Category filter
How to set up restrictions for Apple devices used in education?
TL;DR: Education Restrictions for supervised iOS classroom devices
- Configure the policy from Policies > iOS > Restrictions > Education in the Hexnode UEM console.
- The policy supports classroom restrictions for managed and unmanaged classes on supervised iOS devices.
- Each restriction has a minimum supported iOS version, starting from supervised iOS 10.3 or later depending on the setting.
- Associate the saved policy with devices, device groups, users, user groups, or domains to apply it in bulk.
The Education Restrictions policy in Hexnode UEM configures classroom-focused restrictions for supervised iOS devices used in education environments. IT administrators use this policy to manage instructor capabilities and student actions in managed and unmanaged classes, including screen observation, app and device locking, automatic class joining, and permission requests before students leave a class. After the policy is configured and associated with target devices, users, groups, or domains, Hexnode UEM applies the selected restrictions to supported supervised iOS versions.
Use this policy when student devices must remain focused during classroom sessions and instructors need controlled access to classroom management actions.
How Education Restrictions Work in Hexnode UEM
Education Restrictions in Hexnode UEM are policy settings that control classroom-related actions on supervised iOS devices. The settings affect how instructors and students interact with managed or unmanaged classes, such as whether instructors can observe student screens without prompting or whether students must request permission before leaving an unmanaged class.
Hexnode UEM applies these restrictions through policy association. A policy can be targeted to individual devices, device groups, users, user groups, or domains, which helps administrators deploy the same classroom restrictions across multiple supervised iOS devices.
Configure the Education Restrictions Policy in Hexnode UEM
To configure Education Restrictions for supervised iOS classroom devices in Hexnode UEM:
- On the Hexnode UEM console, go to Policies.
- Create a new policy or edit an existing policy. If you create a new policy, enter a policy name and description.
- Navigate to iOS > Restrictions > Education.
- Click Configure to set up the Education Restrictions policy.
- Click Save.
Education Restrictions Supported by Hexnode UEM
The following Education Restrictions are available for supervised iOS devices in Hexnode UEM.
This table lists Hexnode UEM Education Restrictions for supervised iOS devices, describes what each setting controls in classroom environments, and identifies the minimum supported iOS version for each restriction.
| Restriction | Description | Supported versions |
|---|---|---|
| Force unprompted screen observation for managed classes | If enabled, instructors can remotely view students’ devices in the managed classroom. | Supervised iOS 10.3+ |
| Allow unprompted app and device lock in unmanaged classes | If enabled, instructors can restrict access to apps and devices in an unmanaged class. | Supervised iOS 11.0+ |
| Allow automatic joining of unmanaged classes | If enabled, students can join an unmanaged class automatically. | Supervised iOS 11.0+ |
| Force students to request permission to leave unmanaged classes | If enabled, students who are part of an unmanaged class in the Classroom app must request permission from the teacher to leave the class. | Supervised iOS 11.3+ |
Associate Education Restrictions with Target iOS Devices
Hexnode UEM provides two ways to associate the Education Restrictions policy with devices in bulk, depending on whether the policy has already been saved.
Associate targets before saving the policy
If the Education Restrictions policy has not been saved yet:
- Navigate to Policy Targets.
- Select the devices, device groups, users, user groups, or domains to which the policy must be attached.
- Click Save to apply the policy to the selected targets.
Associate targets after saving the policy
If the Education Restrictions policy has already been saved and the console displays the policy list:
- Select the required policy.
- Click Manage > Associate Targets.
- Search for and select the devices, users, device groups, user groups, or domains to which the policy must be applied.
- Click Associate.
Troubleshoot Education Restrictions on iOS Devices
An Education Restriction does not apply to a student device
Verify that the device is supervised and running the minimum iOS version required for the selected restriction. Also confirm that the policy is saved and associated with the correct device, device group, user, user group, or domain in Hexnode UEM.
A specific classroom restriction is unavailable or ineffective
Check the supported version column in the Education Restrictions table. Some settings require supervised iOS 11.0 or later, while the permission-to-leave restriction requires supervised iOS 11.3 or later.
Frequently Asked Questions
Does Hexnode UEM support Education Restrictions on all iOS devices?
No. The Education Restrictions listed in this article require supervised iOS devices and are available only on the supported iOS versions specified for each restriction.
Can Education Restrictions be deployed to groups in Hexnode UEM?
Yes. The policy can be associated with devices, device groups, users, user groups, or domains from the policy target workflow in Hexnode UEM.
Which Education Restriction requires supervised iOS 11.3 or later?
Force students to request permission to leave unmanaged classes requires supervised iOS 11.3 or later.