- Passcode Enforcement —Requires end users to use a secure password to log in to devices. For more information, see Passcodes and passwords in Apple Platform Security.
- Functionality Restrictions —Prevents end users from accessing device functions that may compromise security
In many environments, best practices for payload management include creating unique configuration profiles to achieve separate goals. This approach reduces complexity in terms of configuring the scope of profiles and identifying issues when troubleshooting.
Creating separate configuration profiles for different purposes allows for easier testing and scoping, and makes future changes easier because you can adjust individual, focused configuration profiles and payloads. For example, you may want to create one configuration profile for passcode enforcement and one for restrictions.
For more information on optimizing payload planning and management, see Plan your configuration profiles for Apple devices in Apple Platform Deployment.
You can distribute mobile device configuration profiles during Automated Device Enrollment. This allows you to install configuration profiles before end users complete the Setup Assistant. For example, you can distribute a configuration profile that enforces a passcode policy that end users must comply with during the Setup Assistant. For more information, see Creating a PreStage Enrollment to Deploy the Automated Device Enrollment Experience to Mobile Devices.