
• User can terminate MDM relationship
–Will lose whatever MDM installed
–Corporate profile settings, etc.
–But now the device tells MDM when that happens
• Doesn’t address co-mingling of data
–Will probably require multi-user model
• Can’t detect jailbreak
• Needs push notification certificate
–Much lower barrier now
• Change (not just erase) passcode
• Can’t disable microphone
• Some basic settings not available in MDM
–PictureFrame restriction
–Can’t lock down accounts
• Geolocation not available
–Find My iPhone appears to use different system
The MDM system is not without some limitations, however. First, the
user can terminate the MDM relationship at any time by simply deleting
the MDM profile. Any profiles which had been installed by MDM (web
clips, account information for corporate email, etc.) also get deleted.
MDM also doesn’t address the co-mingling of data, such as easily
dragging messages from the corporate account to a personal email
account.
There was talk that Apple had included a jailbreak detection command
in an earlier version of MDM, but it's not there now. Third party services
can install their own clients to supplement the MDM feature set, and
some of these do their own jailbreak detection, but there’s nothing built
into the MDM system to do so.
Finally, you need the push notification certificate. This is now a much
lower barrier, though.
Beyond the limitations, there are some simple features that’d be nice to
have. For example, it’d be great if the MDM could not just clear the
passcode, but set a whole new one. This would be useful for a
corporate device where the owner is leaving the company, and we want
to lock them out of the device but not wipe it quite yet.
You also can’t lock down the creation of accounts, though that feature
does exist in the Settings application.
It’d be nice to disable the microphone, for some environments, and
finally, geolocation does not appear to be available through MDM. You
need the Find My iPhone system to do that.
Comentarios a estos manuales