Mitigating Tampering with the Jamf Trust App on iOS and iPadOS - Jamf Security Cloud Portal Setup Guide

Jamf Security Cloud Portal Setup Guide

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
By applying certain deployment settings, you can configure supervised iOS and iPadOS devices to prevent users from circumventing policies. These settings are part of a group of properties called the Restrictions payload within the device configuration profile managed by your MDM software. The configuration profile should include restrictions on the the actions below:
  • Uninstalling the Jamf Trust App

  • Disrupting the connection to the device by disabling data

  • Changing the date and time to circumvent scheduled content filtering policies

You can view all of the properties in the Restrictions payload in the Apple Device Management Profile page.

Requirements
  • Supervised devices with iOS 16.6 or later or iPadOS 16.6 or later

  • Target devices must be enrolled with an MDM software, such as Jamf Pro or Jamf School

  1. In your MDM software, navigate to the configuration profiles.
  2. Create a new profile, or select a profile to edit.
  3. Mark the Jamf Trust App as nonremovable.
  4. Disable allowCellularDataModification.
  5. Enable forceAutomaticDateAndTime.