The Apple profile page allows you to define security profile properties for your MDM profiles. You can optionally select to sign and encrypt profiles here. You can configure these settings during your initial set-up.
For more information about SSL signing certificates, see the following Workspace ONE UEM Knowledge Base article: https://support.workspaceone.com/articles/115001662348.
- Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.
|Encrypt Profiles||Select this checkbox to encrypt all MDM and device profiles that are installed on the devices.|
|Sign Profiles (Requires Server SSL Certificate)||Select this checkbox to sign MDM and device profiles with a SSL certificate that is used to establish trust with the device services server.|
|Prompt devices to update MDM profile for iOS 5 Permissions||This is a legacy setting used to provide compatibility with iOS 5. This checkbox does not need to be selected unless you are working with an iOS 5 device.|
|Signing Certificate||Use the Upload button to upload a third-party SSL certificate to sign the profile. The SSL certificate should be the same one used on the device services end point.|
- Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.