# Getting started with iOS device management

iOS device management involves the administration, security, and monitoring of Apple devices (iPhone, iPad, and iPod touch) within a corporate environment. Hexnode UEM provides a comprehensive framework to streamline this process.

To get started with iOS device management, administrators must follow a structured workflow involving certificate configuration, device enrollment, and policy application.

The Foundation: Prerequisites and APNs 
---------------------------------------

To manage any Apple device, a secure communication channel between the Hexnode portal and Apple’s servers is mandatory.

- **APNs Certificate (Mandatory):** The [Apple Push Notification service](https://www.hexnode.com/mobile-device-management/help/apns-settings/) certificate acts as the digital handshake for all MDM commands. 
    - **Path**: *Admin > APNs*.
    - **Process**: Generate a CSR from Hexnode, sign it via the Apple Push Certificates Portal, and re-upload the signed certificate.
- **System Requirements**: Supports iOS **11.0**+ and **iPadOS 13.1+**.

Enrollment: Matching Method to Ownership 
-----------------------------------------

Enrollment establishes the management link. The choice depends on whether the device is corporate-owned or personal (BYOD).

### Corporate-Owned (Automated & High Control) 

- **[Apple Automated Device Enrollment](https://www.hexnode.com/mobile-device-management/help/enrollment-of-apple-devices-through-dep/) (ADE/DEP)**: Part of Apple Business Manager (ABM). This method offers **non-removable** management and automatic [**Supervision**](https://www.hexnode.com/mobile-device-management/help/ios-supervised-mode/) out of the box.
- [**Apple Configurator**](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-ios-devices-in-hexnode-mdm/#uem-enrollment-with-apple-configurator): Best for mass-enrolling existing devices or devices not in ABM. Requires a Mac and physical connection.

### Employee-Owned (Privacy-First BYOD) 

- [**User Enrollment**](https://www.hexnode.com/mobile-device-management/help/apple-user-enrollment-for-ios-devices/): Specifically designed for privacy. It creates a managed **APFS volume** that siloes corporate data from personal photos and messages.
- [**Email/SMS/QR Enrollment**](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-ios-devices-in-hexnode-mdm/): A flexible method where users download a management profile via a unique link.

Key Management Pillars
----------------------

### Security and Restrictions 

Controlling device functionality is central to iOS management.

- [**Basic Restrictions**](https://www.hexnode.com/mobile-device-management/help/set-up-ios-mdm-restrictions-using-hexnode-mdm/): Prevents access to specific standard apps and features (camera, FaceTime, etc.). Applicable to all iOS devices.
- **Advanced Restrictions**: Enhanced security settings available specifically for [**Supervised devices**](https://www.hexnode.com/mobile-device-management/help/ios-supervised-mode/).
- [**Prevent MDM Removal**](https://www.hexnode.com/mobile-device-management/help/how-to-make-mdm-profile-non-removable-on-ios-devices/): Administrators can restrict users from removing the MDM profile, particularly when devices are enrolled via Apple DEP.
- [**Activation Lock Bypass**](https://www.hexnode.com/mobile-device-management/help/mdm-bypass-activation-lock/): Hexnode allows admins to bypass the activation lock to reset devices that have been locked by a user’s personal Apple ID.

### App Management and Distribution 

Hexnode UEM provides granular control over the application lifecycle.

- [**Managed Apps**](https://www.hexnode.com/mobile-device-management/help/getting-started-with-ios-app-management/): Apps deployed via Hexnode. Admins can [configure settings](https://www.hexnode.com/mobile-device-management/help/how-to-push-ios-app-configuration-using-xml-in-hexnode-mdm/), remove apps on-demand, or automate removal when the MDM profile is deleted.
- [**Silent Installation**](https://www.hexnode.com/mobile-device-management/help/how-to-install-apps-silently/): Apps can be installed without user interaction. 
    - *Requirement*: The device must be in **Supervised Mode**.
- **[Apple VPP](https://www.hexnode.com/mobile-device-management/help/how-to-deploy-apple-vpp-apps-with-hexnode-mdm/) (Volume Purchase Program)**: Allows organizations to buy app licenses in bulk and distribute them silently to supervised devices without requiring an Apple ID.
- [**Blocklist/Allowlist**](https://www.hexnode.com/mobile-device-management/help/how-to-block-apps-on-ios-devices-using-hexnode-mdm/): Admins can block specific apps or restrict the device to run only essential apps.
- [**Kiosk Mode**](https://www.hexnode.com/mobile-device-management/help/how-to-enable-kiosk-mode-for-ios/): Locks the device to a single app or a specific set of apps. (*Requires Supervised Mode*).
- [**Web Clips**](https://www.hexnode.com/mobile-device-management/help/add-web-clips-to-ios-with-hexnode-mdm/): Deploys shortcuts to specific URLs on the home screen, appearing like native app icons.

### Data Separation and Network Security 

To secure corporate data while respecting user privacy (BYOD), Hexnode utilizes containerization.

- [**Business Containers**](https://www.hexnode.com/mobile-device-management/help/how-to-setup-business-container-for-ios-devices-using-hexnode-mdm/): Ensures work data cannot be opened in personal apps and personal data cannot be accessed by managed apps.
- [**Managed Domains**](https://www.hexnode.com/mobile-device-management/help/configure-domain-for-ios-devices-using-hexnode-mdm/): URLs defined as “managed.” Documents downloaded from these domains are treated as corporate data.
- **Managed Accounts**: Remotely configure [email](https://www.hexnode.com/mobile-device-management/help/email-configuration-for-ios/) ([Exchange](https://www.hexnode.com/mobile-device-management/help/configure-exchange-activesync-on-ios-with-hexnode-mdm/), [Google](https://www.hexnode.com/mobile-device-management/help/setup-google-account-on-ios-devices-using-hexnode-mdm/), IMAP/POP), [CalDAV](https://www.hexnode.com/mobile-device-management/help/caldav-settings-for-ios/), [CardDAV](https://www.hexnode.com/mobile-device-management/help/carddav-settings-for-ios/), and [LDAP](https://www.hexnode.com/mobile-device-management/help/ldap-settings-for-ios/) accounts.
- **Network Configurations**: Remotely set up [Wi-Fi](https://www.hexnode.com/mobile-device-management/help/set-up-wifi-for-ios-with-hexnode-mdm/), [VPN](https://www.hexnode.com/mobile-device-management/help/ios-vpn-settings/), [Per-App VPN](https://www.hexnode.com/mobile-device-management/help/how-to-configure-per-app-vpn-in-ios-devices-using-hexnode-mdm/), and [Access Point Names (APN)](https://www.hexnode.com/mobile-device-management/help/configuring-access-point/).
- [**Global HTTP Proxy**](https://www.hexnode.com/mobile-device-management/help/ios-global-http-proxy-settings/): Routes all HTTP traffic through a designated proxy server to inspect traffic and secure data.

### OS Updates and Maintenance 

Maintaining device health is critical for long-term management.

- [**Enforce OS Updates**](https://www.hexnode.com/mobile-device-management/help/enforce-ios-updates-using-hexnode-mdm/): Push the latest iOS version to devices (*Requires Supervised Mode*).
- [**Delay OS Updates**](https://www.hexnode.com/mobile-device-management/help/how-to-delay-ios-updates-on-ios-11-3-devices-using-hexnode/): Administrators can delay software updates for up to 90 days to test for compatibility bugs (*Requires Supervised Mode*).
- [**Remote View**](https://www.hexnode.com/mobile-device-management/help/how-to-enable-remote-view-for-ios-devices-using-hexnode-mdm/): Admins can view the screen of enrolled devices in real-time from the console to assist with support.

### Personalization and User Experience 

Enterprises can brand devices and improve usability.

- [**Home Screen Layout**](https://www.hexnode.com/mobile-device-management/help/how-to-customize-home-screen-layout-for-ios-devices-using-hexnode-mdm/): Customize the arrangement of apps and folders.
- [**Wallpaper**](https://www.hexnode.com/mobile-device-management/help/how-to-set-wallpaper-on-ios-devices-with-mdm/): Enforce company logos on the Lock and Home screens.
- [**Lock Screen Message**](https://www.hexnode.com/mobile-device-management/help/set-lock-screen-message-on-ios-devices-using-hexnode-mdm/): Display asset tag information or return instructions if the device is lost.
- [**Font Management**](https://www.hexnode.com/mobile-device-management/help/add-new-font-to-ios-devices-with-hexnode-mdm/): Upload custom fonts for use within managed applications.

Troubleshooting Common iOS Management Issues 
---------------------------------------------

If you encounter issues while you get started with iOS device management, consult the following troubleshooting steps:

### Issue 1: Unable to Install Apps Silently 

**Cause**: The device is likely not in **Supervised Mode**.

**Solution**: Verify the device supervision status. Silent installation for non-VPP apps strictly requires supervision. For VPP apps, ensure the license assignment is correct.

### Issue 2: MDM Profile Removal by User 

**Cause**: The device was enrolled manually without ADE restrictions.

**Solution**: To prevent removal, enroll devices using the **Automated Device Enrollment**. This allows you to lock the MDM profile to the device.

### Issue 3: “APNs Certificate Expired” Error 

**Cause**: Apple Push Notification certificates are valid for one year.

**Solution**: Renew the APNs certificate using the same Apple ID used to create it initially. If you use a different ID, you will have to re-enroll all devices.

### Issue 4: Hexnode App Logs for Diagnostics 

**Action**: If the Hexnode app behaves unexpectedly, administrators can retrieve app logs remotely.

**Path**: These logs provide technical details on performance and errors, assisting support teams in diagnosing connectivity or policy failures.