- In Jamf School, navigate to Profiles > Overview in the sidebar.
- Click + Create Profile.
- Select the operating system you want to make the profile for or select Upload custom profile.
- Select the type of enrollment you want to make the profile for.
- Enter a name in the Profile name field and configure the additional settings as needed, including the time filter.
- Click Finish.
- In the list of payloads on the left side of the pane, locate the operating system payload category for the devices you are configuring a profile for and click the Restrictions payload.
- Click Configure to configure basic settings, including the allowed functionality and media content.Best Practice:If you want to restrict network access, Jamf recommends configuring and deploying a Wi-Fi or network configuration profile to devices before deploying the restrictions profile so the devices do not lose connectivity. If the following settings are configured in a restrictions profile before a Wi-Fi or network configuration profile is deployed, the devices will lose connectivity and may not be able to reconnect without manual intervention.
(iOS and iPadOS devices) In the Connectivity section under the Functionality tab, the Only allow devices to join Wi-Fi networks configured using a profile checkbox or the Force Wi-Fi to be on checkbox is selected.
(macOS devices) Under the Preferences tab, the Restrict Items, Disable selected preferences, and WiFi checkboxes are selected.
For information about configuring Wi-Fi profiles and network configuration profiles, see Wi-Fi.
- (Optional) To prevent users from disabling Bluetooth, deselect the Allow modifications to Bluetooth settings (including pairing new devices) checkbox.
- (Optional) To defer software updates, select the Defer Software Updates for __ days checkbox and enter the number of days to defer the software update.
- (Optional) To prevent users from installing apps from untrusted sources, deselect the Allow trusting new enterprise app authors checkbox.Note:
This setting does not remove apps that have already been installed. This will also affect trusting your own enterprise apps, so make sure this option is enabled when you install enterprise apps.
- In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
- Configure the scope of the profile by clicking the + icon and adding device groups to the profile scope using the pop-up menu.
- Click the Settings
icon on the right side of the page, and do one of the following:
To install the profile on devices automatically, click Change to automatic installation for all groups.
To allow users to install the profile themselves, click Change to on-demand installation for all groups. The profile will be available for users to install in the Jamf Teacher or Jamf School Student apps.
- Click Save.