such as L2TP, PPTP, Cisco, or other popular technologies.
Wallpaper an image to appear in the background of the home and/or lock screen. Requires supervision.
Web Clip an icon on the home screen that acts as a shortcut to a website.
Web Content Filter a website whitelist or blacklist to control web access in the Safari app. Requires supervision.
Wireless Network a WiFi network that the device can access.

This is not intended to be a comprehensive list. Refer to the SimpleMDM interface for the latest capabilities.

Custom Configuration Profiles


Sometimes an organization needs a feature available in Apple Configurator that isn't supported by SimpleMDM. Or, an organization may have previously built configurations in Apple Configurator that they are not ready to rebuild in SimpleMDM. In these cases, SimpleMDM allows configurations that have been exported by Apple Configurator to be uploaded and distributed to enrolled devices.

To upload a custom configuration to SimpleMDM, follow the instructions below for creating a configuration and choose "Custom Configuration Profile" as the configuration type.

Creating Profiles


Most configurations require first creating a shared configuration profile and then assigning it to device groups. To create a shared configuration profile:

  1. Click Profiles under Configs in the left-side menu.
  2. Click "Create Profile"
  3. Click the type of profile you want to create (for example, "App Restrictions").
  4. Configure the profile settings as needed.

Once you have created the profile, it will be available for assignment via the "Profiles" tab on both the Group Details page and the Device Details page.

Assigning Configuration Profiles to Device Groups


A shared configuration profile will not be pushed to any of your devices until you have assigned it to at least once device group. To assign a configuration to a device group:

  1. Click "Groups" on the left-hand side of the screen.
  2. Click the name of the device group you would like to edit.
  3. Click the "Profiles" tab.
  4. Click "Assign Profile".
  5. Locate the profile that you want to assign and click "Assign".

Once you click "Assign", the profile is automatically pushed to the devices in the device group.

Creating and Assigning Accounts & Device-Specific Profiles


Some configurations, like email accounts, can also be assigned directly to devices instead of device groups. To create an account for a device:

  1. Click "Devices" on the left hand side of the screen.
  2. Click on the name of the device you would like to create an account on.
  3. Click the "Profiles" tab.
  4. Click the "Assign Profile" button in the upper right hand side of the screen.
  5. To assign a profile that has already been created, click "Assign" next to the profile name. Repeat these steps to add additional profiles to the device. To create a new profile or account, click "Create Profile".
  6. If you clicked "Create Profile", select the profile type you'd like to create, fill out the settings, then click "Save".

When you click "Save", the configuration is automatically pushed to the device.

Assigning profiles to Assignment Groups


SimpleMDM now allows profiles to be assigned to devices using Assignment Groups. Unlike Device Groups, a device can be a member of multiple Assignment Groups at once. This can be useful when your deployment requires devices to inherit profiles from multiple groups at the same time.

To assign a profile via an Assignment Group:

  1. Navigate to the Assignments page.
  2. Click "Create Assignment Group" and give it a name.
  3. Make sure "Type" is set to "Standard". Only standard assignment groups support profile assignments.
  4. Optionally set the Profile Priority level*.
  5. Click Save.
  6. Click the new assignment group and use the search bar to search for the profile name you want to add. When it appears in the dropdown list, click the profile name to add it to the assignment group. Repeat this process as needed for additional profiles.
  7. Add any devices or device groups that you want to receive these configuration profiles to the assignment group.
  8. Click "Actions" and select "Sync profiles" to push the profiles to devices that are members of the assignment group right away. Devices that join a group via enrollment or group re-assignment will automatically receive the assigned profiles.**

*Notes on Profile Priority: This setting allows you to control which profile takes priority when conflicting profiles are assigned to the same device via multiple assignment groups. 0 = highest priority, 10 = lowest priority. Priority only impacts other profiles assigned via Assignment Groups. The order of precedence for all profile assignments is: Device (Direct) > Device Group > Assignment Group (Higher priority) > Assignment Group (Lower priority).

**Notes on Syncing Profiles: New profiles assigned via assignment groups will be installed on devices under the following conditions:

  • When an admin selects Actions > Sync Profiles
  • When a device enrolls into or is assigned to the assignment group
  • When a change is made to one of the assigned profile (via the profile settings page) and saved (this triggers a configuration push to all devices with the profile assigned)
  • If another action has not already occurred to trigger the profile sync, devices will receive the profile assignment changes the next time they check in with MDM (which happens approximately every hour automatically, assuming devices are online and responding to APNS)

 

Viewing and Troubleshooting Profiles Assigned to a Device

To view the profiles assigned to a device:

  1. Navigate to the Devices list and click the device.
  2. Click the "Profiles" tab.

This tab will display a list of profile names assigned to the device, along with the following information:

  • Type: the profile type.
  • Assigned Via: where the profile is assigned - this will either be: "Direct" if assigned directly to the individual device, or will display the Device Group or Assignment Group name that is being used to assign the profile to the device.
  • Status: the status of the profile installation. Possible statuses:
    • "Up to date": the profile is installed with no pending changes.
    • "Pending": means it is installed but there are changes pending.
    • "Unknown": means that it is not actually a profile but a command, therefore there is not installation status.
    • Yellow warning symbol: indicates that there is an error - hover over the symbol to receive more information. Some examples of common errors are:
      • "This profile conflicts with another profile assigned to this device and will not be installed."
      • "This type of profile is not compatible with this device."
Was this article helpful?
Still have a question or want to share what you have learned? Visit our Community Discord to get help and collaborate with others.