Shared iPads 编辑
The shared iPad feature allows multiple users to use an iPad. The user experiences can be personalized even though the devices are shared. You can use shared iPads for education or business. Apple School Manager (ASM) supports the instructor and student roles in addition to the roles Apple Business Manager (ABM) supports.
Prerequisites for Shared iPads
- Apple School Manager or Apple Business Manager
- Citrix Endpoint Management
- Any iPad Pro, iPad 5th generation, iPad Air 2 or later, and iPad mini 4 or later
- At least 32 GB of storage
- Supervised devices
Configure Shared iPads
Multiple students or employees can share an iPad for different purposes.
Either you or device owners enroll Shared iPads and then deploy device policies, apps, and media to the devices. After that, users provide their managed Apple ID credentials to sign in to a Shared iPad. If you previously deployed an Education Configuration policy to students, they no longer sign in as an “Other User” to share devices.
Endpoint Management uses two communications channels for Shared iPads: The system channel for the device owner (instructor or supervisor) and the user channel for the current resident user (student or employee). Endpoint Management uses those channels to send the appropriate MDM commands for the resources supported by Apple.
Resources that deploy over the system channel are:
- Device policies, such as Education Configuration, Lock Screen Message, Maximum Resident Users, and Passcode Lock Grace Period
- Device-based volume purchase apps Apple doesn’t support Enterprise apps or user-based volume purchase apps on Shared iPads. Apps installed on a Shared iPad are global to the device and not per user.
- User-based volume purchase iBooks Apple supports assignment of user-based volume purchase iBooks on Shared iPads.
Resources that deploy over the user channel are:
- Device policies: Apps Notifications, Home Screen Layout, and Restrictions Endpoint Management supports only these device policies over the user channel.
When configuring device policies, you specify the deployment channel in the policy setting Profile scope.
To remove device policies that you deployed over the user channel, be sure to choose a Deployment scope of User for the Profile Removal policy.
General workflow
Typically, you provide preconfigured and supervised Shared iPads to device owners. Those individuals then distribute the devices to students or employees. If you don’t distribute pre-enrolled Shared iPads: Be sure to provide the device owners with their Endpoint Management server passwords so they can enroll their devices.
The general workflow for configuring and enrolling Shared iPads is as follows.
- Use the Endpoint Management server console to add ASM or ABM accounts (Settings > Apple Deployment Program) with Shared mode enabled. For more information, see “Manage accounts for Shared iPads” next.
- As described in this section, add the required device policies, apps, and media to Endpoint Management. Assign those resources to delivery groups.
- Have the device owners perform a hard reset on the Shared iPads. The Remote Management screen for enrollment appears.
- The device owners enroll the Shared iPads. Endpoint Management deploys configured resources to each enrolled Shared iPad. After an automatic restart, device owners can share the devices with users. A sign-in page appears on the iPad.
- A device user enters their Managed Apple ID and temporary ASM password. The Shared iPad authenticates to ASM and prompts the user to create an ASM password. For the next sign into the Shared iPad, the device user provides the new ASM password.
- Another device user who shares the iPad can then sign in by repeating the previous step.
Manage accounts for Shared iPads
If you already use Endpoint Management with Apple Education or Apple Business: You have an existing ASM/ABM account configured in Endpoint Management for devices that aren’t shared, such as the devices used by device owners. You can use the same ASM/ABM account and the same Endpoint Management server for both shared and non-shared devices.
Organize Shared iPads into device groups
ASM/ABM lets you organize devices into groups by creating multiple MDM servers. When you assign the Shared iPads to an MDM server, create a device group for each group of Shared iPads:
- Group 1 of Shared iPads > Device Group 1 MDM Server
- Group 2 of Shared iPads > Device Group 2 MDM Server
- Group N of Shared iPads > Device Group N MDM Server
Add ASM accounts for each device group
When you create multiple ASM/ABM accounts from the Endpoint Management server console, you automatically import groups of Shared iPads:
- Device Group 1 MDM Server > Device Group 1 account
- Device Group 2 MDM Server > Device Group 2 account
- Device Group N MDM Server > Device Group N account
Requirements specific to Shared iPads are as follows:
- One ASM/ABM account for each device group with these settings enabled:
- Require device enrollment
- Supervised mode
- Shared mode
- For a given educational organization, be sure to use the same Education suffix for all ASM accounts.
Apps for Shared iPads
Shared iPads support assignment of device-based volume purchase apps. Before deploying an app on a Shared iPad, Endpoint Management sends a request to the Apple volume purchase server to assign volume purchase licenses to the devices. To check the volume purchase assignments, go to Configure > Apps > iPad and expand Volume Purchase.
Media for Shared iPads
Shared iPads support assignment of user-based volume purchase iBooks. Before deploying iBooks on a Shared iPad, Endpoint Management sends a request to the Apple volume purchase server to assign volume purchase licenses to users. To check the volume purchase assignments, go to Configure > Media > iPad and expand Volume Purchase.
Deployment rules for Shared iPads
For Shared iPad deployment, the rules at the delivery group level don’t apply because they relate to user properties. To filter the policies, apps, and media for each group of devices: Add a deployment rule for the resources based on the account name. For example:
- For the Device Group 1 account, set this deployment rule:
Apple Deployment Program account name
Only
Device Group 1 account
<!--NeedCopy-->
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论