Bypass stolen device security delay for BYOD device enrolment into an MDM (MicroMDM) solution.

Hi,

Is there any possible Apple approved way or workaround if we can bypass the stolen device protection delay of 1 hour when a user try to install our MDM server's enrolment profile on unknown location?

I do not want managed apple account solution. I need solution for BYOD devices not for company owned.

Thank you, Software Engineer - iOS

Answered by Device Management Engineer in 887080022

Stolen Device Protection prevents installation of configuration profiles or enrollment in device management for one hour when the device is in an unfamiliar location. This is intended to protect users and their data if their device is stolen along with its passcode.

At the same time, this can be inconvenient for people going through onboarding at a new workplace or school, where it's an unfamiliar location and they are enrolling their device in device management.

It would be ideal to avoid that inconvenience when the enrollment is legitimate. However there needs to be a way for the unmanaged device to differentiate between these two cases. If you have a specific suggestion for improving the legitimate case that does not also lower the protections in the case of a stolen device, please file feedback. We'd love to hear your suggestion!

Hi,

Is there any possible way we can install enrolment provisioning profile using iOS app using User/Account Authentication Enrolment such as described in this thread:

https://developer.apple.com/documentation/devicemanagement/implementing-the-oauth2-authentication-user-enrollment-flow

Stolen Device Protection prevents installation of configuration profiles or enrollment in device management for one hour when the device is in an unfamiliar location. This is intended to protect users and their data if their device is stolen along with its passcode.

At the same time, this can be inconvenient for people going through onboarding at a new workplace or school, where it's an unfamiliar location and they are enrolling their device in device management.

It would be ideal to avoid that inconvenience when the enrollment is legitimate. However there needs to be a way for the unmanaged device to differentiate between these two cases. If you have a specific suggestion for improving the legitimate case that does not also lower the protections in the case of a stolen device, please file feedback. We'd love to hear your suggestion!

Bypass stolen device security delay for BYOD device enrolment into an MDM (MicroMDM) solution.
 
 
Q