Device Management

RSS for tag

Allow administrators to securely and remotely configure enrolled devices using Device Management.

Device Management Documentation

Pinned Posts

Posts under Device Management tag

198 Posts
Sort by:
Post not yet marked as solved
0 Replies
20 Views
Hi, According to https://developer.apple.com/videos/play/wwdc2022/10096/, agent user can disable login item on Ventura. In enterprise environment, IT admin may want some processes are always running in launch daemon. Is there a MDM rule to forbidden agent user to disable special login item? Thank you!
Posted Last updated
.
Post not yet marked as solved
0 Replies
65 Views
We have a project that compiles an app for both x64 and arm64 Mac machines. This build is done via Visual Studio MSBuild with specific RIDs and Mac native code via xcode. Using the 'packages' application we build an distribution package, which contains the two pkgs for the specific architectures. The project contains settings to pick the correct PKG according to the architecture running the installation ('packages' will include a JavaScript script in the Distribution file for this). This all works just fine when running the final PKG manually. But when deploying via Intune as LOB this doesn't work well. It seems Intune will skip the complete Distribution file and will install all the PKGs included in to distribution package. The logfile shows that both x64 and arm64 are installed Install.log This will result in the x64 to be installed, and being overwritten by the arm64 installation. And a non-functional app on a x64 based Mac. We edited the preinstall.sh for both packages and do another architecture check and error-out when running on a wrong platform; but that doesn't work either: Intune will cancel the whole installation transaction when one pkg fails. Resulting in a non-installed package. What would be a good way to create an universal installation/distribution package with both architectures which would be able to be deployed via intune?
Posted
by JSdeJong.
Last updated
.
Post not yet marked as solved
2 Replies
81 Views
Hi, I'm implementing support for device attestation support on step-ca, and the attestation certificate, the leaf one in the x5c payload, doesn't include the nonce extension with the challenge token or the SHA256 version of it as it explains in https://developer.apple.com/videos/play/wwdc2022/10143/ Is this implemented? Can it be a device-related problem, meaning that older models do not support this?
Posted
by maraino.
Last updated
.
Post not yet marked as solved
8 Replies
5.1k Views
Since iOS15 most of our Enterprise-Apps do not launch anymore on MDM-devices. All fine in latest iOS14. Any idea why that happens? I guess it has something to do with the amount or size of included frameworks...maybe. {"app_name":"FiNAS","timestamp":"2021-09-21 11:24:12.00 +0200","app_version":"2.9.0.20210917-1106","slice_uuid":"a120fe26-2550-3039-9355-c2852c57ccc4","build_version":"169","platform":2,"bundleID":"com.schnulli.FiNAS2.internal.iOS","share_with_app_devs":0,"is_first_party":0,"bug_type":"309","os_version":"iPhone OS 15.0 (19A346)","incident_id":"8169FF8E-FEA9-48FC-8505-796AF63F2FFF","name":"FiNAS"} { "uptime" : 2900, "procLaunch" : "2021-09-21 11:23:51.6173 +0200", "procRole" : "Foreground", "version" : 2, "userID" : 501, "deployVersion" : 210, "modelCode" : "iPad5,4", "procStartAbsTime" : 69957265064, "coalitionID" : 578, "osVersion" : { "isEmbedded" : true, "train" : "iPhone OS 15.0", "releaseType" : "User", "build" : "19A346" }, "captureTime" : "2021-09-21 11:24:12.1732 +0200", "incident" : "8169FF8E-FEA9-48FC-8505-796AF63F2FFF", "bug_type" : "309", "pid" : 474, "procExitAbsTime" : 70450601166, "cpuType" : "ARM-64", "procName" : "FiNAS", "procPath" : "\/private\/var\/containers\/Bundle\/Application\/BF8A332E-4567-416F-BA1C-716EDF28CC1C\/FiNAS.app\/FiNAS", "bundleInfo" : {"CFBundleShortVersionString":"2.9.0.20210917-1106","CFBundleVersion":"169","CFBundleIdentifier":"com.schnulli.FiNAS2.internal.iOS","DTAppStoreToolsBuild":"12E507"}, "storeInfo" : {"deviceIdentifierForVendor":"B04DD374-A3C4-4921-8701-C951615784FE","thirdParty":true}, "parentProc" : "launchd", "parentPid" : 1, "coalitionName" : "com.schnulli.FiNAS2.internal.iOS", "crashReporterKey" : "4d203f3c26e70f0c9a5442f39df3402b663b7719", "basebandVersion" : "11.01.02", "isCorpse" : 1, "exception" : {"codes":"0x0000000000000000, 0x0000000000000000","rawCodes":[0,0],"type":"EXC_CRASH","signal":"SIGKILL"}, "termination" : {"flags":6,"code":2343432205,"namespace":"FRONTBOARD","reasons":["<RBSTerminateContext| domain:10 code:0x8BADF00D explanation:process-launch watchdog transgression: application<com.schnulli.FiNAS2.internal.iOS>:474 exhausted real (wall clock) time allowance of 20.00 seconds","ProcessVisibility: Foreground","ProcessState: Running","WatchdogEvent: process-launch","WatchdogVisibility: Foreground","WatchdogCPUStatistics: (","\"Elapsed total CPU time (seconds): 22.970 (user 22.970, system 0.000), 38% CPU\",","\"Elapsed application CPU time (seconds): 0.056, 0% CPU\"",") reportType:CrashLog maxTerminationResistance:Interactive>"]}, "faultingThread" : 0, "threads" : [{"triggered":true,"id":25662,"threadState":{"x":[{"value":1},{"value":0},{"value":6159718480},{"value":6159718480},{"value":0},{"value":0},{"value":0},{"value":0},{"value":6159718064},{"value":6159718072},{"value":4},{"value":1},{"value":1},{"value":576460752303505408},{"value":81920},{"value":23434228096446320},{"value":92},{"value":1034064},{"value":0},{"value":6159718096},{"value":4309237856},{"value":520552456},{"value":3},{"value":6159719800},{"value":6159718176},{"value":0},{"value":6159719392},{"value":6159719640},{"value":1}],"flavor":"ARM_THREAD_STATE64","lr":{"value":4311487112},"cpsr":{"value":536870912},"fp":{"value":6159718048},"sp":{"value":6159718032},"esr":{"value":1442840704,"description":" Address size fault"},"pc":{"value":4311293032,"matchesCrashFrame":1},"far":{"value":4311859200}},"frames":[{"imageOffset":72808,"imageIndex":0},{"imageOffset":266888,"imageIndex":0},{"imageOffset":70936,"imageIndex":0},{"imageOffset":137440,"imageIndex":0},{"imageOffset":97984,"imageIndex":0},{"imageOffset":150060,"imageIndex":0},{"imageOffset":51988,"imageIndex":0},{"imageOffset":21820,"imageIndex":0},{"imageOffset":90204,"imageIndex":0},{"imageOffset":59328,"imageIndex":0},{"imageOffset":136252,"imageIndex":0},{"imageOffset":21040,"imageIndex":0},{"imageOffset":61668,"imageIndex":0},{"imageOffset":135468,"imageIndex":0},{"imageOffset":82764,"imageIndex":0},{"imageOffset":43720,"imageIndex":0},{"imageOffset":135016,"imageIndex":0},{"imageOffset":60240,"imageIndex":0},{"imageOffset":89268,"imageIndex":0},{"imageOffset":210072,"imageIndex":0},{"imageOffset":21040,"imageIndex":0},{"imageOffset":38752,"imageIndex":0},{"imageOffset":145524,"imageIndex":0},{"imageOffset":103100,"imageIndex":0},{"imageOffset":98672,"imageIndex":0}]}], "usedImages" : [ { "source" : "P", "arch" : "arm64", "base" : 4311220224, "size" : 344064, "uuid" : "d7a0282e-93de-3a1e-9813-27e84517cc96", "path" : "\/usr\/lib\/dyld", "name" : "dyld" } ], "sharedCache" : { "base" : 6442926080, "size" : 2184413184, "uuid" : "8157e9d4-d94e-313e-8400-6216ea7efde8" }, "vmSummary" : "ReadOnly portion of Libraries: Total=2352K resident=0K(0%) swapped_out_or_unallocated=2352K(100%)\nWritable regions: Total=2128K written=0K(0%) resident=0K(0%) swapped_out=0K(0%) unallocated=2128K(100%)\n\n VIRTUAL REGION \nREGION TYPE SIZE COUNT (non-coalesced) \n=========== ======= ======= \nSTACK GUARD 16K 1 \nStack 1008K 1 \nVM_ALLOCATE 1.0G 1 \nVM_ALLOCATE (reserved) 32K 2 reserved VM address space (unallocated)\n__DATA 176K 3 \n__DATA_CONST 112K 2 \n__LINKEDIT 416K 3 \n__TEXT 1952K 2 \ndyld private memory 1024K 1 \nmapped file 9568K 22 \n=========== ======= ======= \nTOTAL 1.0G 38 \nTOTAL, minus reserved VM space 1.0G 38 \n", "legacyInfo" : { "threadTriggered" : { } }, "trialInfo" : { "rollouts" : [ ], "experiments" : [ ] } }
Posted
by SupaBasti.
Last updated
.
Post not yet marked as solved
0 Replies
79 Views
I forgot my Admin Password and I am logged into a basic account without admin rights, so I started searching for admin-account-password.bypass-options, and I found a way to reset it by shutting the iMac down, restarting it, and pressing "Command" + "R", until the loading bar appears. Afterwards, there should be an "Utilities" button on the dock, but I can't find it. I was supposed to click "Utilities", then "Terminal", and then type in "reset password", but I can't find the "Utilities" button. I downloaded MacOS Ventura Developer Beta 2, so maybe this method only works with MacOS X and later but not MacOS Ventura so I wanted to ask you guys, if someone could help me out. Thanks for reading this article and I hope you know the answer!
Posted Last updated
.
Post not yet marked as solved
2 Replies
71 Views
The TokenUpdateRequest documentation to an MDM suggests it may be possible for devices to send additional token update messages to the check-in server. "... the iOS device may now send additional Token Update messages to the check-in server at any time while it has a valid MDM enrollment." https://developer.apple.com/documentation/devicemanagement/tokenupdaterequest (1) What triggers are there for the device to resend the TokenUpdateRequest and/or how often it occurs? Additionally the mdm command documentation mentions retry behavior for the put/check-in.  "If the device disconnects from the MDM server while processing a command, it caches the result of the command and reports the result when it reconnects." https://developer.apple.com/documentation/devicemanagement/implementing_device_management/sending_mdm_commands_to_a_device (2) I would like to know the retry policy (maximum number of times, frequency) in this case.
Posted
by samuel_f.
Last updated
.
Post not yet marked as solved
2 Replies
401 Views
I got a client request to build a parental control app like Parentkit(https://parentkit.co/) or Ourpact (http://ourpact.com/) to help parents manage their children devices. After doing some research online, I figured that it could be a MDM feature and requires an apple enterprise account for implementation. However, Apple developer program support does not allow me to create an enterprise account for developing a MDM system for non-company members. They also said that any non-company use of MDM is not allowed by Apple. If what they said is true, MDM implementation should not be allowed in the abovementioned parental control apps. Would they be using other means without the need to register an enterprise account to archieve real-time, over-the-air control on device restriction? If that is the case, what else I should read and work on to build a parental control apps like those without registering an enterprise account?
Posted
by ma_eric.
Last updated
.
Post not yet marked as solved
2 Replies
147 Views
For the Apps & Books Notifications API, I'm looking for more information on the expected values for tracking assignments and user events. For assignment tracking, the documentation lists: "result": "SUCCESS", "type": "ASSOCIATE" "result": "SUCCESS", "type": "DISASSOCIATE" I assume "ASSOCIATE" and "DISASSOCIATE" are the supported values for "type". Also, "result" is either "SUCCESS" or "FAILURE"? As for tracking user events, the documentation lists: "result": "SUCCESS", "type": "CREATE", I assume "CREATE" , "UPDATE" , and "RETIRE" are the supported values for "type" and that "SUCCESS" and "FAILURE" are the supported values for "result"? Looking to get confirmation on this. Thank you! Best, Adam
Posted
by abhenry.
Last updated
.
Post not yet marked as solved
0 Replies
54 Views
What were you doing on the device just before the crash occurred? Pushed an App update for the autonomous kiosk enabled mode via MDM Which of the following did you encounter on-screen when the system crash occurred Stuck on Black Screen (Had to Force Reboot device) Steps to Reproduce: Created two versions of the enterprise app, which will enter guided access mode on launch. With MDM, we have created a Autonomous Kiosk Profile with the app(say Version 1) we created and pushed the profile to the device . Checked that the profile payload is in correct format . On Launching the App , the device enters kiosk mode and i was unable to exit the app (Expected Behaviour). Other Functionalities of the app worked good. Now pushed another enterprise app of higher version (say Version 2) . Actual Behaviour : App got to background and app is seen to updating with a loading symbol over it. After App got successfully updated, App Launches and done. The Device hangs. Cant touch anything or move to background or lock the screen. I could only get back the device only after starting remote Restart command from MDM. Expected Behaviour : On App update , App should get updated and then App should be again relaunched automatically on successful update . System shouldn’t be freezed. can anyone help me with this case? Whether this is the behaviour or anything to add in guided access enabled app? Thanks in Advance
Posted Last updated
.
Post not yet marked as solved
0 Replies
75 Views
Hello, what's the status of managing books with UserEnrollment context ? I remember this used to work with a glitch : end user has to log in into Books with his/her managed Apple id (which could be problematic as you can't have both your books and organization books). But I'm currently not able to make it work - A VPP user is associated (silent invite) to the right managed apple id, enough time (more than an hour) happened since a license has been associated to the VPP user and fetching the license from the API shows it has been set properly. But installing the app via MDM always ends with error: <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>Command</key> <dict> <key>MediaType</key> <string>Book</string> <key>RequestType</key> <string>InstallMedia</string> <key>iTunesStoreID</key> <integer>1525146196</integer> </dict> <key>CommandUUID</key> <string>e802d682-e8b1-6253-04f5-736dab7ecd13</string> </dict> </plist> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>CommandUUID</key> <string>e802d682-e8b1-6253-04f5-736dab7ecd13</string> <key>EnrollmentID</key> <string>971BB6F0-CA43-4B5E-9A1A-7BEF7A7BC286</string> <key>ErrorChain</key> <array> <dict> <key>ErrorCode</key> <integer>12047</integer> <key>ErrorDomain</key> <string>MDMErrorDomain</string> <key>LocalizedDescription</key> <string>A VPP purchase record for the item could not be found.</string> <key>USEnglishDescription</key> <string>A VPP purchase record for the item could not be found.</string> </dict> <dict> <key>ErrorCode</key> <integer>2615</integer> <key>ErrorDomain</key> <string>DeviceManagement.error</string> <key>LocalizedDescription</key> <string>Could not find Volume Purchase Programme assignment.</string> </dict> </array> <key>Status</key> <string>Error</string> </dict> </plist>``` Is this still a supported workflow ? Installing an App works without any issue in the same context.
Posted
by sysedit.
Last updated
.
Post not yet marked as solved
1 Replies
99 Views
Our MDM server is hosted with our enterprise. All the devices pass through the proxy & firewall server to reach it. Due to some misconfiguration, our proxy server responded with 401 to all the requests. Later we noticed that the MDM profile is missing from some of the devices. On checking with the MDM team, they forwarded us to Apple documents saying this is out of their control and 401 response would remove MDM profile. Could this be handled in such a way that, MDM server could have some control over this, say only MDM server can send 401 to remove the profile. Has anyone faced this. Any help this would be appreciated.
Posted Last updated
.
Post not yet marked as solved
1 Replies
122 Views
Hi there, I know we can configure Default and Data APN via a .mobileconfig file but I don't see any way to configure the APN associated with a Personal Hotspot connection in this way. Is this possible at all? Thanks Alan
Posted
by AlanC74.
Last updated
.
Post not yet marked as solved
1 Replies
196 Views
For creating APNS certificate, we use a signed CSR from our MDM vendor which is a .plist file. We were using this for quite some years now. But currently APNS portal throws error saying invalid file type (as attached below) Is the Portal updated to support only .csr / .txt / .rtf? Can anyone help to use the correct file format. (P.S: Works if we edit the extension & upload it)
Posted Last updated
.
Post not yet marked as solved
1 Replies
97 Views
Some customers wants to add a remote file address in the Files App -> Connect to Server option. For now , We cant find any api's to add this to the device via any Commands /Profiles . Is it not at all possible to add this to Files app or am i missing something? If it is not yet supported and no apis available , Will it be available in Future ? Needed some help here.
Posted Last updated
.
Post not yet marked as solved
1 Replies
131 Views
Is software update error 41 the equivalent of a theoretical “DownloadAlreadyPresent” UpdateResults item? When MDM sends ScheduleOSUpdate w/ DownloadOnly to a device that had previously downloaded the update by itself (device has automatic update downloads enabled), it returns: The operation couldn't be completed. (com.apple.softwareupdateservices.errors error 41 Should MDM treat that as a success and move on to InstallASAP?
Posted
by Elektrik.
Last updated
.
Post not yet marked as solved
0 Replies
123 Views
Unable to install "xxxx" Code: -402620388 User Info: {   IDERunOperationFailingWorker = IDEInstalliPhoneLauncher; } -- No code signature found. Domain: com.apple.dt.MobileDeviceErrorDomain Code: -402620388 User Info: {   DVTRadarComponentKey = 261622;   MobileDeviceErrorCode = "(0xE800801C)";   "com.apple.dtdevicekit.stacktrace" = ( 0  DTDeviceKitBase           0x000000012004ac41 DTDKCreateNSErrorFromAMDErrorCode + 220 1  DTDeviceKitBase           0x000000012008732f __90-[DTDKMobileDeviceToken installApplicationBundleAtPath:withOptions:andError:withCallback:]_block_invoke + 155 2  DVTFoundation            0x0000000110cb387e DVTInvokeWithStrongOwnership + 71 3  DTDeviceKitBase           0x0000000120087057 -[DTDKMobileDeviceToken installApplicationBundleAtPath:withOptions:andError:withCallback:] + 1409 4  IDEiOSSupportCore          0x000000011ff60978 __118-[DVTiOSDevice(DVTiPhoneApplicationInstallation) processAppInstallSet:appUninstallSet:installOptions:completionBlock:]_block_invoke.301 + 3520 5  DVTFoundation            0x0000000110dec3ba __DVT_CALLING_CLIENT_BLOCK__ + 7 6  DVTFoundation            0x0000000110decece __DVTDispatchAsync_block_invoke + 196 7  libdispatch.dylib          0x00007ff81b8e00cc _dispatch_call_block_and_release + 12 8  libdispatch.dylib          0x00007ff81b8e1317 _dispatch_client_callout + 8 9  libdispatch.dylib          0x00007ff81b8e7317 _dispatch_lane_serial_drain + 672 10 libdispatch.dylib          0x00007ff81b8e7dfd _dispatch_lane_invoke + 366 11 libdispatch.dylib          0x00007ff81b8f1eee _dispatch_workloop_worker_thread + 753 12 libsystem_pthread.dylib       0x00007ff81ba94fd0 _pthread_wqthread + 326 13 libsystem_pthread.dylib       0x00007ff81ba93f57 start_wqthread + 15 ); } -- Analytics Event: com.apple.dt.IDERunOperationWorkerFinished : {   "device_model" = "iPhone12,1";   "device_osBuild" = "16.0 (20A5283p)";   "device_platform" = "com.apple.platform.iphoneos";   "launchSession_schemeCommand" = Run;   "launchSession_state" = 1;   "launchSession_targetArch" = arm64;   "operation_duration_ms" = 28218;   "operation_errorCode" = "-402620388";   "operation_errorDomain" = "com.apple.dt.MobileDeviceErrorDomain";   "operation_errorWorker" = IDEInstalliPhoneLauncher;   "operation_name" = IDEiPhoneRunOperationWorkerGroup;   "param_consoleMode" = 0;   "param_debugger_attachToExtensions" = 0;   "param_debugger_attachToXPC" = 1;   "param_debugger_type" = 5;   "param_destination_isProxy" = 0;   "param_destination_platform" = "com.apple.platform.iphoneos";   "param_diag_MainThreadChecker_stopOnIssue" = 0;   "param_diag_MallocStackLogging_enableDuringAttach" = 0;   "param_diag_MallocStackLogging_enableForXPC" = 1;   "param_diag_allowLocationSimulation" = 1;   "param_diag_gpu_frameCapture_enable" = 2;   "param_diag_gpu_shaderValidation_enable" = 0;   "param_diag_gpu_validation_enable" = 1;   "param_diag_memoryGraphOnResourceException" = 0;   "param_diag_queueDebugging_enable" = 1;   "param_diag_runtimeProfile_generate" = 0;   "param_diag_sanitizer_asan_enable" = 0;   "param_diag_sanitizer_tsan_enable" = 0;   "param_diag_sanitizer_tsan_stopOnIssue" = 0;   "param_diag_sanitizer_ubsan_stopOnIssue" = 0;   "param_diag_showNonLocalizedStrings" = 0;   "param_diag_viewDebugging_enabled" = 1;   "param_diag_viewDebugging_insertDylibOnLaunch" = 1;   "param_install_style" = 0;   "param_launcher_UID" = 2;   "param_launcher_allowDeviceSensorReplayData" = 0;   "param_launcher_kind" = 0;   "param_launcher_style" = 0;   "param_launcher_substyle" = 0;   "param_runnable_appExtensionHostRunMode" = 0;   "param_runnable_productType" = "com.apple.product-type.application";   "param_runnable_type" = 2;   "param_testing_launchedForTesting" = 0;   "param_testing_suppressSimulatorApp" = 0;   "param_testing_usingCLI" = 0;   "sdk_canonicalName" = "iphoneos16.0";   "sdk_osVersion" = "16.0";   "sdk_variant" = iphoneos; } --
Posted
by xiaoliuTx.
Last updated
.
Post not yet marked as solved
0 Replies
100 Views
You explain at 6:08 that "In iOS and iPadOS 15, we used a simple access token authorization mechanism to allow the MDM server to verify the identity of users. What exactly was the "simple access token authorization mechanism"? I would like to know the outline of the mechanism. If you have a URL that explains the mechanism, please send it to us. Thank you,
Posted
by Yuu22.
Last updated
.
Post not yet marked as solved
1 Replies
2.3k Views
Seems like there's a bug with code signing in Xcode... will load package on a simulator, but not on an actual device after creating an .ipa for development testing. There should be an update to fix this error. Details as follows: Details Domain: com.apple.dt.MobileDeviceErrorDomain Code: -402620388 User Info: {     IDERunOperationFailingWorker = IDEInstalliPhoneLauncher; } -- No code signature found. Domain: com.apple.dt.MobileDeviceErrorDomain Code: -402620388 User Info: {     DVTRadarComponentKey = 261622;     MobileDeviceErrorCode = "(0xE800801C)";     "com.apple.dtdevicekit.stacktrace" = ( 0   DTDeviceKitBase                     0x0000000125237316 DTDKCreateNSErrorFromAMDErrorCode + 220 1   DTDeviceKitBase                     0x000000012527584a __90-[DTDKMobileDeviceToken installApplicationBundleAtPath:withOptions:andError:withCallback:]_block_invoke + 155 2   DVTFoundation                       0x00000001064b6ed4 DVTInvokeWithStrongOwnership + 71 3   DTDeviceKitBase                     0x0000000125275594 -[DTDKMobileDeviceToken installApplicationBundleAtPath:withOptions:andError:withCallback:] + 1420 4   IDEiOSSupportCore                   0x0000000117dedb4e __118-[DVTiOSDevice(DVTiPhoneApplicationInstallation) processAppInstallSet:appUninstallSet:installOptions:completionBlock:]_block_invoke.292 + 3508 5   DVTFoundation                       0x00000001065eac37 __DVT_CALLING_CLIENT_BLOCK__ + 7 6   DVTFoundation                       0x00000001065ec3a3 __DVTDispatchAsync_block_invoke + 931 7   libdispatch.dylib                   0x00007fff2035a623 _dispatch_call_block_and_release + 12 8   libdispatch.dylib                   0x00007fff2035b806 _dispatch_client_callout + 8 9   libdispatch.dylib                   0x00007fff203615ea _dispatch_lane_serial_drain + 606 10  libdispatch.dylib                   0x00007fff203620ad _dispatch_lane_invoke + 366 11  libdispatch.dylib                   0x00007fff2036bc0d _dispatch_workloop_worker_thread + 811 12  libsystem_pthread.dylib             0x00007fff2050245d _pthread_wqthread + 314 13  libsystem_pthread.dylib             0x00007fff2050142f start_wqthread + 15 ); } -- Analytics Event: com.apple.dt.IDERunOperationWorkerFinished : {     "device_model" = "iPhone8,4";     "device_osBuild" = "14.6 (18F72)";     "device_platform" = "com.apple.platform.iphoneos";     "launchSession_schemeCommand" = Run;     "launchSession_state" = 1;     "launchSession_targetArch" = arm64;     "operation_duration_ms" = 1948;     "operation_errorCode" = "-402620388";     "operation_errorDomain" = "com.apple.dt.MobileDeviceErrorDomain";     "operation_errorWorker" = IDEInstalliPhoneLauncher;     "operation_name" = IDEiPhoneRunOperationWorkerGroup;     "param_consoleMode" = 0;     "param_debugger_attachToExtensions" = 0;     "param_debugger_attachToXPC" = 1;     "param_debugger_type" = 5;     "param_destination_isProxy" = 0;     "param_destination_platform" = "com.apple.platform.iphoneos";     "param_diag_MainThreadChecker_stopOnIssue" = 0;     "param_diag_MallocStackLogging_enableDuringAttach" = 0;     "param_diag_MallocStackLogging_enableForXPC" = 1;     "param_diag_allowLocationSimulation" = 1;     "param_diag_gpu_frameCapture_enable" = 0;     "param_diag_gpu_shaderValidation_enable" = 0;     "param_diag_gpu_validation_enable" = 0;     "param_diag_memoryGraphOnResourceException" = 0;     "param_diag_queueDebugging_enable" = 1;     "param_diag_runtimeProfile_generate" = 0;     "param_diag_sanitizer_asan_enable" = 0;     "param_diag_sanitizer_tsan_enable" = 0;     "param_diag_sanitizer_tsan_stopOnIssue" = 0;     "param_diag_sanitizer_ubsan_stopOnIssue" = 0;     "param_diag_showNonLocalizedStrings" = 0;     "param_diag_viewDebugging_enabled" = 1;     "param_diag_viewDebugging_insertDylibOnLaunch" = 1;     "param_install_style" = 0;     "param_launcher_UID" = 2;     "param_launcher_allowDeviceSensorReplayData" = 0;     "param_launcher_kind" = 0;     "param_launcher_style" = 0;     "param_launcher_substyle" = 0;     "param_runnable_appExtensionHostRunMode" = 0;     "param_runnable_productType" = "com.apple.product-type.application";     "param_runnable_swiftVersion" = "5.5";     "param_runnable_type" = 2;     "param_testing_launchedForTesting" = 0;     "param_testing_suppressSimulatorApp" = 0;     "param_testing_usingCLI" = 0;     "sdk_canonicalName" = "iphoneos15.0";     "sdk_osVersion" = "15.0";     "sdk_variant" = iphoneos; } -- System Information macOS Version 11.6 (Build 20G165) Xcode 13.0 (19234) (Build 13A233) Timestamp: 2021-10-20T23:50:45-04:00
Posted
by LeoNTRS.
Last updated
.
Post not yet marked as solved
0 Replies
121 Views
TLDR; does a profile need to be deployed with an MDM server? Is there a way to add a configuration profile (.mobileconfig file) to Xcode device emulator without an MDM server (aka drag and drop the profile into the emulator)? Because right now I am getting an error saying that the "profile must be installed by an Mobile Device Management server". I am asking because I'm doing a proof of concept project and am trying to perform testing before I bring in the MDM server portion.
Posted
by austinp1.
Last updated
.
Post not yet marked as solved
2 Replies
319 Views
I'm curious about suggested workflows for a 3rd party ACME server handling a request for a managed device. Specifically, when the MDM server does not control the ACME server like it likely would when using the ACME payload for the MDM client identity. i.e., an organization with a CA that can distribute client identities using ACME; how should ACME servers validate the request is authorized? The server, of course, would be able to validate that the attestation is valid from Apple, but how would an ACME server validate that the request is authorized for a device? I would assume that the ACME server would use the ClientIdentifier key similarly to a SCEP challenge. And that identifier should be populated in MDM either as a static challenge or dynamically fetched by MDM from the ACME service? Or possibly that the ACME service would need a connection (i.e., through a restful API) to the MDM server to validate it is a device under management and fetch the generated client identifier and therefore determine that the device is authorized to request certs from the enterprise CA? It would be great if the device could attest that it is under management and have an OID for the check-in URL or the APNS topic is registered against. This might eliminate the ACME server's need to authorize a request against the MDM server or help improves the validation of the request etc. In any case, I'm curious on folks' thoughts around this in general :)
Posted Last updated
.