Restricting Apps for Mobile Devices

Jamf Pro Documentation 11.16.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.16.0
ft:locale
en-US
vrm_version
11.16.0

You can use Jamf Pro to create a mobile device configuration profile that restricts end user access to certain iOS, iPadOS, and tvOS apps.

Requirements
  • Supervised mobile devices

  • Supervised Apple TV devices

  1. In Jamf Pro, click Devices in the sidebar.
  2. Click Configuration Profiles in the sidebar.
  3. Click New .
  4. In the General payload, enter a name for the profile and configure other settings on the pane as needed.
  5. Under the Restrictions payload, click Apps.
  6. To allow usage of the App Store on managed iOS, iPadOS, and tvOS devices and control which apps are allowed, do the following:
    Note:

    You may want to restrict the App Store app from tvOS devices entirely to prevent end users from installing apps.

    1. Select iOS,tvOS, and Supervised in the filter.
    2. Choose "Some apps not allowed" or "Only some apps allowed" from the App Usage pop-up menu.
    3. Enter the name of the first app you want to restrict in the App Name field.
    4. Click Add to add additional apps as needed.
    5. Repeat steps c through d as needed.
  7. (iOS only) To restrict users from manually installing apps that are signed with an Apple Enterprise Developer certificate, do the following:
    1. Under the Restrictions payload, click Functionality.
    2. Select iOS in the filter.
    3. Restrict the Trusting new enterprise app authors setting.
  8. (Optional) (iOS only) To restrict users from accessing the App Store and only allow users to install or update apps from MDM, do the following:
    1. Under the Restrictions payload, click Apps.
    2. Select iOS in the filter.
    3. Restrict the Installing apps using Apple Configurator and iTunes setting.
  9. Click the Scope tab, and then configure the target devices or device groups.
    Note:

    If deploying restrictions for tvOS, depending on your organization's approach to setting up smart groups, you may want to create a separate profile for the tvOS app restrictions.

  10. Click Save .

The profile is distributed to the devices in the scope. If a device has two or more configuration profiles with restrictions, it will accept the most restrictive settings.