Category filter

How to set up restrictions for Apple devices used in education?

TL;DR: Education Restrictions for supervised iOS classroom devices

  • Configure the policy from Policies > iOS > Restrictions > Education in the Hexnode UEM console.
  • The policy supports classroom restrictions for managed and unmanaged classes on supervised iOS devices.
  • Each restriction has a minimum supported iOS version, starting from supervised iOS 10.3 or later depending on the setting.
  • Associate the saved policy with devices, device groups, users, user groups, or domains to apply it in bulk.

The Education Restrictions policy in Hexnode UEM configures classroom-focused restrictions for supervised iOS devices used in education environments. IT administrators use this policy to manage instructor capabilities and student actions in managed and unmanaged classes, including screen observation, app and device locking, automatic class joining, and permission requests before students leave a class. After the policy is configured and associated with target devices, users, groups, or domains, Hexnode UEM applies the selected restrictions to supported supervised iOS versions.

Use this policy when student devices must remain focused during classroom sessions and instructors need controlled access to classroom management actions.

Note:


Education Restrictions apply only to supervised iOS devices that meet the supported iOS version listed for each restriction.

How Education Restrictions Work in Hexnode UEM

Education Restrictions in Hexnode UEM are policy settings that control classroom-related actions on supervised iOS devices. The settings affect how instructors and students interact with managed or unmanaged classes, such as whether instructors can observe student screens without prompting or whether students must request permission before leaving an unmanaged class.

Hexnode UEM applies these restrictions through policy association. A policy can be targeted to individual devices, device groups, users, user groups, or domains, which helps administrators deploy the same classroom restrictions across multiple supervised iOS devices.

Configure the Education Restrictions Policy in Hexnode UEM

To configure Education Restrictions for supervised iOS classroom devices in Hexnode UEM:

  1. On the Hexnode UEM console, go to Policies.
  2. Create a new policy or edit an existing policy. If you create a new policy, enter a policy name and description.
  3. Navigate to iOS > Restrictions > Education.
  4. Click Configure to set up the Education Restrictions policy.
  5. Click Save.

Education Restrictions Supported by Hexnode UEM

The following Education Restrictions are available for supervised iOS devices in Hexnode UEM.

This table lists Hexnode UEM Education Restrictions for supervised iOS devices, describes what each setting controls in classroom environments, and identifies the minimum supported iOS version for each restriction.

Restriction Description Supported versions
Force unprompted screen observation for managed classes If enabled, instructors can remotely view students’ devices in the managed classroom. Supervised iOS 10.3+
Allow unprompted app and device lock in unmanaged classes If enabled, instructors can restrict access to apps and devices in an unmanaged class. Supervised iOS 11.0+
Allow automatic joining of unmanaged classes If enabled, students can join an unmanaged class automatically. Supervised iOS 11.0+
Force students to request permission to leave unmanaged classes If enabled, students who are part of an unmanaged class in the Classroom app must request permission from the teacher to leave the class. Supervised iOS 11.3+

Associate Education Restrictions with Target iOS Devices

Hexnode UEM provides two ways to associate the Education Restrictions policy with devices in bulk, depending on whether the policy has already been saved.

Associate targets before saving the policy

If the Education Restrictions policy has not been saved yet:

  1. Navigate to Policy Targets.
  2. Select the devices, device groups, users, user groups, or domains to which the policy must be attached.
  3. Click Save to apply the policy to the selected targets.

Associate targets after saving the policy

If the Education Restrictions policy has already been saved and the console displays the policy list:

  1. Select the required policy.
  2. Click Manage > Associate Targets.
  3. Search for and select the devices, users, device groups, user groups, or domains to which the policy must be applied.
  4. Click Associate.

Troubleshoot Education Restrictions on iOS Devices

An Education Restriction does not apply to a student device

Verify that the device is supervised and running the minimum iOS version required for the selected restriction. Also confirm that the policy is saved and associated with the correct device, device group, user, user group, or domain in Hexnode UEM.

A specific classroom restriction is unavailable or ineffective

Check the supported version column in the Education Restrictions table. Some settings require supervised iOS 11.0 or later, while the permission-to-leave restriction requires supervised iOS 11.3 or later.

Frequently Asked Questions

Does Hexnode UEM support Education Restrictions on all iOS devices?

No. The Education Restrictions listed in this article require supervised iOS devices and are available only on the supported iOS versions specified for each restriction.

Can Education Restrictions be deployed to groups in Hexnode UEM?

Yes. The policy can be associated with devices, device groups, users, user groups, or domains from the policy target workflow in Hexnode UEM.

Which Education Restriction requires supervised iOS 11.3 or later?

Force students to request permission to leave unmanaged classes requires supervised iOS 11.3 or later.

iOS Device Management