2.1.2 Ensure 'Controls when the profile can be removed' is set to 'Always'

Information

This recommendation pertains to the removal of a given configuration profile.

Rationale:

In this section of the benchmark, recommendations are for devices that are owned by the end user. They are voluntarily accepting the configuration profile and should be able to remove it at will.

Impact:

Having a user removing a configuration profile can have impacts for both the organization and the user: the former might lose visibility/control over the device owned by the user, whilst the latter might lose access to the systems due to the removal of the configuration profile.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the General tab.

In the right window pane, under the heading Security, set the menu Controls when the profile can be removed to Always.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/15548