3.1.1 Ensure 'Controls when the profile can be removed' is set to 'Never'

Information

This recommendation pertains to the removal of a given configuration profile.

Typically, the enrollment of devices into a Mobile Device Management (MDM) does not allow a user to remove any managed configurations.

Rationale:

In this section of the benchmark, recommendations are for devices that are owned by the institution. Removal of the configuration profile should be at the discretion of the institution, not the end user, in order to prevent weakening the device's security and exposing its data.

Solution

Open Apple Configurator.

Open the Configuration Profile.

In the left window pane, click on the General tab.

In the right window pane, under the heading Security, set the menu Controls when the profile can be removed to Never.

Deploy the Configuration Profile.

See Also

https://workbench.cisecurity.org/benchmarks/15548