Mobile Device Management (MDM) Overview

University-Owned Apple Devices

 

Overview

Enrolling university-owned Apple devices in JAMF provides centralized management and security. MDM helps protect sensitive data by enforcing security policies, preventing unauthorized access, and supporting compliance with university and regulatory requirements. JAMF also enables remote management capabilities, including the ability to lock or wipe lost or stolen devices.

Before setup, departments should be prepared to identify required apps, Apple account needs, special restrictions, and whether the devices will be used for payment processing or other sensitive operations.

 

Deployment Considerations

  • Applications that need to be installed, including any required apps

  • Additional configuration requirements or restrictions needed for the deployment

  • Whether the devices will be used for payment processing or other sensitive operations

 

Apple Account Options

 Determine whether users need Apple account functionality for their assigned duties.

  • If Apple accounts are needed: decide whether Managed Apple Accounts are preferred.

  • If Apple accounts are not needed: decide whether Apple ID sign-in should be disabled.

  • If Managed Apple Accounts are used: app installations must be handled through the support process.

 

Key Security Controls Enforced Through JAMF

Security Control

Purpose

Encryption and Authentication

Requires a passcode, password, or biometric authentication on iOS devices and ensures device level encryption is enabled.

Legislative Compliance

Enforces settings that restrict software identified as prohibited under Mississippi Senate Bill 2140.

Required Security Software

Deploys Cisco Umbrella, which provides DNS-layer protection against malware, ransomware, phishing, and other malicious activity.

Remote Management

Supports centralized management, monitoring, application deployment, and remote lock/wipe for lost or stolen devices.

Managed Apple Accounts: Important Considerations

Managed Apple Accounts provide a university-managed alternative to personal Apple IDs, with additional administrative control and security. 

Important limitations:

  • Users cannot independently install applications.

  • Application requests must be submitted through the support process.

Departments should confirm these restrictions fit their workflow before opting in.

Billing Information

ITS charges departments $10 per device annually for JAMF licensing.


A valid departmental billing account number is required before enrollment.

 

Next steps: Submit a support ticket [Request assistance with MSU iPhone/iPad via mobile device management] after the devices are received so the assigned desktop support representative can assist with enrollment and configuration in JAMF.