# Wi-Fi Last updated: August 14, 2026 This page explains how to configure Wi-Fi profiles for iOS, Mac, and Apple TV devices using Mobile Device Manager Plus. Administrators can add multiple Wi-Fi network configurations to a single profile, ensuring managed devices automatically connect to enterprise networks when in range. The page covers key settings including security types, enterprise authentication protocols such as TLS, LEAP, EAP-FAST, TTLS, and PEAP, MAC Address Randomization, proxy configuration, and dynamic variables. Wi-Fi networks distributed through MDM cannot be removed or forgotten by end users. You can configure the Wi-Fi settings and configure protocol settings for Mac, Apple TV and iOS devices. For iOS 11.3 and above, the wi-fi sharing feature is restricted by default for the Wi-Fi distributed by Mobile Device Manager Plus. To ease the Wi-Fi configuration process, you can add all the required Wi-Fi configurations to a single profile. This will ensure the device connects to any of the specified Wi-Fi networks when in it's vicinity. It also reduces the chances of the device being unmanaged, in case connection to Wi-Fi networks not distributed by MDM, is restricted. Using this profile, you can ensure managed Apple devices can easily connect to your enterprise's Wi-Fi network. **Note:** Wi-Fi networks deployed through MDM on Apple devices cannot be removed or forgotten by end users. ## Policy Description | PROFILE SPECIFICATION | DESCRIPTION | |---|---| | Wireless Network identification | Network identification | | Connect to this Wi-Fi automatically | Automatically join this Wi-Fi network, on detection | | Hidden network | Enable if target network is not broadcasting | | MAC Address Randomization | Disabling this turns off the Private Address feature on devices running iOS/iPadOS 14 or above, to prevent them from using randomized MAC addresses while connecting to Wi-Fi networks | | Security type | Wireless network encryption while connecting | | Password | Password authentication to connect the Wi-Fi. **Note**: Passwords of Wi-Fi distributed from MDM will be hidden in iOS devices. | | Configure Protocol(Can be configured only if Security Type is one amongst WEP Enterprise, WPA/WPA2 Enterprise and Any(Enterprise) | | | Protocols Supported | Choose the type of protocol. Supported protocols include **TLS, LEAP, EAP-FAST, TTLS, PEAP, EAP-SIM** and **EAP-AKA**. | | Use Protected Access Credential | Enabling protected access | | Provision Protected Access Credential | Allow protected access | | Provision PAC anonymously | Enabling PAC anonymously | | Authentication Protocol(Can be configured only if Protocol Supported is TTLS) | Select the Authentication Protocol to be used | | Configure Authentication(Can be configured only if Security Type is one amongst WEP Enterprise, WPA/WPA2 Enterprise and Any(Enterprise) | | | User Name | User Name of the device, (%username%)will get the appropriate User Name, mapped to the device | | Use per connection Password | User password for initial connection | | Identity Certificate(Can be configured only if Protocol Supported is TLS/EAP-FAST/TTLS/PEAP | Specify the certificate to be used for Client-based authentication. [SCEP](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_scep.html) certificates can also be utilized for this. | | Externally Visible Identification | Visible identification | | Certificate | Specify the CA certificate to be used. | | Trusted Certificate(Can be configured only if Security Type is one amongst WEP Enterprise, WPA/WPA2 Enterprise and Any(Enterprise) | | | Configure Proxy | | | Proxy Settings | Manual or Automatic | ## Dynamic Variables The below mentioned dynamic variables are retrieved from the data that has been provided while enrolling the device. %username% - will get the appropriate user name, mapped to the device ## Frequently Asked Questions **1. Can end users remove a Wi-Fi network that was pushed through MDM?** No. Wi-Fi networks deployed through MDM on Apple devices cannot be removed or forgotten by end users. **2. Which enterprise authentication protocols does the Wi-Fi profile support?** The profile supports TLS, LEAP, EAP-FAST, TTLS, PEAP, EAP-SIM, and EAP-AKA when the Security type is set to WEP Enterprise, WPA/WPA2 Enterprise, or Any(Enterprise). **3. Is MAC address randomization supported for managed Wi-Fi networks?** Yes. Disabling MAC Address Randomization turns off the Private Address feature on devices running iOS/iPadOS 14 or above, so they connect using a fixed MAC address instead of a randomized one. **4. Will the Wi-Fi password be visible to the end user on the device?** No. Passwords for Wi-Fi networks distributed from MDM are hidden on iOS devices.