MDM Device Management SK Flashcards

1
Q

How many times can you enter an incorrect password for a Managed Apple ID before it is disabled?

A

A Managed Apple ID can be locked or disabled when an incorrect password is entered more than 10 times in a row.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How to reset password for Managed Apple IDs?

A

A user can’t reset the password for their Managed Apple ID. An Apple Business Manager, Apple Business Essentials, or Apple School Manager user with the role of Administrator or People Manager can reset the password. An Apple School Manager user with the role of Site Manager can also reset the password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What happens when you use a device with both a Managed Apple ID and a personal Apple ID?

A

When you use a device with both a Managed Apple ID and a personal Apple ID, your personal data and the organization’s data are kept separate and cryptographically secure. You can continue to access your personal data with your personal Apple ID — without the organization having access to this data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Like any Apple ID, Managed Apple IDs can be used on which types of devices?

A

dedicated or shared devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which option doesn’t work for creating a new Apple ID?

A

You can’t create an Apple ID using Apple TV.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What happens if the administrator forgets or loses their password before at least one additional administrator is created for Managed Apple IDs?

A

they must use the iforgot.apple.com website to reset their password for Apple Business Manager, Apple Business Essentials, or Apple School Manager.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Is the iCloud Mail account service available for Managed Apple IDs?

A

Inaccessible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which iCloud services can be accessed if enabled for Managaed Apple IDs using Apple School Manager?

A

If permitted, iCloud data can be accessed on devices and by signing in to iCloud.com. iCloud Backup, iCloud Drive, iCloud Keychain, Calendar, Contacts, Freeform, News, Notes, Photos, Reminders, Safari, Siri, Stocks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Is App Store available for Managed Apple IDs?

A

Allows browsing but can’t buy apps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

In order to protect user privacy, what services are NOT accessible for Managed Apple IDs?

A

Find My-The app appears, but the user can’t use it.
Health- The app appears, but the user can’t use it.
Home- The user can’t add HomeKit devices to the Home app.
Journal- The app appears, but the user can’t use it
iCloud Family Sharing- Unavailable
iCloud Mail- Unavailable
iCloud Services (Private Relay, Hide My Email, Custom Email Domain)- Unavailable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Who can create and manage Managed Apple ID’s?

A

Apple Business Manager, Apple Business Essentials, or Apple School Manager with required role - Only organizations can create and manage Managed Apple IDs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In order for devices and service to work seamlessly across device what must be enabled?

A

Apple ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Can a device be configure with out a Apple ID?

A

Yes, however some services and feature may not be available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How can Managed Apple ID be configured?

A

role-base, administration, identity federation and bulk actions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Can Managed Apple ID be used on dedicaed and shared device?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

When using both a Presonal and Managed Apple ID on the same device, is data share between to the two accounts?

A

data is kept separate and cryptographically secure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What role is used to create users in Apple Business Manager and Apple Business Essentials?

A

Administrator or People Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What role is used to create users in Apple School Manager?

A

Administrator or Site Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Can users reset their own passwords for a Managed Apple ID?

A

No, Administrator is the only one who can reset and update passwords for Managed ID’s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

If a Managed Apple ID is locked due to supected fraudulent activities, how can it be unlocked?

A

Contact Apple

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

When a device is lost, what feature can be used when working with a Managed Apple ID

A

MDM Lost Mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Can Manage Apple ID access iCloud Mail accounts?

A

No, inaccessible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

How does Mananged Apple ID effect App store behavior?

A

Allows browsing but can’t buy apps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

If a user is unsure if they have an Apple ID or forgot the password, where can they go to find out?

A

entering their name and email address at iforgot.apple.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Where can Apple ID users go to managed settings related to signing in, account security, and recovering account access when having trouble signing in?

A

appleid.apple.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

How can a Apple ID keep their account current and safe?

A
  • Change the password periodically.- Update trusted phone numbers and trusted devices.- Use two-factor authentication, including security keys — refer to Two-factor authentication for Apple ID.- Make sure that the notification email address is one they frequently use.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What happens when you sign in to your Apple ID on another Apple device?

A

You can sync designated data and settings from your other devices.When you sign in to your Apple ID on another iPhone, iPad, or Mac, you can choose to sync designated data and settings from other Apple devices using the same Apple ID.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What happens if you complete the setup of a new Apple device without signing in with an Apple ID?

A

Some services and features are unavailable until an Apple ID is associated with the device.You can complete the initial setup and configuration of a new Apple device without signing in with an Apple ID. However, some services and features are unavailable until an Apple ID is associated with the device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which option doesn’t work for creating a new Apple ID?

A

Apple TV - You can’t create an Apple ID using Apple TV.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

In the App Store, a user can browse and view apps but can’t buy them.What’s the possible cause of this issue?

A

The user is signed in with a Managed Apple ID.When signed in with a Managed Apple ID, the user can browse but not buy (or get for free) items from the App Store, the iTunes Store, or Apple Books.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What features between devices can a user access when signed in with the same Managed Apple ID as the primary account on both devices?

A
  • AirDrop
  • AirPlay to Mac
  • Auto Unlock
  • Continuity Camera
  • Continuity Markup and Sketch
  • Handoff
  • Personal Hotspot
  • iPhone cellular calls
  • Sidecar
  • Universal Clipboard
  • Universal Control
32
Q

What collaboration and communication services may be available based on specific criteria between devices when a user is signed in with the same Managed Apple ID as the primary account on both devices?

A

Read subheading: Collaboration and communication services availability —————> Apple School Manager availability VS Apple Business Manager and Apple Business Essentials availability

33
Q

Using Apple School Manager- By default, can users who DON’T have the role of Administrator that sign in with a Managed Apple ID able to access FaceTime and iMessage?

A

No
By default, users who don’t have the role of Administrator that sign in with a Managed Apple ID are UNABLE to access FaceTime and iMessage. You can modify that access.

34
Q

Managed Apple IDs in Apple School Manager- what are the two different levels of access that can be turned on for FaceTime and iMessage?

A

FaceTime and iMessage
- anyone inside and outside of your organization (default)
OR
- allowed with only other users in your

35
Q

Topic: Managed Apple IDs- What happens in case requirements for the management state of a device are changed?

A

a Managed Apple ID is automatically signed out of a device if the device state doesn’t meet the new requirements

36
Q

What enables apple devices to support MDM?

A

Frameworks

37
Q

Using MDM how can an administrator automate installation of certificates and applications and configure access to resources?

A

Profiles and commands

38
Q

In order for a device to be managed what must it have?

A

Enrollment Profile

39
Q

What contains identity certificates and information to associate a device with an MDM solution?

A

Enrollment Profile

40
Q

When an organization-owed device is enrolled using Automated Device Enrollment, what MDM state is it considered to be in?

A

managed and supervised

41
Q

When will a device no longer communicate with a MDM solution?

A

When it is unenrolled

42
Q

Contains one or more payloads

A

Profiles

43
Q

provide specific settings and authorization information

A

Payloads

44
Q

Does the preseence of a profile on a device mean that it is enroll to a MDM solution?

A

No, need to specficly have an enrollement profile

45
Q

How can a enrollment profile be installed?

A

Automatically, manually by an admin, or by user signing in to Managed Apple ID on personal device

46
Q

Has payloads that automate configuration of settings, accounts, restrictions and credentials

A

Configuration profile

47
Q

An update to the existing management protocol. Devices are asynchronously update

A

Declarative Device Management

48
Q

Payloads that represent policy changes the MDM server defines and sends

A

Declarations

49
Q

Used to proactively communicate with MDM server for updating the status of the device.

A

Status Channel

50
Q

On an iPhone where can you check to see if it is MDM enrolled?

A

Settings>General>VPN& Device Managment

51
Q

On a Mac wher can you check to see if it is MDM enrolled?

A

System settings > Privacy & Security > Profiles Also Apple Menu +Option > System information> software>Profiles or Managed Profiles

52
Q

How can you check the details of a profile installed on a mac?

A

System Settings > Privacy & Security > ProfilesDouble click on profile to see details

53
Q

Which enhancements to the user experience are available through an MDM solution?

A

Automated installation of certificates and applications and configuration of emailAn administrator using an MDM solution can securely and wirelessly configure and provision enrolled devices.

54
Q

A device is managed and supervised.Which statement below also applies to the device?

A

It’s organization-owned and went through Automated Device Enrollment.When an organization-owned device is enrolled into an MDM solution using Automated Device Enrollment, that device is both managed and supervised. An MDM administrator has broader control over a supervised device.

55
Q

What is the best way to check whether a Mac is managed through an MDM solution?

A

Access the list in System Settings > Privacy & Security > Profiles.If there’s an MDM profile, the device is managed.

56
Q

What is the best way to check whether managed settings of iPhone or iPad devices are interacting with your troubleshooting of Wi-Fi issues?

A

Find the MDM profile, and tap More Details.Examine the configuration profiles, and determine whether a network or certificate profile is interacting with your troubleshooting.

57
Q

A user can’t print at the office while using their Managed Apple ID on their user-owned iPhone.During troubleshooting, where would you check for MDM settings interacting with AirPrint?

A

Settings > General > VPN & Device Management > Managed Account > Profiles and Device ManagementFor a user-owned iPhone, the Managed Account contains the profiles.

58
Q

Managed Apple ID’s are created after?

A
  • Create accounts manually- Use federated authentication with Google Workspace or Microsoft Azure Active Directory (Azure AD)- See Intro to federated authentication.Note: If your organization is using federated authentication, the Default Managed Apple ID Format setting doesn’t apply.- Use SCIM with Azure AD- See Review SCIM requirements.- Sync with Google Workspace
59
Q

What are two ways a Apple ID are used?

A

Accounts and Roles

60
Q

Define which task users can perform with their managed account

A

Roles

61
Q

Can you change the Managed Apple ID of a user with admin role?

A

No, to change first need to change admin role then change Managed Apple ID then return admin role

62
Q

What happens when a Managed Apple ID is changed however an element is missing or empty for the user that was changed?

A

The user’s Managed Apple ID won’t be updated

63
Q

What happens when a new Managed Apple ID format is put in place, however the result is an ID that matches one that alreay exisit?

A

A number is added to the end of the new Managed Apple ID

64
Q

Are managed users notified when changes take place to thier ID?

A

No, admin must notify

65
Q

1.ACME, Inc.’s administrators are planning to switch to an eSIM exclusive environment. Users are upgrading their iPhone with models that support ONLY eSIM. Which feature MUST ACME’S carrier support so that users can seamlessly continue to use their lines with eSIM-only iPhone models? A. eSIM Plan Transfer B. eSIM Quick Transfer C. eSIM Convert D. eSIM Carrier Transfer Answer:A

A

Answer: A eSIM Plan Transfer

66
Q

Which tool should you use first to troubleshoot Mail connectivity issues in macOS?

A. Message Viewer
B. Network Diagnostics
C. Wireless Diagnostics
D. Connection Doctor

A

Answer: B. Network Diagnostics

67
Q

Where should you go in macOS to limit AirPlay Receiver ONLY to devices signed in to your Apple ID?

A. Go to System Settings > General > AirDrop & Handoff, then select Current User for the “Allow
AirPlay for” option.
B. Open the AirPlay app from the Utilities folder, then select Current User for the “Allow AirPlay for”
option.
C. Go to System Settings > Privacy & Security, then select Apple ID for the “Allow AirPlay for” option.
D. Go to System Settings, then select Apple ID for the “Allow AirPlay for” option in the Sharing
settings.

A

Answer: A: Go to System Settings > General > AirDrop & Handoff, then select Current User for the “Allow
AirPlay for” option.

68
Q

How should you schedule an email to send in Mail on iPhone?

A. Tap Settings > Mail > Schedule and configure the send date and time.
B. Touch and hold the mail body and configure the send date and time.
C. Touch and hold the send button and set the send date and time.
D. Tap the calendar icon in the mail menu bar and configure the send date and time.

A

Answer: C. Touch and hold the send button and set the send date and time.

69
Q

Which Wi-Fi authentication settings does Apple recommend for better security for Wi-Fi routers and access points?

A. WPA3 Personal or WPA Personal
B. WPA3 Personal or WPA/WPA2
C. WPA3 Personal or WPA2/WPA3 Transitional
D. WPA2/WPA3 Transitional or WEP Transitional Security Network

A

Answer: C. WPA3 Personal or WPA2/WPA3 Transitional

70
Q

Which two types of Activation Lock are available to organizations?
A. Individual-linked
B. Device-linked
C. User-linked
D. Personal
E. Organization

A

Answer: B, E

71
Q

Which action in Apple Configurator for Mac should you select to retain user data (if recoverable) if iPhone or iPad devices are unresponsive or in recovery mode?
A. Restore
B. Revive
C. Update
D. Erase all Content and Settings

A

Answer:B

72
Q

Study up on: SIP/XProtext. What does XProtect do if it detects malware? Rapid Security Response, WiFi preferences and how a device chooses orders (and security types WPA3/2 Transitional WPA, WEP, Certificate based etc), what the caution symbol on a wifi means, iphone diagnostics and where to find the files, Apple diagnostics (Activity Monitor vs. Console), Revive/ Restore via Apple Configurator, VPN and Device Management, Managed Apple IDs (what they can and cant do), hitting option-wifi to get to wifi diagnostics and what type of file it creates and where it’s located, how to get into safe/recovery mode with Apple Silicon Mac (hold down power button, hit shift to go into safe mode, enter admin password etc..), iCloud backup (what triggers it? how do you set it up? what does it back up?), Accessibility features and settings and their names/ purposes (those got me), troubleshoot Sidecar and Universal Control (same AppleID, bluetooth, display settings etc), some “Gotchas” about paths to settings (make sure you know where to go for like… mobile configs on a phone for example). What various symbols mean (missing OS on a Mac for example). Lockdown mode and what it does (especially with Safari, those got me too). Where are passkeys stored? Where would you delete one (where in settings)?

A
73
Q

how to access emergency sos on your iphone?

A

Press and hold the side button and one of the volume buttons until the Emergency SOS slider appears. Drag the Emergency Call slider to call emergency services. If you continue to hold down the side button and volume button, instead of dragging the slider, a countdown begins and an alert sounds.

74
Q

What is Lockdown Mode?

A

Lockdown Mode is an optional, extreme protection that’s designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats. Most people are never targeted by attacks of this nature.
When Lockdown Mode is enabled, your device won’t function like it typically does. To reduce the attack surface that potentially could be exploited by highly targeted mercenary spyware, certain apps, websites, and features are strictly limited for security and some experiences might not be available at all.
Lockdown Mode is available in iOS 16 or later, iPadOS 16 or later, watchOS 10 or later, and macOS Ventura or later. Additional protections are available in iOS 17, iPadOS 17, watchOS 10, and macOS Sonoma. For a complete set of protections, update your devices to the latest software before turning on Lockdown Mode.

75
Q

How Lockdown Mode protects your device

A

How Lockdown Mode protects your device
When Lockdown Mode is enabled, some apps and features will function differently, including:
Messages - Most message attachment types are blocked, other than certain images, video, and audio. Some features, such as links and link previews, are unavailable.
Web browsing - Certain complex web technologies are blocked, which might cause some websites to load more slowly or not operate correctly. In addition, web fonts might not be displayed, and images might be replaced with a missing image icon.
FaceTime - Incoming FaceTime calls are blocked unless you have previously called that person or contact. Features such as SharePlay and Live Photos are unavailable.
Apple services - Incoming invitations for Apple services, such as invitations to manage a home in the Home app, are blocked unless you have previously invited that person. Game Center is also disabled.
Photos - When you share photos, location information is excluded. Shared albums are removed from the Photos app, and new Shared Album invitations are blocked. You can still view these shared albums on other devices that don’t have Lockdown Mode enabled.
Device connections - To connect your iPhone or iPad to an accessory or another computer, the device needs to be unlocked. To connect your Mac laptop with Apple silicon to an accessory, your Mac needs to be unlocked and you need to provide explicit approval.
Wireless connectivity - Your device won’t automatically join non-secure Wi-Fi networks and will disconnect from a non-secure Wi-Fi network when you turn on Lockdown Mode. 2G cellular support is turned off.
Configuration profiles - Configuration profiles can’t be installed, and the device can’t be enrolled in Mobile Device Management or device supervision while in Lockdown Mode.
Phone calls and plain text messages continue to work while Lockdown Mode is enabled. Emergency features, such as SOS emergency calls, are not affected.