<?xml version="1.0" encoding="utf-8"?><rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Ivanti Blog: Posts by </title><description /><language>en</language><atom:link rel="self" href="https://www.ivanti.com/blog/authors/yosune-baltra/rss" /><link>https://www.ivanti.com/blog/authors/yosune-baltra</link><item><guid isPermaLink="false">ce8d12d4-669e-4bab-be1f-3bdffdcbdeda</guid><link>https://www.ivanti.com/blog/apple-business-manager-device-migration-what-you-need-to-know</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint Management</category><title>Apple Business Manager Device Migration: What You Need to Know</title><description>&lt;p&gt;With Apple’s OS 26 release, IT admins using Apple Business Manager (ABM) or Apple School Manager (ASM) have a great new tool in their toolbelt: device migration. This makes switching devices between MDM platforms much easier, with minimal disruption for end users.&lt;/p&gt;

&lt;p&gt;Here, we’ll unpack what you need to know, and how &lt;a href="https://www.ivanti.com/blog/apple-wwdc25-announcements"&gt;ABM device migration&lt;/a&gt; makes it incredibly easy to switch to &lt;a href="https://www.ivanti.com/products/ivanti-neurons-for-mdm"&gt;Ivanti Neurons for MDM&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;Key ABM device migration features&lt;/h2&gt;

&lt;p&gt;Apple’s new ABM device migration features make it easier to move devices between different &lt;a href="https://www.ivanti.com/use-cases/ensure-mobile-device-management"&gt;MDM solutions&lt;/a&gt;, without manual steps or interrupting users.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;No manual re-enrollment.&lt;/strong&gt; You can transfer devices from one MDM server to another, or from one vendor’s MDM to another (including Ivanti Neurons for MDM), without erasing or manually re-enrolling devices. All existing user data and device configurations will automatically be applied during migration. The end user will be able to complete the re-enrollment with two guided clicks: one for restarting the device and one for re-enrollment into the new MDM.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enrollment deadlines.&lt;/strong&gt; This is the newest feature introduced by Apple in ABM and ASM. You can set and enforce deadlines for moving devices to the new MDM instance. If a device isn’t enrolled in time, it will be locked and the user will be asked to finish enrollment. With this deadline you will be able to trigger the automated process for re-enrollment in the new MDM. It will prompt the end user with screens to complete the re-enrollment seamlessly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;End user experience.&lt;/strong&gt; The end user experience won't notice any changes during migration, except if the enrollment deadline has passed. Once the migration is complete, the user will get a prompt to restart the device. After the device restarts, the end user will get a prompt to re-enroll the device in the new management solution, which takes one click.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;API-driven.&lt;/strong&gt; The process can also be managed through the ABM or ASM portal using Apple’s new APIs (which you need to activate). This means that customers that use an API infrastructure can &lt;a href="https://developer.apple.com/documentation/applebusinessmanagerapi/create-an-orgdeviceactivity" rel="noopener" target="_blank"&gt;bulk assign or unassign devices&lt;/a&gt; with the new Apple ABM APIs without having to access the ABM console.&lt;/p&gt;

&lt;h2&gt;ABM device migration use cases&lt;/h2&gt;

&lt;p&gt;When would you use this feature? Here are a few key use cases.&lt;/p&gt;

&lt;h3&gt;Cloud migration&lt;/h3&gt;

&lt;p&gt;ABM device migration allows you to move from on-premises MDM to cloud-based MDM without re-enrolling devices. For Ivanti customers, this feature makes it easy to move to Ivanti Neurons for MDM from Ivanti Endpoint Manager (for MacOS) or Ivanti Endpoint Manager Mobile (for all Apple devices).&lt;/p&gt;

&lt;h3&gt;Switching MDM providers&lt;/h3&gt;

&lt;p&gt;ABM device migration simplifies switching from another MDM provider to Ivanti Neurons for MDM, or consolidating all type of devices (Android, Windows, Apple,) on a single platform from MDMs that only manage Apple devices, such as Jamf or Kandji.&lt;/p&gt;

&lt;h3&gt;School district device realignment&lt;/h3&gt;

&lt;p&gt;Educational institutions can realign devices between departments or campuses while maintaining all Apple management and assignment settings.&lt;/p&gt;

&lt;h3&gt;Mergers, acquisitions or reorganizations&lt;/h3&gt;

&lt;p&gt;If you’re combining or separating IT infrastructure due to M&amp;amp;A or reorganization, you can move devices to new MDM environments with minimal user disruption.&lt;/p&gt;

&lt;h2&gt;Setting up ABM device migration: a step-by-step guide&lt;/h2&gt;

&lt;h3&gt;Before you begin&lt;/h3&gt;

&lt;p&gt;There are two important considerations before you begin:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Device migration &lt;em&gt;only&lt;/em&gt; works on devices running iOS 26, iPadOS 26 or macOS26 (or later). Make sure your devices are updated first.&lt;/li&gt;
	&lt;li&gt;You don’t need to make any changes on the MDM server side to support device migration, but target MDM servers should be prepared to receive new device assignments and enrollment requests.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Device Migration via the ABM console&lt;/h3&gt;

&lt;p&gt;Sign in to Apple Business Manager and navigate to &lt;strong&gt;Devices&lt;/strong&gt;. From here, use the search bar to find the target devices by serial number, order number or other identifiers. Then, select the devices you wish to set a migration deadline for.&lt;/p&gt;

&lt;p&gt;Next, review the device details: Click on the device to open its detailed view and confirm that it is assigned to the correct MDM server. You can now set the migration deadline.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture1.png"&gt;&lt;/p&gt;

&lt;p&gt;From here, click on &lt;strong&gt;Assign Device Management&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture2.png"&gt;&lt;/p&gt;

&lt;p&gt;In the pop-up, you can choose the new MDM organization that the device needs to be assigned to.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture3.png"&gt;&lt;/p&gt;

&lt;p&gt;Next, choose the deadline.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture4.png"&gt;&lt;/p&gt;

&lt;p&gt;Select the desired date and time for the deadline. This is the final date users have to migrate their device to the assigned MDM server. If users don’t follow the prompts they’ll be locked out the device. Then, click &lt;strong&gt;Continue&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture5.png"&gt;&lt;/p&gt;

&lt;p&gt;On the device the user will receive a notification to restart their device.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture6.png"&gt;&lt;/p&gt;

&lt;p&gt;After restarting, the device will request the user to enroll in the new management service.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture7.png"&gt;&lt;/p&gt;

&lt;h3&gt;Device migration via APIs&lt;/h3&gt;

&lt;p&gt;Setting up ABM device migration via APIs is simple, and it’s done completely in ABM (or ASM), no matter which MDM you are switching to or from.&lt;/p&gt;

&lt;p&gt;First, log in to your Apple Business Manager or Apple School Manager account and navigate to &lt;strong&gt;Settings &amp;gt; Device Manager Settings&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Then, review and enable the required APIs to allow device migration. (If you’re not sure how, check the Apple admin guide for step-by-step help.)&lt;/p&gt;

&lt;p&gt;Once the APIs are enabled, you can simply follow Apple’s migration workflow to select devices and designate the new target MDM server. Optionally, you can set an enrollment deadline for migrated devices.&lt;/p&gt;

&lt;h2&gt;Additional ABM device migration resources&lt;/h2&gt;

&lt;p&gt;If you need more detailed information, you can refer to:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;a href="https://support.apple.com/guide/deployment/welcome/web" rel="noopener" target="_blank"&gt;Apple Platform Deployment Guide&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="https://support.apple.com/guide/apple-business-manager/welcome/web" rel="noopener" target="_blank"&gt;Apple Business Manager User Guide&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="https://support.apple.com/guide/apple-school-manager/welcome/web" rel="noopener" target="_blank"&gt;Apple School Manager User Guide&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="https://success.ivanti.com/" target="_blank"&gt;Ivanti Success Portal&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Fri, 12 Sep 2025 17:27:33 Z</pubDate></item><item><guid isPermaLink="false">31bf4b1c-e4f6-4de2-8af2-9da46c453fd4</guid><link>https://www.ivanti.com/blog/apple-wwdc25-announcements</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint Management</category><title>Apple WWDC25 Announcement of Enterprise IT Enhancements</title><description>&lt;p&gt;At WWDC25, Apple announced a set of updates to simplify IT management for enterprises. These updates, spread across macOS 26, iOS 26, iPadOS 26, tvOS 26 and visionOS 26, introduce practical tools to improve device, application and user management.&lt;/p&gt;

&lt;p&gt;This article outlines the specific capabilities and how they can be applied effectively in enterprise environments.&lt;/p&gt;

&lt;h2&gt;Enhanced Apple Business Manager for flexible device management&lt;/h2&gt;

&lt;p&gt;Apple Business Manager (ABM) improvements in iOS 26, iPadOS 26 and macOS 26 bring enhanced flexibility to enterprise IT operations. Being able to migrate devices between &lt;a href="https://www.ivanti.com/autonomous-endpoint-management/mobile-device-management"&gt;Mobile Device Management (MDM)&lt;/a&gt; solutions means that businesses can react to evolving technological requirements or vendor changes without needing to reconfigure devices manually. For example, an organization switching to one of Ivanti’s on-premises solutions to Ivanti Neurons for MDM can retain operational continuity by utilizing the new ABM Device Migration APIs while aligning configurations with the latest policies.&lt;/p&gt;

&lt;p&gt;Administrators can now enforce enrollment deadlines for Managed Apple Accounts, helping enterprises integrate new devices into their IT systems on schedule. This feature is particularly helpful for compliance with internal policies or regulatory requirements, ensuring devices are accounted for during deployments.&lt;/p&gt;

&lt;p&gt;Enhanced onboarding processes with Account Driven Enrollments, supported by the Service Discovery API, simplify enrollment by enabling preconfigured settings to guide users through setup. This reduces time spent onboarding large numbers of employees or devices.&lt;/p&gt;

&lt;p&gt;Organizations can also bolster account security with stricter access controls. By allowing only Managed Apple Accounts during device setup and login, enterprises can prevent personal accounts from compromising company data or workflows. Additionally, including warranty and AppleCare coverage details lets enterprises plan for the entire lifecycle of their devices, optimizing replacement or support strategies to maintain productivity while minimizing downtime.&lt;/p&gt;

&lt;h2&gt;Modernized app management with Declarative Device Management&lt;/h2&gt;

&lt;p&gt;Declarative Device Management (DDM) updates provide better tools for managing app lifecycles in enterprise environments. Administrators get granular control over app installations and updates, so you can enforce mandatory upgrades for security-critical applications or postpone non-essential updates to avoid disruptions during critical operations. Similarly, the ability to pin apps to specific versions can stabilize environments where software dependencies are tightly coupled.&lt;/p&gt;

&lt;p&gt;Real-time reporting of app installation and update statuses offers IT teams actionable insights into compliance and troubleshooting. For instance, administrators managing thousands of devices can track which apps are outdated or whether installation errors occurred, resolving issues without delays. Furthermore, organizations managing extensive mobile fleets can restrict app downloads over cellular data to conserve bandwidth and ensure adherence to security policies, useful in industries with strict data regulations or cost-control measures.&lt;/p&gt;

&lt;p&gt;Updates to macOS 26 let enterprises scale their device operations more effectively. Declarative Application Management lets administrators deploy apps — whether they are from the App Store or custom-built solutions — across thousands of devices simultaneously, streamlining rollouts during enterprise deployments or product launches. The ability to deploy .pkg files caters to organizations relying on proprietary software or specific configurations.&lt;/p&gt;

&lt;p&gt;VisionOS 26 also supports deploying managed applications via DDM.&lt;/p&gt;

&lt;h2&gt;Improved Safari configuration for efficiency and compliance&lt;/h2&gt;

&lt;p&gt;Safari updates bring practical configuration tools that enterprises can use to align browser settings with organizational needs. Administrators can now preconfigure bookmarks to direct employees to relevant software tools, company websites or knowledge bases upon login, reducing onboarding times and improving workforce efficiency. You can set landing pages to match company branding and guarantee employees start their browsing sessions on compliant and secure portals, which is especially useful for maintaining organizational policies.&lt;/p&gt;

&lt;h2&gt;Better audio accessory management for shared device scenarios&lt;/h2&gt;

&lt;p&gt;For shared device deployments, such as in healthcare, education or retail, Apple’s enhanced audio pairing management introduces useful controls to maintain security while enabling flexibility. Administrators can allow temporary audio accessory pairing without data syncing to iCloud, ensuring that employee or customer data is not inadvertently retained on shared devices. For added security, pairing data can be erased automatically based on predefined schedules, such as each night.&lt;/p&gt;

&lt;p&gt;These controls are critical for shared environments where sensitive data protection and operational continuity are key. For example, hospitals using shared iPads for patient intake can ensure that data is cleared between users while still enabling seamless accessory use for each individual session.&lt;/p&gt;

&lt;h2&gt;Platform Single Sign-On for simplified authentication&lt;/h2&gt;

&lt;p&gt;The new Platform Single Sign-On (SSO) tools in macOS 26 reduce friction during the authentication process for enterprise employees. Platform SSO can now be activated during automated device enrollment, meaning employees can immediately access managed apps, company services and their Managed Apple Accounts without additional sign-ins. This feature simplifies the device setup process for organizations onboarding large numbers of employees or contractors.&lt;/p&gt;

&lt;p&gt;The addition of Authenticated Guest Mode benefits shared environments, such as schools or hospitals, by allowing temporary logins via organizational Identity Provider (IdP) credentials. This ensures that users can access only the resources they are authorized for, while personal data is automatically erased upon logout. This is especially beneficial in environments with transient users where data security and quick turnover are priorities.&lt;/p&gt;

&lt;h2&gt;Return to Service: streamlined device reuse&lt;/h2&gt;

&lt;p&gt;Apple’s improvements to the Return to Service workflow allow enterprises to retain managed apps during device preparation for reuse. This feature significantly reduces the time needed to prepare devices for new users in shared-use scenarios. For instance, retail organizations can erase user data while retaining critical operational apps, allowing devices to be redeployed within minutes rather than hours. Automated re-enrollment into MDM ensures that settings, restrictions and compliance policies are applied quickly and consistently.&lt;/p&gt;

&lt;p&gt;If you have a healthcare use case, check out Return to Service features supported by &lt;a href="https://www.ivanti.com/products/ivanti-neurons-for-mdm"&gt;Ivanti Neurons for MDM&lt;/a&gt;. By adding a Return to Service option on your Ivanti iOS client, your floor staff can safely repurpose devices with one click.&lt;/p&gt;

&lt;h2&gt;ManagedApp Framework for secure enterprise app configurations&lt;/h2&gt;

&lt;p&gt;The ManagedApp Framework, built on Declarative Device Management, introduces a structured approach to defining and passing configuration details to enterprise apps. This framework allows IT administrators to establish app behavior — such as server URLs, credential parameters or connection policies — tailored to specific employees or teams.&lt;/p&gt;

&lt;p&gt;For example, an IT department can provide custom app settings for field technicians that include preconfigured server endpoints and unique digital certificates, while offering a more limited set of configurations for interns or temporary staff. The framework integrates seamlessly with features like Single Sign-On and Managed Device Attestation for secure, scalable and compliance-ready app deployments across industries. This feature requires support both from the application and from the MDM side.&lt;/p&gt;

&lt;h2&gt;Software updates changes in iOS/iPadOS/macOS 26&lt;/h2&gt;

&lt;p&gt;Apple is deprecating legacy software update management methods in iOS, iPadOS and macOS 26, and removing support in 2027 OS versions, requiring all organizations to transition to the new Declarative Management Software Update Enforcement and Software Update settings. Ivanti fully supports these new workflows, enabling automated and proactive update management. Declarative Management Updates are supported on iOS/iPadOS 17+ and macOS 14+. To prepare, customers should update their device management policies in Ivanti, configure Software Update Enforcement and settings for their devices and ensure compliance with Apple’s updated requirements—securing a smooth transition ahead of the deadline.&lt;/p&gt;

&lt;h2&gt;Key takeaways for enterprise IT&lt;/h2&gt;

&lt;p&gt;Apple’s WWDC announcements introduce meaningful improvements for enterprise IT, from streamlined device reuse to more flexible management and security controls. Using Ivanti’s endpoint management solutions alongside these new Apple features will help organizations automate deployments, ensure compliance and support diverse user needs with greater efficiency.&lt;/p&gt;
</description><pubDate>Fri, 18 Jul 2025 14:15:25 Z</pubDate></item><item><guid isPermaLink="false">6a220831-f48d-4163-87fb-942ca6c2ff3d</guid><link>https://www.ivanti.com/blog/a-guide-to-apple-declarative-device-management-for-enterprises</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint Management</category><category>Security</category><title>A Guide to Apple Declarative Device Management for Enterprises</title><description>&lt;p&gt;Apple declarative management introduces a shift from the traditional command-based model to a more autonomous and flexible framework. This approach aims to improve the efficiency and responsiveness of managing Apple devices.&lt;/p&gt;

&lt;p&gt;The components of Apple declarative management — declarations, assets, predicates and status channels — work together to create a more efficient, scalable and responsive &lt;a href="https://www.ivanti.com/products/ivanti-neurons-for-mdm"&gt;MDM&lt;/a&gt; framework. Declarations define the desired states; assets provide the necessary resources; predicates enable context-aware policy application; and status channels facilitate efficient communication.&lt;/p&gt;

&lt;p&gt;Apple is deprecating legacy software updated management methods in iOS, iPadOS and macOS 26 and removing support in 2027 OS versions, requiring you to transition to the new declarative management software update enforcement and software update settings. Ivanti fully supports these new workflows for automated and proactive update management.&lt;/p&gt;

&lt;h2&gt;The shift to declarative device management&lt;/h2&gt;

&lt;p&gt;Let's explore the technical aspects of Apple declarative device management and its benefits for MDM users.&lt;/p&gt;

&lt;p&gt;Traditional MDM operates on a command-and-control basis, in which servers send commands to devices to perform actions such as installing apps or enforcing policies. Devices then report their status back to the server, necessitating constant communication.&lt;/p&gt;

&lt;p&gt;This frequent check-in process is needed for devices remain compliant with the organization's policies and that changes or updates are promptly applied. Without regular check-ins, administrators would have limited visibility into the device's status, making it challenging to verify compliance, deploy updates or address security issues in real-time.&lt;/p&gt;

&lt;p&gt;Apple declarative device management utilizes a declarative format with which administrators define desired states and policies. Devices receive these declarations and autonomously enforce the desired state, reporting back to the server only when there is a change.&lt;/p&gt;

&lt;p&gt;In this model, the device's operating system plays a critical role in making the device more autonomous. The OS continuously evaluates the current state of the device against the desired state defined by the declarations. If discrepancies are detected, the device will self-heal.&lt;/p&gt;

&lt;p&gt;The OS independently applies the necessary changes defined in declarations and predicates to align with the specified policies. This autonomous evaluation and enforcement capability minimizes the reliance on server commands and allows for real-time adjustments, ensuring devices remain compliant even when offline or out of network range.&lt;/p&gt;

&lt;h2&gt;Key components of Apple declarative device management&lt;/h2&gt;

&lt;h4&gt;Declarations&lt;/h4&gt;

&lt;p&gt;Declarations represent the desired state or configuration that an administrator wants to apply to devices. Declarations are sent to devices, which then interpret and autonomously enforce these states. The key features of declarations include:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;strong&gt;Configuration definition:&lt;/strong&gt; Administrators define configurations in a declarative format. This includes settings for Wi-Fi, VPN, device restrictions and more.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;Autonomous enforcement:&lt;/strong&gt; Devices interpret the declarations and apply the specified policies independently, without requiring continuous communication with the server.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;Assets&lt;/h4&gt;

&lt;p&gt;In Apple Declarative Management, &lt;a href="https://support.apple.com/guide/deployment/authentication-credentials-identity-asset-dep597c7b47d/1/web/1.0" rel="noopener" target="_blank"&gt;assets&lt;/a&gt; are resources used by devices to implement policies and configurations defined in declarations. These assets include certificates, data and user information.&lt;/p&gt;

&lt;p&gt;Certificates are used for authentication, encryption and secure communication among devices and services. Administrators deploy digital certificates via declarations to enable secure access to corporate networks, email, VPNs and other resources. These certificates can be updated independently from the declarations, maintaining current security credentials without a complete policy overhaul.&lt;/p&gt;

&lt;p&gt;Data consists of configuration files, scripts, binaries and content resources. Configuration files contain specific settings for applications or network configurations, while scripts and binaries automate tasks or add functionality. Content resources include branding materials or compliance documents. Managing data as assets allows for efficient updates and reuse across multiple declarations.&lt;/p&gt;

&lt;p&gt;User information includes user profiles, preferences and roles within the organization. This information tailors device settings and permissions based on user roles. Dynamic data, such as location-based information or activity logs, ensures device configurations adapt to the user's current needs.&lt;/p&gt;

&lt;p&gt;Assets are managed separately from declarations, allowing for efficient reuse and updates. When an asset is updated, all declarations referencing that asset can automatically apply the updated version.&lt;/p&gt;

&lt;h4&gt;Predicates&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://developer.apple.com/library/archive/documentation/Cocoa/Conceptual/Predicates/AdditionalChapters/Introduction.html#//apple_ref/doc/uid/TP40001789" rel="noopener" target="_blank"&gt;Predicates&lt;/a&gt; in Apple Declarative Management work as the conditional logic elements within declarations that define when and how specific policies should be applied to devices. Predicates are evaluated on the device itself, allowing for real-time, context-aware decision-making. They consist of logical expressions that can reference various device attributes and contextual information. When the conditions specified by a predicate are met, the corresponding policies or configurations within the declaration are enforced.&lt;/p&gt;

&lt;p&gt;Predicates leverage the syntax and capabilities of the Cocoa programming language to define conditions under which specific policies should be applied. Cocoa predicates are expressions that evaluate a Boolean value, enabling complex logical conditions using attributes such as device type, OS version, network status and more.&lt;/p&gt;

&lt;h4&gt;Status channels&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://support.apple.com/guide/deployment/declarative-status-reports-depd90ee8a5f/web" rel="noopener" target="_blank"&gt;Status channels&lt;/a&gt; are communication pathways that devices use to report their state back to the server. Unlike traditional MDM, with which devices constantly check in with the server, status channels enable asynchronous and event-driven communication. Key features of status channels include:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;strong&gt;Asynchronous reporting:&lt;/strong&gt; Devices send status updates only when there is a change in their state or when specific conditions are met.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;Efficient communication:&lt;/strong&gt; This reduces the need for continuous polling, minimizing network traffic and server load.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;Real-time monitoring:&lt;/strong&gt; Administrators receive timely updates about the compliance and state of devices, allowing for prompt action if necessary.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Status channels ensure that administrators are informed of any deviations from the desired state, enabling proactive management and quick remediation.&lt;/p&gt;

&lt;h2&gt;Apple declarative device management in Ivanti UEM solutions&lt;/h2&gt;

&lt;p&gt;Ivanti keeps its products updated with the latest enhancements in the device management industry. Both our UEM cloud and on-premises solutions support declarative management.&lt;/p&gt;

&lt;p&gt;Declarative device management is not a full replacement of the traditional MDM protocol. Therefore, solutions will present a hybrid approach, leveraging the best of both frameworks. Ivanti customers will see progressive and seamless integration of the new capabilities in our platforms as Apple also makes improvements to the framework with every new release of its operating systems.&lt;/p&gt;

&lt;hr&gt;
&lt;h3&gt;Related Content&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.ivanti.com/devices/ios-device-management"&gt;iOS Device Management solutions&lt;/a&gt;&lt;/p&gt;
</description><pubDate>Sat, 07 Jun 2025 13:00:01 Z</pubDate></item><item><guid isPermaLink="false">97d6a618-6e80-482b-b581-806fced981ef</guid><link>https://www.ivanti.com/blog/apple-declarative-device-management-updates</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint Management</category><title>Optimizing Apple DDM with Ivanti’s Latest Innovations</title><description>&lt;p&gt;The explosion in devices—particularly Apple devices—deployed across a modern enterprise is increasing the already arduous device management burden on IT and cybersecurity teams.&lt;/p&gt;

&lt;p&gt;According to recent &lt;a href="https://www.computerworld.com/article/1634358/three-quarters-of-large-us-firms-now-using-more-apple-devices-survey.html?utm_source=chatgpt.com" rel="noopener" target="_blank"&gt;research&lt;/a&gt;, 76% of large enterprises are using more Apple devices, and 57% of US firms say Apple adoption is outpacing other options. So, it’s become crucial for more enterprises to leverage Apple Declarative Device Management (DDM) to streamline device management, automate compliance and enhance scalability.&lt;/p&gt;

&lt;p&gt;Apple's approach to DDM was introduced in 2021 and expanded with each OS release. It’s created a fundamental shift in device management, streamlining software updates and patching. Now, IT teams can define desired states so Apple devices can self-enforce configurations and updates &lt;em&gt;locally&lt;/em&gt;, reducing reliance on servers and manual intervention.&lt;/p&gt;

&lt;p&gt;Thus, updates can happen faster, errors can be minimized, and end-user experiences can be improved invisibly and proactively. Which appreciably eases IT workloads while sustaining security and operational agility.&lt;/p&gt;

&lt;p&gt;Apple is deprecating legacy software update management in iOS, iPadOS and macOS26, and they will remove support in 2027 OS versions, which means now is the time to make the switch to DDM. Let's explore how Ivanti's MDM and UEM products will enable admins to get the most out of Apple DDM.&lt;/p&gt;

&lt;h2&gt;What is declarative device management (DDM)?&lt;/h2&gt;

&lt;p&gt;DDM is an advanced approach to managing devices, primarily in enterprise or organizational IT environments. It empowers administrators to define a device or system's desired state and allows the system to automatically enforce and maintain that state.&lt;/p&gt;

&lt;p&gt;The DDM model shifts away from traditional imperative management, where configurations and actions are centrally scripted and managed by IT administrators. That approach requires direct instructions to achieve the desired outcome on each device.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key features and benefits of DDM&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;What are DDM’s advantages over a traditional device management model?&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Administrators can specify the desired state or behavior of a device, focusing on "what" it should look like instead of "how" to achieve that state. For example, rather than scripting individual commands for configuring security settings, an admin can simply declare the required settings and the system will enforce them.&lt;/li&gt;
	&lt;li&gt;Devices autonomously monitor their configurations to ensure compliance with a predefined state. If a device deviates, it automatically corrects itself to restore compliance without manual intervention.&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;DDM proves highly effective in large-scale settings since it minimizes the need for repetitive and manual configuration tasks.&lt;/li&gt;
	&lt;li&gt;DDM minimizes the complexity of management workflows and ensures consistency across devices.&lt;/li&gt;
	&lt;li&gt;DDMs employ modern management protocols for faster and more reliable updates to device configurations and policies.&lt;/li&gt;
	&lt;li&gt;DDM is commonly implemented in cloud-based mobile device management (MDM) solutions, leveraging the cloud for synchronization, monitoring and enforcement, although it can also be implemented in on-prem solutions.&lt;/li&gt;
	&lt;li&gt;DDM reduces manual effort by automating configuration and enforcement processes.&lt;/li&gt;
	&lt;li&gt;Ensures consistency and compliance across devices, reducing the risk of human error.&lt;/li&gt;
	&lt;li&gt;Dynamic updates means quicker application of policies and settings versus traditional methods.&lt;/li&gt;
	&lt;li&gt;Changes are implemented seamlessly without disrupting the user experience.&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;
&lt;blockquote&gt;
&lt;h2&gt;An example DDM use case&lt;/h2&gt;

&lt;p&gt;In a hypothetical example, an IT administrator declares that all employee devices within the enterprise environment must:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Have a specific version of the operating system.&lt;/li&gt;
	&lt;li&gt;Enable encryption.&lt;/li&gt;
	&lt;li&gt;Restrict access to certain applications.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Using DDM, these requirements are automatically applied, continuously enforced and remediated if there’s any deviation.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;
&lt;h2&gt;Software updates and OS patching via Apple DDM&lt;/h2&gt;

&lt;p&gt;Utilizing Apple Declarative Device Management for software updates and operating system (OS) patching seriously improves these processes, making them more proactive, efficient and seamless. It simplifies administration, cuts down on delays and guarantees a fleet of devices is always secure and up-to-date.&lt;/p&gt;

&lt;h4&gt;Software update benefits&lt;/h4&gt;

&lt;p&gt;&lt;em&gt;Centralized control with distributed execution&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Administrators set configurations centrally but rely on the device's local capabilities for execution.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Proactive local enforcement&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Updates are enforced at the device level, eliminating the need for constant server intervention. Admins set a desired OS version and deadline, and the device autonomously ensures compliance.&lt;/li&gt;
	&lt;li&gt;The device monitors itself, applying updates without the need for constant server communication.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Automation&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Admins can configure specific versions and deadlines and update schedules (e.g., after work hours), automating the process while minimizing end-user disruption.&lt;/li&gt;
	&lt;li&gt;For example, a critical security patch can be scheduled for a particular time, ensuring all devices are updated without user intervention.&lt;/li&gt;
	&lt;li&gt;If a device is powered off and misses the update deadline declarative management reschedules the update automatically for a later time.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;User notification and experience&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Notifications begin 14 days before the deadline, reminding users to update at their convenience. On the deadline, the device automatically reboots and installs updates if necessary.&lt;/li&gt;
	&lt;li&gt;Admins can customize these notifications or suppress early reminders (e.g., for retail or healthcare environments).&lt;/li&gt;
	&lt;li&gt;Admins can configure the level of user interaction allowed by Apple DDM, such as permitting manual updates before the enforced deadline or limiting user deferrals.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Faster updates with reduced network dependency&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Unlike traditional MDM, where the server continuously checks device status, DDM reduces latency by shifting the compliance mechanism to the endpoint.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Enhanced status reporting&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Devices proactively report the status of updates to the server including whether an update is in progress, completed successfully or failed. In case of failure, detailed error logs are available.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;OS patching benefits&lt;/h4&gt;

&lt;p&gt;&lt;em&gt;Predicates for context-aware updates&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;DDM allows conditional rules (predicates) for updates, such as only applying a patch when a device is charging or has a battery above 80%.&lt;/li&gt;
	&lt;li&gt;These conditions are evaluated locally on the device, making updates context-sensitive and efficient.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Seamless transition to new OS versions&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;DDM automatically manages the transition to new OS releases or security patches without requiring manual admin oversight at each step.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Local action without internet&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Devices can enforce configurations and patches even when offline, applying updates based on preloaded criteria and activating changes when conditions permit (e.g., when connected to power or during off-hours).&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;
&lt;blockquote&gt;
&lt;h2&gt;Another practical use case&lt;/h2&gt;

&lt;p&gt;In an organization with 1,000+ iPhones and MacBooks, a zero-day vulnerability requires immediate patching. The solution?&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;The admin declares a patch deadline and target version using Apple DDM.&lt;/li&gt;
	&lt;li&gt;Devices enforce the update based on local predicates, ensuring the patch is applied under optimal conditions (e.g., during low battery drain times).&lt;/li&gt;
	&lt;li&gt;Users receive notifications prior to the update so they’re informed without interrupting workflows.&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;h2&gt;Ivanti’s declarative management support&lt;/h2&gt;

&lt;p&gt;Ivanti’s declarative management support builds on Apple’s Declarative Device Management (DDM) framework to offer a seamless, proactive and efficient approach to managing Apple devices. What are some of its key components?&lt;/p&gt;

&lt;h4&gt;Integration with Apple’s DDM framework&lt;/h4&gt;

&lt;p&gt;Ivanti utilizes Apple’s DDM as an enhancement to the existing Mobile Device Management (MDM) protocol – &lt;em&gt;not&lt;/em&gt; a complete replacement but an additional layer designed to:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Automate device responses: Allow devices to enforce configurations and policies locally, reducing reliance on the server for continuous checks.&lt;/li&gt;
	&lt;li&gt;Enable real-time proactivity: Devices can autonomously apply updates or configurations when predefined conditions (predicates) are met.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;Software update enforcement&lt;/h4&gt;

&lt;p&gt;Ivanti's platform supports Apple’s declarative software update management, which introduces:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Enforcement settings: Administrators can specify OS versions, deadlines and update schedules.&lt;/li&gt;
	&lt;li&gt;Proactive local actions: Devices monitor themselves and apply updates without requiring manual input or waiting for server-side triggers.&lt;/li&gt;
	&lt;li&gt;Improved communication: Devices report their update progress, success or failure directly to the Ivanti management server, providing admins with real-time visibility.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;Predicate management&lt;/h4&gt;

&lt;p&gt;A standout feature of Ivanti’s support is its handling of predicates – logical conditions that devices evaluate before applying configurations or updates. For example:&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;A policy applies only if the device’s battery is above 80%.&lt;/li&gt;
	&lt;li&gt;A configuration activates when the device is charging.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Simplified predicate management in Ivanti’s console&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Ivanti provides a dedicated interface for creating, managing and reusing predicates across configurations.&lt;/li&gt;
	&lt;li&gt;These predicates can be easily applied to declarative configurations, streamlining complex workflows.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;User experience and notifications&lt;/h4&gt;

&lt;p&gt;Ivanti enhances the user experience by leveraging Apple’s notification capabilities:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Notifications can start 14 days before the update deadline, with options to tailor their frequency and content.&lt;/li&gt;
	&lt;li&gt;Critical updates can override user deferrals by enforcing reboots and updates at the scheduled deadline.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Past-due handling&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;If a device misses the deadline (e.g., turned off), Ivanti reschedules updates automatically ensuring compliance.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Supported configurations&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Ivanti ensures backward compatibility and a smooth transition to declarative management by supporting both legacy MDM and newer DDM configurations.&lt;/li&gt;
	&lt;li&gt;Existing policies and workflows continue without disruption.&lt;/li&gt;
	&lt;li&gt;Declarative configurations (e.g., predicates and local enforcement) are gradually integrated and highlighted within the platform.&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Related: Watch the webinar &lt;a href="https://www.ivanti.com/webinars/2024/mastering-apple-device-management-with-ivanti"&gt;Mastering Apple Device Management with Ivanti&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;Ivanti’s guidance for updating and patching Apple devices with declarative device management&lt;/h2&gt;

&lt;p&gt;Ivanti’s approach to supporting Apple DDM leverages the proactive capabilities of Apple's declarative management framework, combining it with a user-friendly interface, automation and support for complex enterprise workflows. This comprehensive guidance enhances enterprise device management efficiency and security.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enforcing updates and patches&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Automated scheduling lets admins enforce updates by specifying the target OS version along with a specific date and time for the update to occur. This eliminates the need for manual updates and ensures compliance with organizational policies.&lt;/li&gt;
	&lt;li&gt;Devices enforce update enforcement locally, applying updates based on preconfigured conditions without relying on continuous server communication.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Managing user notifications&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Notifications are sent to end users starting 14 days before the update deadline, providing transparency and encouraging users to update at their convenience.&lt;/li&gt;
	&lt;li&gt;For specific use cases such as retail or healthcare, flexible notification configurations let admins suppress early notifications and opt for last-minute alerts to minimize disruption.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Improving compliance and visibility&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Devices proactively report their update status to the Ivanti server, reporting whether updates are in progress, completed successfully or failed. Administrators also gain access to detailed error logs to troubleshoot issues.&lt;/li&gt;
	&lt;li&gt;If a device misses the deadline (e.g., if it is powered off), the device automatically reschedules the update for the next available hour.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Using predicates for conditional updates&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Administrators can define predicate logic for when updates should be applied.&lt;/li&gt;
	&lt;li&gt;Since conditions are evaluated locally, updates can happen even when the device is offline.&lt;/li&gt;
	&lt;li&gt;Ivanti provides tools for creating, managing and reusing predicates across configurations, making conditional updates simpler and easier to implement.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Enhancing user experience&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;End users get clear communication about the update schedule, including the enforced deadline. They have the option to install updates manually before the deadline to avoid automatic enforcement.&lt;/li&gt;
	&lt;li&gt;Updates can be scheduled during off-hours to minimize disruption of the user's daily activities.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Streamlining patch management&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Ivanti supports declarative patch management -Apple system updates.&lt;/li&gt;
	&lt;li&gt;Administrators can enforce updates, including critical security patches, ensuring devices remain secure and compliant.&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Related: Read our Knowledge Base article on &lt;a href="https://forums.ivanti.com/s/article/How-to-enforce-Apple-Software-Updates-with-Neurons-for-MDM-and-EPMM?language=en_US" target="_blank"&gt;How to enforce Apple Software Updates with Neurons for MDM and EPMM&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;A standout approach to supporting Apple DDM&lt;/h2&gt;

&lt;p&gt;Ivanti's approach to Apple Declarative Device Management stands out because it extends an organization’s automation, local enforcement and proactive capabilities.&lt;/p&gt;

&lt;p&gt;Administrators benefit from user-friendly tools, customizable notifications and detailed status reporting, while end-user disruption is minimized through scheduled updates and seamless workflows. With Ivanti, Apple DDM becomes even more efficient, secure and scalable for the organizations that rely on it.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Related: &lt;a href="https://www.ivanti.com/blog/a-guide-to-apple-declarative-device-management-for-enterprises"&gt;A Guide to Apple Declarative Device Management for Enterprises&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;/p&gt;
</description><pubDate>Tue, 21 Jan 2025 20:10:27 Z</pubDate></item><item><guid isPermaLink="false">4a8e15f9-9fb1-4517-884b-8ee4affb2f73</guid><link>https://www.ivanti.com/blog/wwdc-2024-what-it-admins-need-to-know-about-apple-s-announcements</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><category>Security</category><category>Endpoint Management</category><category>DEX</category><title>WWDC 2024: What IT Admins Need to Know About Apple’s Announcements</title><description>&lt;p&gt;Apple's announcements at this year’s Worldwide Developers Conference have surprised everyone with new capabilities designed to make the IT admin's life easier for managing and securing devices.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;As we expected, Apple kept expanding declarative management configurations and capabilities for securing iPhones and iPads and robust management of macOS in the enterprise. There was also a significant emphasis on device management for Apple Vision Pro, adding the ability to enroll visionOS devices via automated device enrollment. Also, there were new configurations and commands announced that will be supported by MDM, which will make the enterprise use cases more robust.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Here are the main announcements in Apple Business Manager, iOS18, macOS15 and visionOS 2.0 that IT admins should be aware of:&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;General WWDC announcements&amp;nbsp;&lt;/h2&gt;

&lt;h4&gt;Apple Intelligence&lt;/h4&gt;

&lt;p&gt;Perhaps the biggest announcement from Apple this year was &lt;a href="https://www.apple.com/apple-intelligence/" rel="noopener" target="_blank"&gt;Apple Intelligence&lt;/a&gt;, the new AI introducing Writing Tools, Smart Reply, Reduce Interruptions, Image Playground, etc. Apple Intelligence runs on-device and in Private Cloud Compute, which does not store customer data and protects user privacy. For certain requests, Apple Intelligence has been integrated with ChatGPT.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Apple has shared that MDM restrictions will be available for Apple Intelligence, including the ability to restrict Siri, Writing Tools, Image Playground, and the ChatGPT integration. IT teams will be able to choose which restrictions best fit their organization.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Refer to your &lt;a href="https://beta.apple.com/it" rel="noopener" target="_blank"&gt;Appleseed for IT developer program&lt;/a&gt; for more information and updates on what's new for IT.&amp;nbsp;&lt;/p&gt;

&lt;h4&gt;Apple Business Manager&lt;/h4&gt;

&lt;p&gt;For customers leveraging Apple Business Manager, they will be able to take advantage of new capabilities that streamline some operations.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;First, Apple has been pushing to move enterprise use cases to adopting managed Apple IDs instead of Apple IDs. Apple IDs are now called Apple Accounts, and Managed Apple IDs are called Managed Apple Accounts.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Apple has released a new process to streamline the recognition of the domain so customers can seamlessly convert Apple Accounts to Managed Apple Accounts with low impact on end users. Any Apple Account using a corporate domain can be set to migrate automatically to a managed account. The end user will need to accept this migration. If the end user doesn't accept migration after 30 days, the account will be automatically transformed into a managed account, and the personal Apple Account will be renamed.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The second feature specific to Apple Business Manager is the ability to manage Activation Lock on devices that are in an organization’s Apple Business Manager account. Previously, when a device was locked and retired from MDM, the only way to repurpose the device was to call Apple service. Now, if the device is enrolled in Apple Business Manager, the IT admin can unlock the device directly from the Apple Business Manager page.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Lastly, Apple has added the new Apple Vision Pro to the devices that can be onboarded by organizations via automated device enrollment. This new feature will allow devices to be supervised during activation and will simplify the initial device setup.&amp;nbsp;&lt;/p&gt;

&lt;h4&gt;Software update enforcement enhancements&amp;nbsp;&lt;/h4&gt;

&lt;p&gt;Last year, Apple released new software update enforcement with the ability to set a deadline for all devices to upgrade to a specific version. In this workflow, the end user receives notifications starting 14 days before the deadline. This year, Apple has moved the existing management controls over to declarative device management to give the IT admin much more detailed command over the behavior of the update, similar to what the admin had in the previous model.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;IT admins can control:&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Automatic software update behavior.&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;Rapid Security Response behavior.&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;Deferral of software updates (one to 90 days).&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;Whether local administrator authorization is required to update macOS.&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;Enrollment into beta programs (support for macOS later this year).&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;Default notification behavior when enforcing software updates.&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;Visibility (recommended cadence) of software upgrades (iOS and iPadOS only).&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These new settings are meant to be a complete replacement of the previous workflows for software updates via MDM.&amp;nbsp;&lt;/p&gt;

&lt;h4&gt;Streamlining OS beta testing in the enterprise&amp;nbsp;&lt;/h4&gt;

&lt;p&gt;For customers with rigorous beta testing for each new OS version from Apple, Apple has released an easier way to manage the installation of versions on devices. Enrolling devices into the beta program and controlling the upgrade behavior for those devices can be streamlined and updated as needed.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;First, all devices will need to leverage a feature released last year to allow for automated device enrollment into the beta program. Now, with this year’s release, all the Software Update settings will also be applicable for those devices in beta versions.&amp;nbsp;&lt;/p&gt;

&lt;h4&gt;Safari extensions managed via MDM&lt;/h4&gt;

&lt;p&gt;For a long time, IT admins have been asking for a way to manage and approve Safari extensions to improve the user experience when opening domains. In this release, Apple has made available a new payload that allows or excludes some domains for Safari extensions.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;iOS and iPadOS&amp;nbsp;&lt;/h2&gt;

&lt;h4&gt;Cellular networks updates&amp;nbsp;&lt;/h4&gt;

&lt;p&gt;As with last year, Apple continues to make cellular networks more flexible and robust for customers. Last year, we saw more flexibility in configuring private networks for eSIM devices and creating specific slices on cellular bandwidth for dedicated application network traffic. This year, Apple has added the ability to support multiple private networks and leverage cellular slicing at the per-app VPN level.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;New eSIM management keys include the ability to preserve the eSIM information even when the end user wipes the device and the ability to set up an eSIM with a link or a QR code on the device.&amp;nbsp;&lt;/p&gt;

&lt;h4&gt;App Management Security&amp;nbsp;&lt;/h4&gt;

&lt;p&gt;Apple added a feature for end users to hide or lock an application. This means the application will require Face ID, Touch ID or a passcode to open and can be hidden from the home screen. Apple will release application-level controls to configure these options via MDM.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Starting with iOS 18, proprietary in-house apps manually installed without using MDM will require a device restart to complete the trust of the provisioning profile.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;macOS improvements&lt;/h2&gt;

&lt;h4&gt;More flexible management via MDM&amp;nbsp;&lt;/h4&gt;

&lt;p&gt;In macOS 14.5, new management tools have been released to manage files via MDM. These include sshd, sudo and PAM.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In macOS 15, executables, scripts and launched configuration files can be installed using MDM and are stored in a secure and tamper-resistant location, similar to service configuration files introduced last year. This provides an easy way for organizations to deploy and control managed services.&amp;nbsp;&lt;/p&gt;

&lt;h4&gt;Better user experience during authentication&amp;nbsp;&lt;/h4&gt;

&lt;p&gt;Authenticating via passwords is always problematic in the enterprise, as users forget passwords and devices get blocked. Leveraging new improvements to the platform, single sign-on and extensible single sign-on with Kerberos, Apple is simplifying the authentication process for enterprises while providing secure access and streamlining the authentication process for the end-user. New login policies are available via FileVault, login window and lock screen.&amp;nbsp;&lt;/p&gt;

&lt;h4&gt;More security via disk management configuration&amp;nbsp;&lt;/h4&gt;

&lt;p&gt;In the last release, Apple deprecated the media restriction payload. This year, Apple announced a new declarative device management payload to manage external and network storage. This new disk management configuration will define the mount policy to allow, disallow, or set volumes to read-only, making access to external storage secure and robust.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;Apple Vision Pro improvements&amp;nbsp;&lt;/h2&gt;

&lt;p&gt;In the visionOS 1.1 release, enrolling devices into MDM required devices to be registered via Account-Driven Device Enrollment or Account-Driven User Enrollment using a Managed Apple Account. With the announcement of visionOS 2.0, customers will be able to enroll devices via Automated Device Enrollment, allowing them to be supervised and simplifying the initial device setup. Another important improvement is the addition of more commands and payloads for visionOS management, including configurations such as device lock, activation lock, passcode management and others.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Additionally, Apple released a new set of APIs for visionOS application developers aimed at enhancing the enterprise use case. These new APIs will allow applications to integrate live feeds, screen sharing and QR code scanning, enabling new use cases for support teams to assist remotely with tasks and requirements.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;While the most significant and impactful capabilities released by Apple center on Apple Intelligence, it's clear Apple is also making substantial progress in enhancing enterprise use cases by simplifying the adoption of Managed Apple Accounts for enterprise customers; introducing more granular controls for a robust macOS management experience; and expanding Apple Vision Pro support for Automated Device Enrollment and other enterprise use cases.&amp;nbsp;&lt;/p&gt;
</description><pubDate>Mon, 05 Aug 2024 08:00:00 Z</pubDate></item><item><guid isPermaLink="false">c0deeef4-190a-46b8-a64a-1d5919c850db</guid><link>https://www.ivanti.com/blog/how-mdm-can-help-manage-the-apple-watch-at-work</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint Management</category><title>How MDM Can Help Manage the Apple Watch at Work</title><description>&lt;p&gt;The Apple Watch has emerged as more than just a personal device. It's a tool that can enhance productivity, streamline communications and bolster security for organizations across various industries. With increased usage comes the need to manage these devices effectively and securely. This is where MDM steps in as a critical solution.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Ivanti Neurons for MDM solution provides IT administrators the tools necessary to manage, secure and optimize the use of Apple Watch within their organizations. From enforcing security policies and managing configurations to deploying apps and monitoring device performance, MDM ensures that Apple Watch is used efficiently and safely in the workplace.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;As businesses increasingly rely on wearable technology to support their operations, understanding the importance of MDM in Apple Watch management becomes essential. Let's explore why MDM is crucial for managing Apple Watch and how it can benefit your organization.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;How workplaces can use MDM for Apple Watch&lt;/h2&gt;

&lt;p&gt;Ivanti Neurons for MDM can significantly benefit organizations and individuals managing multiple devices. Deploying Apple Watch in an organization requires careful planning and execution. MDM simplifies this process by supporting various deployment models and ensuring that devices are properly paired and configured with necessary policies and applications from the start. This streamlining helps scale up deployment without significant administrative overhead.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Here’s how Ivanti Neurons for MDM can assist:&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enhanced security&lt;/strong&gt;: MDM allows administrators to enforce security policies on Apple Watch devices. This includes requiring passcodes, enforcing encryption and remotely wiping the device in case of loss or theft, ensuring sensitive data remains secure. This enables secure data exchange and communications, whether through emails from clients, application updates or calendar entries. Security measures also include features like biometric authentication.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Centralized configuration management&lt;/strong&gt;: MDM enables centralized management of Apple Watch settings and configurations. Administrators can remotely configure Wi-Fi, VPN, email and other settings, ensuring that devices are properly configured for organizational use and compliance requirements.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Efficient app deployment and management&lt;/strong&gt;: MDM facilitates the deployment and management of apps on Apple Watch devices. Administrators can remotely install, update or remove apps, ensuring that users can access the necessary tools and resources to perform their tasks efficiently. Employees are empowered with access to essential information and tools directly on their wrists. Workers in service stations or retail stores can receive app notifications from the managed apps distributed to them via Ivanti Neurons for MDM.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Remote monitoring and troubleshooting&lt;/strong&gt;: MDM lets administrators remotely monitor Apple Watch devices for compliance with security policies and detect any issues that might arise. They can troubleshoot problems remotely, reducing the need for in-person support and minimizing downtime. Whether employees are working in remote construction sites, field research locations or outdoor facilities, they can receive support for their devices remotely.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Activation lock and device control&lt;/strong&gt;: MDM enables features like Activation Lock, which helps prevent unauthorized access by ensuring that a lost or stolen Apple Watch remains locked to the user’s account. This feature, coupled with the ability to remotely lock or wipe devices, gives organizations greater control over their assets and enhances overall security.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Comprehensive inventory management&lt;/strong&gt;: MDM provides administrators with visibility into their Apple Watch inventory, including information such as device model, serial number and software version. This helps organizations keep track of their assets and ensure compliance with licensing requirements.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;Key considerations for Apple Watch deployment&lt;/h2&gt;

&lt;p&gt;Organizations must keep a few important points in mind when planning Apple Watch deployment:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Apple Watch needs to be paired with a supervised iPhone.&lt;/li&gt;
	&lt;li&gt;The supervised iPhone must be enabled with Declarative Management.&lt;/li&gt;
	&lt;li&gt;Apple Watch management is supported with watchOS 10 and later.&lt;/li&gt;
	&lt;li&gt;Before pairing Apple Watch to iPhone, an Apple Watch Enrollment token must be distributed to the iPhone.&lt;/li&gt;
	&lt;li&gt;Apple Watch management supports iPhone apps, companion apps and standalone apps. Depending on the type of apps your users need, your organization must plan accordingly.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Ivanti Neurons for MDM is an essential component of managing Apple Watch in a professional setting. It not only enhances security and compliance but also ensures that the devices are effectively supporting the organization's operational goals. As wearable technology continues to evolve, the role of MDM will only become more significant in leveraging the full potential of Apple Watch in the workplace.&amp;nbsp;&lt;/p&gt;
</description><pubDate>Mon, 03 Jun 2024 15:45:53 Z</pubDate></item><item><guid isPermaLink="false">8922f641-7510-4479-8f4d-0f05355f3681</guid><link>https://www.ivanti.com/blog/upgrade-to-windows-11-with-ivanti-neurons-for-mdm</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint Management</category><title>Upgrade to Windows 11 with Ivanti Neurons for MDM</title><description>&lt;p&gt;With support for Windows 10 ending on Oct. 14, 2025, users are faced with deciding how and when they wish to upgrade to Windows 11. Since some old devices won’t be able to upgrade to Windows 11, new devices must be purchased.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Administrators should start evaluating the transition to Windows 11 by upgrading their current fleet or evaluating a device refresh that will come with Windows 11.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.ivanti.com/products/endpoint-manager"&gt;Ivanti Endpoint Management (EPM)&lt;/a&gt; customers will be able to start imaging those devices at the push of a button with the new features in Ivanti’s cloud-based &lt;a href="https://www.ivanti.com/glossary/modern-device-management"&gt;Modern Device Management (MDM)&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Your organization might be ready to upgrade to Windows 11 or need to plan for it. Ivanti technicians can help upgrade the devices at your own pace. You can block Windows 11 updates or target a configuration and proceed with the upgrade.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Let’s analyze some of those challenges and how Ivanti Neurons for MDM helps streamline the process with minimal end-user impact.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;Upgrading to Windows 11&amp;nbsp;&lt;/h2&gt;

&lt;p&gt;For starters, this Windows upgrade introduces a broad set of capabilities and controls that can take much longer to install, for many reasons. More importantly, each update introduces a new set of potential compatibility and reliability problems.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;While some updates are small and might not be noticed during installation, others are quite large and can take a while to install. In an enterprise environment, this can disrupt end users. Windows 11 added not only new features end users can enjoy, but also security and performance improvements that make the transition even more challenging.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Remotely targeting only Windows 11-compatible devices can minimize upgrade failure. In &lt;a href="https://www.ivanti.com/products/ivanti-neurons-for-mdm"&gt;Ivanti Neurons for MDM&lt;/a&gt;, you can specify where you’d like your Windows 11 upgrades to come from — WSUS or Windows Updates. In our recent release, we’ve added the ability to choose sources for each Windows OS update type: feature updates, quality updates, driver updates and other Microsoft updates. Every device will connect to the corresponding source and report the applicable version of the upgrade.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;For a device to report on the applicable Windows 11 versions, in this latest release we’ve added the Product Version field. Here, customers must specify the 11 version for the device to know that it needs to upgrade, instead of just keep updating Windows 10 patches.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Once devices start reporting the Windows 11 version, Ivanti Neurons for MDM platform will scan them and present them in the Windows Update page so our admins can approve the upgrade. Devices not eligible for an upgrade due to system or software incompatibility will automatically be left untouched and not report incompatible versions.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;Follow these steps&amp;nbsp;&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Manage Windows 11 Upgrades at your own pace:&lt;/strong&gt; Microsoft recently announced that Windows 11 upgrades will be offered to all unmanaged Windows devices. Having end users upgrading to Windows 11 could create plenty of issues – and many helpdesk tickets.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;When Windows devices are managed with &lt;a href="https://www.ivanti.com/products/ivanti-neurons-for-mdm"&gt;Ivanti Neurons for MDM&lt;/a&gt;, Windows 10 devices will only get Windows 10 updates, unless you specifically target the Windows 11 upgrade for your fleet. Using our Software Update configurations will give you granular controls over the upgrade process, schedules, reboots and notifications.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;If your organization doesn’t have a good way to manage Windows 11 upgrades and is concerned about devices being upgraded by end users directly, &lt;a href="https://www.ivanti.com/products/ivanti-neurons-for-unified-endpoint-management" target="_blank"&gt;Ivanti Neurons for UEM&lt;/a&gt; for Windows might be a good fit for your organization.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Customize upgrades with low end user impact:&lt;/strong&gt; Ivanti Neurons for MDM provides a complete set of functionalities to customize the upgrade's behavior. Customers can schedule, differ and pause the updates and configure the level of notifications the end user will get before the upgrade. These controls are very granular, letting administrators choose different behaviors for each update type: feature, quality, driver and others.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;For instance, with Ivanti Neurons for MDM, you can provide off-hour windows to make sure upgrades are downloaded without impacting your end users. Administrators can also configure the ability for end users to upgrade on their own schedule.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Roll out Windows 11 Copilot AI at your own pace:&lt;/strong&gt; Copilot in Windows provides centralized generative AI assistance to users, appearing as a sidebar docked on the Windows desktop. Since users could copy and paste sensitive information into it, organizations must properly configure the chat provider platform for Copilot in Windows. With Ivanti Neurons for MDM, you can create configurations for different device groups and enable Copilot after testing. Administrators can choose upgrade to Windows 11 while having Copilot disabled for all devices and enabling it in phases later by device group.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Image your start menu and task bar for Windows 11:&lt;/strong&gt; Another challenge users face when planning their Windows 11 upgrade is the change in the user interface. Windows 11 has a new start menu at the bottom of the screen instead of on the left; the task bar differs, too. With the changes recently rolled out in Ivanti Neurons for MDM, administrators can create images targeted for Windows 11 devices. As soon as devices get upgraded, the new Windows 11 start menu and task bar image will be pushed to the devices.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Track upgrades and troubleshoot remotely: &lt;/strong&gt;After the device has been configured with the Windows Software Update configuration, every device will report the applicable versions and start updating according to the specifications or will wait for administrator approval. Administrators can approve any Windows 11 updates reported by the device and have visibility into which devices are eligible, pending upgrade, upgraded or failed. They can also create charts on the dashboard to track adoption of the Windows version deployed to the endpoints.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Automate enrollment of newly refreshed Windows 11 devices via Ivanti Neurons for UEM:&lt;/strong&gt; Many firms are deciding to start a device refresh process of their fleet, instead of trying to jump through all the hoops required to upgrade existing devices. As companies work with their distributors to purchase and ship devices to their end users, they need to plan for the most efficient way to image and provision Windows 11 compatible configurations and applications.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;One way is via Autopilot enrollment. Ivanti Neurons for MDM provides the easiest way to image and provision devices with the OOBE via Autopilot, automating the setup of the devices and the installation of application. With the previously described features, administrators can tailor the policies to Windows 11 images and applications compatible with this new operating system. Ivanti Neurons for MDM supports Autopilot without incurring additional MDM user license costs.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;On the other hand, if you are using any other agent-based Windows Management solution, you can automate the enrollment via Ivanti Neurons UEM Deployment Package. Via the agent, push a deployment package to devices and enroll them seamlessly, with no end user impact, into Ivanti Neurons for UEM and start managing your Windows 11 upgrades.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;Know before you upgrade&amp;nbsp;&lt;/h2&gt;

&lt;p&gt;Follow these suggestions to make your transition smooth:&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Windows 11 has specific &lt;a href="https://www.microsoft.com/en-us/windows/windows-11-specifications" rel="noopener" target="_blank"&gt;system requirements&lt;/a&gt;. Make sure your fleet meets these requirements for your devices to be eligible for upgrade.&amp;nbsp;&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;Windows 11 requires Secure Boot be enabled. Secure Boot is designed to prevent malicious software from loading when a PC starts. Most modern PCs are capable of Secure Boot, but in some instances, there may be settings that cause the PC to appear to not be. Check with your device manufacturer for support on Secure Boot. Ivanti has partnered with Lenovo to configure Secure Boot via Configurations.&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;Windows 11 has over 1,000 new management controls to make it easier to move away from older management systems like Group Policy.&amp;nbsp;&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;Windows 11 is built on the Windows 10 code base, so it is natively compatible with the software and solutions used today. However, some solutions might work differently in Windows 11 or have different requirements. Create a pilot device group to test the Windows 11 upgrade, security solutions and new configuration before rolling it out to the larger population of devices.&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;To leverage the Windows Autopilot features, Ivanti Neurons for MDM needs to be integrated with a &lt;a href="https://learn.microsoft.com/en-us/autopilot/licensing-requirements" rel="noopener" target="_blank"&gt;Microsoft Entra environment&lt;/a&gt;.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Fri, 12 Apr 2024 04:00:03 Z</pubDate></item><item><guid isPermaLink="false">00d71fc2-4d46-4154-b392-638e587bc277</guid><link>https://www.ivanti.com/blog/what-it-administrators-want-to-know-about-apple-vision-pro</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint Management</category><title>What IT Administrators Want to Know About Apple Vision Pro</title><description>&lt;p&gt;Apple’s release of Apple Vision Pro on Feb. 2, 2024, sparked widespread anticipation among tech enthusiasts worldwide. Even more among enterprise customers when Apple announced MDM management capabilities in visionOS 1.1.&lt;/p&gt;

&lt;p&gt;Apple Vision Pro lets users interact with apps while remaining connected to their physical surroundings or immerse themselves entirely in a virtual environment of their choosing. This flexibility opens infinite possibilities for personal and enterprise applications, fundamentally transforming the way we experience computing.&lt;/p&gt;

&lt;p&gt;For enterprises, Apple Vision Pro features present opportunities across various use cases, including productivity and collaboration with the device's infinite canvas to access and multitask seamlessly and collaborate on projects in real-time; remote training, allowing instructors to guide trainees through simulations and hands-on tasks from anywhere in the world; guided work to display contextual information such as equipment manuals, safety procedures or troubleshooting guides, enhancing workers' understanding and performance; and even co-design sessions, where engineers immerse themselves and visualize, review, and iterate on designs together.&lt;/p&gt;

&lt;p&gt;In response to growing demand for enterprise-ready solutions, Apple also introduced &lt;a href="https://www.ivanti.com/autonomous-endpoint-management/mobile-device-management"&gt;Mobile Device Management (MDM)&lt;/a&gt;&amp;nbsp;controls for Apple Vision Pro. The developer beta of visionOS 1.1 lets MDM developers test configurations for enterprise networking (Wi-Fi, VPN, per-app VPN), single sign-on, restrictions, identity certificates, managed app installation and more, ensuring the security of the data and seamless integration into existing IT infrastructures.&lt;/p&gt;

&lt;p&gt;Apple Vision Pro has the security and privacy features expected for an enterprise-grade device. Apple introduced biometrics like Touch ID and Face ID to iPhone, iPad, and Mac; now, Apple Vision Pro includes Optic ID, which provides authentication via iris recognition. Apple’s M2 processor and Secure Enclave protect Optic ID data, and provides the encryption and security enterprise customers expect.&lt;/p&gt;

&lt;p&gt;Some highlights on the ability to manage Apple Vision Pro are:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;strong&gt;MDM Enrollment:&lt;/strong&gt; Management of the Apple Vision Pro requires registration via account-driven Device Enrollment or account-driven User Enrollment with a Managed Apple ID. Apple has stated that Automated Device Enrollment, adding devices to Apple Business Manager or Apple School Manager, and supervision are not supported at this time.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;MDM Configurations:&lt;/strong&gt; MDM payloads and declarative device management are both supported for applying configurations to Apple Vision Pro, ensuring comprehensive management capabilities for enterprise deployments.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;App Deployment:&lt;/strong&gt; Apple has announced over 1,000 spatial apps built for Apple Vision Pro and more than 1 million compatible iOS and iPadOS apps. Apps can be deployed using MDM, similar to other Apple devices. Native visionOS apps are not in the volume Apps and Books store yet, but compatible and in-house apps can still be deployed.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;Additional Management:&lt;/strong&gt; Apple Vision Pro will support gathering inventory data, and can be remotely erased in case it goes missing. The management model is similar to iPhone and iPad, and Apple has taken the same approach with Apple Vision Pro.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;Integration:&lt;/strong&gt; Apple Vision Pro seamlessly integrates with IT systems, like corporate Wi-Fi networks, VPN, email, identity providers, and cloud storage providers. Plus, Apple Vision Pro offers compatibility with other Apple services and devices out of the box.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;At Ivanti, we are dedicated to enabling our customers with the tools to support all enterprise use cases. Our goal is to empower our customers with tailored solutions, driving productivity and innovation. Stay tuned for updates on MDM compatibility and support in our Ivanti &lt;a href="https://www.ivanti.com/solutions/secure-unified-endpoint-management"&gt;UEM solutions&lt;/a&gt;, designed to seamlessly manage Apple Vision Pro devices.&lt;/p&gt;
</description><pubDate>Mon, 11 Mar 2024 15:59:25 Z</pubDate></item><item><guid isPermaLink="false">39a425cb-5f0b-46b7-9a91-43cfba70a037</guid><link>https://www.ivanti.com/blog/making-sense-of-wwdc23-what-it-admins-need-to-know-to-manage-apple-devices</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint Management</category><title>WWDC23: What IT Admins Need to Know to Manage Apple Devices</title><description>&lt;p&gt;Apple’s annual developer conference, &lt;a href="https://developer.apple.com/wwdc23/" rel="noopener" target="_blank"&gt;WWDC&lt;/a&gt;, is a firehose of information for anyone who manages Apple devices.&lt;/p&gt;

&lt;p&gt;New operating systems (notably iOS 17, iPadOS 17,&amp;nbsp;macOS 14 and watchOS 10) and new products (15-inch MacBook Air and Apple&amp;nbsp;Vision Pro) might have dominated the headlines, but WWDC23 also brought a host of&amp;nbsp;no less consequential new capabilities for enterprise device management.&lt;/p&gt;

&lt;p&gt;So what should IT admins pay attention to in the lead up to this fall’s OS updates?&lt;/p&gt;

&lt;h2&gt;A big step forward in declarative device management&lt;/h2&gt;

&lt;p&gt;Apple introduced &lt;strong&gt;declarative management&lt;/strong&gt; in 2021 as an extended functionality to the MDM protocol, and this year they continued the trend of releasing configurations that can coexist on MDM and declarative management at the same time as part of a gradual transition. Apple has announced a &lt;a href="https://developer.apple.com/videos/play/wwdc2023/10041/" rel="noopener" target="_blank"&gt;transition path&lt;/a&gt; from today’s MDM protocol to declarative management, which will make the changeover seamless for end users.&lt;/p&gt;

&lt;p&gt;What’s new this year is that Apple is also releasing features that can &lt;em&gt;only&lt;/em&gt; be supported via declarative management – &lt;strong&gt;passkeys&lt;/strong&gt;&amp;nbsp;and &lt;strong&gt;Apple Watch management&lt;/strong&gt;. Ivanti’s UEM products will support declarative device management, and therefore these new features, in the next few quarters.&lt;/p&gt;

&lt;h2&gt;Simpler device enrollment – for IT &lt;em&gt;and&lt;/em&gt; for end users&lt;/h2&gt;

&lt;p&gt;Getting rid of manual processes is a clear theme for the device enrollment enhancements released this year.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Return to service&lt;/strong&gt;, a new capability for bringing devices back into management, lets IT admins send a command to erase and then re-enroll a device automatically – a process that until now was manual. This feature is particularly useful for devices without dedicated users that need to be remotely reconfigured without manual intervention, for example an iPad that needs to be reset after a patient is discharged from a hospital.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Account-driven device enrollment&lt;/strong&gt; (an enhancement to account-driven user enrollment, which is already available) enrolls devices automatically when users sign in with their work or school account, rather than requiring the user to install a profile manually. Eliminating this extra step can streamline device onboarding.&lt;/p&gt;

&lt;p&gt;On the topic of device enrollment, &lt;strong&gt;Setup Assistant&lt;/strong&gt; also saw enhancements worth paying attention to: the ability to restrict enrollment to devices that meet &lt;strong&gt;minimum OS requirements&lt;/strong&gt;, and the ability to &lt;strong&gt;configure FileVault&lt;/strong&gt; during setup. These features let companies ship devices directly from the supplier to the end user without needing a manual setup to ensure basic security features are in compliance.&lt;/p&gt;

&lt;h2&gt;Easy end user authentication for a better end user experience&lt;/h2&gt;

&lt;p&gt;Updates to &lt;strong&gt;Managed Apple IDs&lt;/strong&gt; give organizations access to a range of improved authentication features that make it easier for end users to access their devices and services. Managed Apple IDs now include support for iCloud Keychain, Apple Wallet, and access management controls that enable organizations to restrict access to specific services and dictate the management state of a device when a user signs in. Additionally, passkeys can now be synced across managed devices for an even more secure authentication experience.&lt;/p&gt;

&lt;p&gt;Platform single sign-on (SSO) now lets you &lt;strong&gt;create local user accounts on a shared Mac&lt;/strong&gt; using credentials from the Identity Provider (IdP).&lt;/p&gt;

&lt;p&gt;Finally, &lt;strong&gt;Managed Device Attestation&lt;/strong&gt; is now available on macOS and offers strong assurances about the security posture and properties of a device.&lt;/p&gt;

&lt;h2&gt;Useful updates to device and application connectivity&lt;/h2&gt;

&lt;p&gt;For an alternative to VPN, you can now use a new &lt;strong&gt;built-in relay&lt;/strong&gt; to secure traffic using an HTTP/3 or HTTP/2 tunnel. The configuration is domain-based and can be applied to managed apps, domains, or the entire device.&lt;/p&gt;

&lt;p&gt;Apple has also expanded &lt;strong&gt;802.1X support for Ethernet&lt;/strong&gt;, which previously was only supported for macOS, allowing you to connect an iPhone, iPad&amp;nbsp;or Apple TV&amp;nbsp;to a restricted network&amp;nbsp;that requires authentication without needing to rely on WiFi.&lt;/p&gt;

&lt;h2&gt;Finally – private network and network slicing support&lt;/h2&gt;

&lt;p&gt;Long-awaited support for &lt;strong&gt;private 5G and LTE networks&lt;/strong&gt; is finally here for iOS 17 and iPadOS 17.&lt;/p&gt;

&lt;p&gt;Administrators can activate private SIMs automatically when a device enters a geofence in order to &lt;strong&gt;prioritize cellular over Wi-Fi&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;And with &lt;strong&gt;5G network slicing&lt;/strong&gt;, mobile network operators can customize traffic through a 5G standalone network with specific quality-of-service requirements for network latency, throughput and packet loss.&lt;/p&gt;

&lt;h2&gt;Discovering new use cases for wearables in the workplace?&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Apple Watch&lt;/strong&gt;&amp;nbsp;is newly supported as a managed device. An Apple Watch that is paired to a Supervised iPhone can now be enrolled and managed with watchOS 10 – with the very important requirement&amp;nbsp;that declarative management configuration must be enabled.&lt;/p&gt;

&lt;h2&gt;Planning ahead for this fall’s OS updates&lt;/h2&gt;

&lt;p&gt;Ivanti is actively testing the betas of iOS 17 and macOS 14 to make sure you can take advantage of these new features for a better end-user experience and streamlined IT processes.&lt;/p&gt;

&lt;p&gt;Look out for communication on compatibility as we plan for &lt;strong&gt;day zero support&lt;/strong&gt; for Ivanti products.&lt;/p&gt;
</description><pubDate>Tue, 25 Jul 2023 19:51:36 Z</pubDate></item><item><guid isPermaLink="false">4719afca-c762-48f1-850c-e35e86c4d90a</guid><link>https://www.ivanti.com/blog/windows-11-22h2-and-ivanti-uem-the-new-features-enterprise-users-should-know</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint Management</category><title>Windows 11 22H2 and Ivanti UEM: The New Features Enterprise Users Should Know</title><description>&lt;p&gt;The Windows 11 22H2 release demonstrates that Microsoft is embracing the Everywhere Workplace, with new features and capabilities to support remote workers and BYOD deployments.&lt;/p&gt;

&lt;p&gt;What enhancements should IT admins pay attention to? These are the features worth taking advantage of – and since&amp;nbsp;&lt;a href="https://www.ivanti.com/autonomous-endpoint-management/unified-endpoint-management"&gt;Ivanti UEM solutions&lt;/a&gt;&amp;nbsp;support devices on Windows 11 22H2, customers can roll out the latest OS to their whole fleet from day zero. Stay tuned for updates on support for new management features.&lt;/p&gt;

&lt;h2&gt;Productivity enhancements for end users&lt;/h2&gt;

&lt;p&gt;These collaboration and productivity features – many of which employees can personalize to their liking – are particularly useful for employees working remotely or while in transit.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Group apps into a folder on the Start menu&lt;/strong&gt;.&amp;nbsp;Employees can also personalize the Start menu to add more apps or recommendations.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Add and view favorites on the File Explorer home screen&lt;/strong&gt;.&amp;nbsp;File Explorer tabs help organize content to quickly switch between multiple projects.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Avoid distracting notifications&lt;/strong&gt;.&amp;nbsp;Focus assist is set by default to activate automatically under certain conditions. Employees can adjust and extend focus time from the Focus Assist settings on the taskbar.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Improve video and audio calls&lt;/strong&gt;&amp;nbsp;with Windows Studio Effects.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Make Teams meetings more accessible&lt;/strong&gt;.&amp;nbsp;Live captions make video meetings easier to follow.&lt;/p&gt;

&lt;h2&gt;Security enhancements for IT&lt;/h2&gt;

&lt;p&gt;IT teams are acutely aware of the security threat posed by unmanaged devices and access to corporate data from personal computers – but they also need to accommodate employees’ expectations to be able to work from their device of choice. Many of the security enhancements in the latest Windows 11 release take aim at closing that gap between employee experience and security requirements.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Windows Defender Credential Guard&lt;/strong&gt;&amp;nbsp;is now enabled by default with Windows 11 Enterprise, providing virtualization security to protect against credential theft.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Credential isolation with Local Security Authority&lt;/strong&gt;&amp;nbsp;is also enabled by default, providing extra protection to new enterprise-joined Windows 11 devices.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Hypervisor-protected code integrity&lt;/strong&gt;&amp;nbsp;is also enabled by default on all new Windows 11 devices.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Microsoft Vulnerable Driver Blocklist&lt;/strong&gt;&amp;nbsp;safeguards against advanced threats and ransomware attacks.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Configuration Lock for Secure Core PC&lt;/strong&gt;&amp;nbsp;lets IT lock down security policies so they can’t be changed inadvertently, closing the window of opportunity for an attacker. IT can set monitor settings to ensure that devices comply with company security policies and automatically revert changes immediately.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Smart Apps Control&lt;/strong&gt;&amp;nbsp;identifies trustworthy apps using threat intelligence signals and only allows processes to run if they are predicted to be safe, perfect for BYOD devices or small businesses. (Enterprise customers can use Windows Defender Application Control or AppLocker).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enable passwordless authentication&lt;/strong&gt;&amp;nbsp;with Windows Hello for Business and a unique identifier, such as a biometric element.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enhanced Phishing Protection in Microsoft Defender SmartScreen&lt;/strong&gt;&amp;nbsp;detects difficult-to-observe password phishing attacks and takes immediate action to prevent further compromise, informing employees right away that they need to change their password and automatically alerting IT of the incident.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Windows Autopatch&lt;/strong&gt;&amp;nbsp;keeps Windows, Microsoft Edge and Office deployments up-to-date and optimizes secure productivity.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Windows 11 in-product messages&lt;/strong&gt;&amp;nbsp;let IT communicate targeted information to the end user, for example providing direction during device setup in the Get Started application or sending messages to the lock screen or desktop.&lt;/p&gt;

&lt;h2&gt;Learn more about Ivanti UEM&lt;/h2&gt;

&lt;p&gt;To learn more about how Ivanti UEM solutions support modern management and BYOD use cases, visit the&amp;nbsp;&lt;a href="https://www.ivanti.com/devices/windows-device-management"&gt;Ivanti Neurons for UEM for Windows Device Management&lt;/a&gt;&amp;nbsp;page or download the&amp;nbsp;&lt;a href="https://www.ivanti.com/resources/v/doc/ivi/2676/bd00fd0ccd74"&gt;detailed datasheet&lt;/a&gt;.&lt;/p&gt;
</description><pubDate>Thu, 22 Sep 2022 19:10:06 Z</pubDate></item><item><guid isPermaLink="false">7ac23234-735c-4717-8f8a-9ce13319bb52</guid><link>https://www.ivanti.com/blog/what-s-new-in-ivanti-neurons-for-mobile-device-management</link><atom:author><atom:name>Kate Kim</atom:name><atom:uri>https://www.ivanti.com/blog/authors/kate-kim</atom:uri></atom:author><atom:author><atom:name>Charlie Rasch</atom:name><atom:uri>https://www.ivanti.com/blog/authors/charlie-rasch</atom:uri></atom:author><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/blog/authors/yosune-baltra</atom:uri></atom:author><title>What's New in Ivanti Neurons for Mobile Device Management?</title><description>&lt;p&gt;The latest release of &lt;a href="https://www.ivanti.com/products/ivanti-neurons-for-mdm"&gt;Ivanti Neurons for MDM&lt;/a&gt;&amp;nbsp;includes enhancements for managing COSU devices and transitioning to cloud-based device management.&lt;/p&gt;

&lt;h2&gt;Provide&amp;nbsp;extra security and support for your Android COSU devices&lt;/h2&gt;

&lt;p&gt;Corporate-owned single-use (COSU) devices are dedicated for a single use, and Android Enterprise's capabilities can help configure those devices to best serve that purpose. Use cases for COSU devices include:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Point-of-sale (POS) systems in retail.&lt;/li&gt;
	&lt;li&gt;Handheld barcode scanners in supply chain.&lt;/li&gt;
	&lt;li&gt;Smart panels (such as information kiosks, timecard entry panels, physical access entry panels, etc.) across a number of industries, including healthcare, retail and manufacturing.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These locked-down devices can be dedicated to a single user, multiple users&amp;nbsp;or external users. The Android Enterprise COSU configuration provides more control over how your staff and customers use the device&amp;nbsp;by compartmentalizing the operating system to deploy in a locked-down environment, running a single application or a specific set of apps. Usually, one application is intended to run on the device and that’s all. COSU improves security, efficiency, processes, compliance and user experience by locking devices down to execute a small range of specific tasks.&lt;/p&gt;

&lt;p&gt;With the latest release of Ivanti Neurons for MDM, several new features have been added to better secure and support your COSU devices.&lt;/p&gt;

&lt;h3&gt;5G slicing support&amp;nbsp;&lt;/h3&gt;

&lt;p&gt;With more COSU devices deployed in remote locations, 5G support becomes more essential for securing those devices. Not only does Neurons for MDM provides 5G information to let you know if your device is part of your private 5G network slice, 5G network slicing allows your provider to take a shared physical network and portion it out into logical segments. Each segment is provisioned for a different set of users, devices&amp;nbsp;and applications,&amp;nbsp;and the logical separations mean the traffic from one slice does not interfere with another.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In a retail environment, different slices can be configured to provide for your mobile POS&amp;nbsp;devices and for your customer kiosks. Your remote retail environments might employ these slicing schemes to provide better employee and customer experience, while behind the scenes keeping track of inventory. These slices would separate each other’s traffic and resources, improving security. 5G slicing can be enabled in the lockdown Android Enterprise configuration within Ivanti Neurons for MDM.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;h3&gt;Configuring higher app priority distribution and updates on your COSU devices&amp;nbsp;&lt;/h3&gt;

&lt;p&gt;With Ivanti Neurons for MDM, IT can set higher-priority apps for enrollment and update on COSU devices. This will allow admins to set which applications are critical for deployment and updating.&amp;nbsp; This is important especially if the update would resolve or prevent a production-related issue. Getting these updates out as fast as possible can reduce downtime or even prevent a production-affecting event from surfacing.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;h3&gt;Providing additional USB security to your COSU devices&amp;nbsp;&lt;/h3&gt;

&lt;p&gt;With Ivanti Neurons for MDM, you can configure the USB port to be used for charging only to prevent the USB port from being used as a physical vector for malicious attacks, keeping unauthorized users from accessing confidential data. This&amp;nbsp;is important particularly important for&amp;nbsp;COSU devices in an open area, such as kiosks and POS devices in retail stores.&lt;/p&gt;

&lt;h3&gt;Unattended remote session support&amp;nbsp;&lt;/h3&gt;

&lt;p&gt;Remote session support becomes even more of a necessity for remote COSU devices,&amp;nbsp;particularly in a retail environment where there maybe no one is available&amp;nbsp;after the store closes&amp;nbsp;to troubleshoot and resolve technical issues.&lt;/p&gt;

&lt;p&gt;With Neurons for MDM, you can initiate a remote session from within the console without requiring input from any user at that location, making it easy&amp;nbsp;to manage COSU devices when there is no physical access to those devices.&lt;/p&gt;

&lt;h2&gt;Easily transition Windows devices to cloud-based modern management&lt;/h2&gt;

&lt;p&gt;We are excited to announce an Ivanti Neurons for MDM deployment package with the Q2 release to support customers with an easy transition for their Windows devices from traditional management to modern management.&lt;/p&gt;

&lt;h3&gt;Ivanti Neurons for MDM deployment package&lt;/h3&gt;

&lt;p&gt;IT can enroll devices managed by Microsoft Configuration Manager (formerly SCCM) or Ivanti Endpoint Manager into Ivanti Neurons for MDM. The Deployment Package tool allows organizations to streamline the transition of Windows devices to cloud-based modern management, without downtime or end-user interruption. Seamless transition is achieved by downloading a unique deployment package from the Neurons for MDM console, then deploying it through the existing management tool or domain. Once the package is deployed, it will silently enroll endpoints into Neurons for MDM for ongoing management. This approach allows administrators to first migrate devices easily, then have flexibility to configure devices later over the air. When device enrollment is completed silently into Neurons for MDM, it is joined with MDM and gets co-managed by two management authorities. Once an administrator configures the desired Windows experience within Neurons for MDM, a legacy management platform can be decommissioned, leaving Neurons for MDM as the&amp;nbsp;single management authority of the device.&lt;/p&gt;

&lt;p&gt;This package can be deployed in environments that do not leverage Azure Active Directory (AAD). The main elements of Neurons for MDM modern Windows management suite do not require AAD. Co-management or co-existence may require certain workloads or configurations to be deployed upon silent enrollment, to avoid any impact during transition.&lt;/p&gt;

&lt;h3&gt;Why move to cloud-based modern management?&lt;/h3&gt;

&lt;p&gt;As UEM solutions have evolved and added more capabilities over the years, it has become&amp;nbsp;critical to provide a consistent user experience and management capabilities between mobile (iOS and Android) and Windows devices. Cloud-based modern device management on Windows devices is fundamentally different from&amp;nbsp;traditional device management, but similar to mobile device management on iOS and Android.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;One of key differences is profile-based management. Breaking from image-based management relieves significant IT workload from manual device imaging and maintenance. A profile is a collection of configuration settings that are applied to a device based on group membership, which allows profiles to be created as a module with multiple profiles assigned to a single user depending on their job function and required apps.&amp;nbsp;With profile-based management, IT can remotely make changes on any configuration and push patch updates over the air.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Those differences mean that cloud-based modern management significantly reduces IT overhead and the complexity of managing Windows devices.&lt;/p&gt;

&lt;p&gt;There are a number of drivers for considering a&amp;nbsp;transition from client-based to cloud-based modern device management:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;strong&gt;Higher scalability and lower cost impact.&lt;/strong&gt;&amp;nbsp;We can view scalability into two different ways – faster deployment and ease&amp;nbsp;of scaling.&amp;nbsp;First, a cloud-based solution&amp;nbsp;is&amp;nbsp;faster to deploy compared to an on-prem solution.&amp;nbsp;Second, if you want to deploy more devices with a cloud-based solution, you don’t need to build a new server, which would be required for&amp;nbsp;an on-prem solution to scale.&amp;nbsp;Also, cloud-based solutions are&amp;nbsp;managed by the vendor, so customers can save the cost of&amp;nbsp;managing&amp;nbsp;infrastructure and servers on their own.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;Better security posture.&lt;/strong&gt;&amp;nbsp;Some might argue that on-prem has a better reputation when it comes to security posture. And it is true that some customers in heavily regulated industries still prefer to continue using on-prem solutions. The caveat is that security posture really depends on a customer’s infrastructure, and it often&amp;nbsp;requires a heavy investment for customers to build their own security infrastructure and hire experts to manage it.&amp;nbsp;Cloud service providers, including Ivanti, meet a high security standard with various certifications&amp;nbsp;— for example, Ivanti Neurons for MDM is FedRAMP&amp;nbsp;and SOC2 certified.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;Improved productivity and user experience.&lt;/strong&gt;&amp;nbsp;Remember&amp;nbsp;the significant efforts that went into the Windows 10 migration of a few years ago — and the loss of productivity due to downtime during the update?&amp;nbsp;Modern device management minimizes impacts on productivity between Windows OS updates, as devices are being managed like smartphones.&amp;nbsp;Modern device management also allows you to leverage a zero-touch provisioning solution that integrates systems like Windows Autopilot, Apple Business Manager, Android Enterprise&amp;nbsp;and Samsung Knox Mobile Enrollment.&amp;nbsp;IT can ship a Windows device directly to a user, and it automatically gets enrolled into the cloud-based UEM solution.&amp;nbsp;You can cut onboarding time from weeks to two days, which results not only in a faster onboarding but also&amp;nbsp;higher user satisfaction.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Learn more&lt;/h2&gt;

&lt;p&gt;For more information about Ivanti Neurons for MDM, visit the &lt;a href="https://www.ivanti.com/products/ivanti-neurons-for-mdm"&gt;product page&lt;/a&gt;&amp;nbsp;or view the &lt;a href="https://help.ivanti.com/mi/help/en_us/cld/8x/rn/default.htm" target="_blank"&gt;release notes&lt;/a&gt;.&lt;/p&gt;
</description><pubDate>Mon, 02 May 2022 18:25:13 Z</pubDate></item></channel></rss>