Contents
- Management of mobile devices
- Managing Android devices
- Managing iOS MDM devices
- Signing device management profiles with a certificate
- Adding a configuration profile
- Installing a configuration profile on a device
- Removing a configuration profile from a device
- Configuring managed apps
- Installing an app on a mobile device
- Updating an app installed on a device
- Removing an app from a device
- Configuring roaming on an iOS MDM mobile device
- Viewing information about an iOS MDM device
- Disconnecting an iOS MDM device from management
- Configuring kiosk mode for iOS MDM devices
Management of mobile devices
This section contains information about how to remotely manage mobile devices in Kaspersky Security Center Web Console.
Managing Android devices
Kaspersky Security Center Web Console lets you manage Android devices in the following ways:
- Centrally manage devices by using commands.
- View information about the settings for management of Android devices.
- Install apps by using mobile app packages.
- Disconnect Android devices from management.
Corporate devices
This section contains information about managing the settings of corporate Android devices. For information about installing Kaspersky Endpoint Security for Android on corporate devices, see here.
Restricting Android features on devices
These settings apply to corporate devices.
You can restrict Android operating system features on corporate devices. For example, you can restrict factory reset, changing credentials, use of Google Play and Google Chrome, file transfer over USB, changing location settings, and management of system updates. You can also restrict operating system features on personal devices and devices with a corporate container.
To restrict Android features:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select Android and go to the Restrictions section.
- On the Device feature restrictions card, click Settings.
The Device feature restrictions window opens.
- Enable the settings using the Device feature restrictions toggle switch.
- Enable device feature restrictions using toggle switches on the corresponding tabs and select the required restrictions.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with Kaspersky Security Center.
Restrict device features
On the General tab, you can enable or disable the following features.
- Features in the Data loss protection section:
- Features in the Calls and SMS section:
- Features in the Location services section:
- Features in the Keyguard section:
- Features in the Users and accounts section:
Restrict app features
On the Apps tab, you can enable or disable the following features.
- Features in the General section:
- Features in the Google apps section:
- Features in the Camera section:
- Granting runtime permissions for apps
Restrict storage features
On the Storage tab, in the General section, you can enable or disable the following features.
- Prohibit debugging features
- Prohibit mounting physical external media
- Prohibit file transfer over USB
- Prohibit backup service
Restrict network features
On the Network tab, you can enable or disable the following features.
- Features in the General section:
- Features in the Wi-Fi section:
- Features in the Bluetooth section:
- Features in the Mobile networks section:
Additional restrictions
On the Additional settings tab, you can enable or disable the following features.
- Features in the Language, date, and time section:
- Features in the Display section:
- Features in the Screen on section:
- Features in the Microphone section:
- Features in the Volume section:
Restrict system updates
Management of update settings on mobile devices is vendor-specific. On some Android devices, the restriction on manual installation of operating system updates may not work correct.
On the OS update tab, you can configure the following settings.
- In the Update mode section:
- In the Freeze periods section:
Configuring kiosk mode for Android devices
These settings apply to corporate devices.
Kiosk mode is a Kaspersky Endpoint Security for Android feature that lets you limit the apps available to a device user to a single app or a set of multiple apps. You can also efficiently manage some device settings.
Kiosk mode does not affect the work of the Kaspersky Endpoint Security for Android app. It runs in the background, shows notifications, and can be updated.
Types of kiosk modes
The following types of kiosk mode are available in Kaspersky Endpoint Security:
- Single-app mode
Kiosk mode with only a single app. In this mode, a device user can open only the one app that is allowed on the device and specified in the kiosk mode settings. If the app that you want to add to kiosk mode is not installed on the device, kiosk mode activates after the app is installed.
On Android 9 or later, the app launches directly in kiosk mode.
On Android 8 or earlier, the specified app must support kiosk mode functionality and call the
startLockTask()
method itself to launch the app. - Multi-app mode
Kiosk mode with multiple apps. In this mode, a device user can open only the set of apps that are allowed on the device and specified in the kiosk mode settings.
Before you configure kiosk mode
Before you configure kiosk mode, do the following:
- Before specifying the apps that are allowed to be run on the device in kiosk mode, you first need to select the Install action for these apps on the App management tab of the App Control card. Then, they will appear in the App package list of the kiosk mode.
- Before activating kiosk mode, we recommend that you prohibit starting Google Assistant by enabling the corresponding restriction in Assets (Devices) → Policies & profiles → Application settings → Android → Restrictions → Device feature restrictions → Apps → Prohibit Google Assistant. Otherwise, Google Assistant starts in kiosk mode and allows non-trusted apps to be opened.
Open the kiosk mode settings
To open the kiosk mode settings:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select Android and go to the Restrictions section.
- On the Kiosk mode card, click Settings.
The Kiosk mode window opens.
Configure single-app mode
To configure single-app mode:
- Enable the settings using the Kiosk mode toggle switch.
- In the Operating mode drop-down list, select Single-app mode.
- In the App package drop-down list, select an app package with the app that is allowed to be run on the device.
- Specify any required restrictions. For available restrictions, see the "Kiosk mode restrictions" section below.
- Select the Allow navigation to trusted apps check box if you want to add other apps that a device user can navigate to. For more details, see the "Add additional apps" section below.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with Kaspersky Security Center.
Configure multi-app mode
To configure multi-app mode:
- Enable the settings using the Kiosk mode toggle switch.
- In the Operating mode drop-down list, select Multi-app mode.
- Click Add package and select the apps that are allowed to be run on the device.
- Specify any required restrictions. For available restrictions, see the "Kiosk mode restrictions" section below.
- Select the Allow navigation to trusted apps check box if you want to add other apps that a device user can navigate to. For more details, see the "Add additional apps" section below.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with Kaspersky Security Center.
Kiosk mode restrictions
You can set the following restrictions in kiosk mode:
- Prohibit Overview button
- Prohibit Home button
- Prohibit status bar
- Prohibit system notifications
- Prohibit enabling kiosk mode if not all selected apps are updated or installed
Disabling kiosk mode using a one-time code
A one-time code is a secret code for disabling kiosk mode. The code is generated by Kaspersky Security Center and is unique for each mobile device. You can change the length of the one-time code (4, 8, 12, or 16 digits) in the Kiosk mode settings of the policy.
To configure disabling kiosk mode:
- In the Disable using one-time code section, select the Allow disabling kiosk mode using one-time code check box.
- If necessary, change the length of the one-time code in the corresponding drop-down list. By default, the code is 4 digits long.
- Click OK.
- Click Save to save the changes you have made.
Kiosk mode can now be disabled using a one-time code. The length of the one-time code is set to the selected value.
Mobile device settings are changed after the next device synchronization with Kaspersky Security Center.
To disable kiosk mode on a user's mobile device using one-time code:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- Click the mobile device for which you want to get a one-time code.
- Select Applications → Kaspersky Mobile Devices Protection and Management.
The Kaspersky Mobile Devices Protection and Management properties window opens.
- Select the Application settings tab.
The unique code for the selected device is displayed in the One-time code field of the One-time code to disable kiosk mode section.
- Use any available method (such as email) to communicate the one-time code to the user of the device.
- After receiving a one-time code, the user must do the following:
- To open a window with a field for entering the one-time code, do one of the following:
- Tap the back button 3 or more times.
- Tap the Home button 3 or more times, if the Prohibit Home button check box is cleared in the Restrictions section of the Kiosk mode card.
- Tap and hold the shield image on the Kaspersky Endpoint Security for Android home screen.
- Enter the one-time code.
- To open a window with a field for entering the one-time code, do one of the following:
Kiosk mode is disabled on the user's mobile device.
To enable kiosk mode again after disabling it using one-time code, you must configure kiosk mode settings and synchronize the user's mobile device with Kaspersky Security Center. The user must then confirm enabling kiosk mode in the message that appears on the device.
Add additional apps
Besides locking the device to a single app or set of apps, you can also specify additional apps, that the main app can use. These additional apps allow the apps added to kiosk mode to provide their full functionality. For example, the user can view a document or access a website opened from the main app. By default, these additional apps are hidden on a device and a user cannot launch them manually.
To add additional apps:
- In the Additional apps section, select the Allow navigation to trusted apps check box.
- Click Add package and specify the desired app package name.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with Kaspersky Security Center.
Connecting to a NDES/SCEP server
These settings apply to corporate devices.
You can connect to an NDES/SCEP server to obtain a certificate from a certificate authority (CA) using the Simple Certificate Enrollment Protocol (SCEP). To do this, you need to add a connection to the certificate authority and a certificate profile.
To add a connection to the certificate authority and a certificate profile:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select Android and go to the Device configuration section.
- On the SCEP and NDES card, click Settings.
The SCEP and NDES window opens.
- Enable the settings using the SCEP and NDES toggle switch.
The Add connection to certificate authority window opens.
- Add a connection to the certificate authority:
- In the Connection name field, enter the name of the connection to the certificate authority.
- In the Protocol type drop-down list, select the protocol version.
- In the Server URL field, enter the URL of a NDES or SCEP server.
The format of the NDES server URL is
http://<ServerName>/certsrv/mscep/mscep.dll
. - In the Challenge phrase type drop-down list, select one of the following options to configure the authentication challenge:
- If you selected the Static option, in the Static challenge phrase field, enter the authentication phrase.
- Click Add.
The connection to the certificate authority is added. You can add multiple connections to certificate authorities.
- Select the Certificate profile tab and click Add.
The Add profile window opens.
- Add a certificate profile:
- In the General settings section, in the Profile name field, enter the unique certificate profile name.
- In the Certificate authority (CA) drop-down list select the certificate authority that you added on the Certificate authority tab.
- In the Subject Name field specify the subject of the certificate. Subject name is a unique identifier that includes information about what is being certified, such as common name, organization, organizational unit, and country code. You can either enter a value or select a macro by clicking the
button.
- If you want to add an alternative name that represents the certificate subject name, click Add Subject Alternative Name and configure the following settings:
- In the Type of Subject Alternative Name drop-down list select the subject alternative name type.
- In the Subject Alternative Name field enter the alternative name. You can either enter a value or select a macro by clicking the
button.
You can add multiple subject alternative names.
- In the Key section, in the Key size (bit) drop-down list, select the certificate's private key length.
- In the Private key type drop-down list select the certificate's private key type:
- If you want the certificate to be automatically reissued to the device before it expires, in the Certificate section, select the Renew certificate automatically check box. This check box is cleared by default.
- If you selected the Renew certificate automatically check box, enter the number of days before the expiration date when the certificate is reissued in the Renew certificate before it expires in (days) field.
- Click Add.
The certificate profile is added. You can add multiple certificate profiles.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with Kaspersky Security Center.
You can edit or remove the added connections to certificate authorities and certificate profiles by clicking Edit and Delete at the top of the list.
If you delete a connection to a certificate authority, all certificate profiles that use it are also removed.
Page topEnabling certificate-based authentication of devices
To enable certificate-based authentication of a device:
- Open the command line on a device where the Administration Server is installed.
- Go to the directory containing the klscflag utility.
By default, the utility is located in
/opt/kaspersky/ksc64/sbin
. - Run the following command under an account with root privileges to configure certificate-based authentication of devices on the Administration Server:
./klscflag -fset -pv ".core/.independent" -s KLLIM -n LP_MobileMustUseTwoWayAuthOnPort13292 -t d -v 1
- Restart the Administration Server service.
After you start the Administration Server service, certificate-based authentication of the device using a shared certificate will be required.
The first connection of the device to the Administration Server does not require a certificate.
By default, certificate-based authentication of devices is disabled.
Page topCreating a mobile application package for Android devices
To create a mobile app package:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Apps & files.
- Click Android.
- Click Apps and then click Add.
The Add app window opens.
- Specify the app name in the App name field. This name will be used to identify the app in policy settings.
- Click Select and select an APK file on your computer.
- Click Save to save the changes you have made.
The newly created app package is displayed in the list of apps on the Apps tab.
If you select a large APK file, the app may take some time to upload. Do not close the Apps & files section until the app is uploaded.
In the Apps & files section, you can also add iOS apps.
Sending files to Android devices
This functionality is available with Kaspersky Security Center Linux 15.2 or later.
Kaspersky Security Center Web Console lets you send files in any format to Android devices in all operating modes.
Sending files is available with a license that provides the extended functionality of Kaspersky Secure Mobility Management. For detailed information on licenses, refer to the About the license section.
Before you send files to devices, you must add files to the Administration Server. You can add files in the Apps & files section and then select which files to send to devices in the File sharing policy settings.
Each file may be no larger than 1.5 GB.
For file sharing to work, Kaspersky Endpoint Security for Android must be granted the "All files access" permission on devices running Android 11 or later or the "Storage" permission on devices running Android 10 or earlier.
On devices with a corporate container, you can copy the files that you send to the corporate container to the user's personal space.
Adding and managing files
To add files to the Administration Server:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Apps & files.
- Select Android → Files.
The list of files opens.
- Click Add.
The Add file window opens.
- Click Select to select the file that you want to add.
- If necessary, in the Description field, enter additional information about the file.
- Click Add.
The file will be added to the Administration Server.
You can delete files or download them to your computer using the corresponding buttons at the top of the list.
If you delete a file in the Apps & files section, it is deleted from the Administration Server but remains on devices. To remove the file from devices, delete it in the File sharing policy settings.
You can view information about any file in the list by clicking its name.
Sending files to devices
To send files to devices:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select Android and go to the Device configuration section.
- On the File sharing card, click Settings.
The File sharing window opens.
- Enable the settings using the File sharing toggle switch.
- Click Add.
The Add file window opens.
- In the File name drop-down list, select a file that you added in the Apps & files section.
- In the Root folder drop-down list, do one of the following:
- Select a standard root folder on devices.
- Select Custom folder to specify the root folder manually in the Folder field.
- In the Folder field, do one of the following:
- If you selected a standard root folder, specify the rest of the path of the folder to which the file will be sent.
- If you selected Custom folder, specify the full path of the folder to which the file will be sent.
The path must use slashes (/) as separators and may include letters, digits, underscore characters (_), and dashes (-).
If the folder you specify does not exist on devices, Kaspersky Endpoint Security for Android creates it automatically.
- If you want to send several files to devices, click Add file and repeat steps 7-9.
- Click Add.
The new file appears in the list.
- Click OK.
- Click Save to save the changes you have made.
Files are sent to devices after the next device synchronization with Kaspersky Security Center. Due to technical limitations, delivering large files to devices may take some time.
You can delete files from devices using the corresponding button at the top of the list.
If you delete a file in the File sharing policy settings, it is deleted from devices but remains on the Administration Server.
Page topViewing information about an Android device
To view information about an Android device:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
The list of managed mobile devices opens.
- To filter Android devices, click the OS column heading and select Android.
The list of Android devices is displayed.
Depending on the database you use, searches may be case-sensitive.
- Select the mobile device you want to view information about.
A window with the properties of the Android device opens.
The mobile device properties window displays information about the connected Android device.
IMEI numbers are displayed for all devices running Android 5–9, corporate devices running Android 10 or later, and devices with a corporate container running Android 10–11.
If an old version of Kaspersky Endpoint Security for Android (10.52.1.3 or earlier) is installed on the devices the Operating mode value is set to Unknown.
Disconnecting an Android device from management
To disconnect an Android device from management, the user has to remove Kaspersky Endpoint Security for Android from the mobile device. After the user has removed Kaspersky Endpoint Security for Android, the administrator can remove the mobile device from the list of managed devices in Web Console.
If Kaspersky Endpoint Security for Android has not been removed from the mobile device, that mobile device reappears in the list of managed devices after synchronization with the Administration Server.
To remove an Android device from the list of managed devices:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
The list of managed mobile devices opens.
- To filter Android devices, click the OS column heading and select Android.
The list of Android devices is displayed.
- Select the mobile device you want to disconnect.
- Click Delete.
The mobile device is removed from the list of managed devices.
Page topManaging iOS MDM devices
This section describes advanced features for management of iOS MDM devices in Kaspersky Security Center Web Console.
Signing device management profiles with a certificate
This functionality is available with Kaspersky Security Center Linux 15.2 or later.
You can sign device management profiles with a certificate received from a trusted certification authority.
A certificate is not required for the device management profile to operate correctly. If the device management profile is not signed with a certificate, then when installing the device management profile, a warning appears and users are prompted to confirm that they trust the organization that sent the certificate.
To sign device management profiles with a certificate:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → iOS MDM Servers.
The list of iOS MDM Servers opens.
- Click Signing certificate.
The Signing certificate window opens.
- In the Certificate format field, specify the public or private certificate type:
- If the PKCS #12 value is selected, specify the certificate file and the password.
- If the X.509 value is selected:
- Specify the private key file.
- Specify the public key file.
- Specify the private key password.
- Click Save.
Device management profiles that you create will now be signed with the specified certificate.
Page topAdding a configuration profile
To create a configuration profile, you can use Apple Configurator 2, which is available on the Apple website. Apple Configurator 2 works only on devices running macOS. If you do not have such devices at your disposal, you can use iPhone Configuration Utility. However, Apple no longer supports iPhone Configuration Utility.
To add a configuration profile to an iOS MDM Server:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → iOS MDM Servers. In the list of iOS MDM Servers that opens, click the iOS MDM Server whose settings you want to configure.
- In the iOS MDM Server settings window, select Application settings.
- Select the Configuration profiles tab.
- To add a new configuration profile, click Add.
- In the window that opens, select the configuration profile that you want to add.
The configuration profile name should not be longer than 100 characters. If you enter a longer name, only part of it will be displayed.
The new configuration profile will be displayed in the list of configuration profiles.
You can install the profile that you have created on iOS MDM devices.
Page topInstalling a configuration profile on a device
To install a configuration profile on an iOS MDM device:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of devices that opens, select the devices that you want to install configuration profiles on.
- Click Send command.
- In the Send command window that opens, in the Command field, select the Install configuration profile command.
- In the Configuration profiles section, select the configuration profiles that you want to install on the devices.
- Click Send.
The command is sent to the devices you selected.
To view the list of configuration profiles installed on a device:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of devices that opens, click the device whose properties you want to view.
The device properties window opens.
- Select the Configuration profiles tab.
The list of configuration profiles installed on the device is displayed.
Page topRemoving a configuration profile from a device
To remove a configuration profile from an iOS MDM device:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of devices that opens, select the devices that you want to remove configuration profiles from.
- Click Send command.
- In the Send command window that opens, in the Command field, select the Delete configuration profile command.
- In the Configuration profiles section, select the configuration profiles that you want to remove from the devices.
- Click Send.
The command is sent to the devices you selected.
The profile may be displayed in the list of configuration profiles installed on the device for several minutes after it has been deleted.
To view the list of configuration profiles installed on a device:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of devices that opens, click the device whose properties you want to view.
The device properties window opens.
- Select the Configuration profiles tab.
The list of configuration profiles installed on the device is displayed.
Page topConfiguring managed apps
Before installing an app on an iOS MDM device, you must add that app to the Administration Server. An app is considered managed if it has been installed on a device through Kaspersky Mobile Devices Protection and Management. A managed app can be managed remotely by means of Kaspersky Mobile Devices Protection and Management.
To add a managed app to an iOS MDM Server:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Apps & files.
- Click iOS, and then click Add.
The Add app window opens.
- Specify the app name in the App name field. This name will be used to identify the app in policy settings.
- In the Installation method field, select one of the following methods to add the app:
- Installation package
- Link to manifest file
A manifest file is a PLIST file, which is required to install an app on an iOS device. These files are dictionaries containing app installation settings (for example, the location of the installation package). When you use a manifest file to add an app, you have to fill in these settings manually. When you add an app from the App Store or an IPA file, the manifest file is generated automatically.
To get a manifest file for an app, we recommend first adding the app to the iOS MDM Server using an IPA file. In this case, the iOS MDM Server automatically generates a manifest file, which you can download and modify later.
- App Store
- Do one of the following:
- If you selected Installation package, click Select, and upload an IPA file from your computer.
- If you selected Link to manifest file, specify a link to a manifest file that can be used to download the app.
- If you selected App Store, specify a link or ID of the app to be added from the App Store.
- If necessary, configure the following settings:
- Select the Remove when device management profile is deleted check box if you want the app to be removed from the user's mobile device along with the device management profile. This check box is selected by default.
- Select the Block backup of app data to iCloud check box if you want to block backup of the app data to iCloud.
- If you want to add a custom configuration for the app, in the App configuration section, click Select and select a configuration file in PLIST format on your computer.
To generate a configuration file, you can use a configuration generator (for example, https://appconfig.jamfresearch.com/generator) or refer to the official documentation on the app to be configured.
Example of a basic configuration for the Microsoft Outlook app
Example of a configuration file for the Microsoft Outlook app
You can use macros in the corresponding fields of the configuration file to replace values. Available macros
- Click Save to save the changes you have made.
The newly created app is displayed in the table of apps on the iOS tab.
If you select a large IPA file, the app may take some time to upload. Do not close the Apps & files section until the app is uploaded.
You can view and edit app properties by clicking the app in the list or remove the app using the Delete button.
Installing an app on a mobile device
To install an app on a mobile device:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of devices that opens, select the devices that you want to install apps on.
- Click Send command.
- In the Send command window that opens, in the Command field, select the Install app command.
- In the Apps field, select the apps that you want to install on the devices.
- Click Send.
The command is sent to the devices you selected.
Page topUpdating an app installed on a device
You can update an app on an iOS MDM device in the Send command window or on the Apps tab in the device properties window.
In the Send command window, you can update apps on multiple devices.
To update an app on an iOS MDM device in the Send command window:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of devices that opens, select the devices that you want to update apps on.
- Click Send command.
- In the Send command window that opens, in the Command field, select the Update app command.
- In the Apps section, select the apps that you want to update on the devices.
- Click Send.
The command is sent to the devices you selected.
To update an app on an iOS MDM device in the device properties window:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of devices that opens, click the name of the device that you want to update apps on.
The device properties window opens.
- Select the Apps tab.
- At the top of the apps list, click Update.
- In the window that opens, select the apps that you want to update on the device and click Update.
The command is sent to the device.
Updating apps may take a few minutes. The command is executed only if a device is connected to the internet. To check whether an app has been updated, click Refresh list.
Page topRemoving an app from a device
You can remove an app from an iOS MDM device in the Send command window or on the Apps tab in the device properties window.
In the Send command window, you can remove apps from multiple devices.
To remove an app from an iOS MDM device in the Send command window:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of devices that opens, select the devices that you want to remove apps from.
- Click Send command.
- In the Send command window that opens, in the Command field, select the Delete app command.
- In the Apps section, select the apps that you want to remove from the devices.
- Click Send.
The command is sent to the devices you selected.
To remove an app from an iOS MDM device in the device properties window:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of devices that opens, click the name of the device that you want to remove apps from.
The device properties window opens.
- Select the Apps tab.
- In the apps list, select the apps that you want to remove from the device and click Delete.
The command is sent to the device.
Removing apps may take a few minutes. The command is executed only if a device is connected to the internet. To check whether an app has been removed, click Refresh list.
Configuring roaming on an iOS MDM mobile device
To configure roaming:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of devices that opens, select the devices that you want to configure roaming settings for.
- Click Send command.
- In the Send command window that opens, in the Command field, select the Change roaming settings command.
- In the Action section, do one of the following:
- If you want to enable data roaming, select Enable data roaming.
- If you want to disable data roaming, select Disable data roaming.
- Click Send.
The command is sent to the devices you selected.
Page topViewing information about an iOS MDM device
To view information about an iOS MDM device:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
The list of managed mobile devices opens.
- To filter iOS MDM devices, click the Operating mode column heading and select the operating mode of the iOS MDM device you want to view information about.
The list of iOS MDM devices is displayed.
Depending on the database you use, searches may be case-sensitive.
- Select the mobile device you want to view information about.
A window with the properties of the iOS MDM device opens.
The General tab of the properties window displays information about the connected iOS MDM device.
The Certificates tab of the properties window displays information about the certificates installed on the selected iOS MDM device.
The Apps tab of the properties window displays information about the apps installed on the selected iOS MDM device.
The Configuration profiles tab of the properties window displays information about the configuration profiles installed on the selected iOS MDM device.
Disconnecting an iOS MDM device from management
If you want to stop managing an iOS MDM device, you can disconnect it from management in Kaspersky Security Center.
We do not recommend disconnecting the device from management by removing the device management profile, since such device may not work correctly when reconnected. To stop managing an iOS MDM device, disconnect it from the iOS MDM Server as described in this section.
To disconnect an iOS MDM device from the iOS MDM Server:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
The list of managed mobile devices opens.
- To filter iOS MDM devices, click the Operating mode column heading and select the operating mode of the iOS MDM device you want to disconnect.
The list of iOS MDM devices operating in the selected mode is displayed.
- Select the mobile device you want to disconnect.
- Click Delete.
In the list, the iOS MDM device is marked for removal. Within one minute, the device is removed from the database of the iOS MDM Server, after which it is automatically removed from the list of managed devices.
After the iOS MDM device is disconnected from management, all installed configuration profiles, the device management profile, and apps for which the Remove when device management profile is deleted option has been enabled in the iOS MDM Server settings, will be removed from the device. The iOS MDM policy will also be deleted.
Page topConfiguring kiosk mode for iOS MDM devices
These settings apply to supervised devices.
Kiosk mode is an iOS feature that lets you limit the apps available to a device user to a single app. In this mode, a device user can open only the one app that is allowed on the device and specified in the kiosk mode settings.
Open the kiosk mode settings
To open the kiosk mode settings:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
- In the policy properties window, select Application settings.
- Select iOS and go to the Restrictions section.
- On the Kiosk mode card, click Settings.
The Kiosk mode window opens.
Configure kiosk mode
To enable kiosk mode:
- Enable the settings using the Kiosk mode toggle switch to activate kiosk mode on a supervised device.
- In the Bundle ID field, enter the unique identifier of an app selected for kiosk mode (for example, com.apple.calculator).
How to get the bundle ID of an app
To select a different app, you need to disable kiosk mode, save the changes to the policy, and enable kiosk mode for a new app.
The app that is selected for kiosk mode must be installed on the device. Otherwise, the device will be locked until kiosk mode is disabled.
The use of the selected app must also be allowed in the policy settings. If the use of the app is prohibited, kiosk mode will not be enabled until the selected app is removed from the list of forbidden apps.
In some cases, kiosk mode can still be enabled even when the use of the selected app is prohibited in the policy settings.
- Specify the settings that will be enabled on the device in kiosk mode in the corresponding section. For available settings, see the "Kiosk mode settings" section below.
- Specify the settings that the user can edit on the device in kiosk mode in the corresponding section.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with the iOS MDM Server.
As a result, once the policy is applied, kiosk mode is enabled. The selected app is forced to open on a supervised device, and the use of other apps is prohibited. The selected app reopens immediately after the device is restarted.
To edit the kiosk mode settings, you need to disable kiosk mode, save changes to the policy, and then enable kiosk mode again with the new settings.
To disable kiosk mode:
- Disable the settings using the Kiosk mode toggle switch to deactivate kiosk mode on a supervised device.
- Click OK.
- Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with the iOS MDM Server.
As a result, once the policy is applied, kiosk mode is disabled and the use of all apps is allowed on the supervised device.
Now, you can enable kiosk mode again with the new settings.
Kiosk mode settings
- Auto-Lock
- Touch (not recommended to disable)
- AssistiveTouch
- Voice Control
- VoiceOver
- Speak Selection
- Volume Buttons
- Mono Audio
- Zoom
- Auto-Rotate Screen
- Invert Colors
- Ring/Silent Switch
- Sleep/Wake Button