2.1.1 Ensure a 'Consent Message' has been 'Configured'

Information

This recommendation pertains to the configuration of a consent message shown at the time of a configuration profile installation.

Typically, the enrollment of devices into a Mobile Device Management (MDM) solution requires users to provide their approval. Such approval can waive the need of a consent message. The enrolled MDM must be the organization approved MDM.

Rationale:

In this section of the benchmark, recommendations are for devices that are owned by the end user. They are voluntarily accepting the configuration profile and should be provided an explicit opportunity to consent.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the General tab.

In the right window pane, under the heading Consent Message, insert an appropriate consent message.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/15548