<?xml version="1.0" encoding="utf-8"?><rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Ivanti Blog: Posts by </title><description /><language>en</language><atom:link rel="self" href="https://www.ivanti.com/en-au/blog/authors/yosune-baltra/rss" /><link>https://www.ivanti.com/en-au/blog/authors/yosune-baltra</link><item><guid isPermaLink="false">ef68e054-c2be-48b9-9675-032ffcf2d8fd</guid><link>https://www.ivanti.com/en-au/blog/making-sense-of-wwdc23-what-it-admins-need-to-know-to-manage-apple-devices</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/en-au/blog/authors/yosune-baltra</atom:uri></atom:author><title>WWDC23: What IT Admins Need to Know to Manage Apple Devices</title><description>&lt;p&gt;Apple’s annual developer conference, &lt;a href="https://developer.apple.com/wwdc23/" rel="noopener" target="_blank"&gt;WWDC&lt;/a&gt;, is a firehose of information for anyone who manages Apple devices.&lt;/p&gt;

&lt;p&gt;New operating systems (notably iOS 17, iPadOS 17,&amp;nbsp;macOS 14 and watchOS 10) and new products (15-inch MacBook Air and Apple&amp;nbsp;Vision Pro) might have dominated the headlines, but WWDC23 also brought a host of&amp;nbsp;no less consequential new capabilities for enterprise device management.&lt;/p&gt;

&lt;p&gt;So what should IT admins pay attention to in the lead up to this fall’s OS updates?&lt;/p&gt;

&lt;h2&gt;A big step forward in declarative device management&lt;/h2&gt;

&lt;p&gt;Apple introduced &lt;strong&gt;declarative management&lt;/strong&gt; in 2021 as an extended functionality to the MDM protocol, and this year they continued the trend of releasing configurations that can coexist on MDM and declarative management at the same time as part of a gradual transition. Apple has announced a &lt;a href="https://developer.apple.com/videos/play/wwdc2023/10041/" rel="noopener" target="_blank"&gt;transition path&lt;/a&gt; from today’s MDM protocol to declarative management, which will make the changeover seamless for end users.&lt;/p&gt;

&lt;p&gt;What’s new this year is that Apple is also releasing features that can &lt;em&gt;only&lt;/em&gt; be supported via declarative management – &lt;strong&gt;passkeys&lt;/strong&gt;&amp;nbsp;and &lt;strong&gt;Apple Watch management&lt;/strong&gt;. Ivanti’s UEM products will support declarative device management, and therefore these new features, in the next few quarters.&lt;/p&gt;

&lt;h2&gt;Simpler device enrollment – for IT &lt;em&gt;and&lt;/em&gt; for end users&lt;/h2&gt;

&lt;p&gt;Getting rid of manual processes is a clear theme for the device enrollment enhancements released this year.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Return to service&lt;/strong&gt;, a new capability for bringing devices back into management, lets IT admins send a command to erase and then re-enroll a device automatically – a process that until now was manual. This feature is particularly useful for devices without dedicated users that need to be remotely reconfigured without manual intervention, for example an iPad that needs to be reset after a patient is discharged from a hospital.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Account-driven device enrollment&lt;/strong&gt; (an enhancement to account-driven user enrollment, which is already available) enrolls devices automatically when users sign in with their work or school account, rather than requiring the user to install a profile manually. Eliminating this extra step can streamline device onboarding.&lt;/p&gt;

&lt;p&gt;On the topic of device enrollment, &lt;strong&gt;Setup Assistant&lt;/strong&gt; also saw enhancements worth paying attention to: the ability to restrict enrollment to devices that meet &lt;strong&gt;minimum OS requirements&lt;/strong&gt;, and the ability to &lt;strong&gt;configure FileVault&lt;/strong&gt; during setup. These features let companies ship devices directly from the supplier to the end user without needing a manual setup to ensure basic security features are in compliance.&lt;/p&gt;

&lt;h2&gt;Easy end user authentication for a better end user experience&lt;/h2&gt;

&lt;p&gt;Updates to &lt;strong&gt;Managed Apple IDs&lt;/strong&gt; give organizations access to a range of improved authentication features that make it easier for end users to access their devices and services. Managed Apple IDs now include support for iCloud Keychain, Apple Wallet, and access management controls that enable organizations to restrict access to specific services and dictate the management state of a device when a user signs in. Additionally, passkeys can now be synced across managed devices for an even more secure authentication experience.&lt;/p&gt;

&lt;p&gt;Platform single sign-on (SSO) now lets you &lt;strong&gt;create local user accounts on a shared Mac&lt;/strong&gt; using credentials from the Identity Provider (IdP).&lt;/p&gt;

&lt;p&gt;Finally, &lt;strong&gt;Managed Device Attestation&lt;/strong&gt; is now available on macOS and offers strong assurances about the security posture and properties of a device.&lt;/p&gt;

&lt;h2&gt;Useful updates to device and application connectivity&lt;/h2&gt;

&lt;p&gt;For an alternative to VPN, you can now use a new &lt;strong&gt;built-in relay&lt;/strong&gt; to secure traffic using an HTTP/3 or HTTP/2 tunnel. The configuration is domain-based and can be applied to managed apps, domains, or the entire device.&lt;/p&gt;

&lt;p&gt;Apple has also expanded &lt;strong&gt;802.1X support for Ethernet&lt;/strong&gt;, which previously was only supported for macOS, allowing you to connect an iPhone, iPad&amp;nbsp;or Apple TV&amp;nbsp;to a restricted network&amp;nbsp;that requires authentication without needing to rely on WiFi.&lt;/p&gt;

&lt;h2&gt;Finally – private network and network slicing support&lt;/h2&gt;

&lt;p&gt;Long-awaited support for &lt;strong&gt;private 5G and LTE networks&lt;/strong&gt; is finally here for iOS 17 and iPadOS 17.&lt;/p&gt;

&lt;p&gt;Administrators can activate private SIMs automatically when a device enters a geofence in order to &lt;strong&gt;prioritize cellular over Wi-Fi&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;And with &lt;strong&gt;5G network slicing&lt;/strong&gt;, mobile network operators can customize traffic through a 5G standalone network with specific quality-of-service requirements for network latency, throughput and packet loss.&lt;/p&gt;

&lt;h2&gt;Discovering new use cases for wearables in the workplace?&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Apple Watch&lt;/strong&gt;&amp;nbsp;is newly supported as a managed device. An Apple Watch that is paired to a Supervised iPhone can now be enrolled and managed with watchOS 10 – with the very important requirement&amp;nbsp;that declarative management configuration must be enabled.&lt;/p&gt;

&lt;h2&gt;Planning ahead for this fall’s OS updates&lt;/h2&gt;

&lt;p&gt;Ivanti is actively testing the betas of iOS 17 and macOS 14 to make sure you can take advantage of these new features for a better end-user experience and streamlined IT processes.&lt;/p&gt;

&lt;p&gt;Look out for communication on compatibility as we plan for &lt;strong&gt;day zero support&lt;/strong&gt; for Ivanti products.&lt;/p&gt;
</description><pubDate>Tue, 25 Jul 2023 19:51:36 Z</pubDate></item></channel></rss>