Restricting Access to Device Functionality

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

The Restrictions payload allows you to prevent end users from accessing device functionality. For example, you can add a restriction to prevent end users from using the camera or using AirDrop to send files to other nearby devices.

Note:

Some functionality cannot be restricted on personally owned devices. For example, you can restrict the camera and screenshots on institutionally owned devices, but you cannot do so on personally owned devices.

  1. On the Configuration Profiles page, do one of the following:
    • Click New to create a new configuration profile.

    • Select an existing configuration profile and click Edit .

  2. Click the Restrictions payload, and then click Functionality.
  3. Jamf recommends configuring the following restrictions settings for mobile devices:
    • Use of cameraRestrict
    • AirDropRestrict
    • Documents from managed sources open in unmanaged destinationsRestrict
    • Documents from unmanaged sources open in managed destinationsRestrict
    • Managed apps can use iCloud syncRestrict
    • Pasteboard respects managed/unmanaged document restrictionsEnforce
  4. Click the Scope tab and configure the scope of the configuration profile.
  5. Click Save .