In Addigy, you can create or Import MDM Configurations to enforce settings on macOS, iOS, and tvOS Devices. The following links to our docs page regarding MDM Profiles (aka MDM Configurations): https://docs.addigy.com/mdm/MDM_Configurations/#macos-mdm-configurations
Note: This will require your device to be enrolled via MDM.
Creating an MDM Profile
To create an MDM Configuration, navigate to the Catalog page and then select the MDM Profiles tab:
Select "New" within the MDM Profiles Pane, and you will be able to select your desired MDM Configuration Payloads:
Once you select your desired MDM profile, setup your desired settings in your MDM Configuration and press "Create Profile":
With this item created in your Catalog, you can now deploy this using the GoLive page to test this on an individual device and then add it to a Policy to deploy this item in bulk.
Modular MDM Profiles
Our MDM Profiles are modular in the sense that you can completely omit settings in MDM Profiles (known as MDM keys) from your profiles, which in turn allows end-users to edit those settings on their devices.
In my below screenshot, I include and allow the iCloud drive. I also include but disable the iCloud keychain. Lastly, I completely omit the iCloud photo library, which allows the end-user to change that setting.
Importing an MDM Profile
To Import an MDM Configuration, navigate to the Catalog page and then select the MDM Profiles tab:
Select "Import" to bring up the Import UI
In the Import UI you can select the profile with a drag and drop action or use the file picker by clicking on the upload icon. Once the file is selected it will be displayed in the table under the import button showing what payloads are to be imported.
To complete the import select "Import".
Supported payload types are (for others not listed use the Custom Profile function):
Profile | Payload |
ACME |
com.apple.security.acme |
SCEP |
com.apple.security.scep |
DNS Settings |
com.apple.dnsSettings.managed |
Content Caching |
com.apple.AssetCache.managed |
Wi-Fi |
com.apple.wifi.managed |
Time Machine |
com.apple.MCX.TimeMachine |
Lock Screen Message |
com.apple.shareddeviceconfiguration |
Passcode |
com.apple.mobiledevice.passwordpolicy |
Printing |
com.apple.mcxprinting |
Single App Lock |
com.apple.app.lock |
Network Usage |
com.apple.networkusagerules |
Notifications |
com.apple.notificationsettings |
Web Content Filter |
com.apple.webcontent-filter |
Restrictions |
com.apple.applicationaccess |
Kernel Extension Policy |
com.apple.syspolicy.kernel-extension-policy |
App Store |
com.apple.appstore |
Login Items |
com.apple.loginitems.managed |
Finder |
com.apple.finder |
Dock |
com.apple.dock |
Privacy Preferences Policy Control |
com.apple.TCC.configuration-profile-policy |
Restrictions |
com.apple.gamed |
Restrictions |
com.apple.desktop |
Screen Saver (Device) |
com.apple.screensaver |
Screen Saver (User) |
com.apple.screensaver.user |
System Preferences |
com.apple.systempreferences |
Software Update |
com.apple.softwareupdate |
Associated Domains |
com.apple.associated-domains |
VPN |
com.apple.vpn.managed |
Web Clip |
com.apple.webClip.managed |
System Extension |
com.apple.system-extension-policy |
AirPlay |
com.apple.airplay |
Extensible SSO |
com.apple.extensiblesso |
Service Management |
com.apple.servicemanagement |
Relay |
com.apple.relay.managed |
Exporting an MDM Profile
To Export an MDM Configuration, navigate to the Catalog page and then select the MDM Profiles tab:
Next to a given profile select the Actions ellipsis and select the desired download option: