pdf icon
Category Filter

Create Profiles

Profiles are created to impose one or more policies and restrictions to the managed devices/groups. You need to create separate MDM profiles for iOS, Android and Windows devices. This is to implement/associate policies with the devices.
Follow the steps mentioned below to create a profile.

  1. On the web console, navigate to Profiles
  2. Click Create Profile and choose the platform as iOS/iPadOS, Android or Windows, for which you wanted to create the profile.
    Provide the below mentioned basic information:
    1. Name of the Profile: Unique name to identify the profile
    2. Description: A brief description about the profile
    3. Customize Profile for (This is applicable only for Android) : In case of KNOX devices, apart from creating profile for Device, profiles can be created for KNOX containers by choosing the option KNOX Container. For all other Android devices, choose the option Device to create profile for devices.
  3. Click Continue
  4. Under Define Profile from the left pane, select the configuration profile ( iOS/iPadOS / Android / Windows ) and define the policies and restrictions of the profile. You will have to save the individual configurations before you move on to the next configuration within the same profile.
  5. After specifying the required configurations, click Publish.
  6. A published profile is not applied to any of the devices until they are associated to the devices or groups.

Associating multiple profiles to the same device

Let us assume you are associating two profiles to the same device:

Profile 1: Restricts camera and sets minimum passcode length as 4

Profile 2: Allows camera and sets minimum passcode length as 6

Let us see how the profiles get applied on the devices:

PLATFORM DESCRIPTION CAMERA MINIMUM PASSCODE LENGTH
iOS Most secure combination of settings get applied Restricted 6
Windows Most secure combination of settings get applied Restricted 6
Android Most recent profile settings get applied Allowed 6

Modify a profile

To modify a profile,

  1. On the web console, navigate to Device Mgmt > Profiles.
  2. Here you can view the list of all the profiles that have been created already.
  3. Click on the ellipsis icon under the Actions column, of the profile that you want to modify and select Modify Profile from the dropdown. You can add or remove configurations from the profile.
  4. After making the required changes, click Save to save the changes.
  5. Click Publish to save the changes made to the Profile.

When a profile is modified and published, it is not applied to the devices to which they were applied before. A new version of the profile is listed, you can upgrade the latest version to the group, so that the current members of the group will have the latest version of the profile applied to them.  The previous version of profile will be overwritten by the latest version.  

Copy a Profile

Copy Profile lets you duplicate profiles which were previously created using Mobile Device Manager Plus (MDM). Instead of creating profiles and configuring policies from scratch every single time, you can duplicate an existing profile and subsequently add/remove/modify the configured policies according to your organizational needs. This way, existing profiles can be used as a base instead of creating new ones. MDM differentiates the duplicate profiles from the original ones with the profile name followed by _Copy. The profile name can be modified as well.

Benefits:

  • Clone a profile, customize policies, test them on your managed test devices before associating with other devices.
  • Change policies for a select subset of users using cloned profiles.
  • Saves time and effort in creating and configuring profiles. Use existing profiles as a base instead of creating new ones from scratch.
  • Create clones of profiles and rename them according to your preference.

To duplicate a profile on MDM,

  1. Navigate to the Device Mgmt tab on the MDM console.
  2. On the left pane, click on the Profiles tab to view the list of profiles which have been previously created.
  3. Choose the profile that you want to duplicate and click on the ellipsis under the Actions column. Now, click on Copy Profile.
  4. Save the profile after making changes to the profile name/policies, if required.
  5. Click on Publish to save the changes.
  • Modify a profile to make changes to the existing profile. This alters the configuration of the profile.
  • Copy a profile to duplicate the existing profile which can subsequently be modified, without having to disturb the original profile's configuration.

Moving a profile to Trash

When you want to delete a profile associated with devices/groups, you can simply move the profile to Trash. Moving profiles to Trash ensures the profiles are automatically disassociated from the devices/groups. These profiles are automatically deleted after 90 days. The profiles can also be deleted or restored manually from Trash by the user. However, the restored profiles don't automatically get associated with the previously associated groups/devices. These restored profiles can be associated to the devices/groups.
The following steps explain the moving of profiles to Trash:

  1. On the web console, navigate to Profiles
  2. Under Profiles tab, you can view the list of all the profiles that have been created already.
  3. Select the profiles to be moved to Trash
  4. Click on the Move to Trash button and the profiles are moved to Trash.

The profiles can be viewed by clicking . The profiles can be deleted or restored from here.

Best Practices

  • Policies which require constant changes such as Restrictions should not be grouped with e-mail account related policies such as Exchange, Wi-Fi etc., as every time a modified version of the profile containing all these policies is re-distributed, the passcode for the account-based services such as Exchange and configurations such as Wi-Fi preferences, previously synced mails etc., specified in the account-related policies is reset and has to be manually entered by the user again. Consider the case of Exchange - as MDM uses third-party mail clients such as Gmail, Samsung mail to configure Exchange, even reassociating the same policy (with/without modification) removes the existing configuration and then configures Exchange based on the newly associated policy. This may require some user input.
  • SCEP and the associated account policies which are to utilize the certificate provisioned by SCEP must be configured in the same profile. This ensures the same SCEP certificate is used for all the account-related policies configured in the profile.

 

Jump To