Close ad

Serial "We deploy Apple products in business" we help spread awareness of how iPads, Macs or iPhones can be effectively integrated into the operations of companies and institutions in the Czech Republic. In the first part, we will focus on the MDM program.

The whole series you can find it on Jablíčkář under the label #byznys.


In the first part of our series, we will look at the integration of iPads into a manufacturing company that uses them to streamline work directly in production, specifically at the initial process of product selection, their installation and subsequent management.

AVEX Steel Products is a manufacturer of storage and transport pallets for the automotive industry. In the past, like most companies today, the company dealt with the issue of work efficiency at individual workplaces. In this particular case, AVEX focused on increasing productivity by eliminating existing dysfunctional mechanisms based on the distribution of information in production on paper.

Individual workstations obtained information about the order, storage and production in paper form, or went to the shift manager, who had all the data at his station on the computer. They decided to solve this unproductive and, above all, inefficient way of transmitting information to individual production workers by introducing tablets to individual workstations.

Tablets thus began to replace paper with drawings, information about orders and warehouse management. People stopped losing papers with information, gained an overview of the order and could start focusing primarily on their work and not on administration.

ipad-business5

The first steps when you want to deploy iPads in your company

The way tablets are used today at AVEX has fundamentally changed the entire course of production and the overall awareness of individual orders. However, we will return to how this fundamental change took place, which led to increased productivity and more efficient operations at AVEX, in one of the following parts. Now we will focus on the necessary theory that everything starts with.

At the very beginning of everything for the AVEX company was the decision of which tablets to purchase and how the company would take care of them. The following questions were absolutely key to their deployment.

  1. Which tablet to choose?
  2. How to deal with preparing and setting up a large number of tablets?
  3. How to install the necessary applications for the distribution of drawings, orders and warehouses on tablets?
  4. How will the company take care of the tablets?
  5. How to ensure user comfort in production without placing increased demands on employees for technical knowledge of tablet settings?

At the time the project was implemented, there was only one tablet on the market that met all the defined criteria. They were far from just the price, but above all the references from similar deployments in the production environment, the simplicity of developing a stable application for the company's tailor-made production needs, the possibility of controlling the tablet remotely, making it impossible for the user to accidentally delete applications and modify the settings in the tablet.

Although the tablets you can buy on the market today appear to fulfill all these functions, they are still a long way behind the capabilities of the iPad itself.

ipad-business11

So iPads were bought for AVEX and the next step was on the line. A company needs to install several applications that will allow users in production to access information and work with orders in production. Imagine a large number of devices and an IT administrator who must first set them all up, install applications, connect to Wi-Fi and secure against accidental uninstalls and changes to settings. In addition, it is also necessary to ensure the security of the data that the applications contain and to prevent their possible theft from operation.

At this stage, MDM (Mobile Device Management) technology comes into play. Everything that the company will need to set up, install and manage iPads is handled by this technology from Apple.

There are several MDM service providers on the market and prices range from 49 to 90 crowns per device per month. Companies can also use native server applications from Apple, which will ensure the management of all iOS and Mac devices without monthly fees and so-called on premise.

Before choosing the right solution, you need to define what you will require from this service. Individual providers may differ from each other in the options of functionality offered, and the final price is also related to this. In our case, we will focus on the basic functions of MDM, which sufficiently meet all the criteria of the AVEX company.

MDM as the key to everything

MDM is a solution for the management of mobile devices and at the same time a technology that will suddenly become the best assistant for an IT worker who is in charge of managing iPads.

"Thanks to MDM, the administrator of mobile devices can perform time-consuming operations, such as mass installation of applications or Wi-Fi settings, and all this within a few seconds," explains Jan Kučerík, who has long been involved in the implementation of Apple products in various sectors of human activity and with whom we are working together on this series. "It is enough for the administrator to enter the command for the given operation for all iPads at once from any device with a web browser."

“Installation starts in seconds, regardless of where the individual iPads are currently located. For example, the installation can be done from an iPhone while traveling between the office and the warehouse. The administrator also has a complete overview of all devices, for example, he can see how much disk space is left in each iPad or what the current battery status is," Kučerík adds.

For the needs of a manufacturing company like AVEX, you can use MDM to hide, for example, the App Store or iTunes and thus prevent end users from logging in under a different Apple ID. You can completely disable the deletion of applications, disable the change of the background or define the parameters of the code lock as one of the elements of company security. MDM can also hide any app on the iPad.

"It's not always desirable for the end user to browse Facebook or the Internet," Kučerík gives an example, adding that MDM also handles password management and Wi-Fi settings, which is also a key feature.

MDM

The app disappears when needed

In a corporate environment, you can even set a location where all devices automatically turn off or have their cameras disappear, which is handy when you need to protect manufacturing secrets, for example. "You don't have to cover the lenses with adhesive tape, as is common practice today," continues Kučerík.

There are several applications of geolocation functions in MDM. The administrator of the iPads can set the geolocation policy of the iPads so that if the device leaves the defined area, the data can be deleted automatically. The administrator is always informed about the violation of the set location by the user as soon as the device leaves the defined area. There are many uses, and most of them lead to the maximum security of company data against their misuse.

“MDM allows me to send to any iPad the application I need there. I can set a security policy for an iPad or a group of iPads and disable unnecessary or unnecessary functionality due to the desired use of the iPad. At the same time as monitoring the geographic location, MDM is a powerful tool for the corporate environment," confirms AVEX Steel Products IT manager Stanislav Farda.

How about privacy?

At the moment, it can be argued that, thanks to MDM, the privacy and security of user-entered data is disappearing from iPads and iPhones. What if the user wants to use their own device? Can an administrator view my messages, emails or view photos? We divide the MDM setting modes for iOS devices into two – supervised and unsupervised, so-called BYOD (Bring Your Own Device).

"Equipment that is owned by a private person and not owned by a company, we mostly set it up in unsupervised mode. This mode is significantly more benevolent, and the MDM administrator cannot remotely do whatever they want with the user's device.

"This setup primarily serves as remote technical support and a tool for providing settings and installing applications in the environment in which the user moves within the company," explains Kučerík.

Unsupervised mode

So how does the unsupervised setting behave and what benefits does it bring to the user in a corporate environment and what can the administrator remotely set using MDM? "This includes access to Wi-Fi networks, setting up VPNs, Exchange servers and e-mail clients, it can install new fonts, install signature and server certificates, install applications for business use, set up access to AirPlay, install printers or add access for subscribed calendars and contacts," lists Kučeřík.

Installing applications in unsupervised mode is significantly different from that with higher supervision. In this case, the user receives information on the display of his iOS device that the MDM administrator is about to install the application on his device. It is then up to the user to allow or deny the installation.

IMG_0387-960x582

The MDM administrator does not have any possibility to see and view the contents of the user's device in this mode. Apple itself would never allow such a function and only gives MDM administrators a tool that ensures maximum user comfort, not spying. "This setting cannot be bypassed in any way," emphasizes Kučerík, noting that it is similar to tracking the location and location where the device is located.

"Device location, or determining where your device is currently located, is a feature that as an MDM user you would have to confirm on your device by enabling location services in the MDM app that your administrator has installed on your iOS device will install. Without a combination of your enabling this function on the device as part of location services and written consent, it is not possible to determine your current location," assures Kučerík.

As a rule, the network administrator can only display the location of your network connection provider, which is often on the opposite side of the country depending on who your internet connection provider is.

Supervision mode

Settings in supervision mode are mainly used for iOS devices that are owned by the company and employees only have iPads on loan. In this case, the MDM administrator can do almost anything with the device. Again, it needs to be mentioned that as with the unsupervised version, the administrator cannot view the contents of the device and read emails, view photos, etc. But these are the only nooks and crannies that the MDM administrator can't get into. The rest of the door is wide open for him here.

But what about device location tracking in this case? "There are laws in the Czech Republic, and even MDM administrators must comply with them when it comes to tracking the location of devices. In the case of a supervised device, it is the responsibility of the owner of the device who lent it to you to use, to inform you that the device is under surveillance and its location is being monitored. In this way, the owner or company fulfills the notification obligation. Ideally, the employer should have informed the user in writing," Kučerík explains.

An important element of the supervised setting is the possibility of using the so-called Single App Mode. This allows, for example, a single application to be run on selected iPads in the company without users being able to turn it off or go anywhere else on the iPad.

This function brings its benefits when the iPad is to serve as a single-purpose tool for the performance of a defined function. The iPad administrator has an application for this tool available on their iOS device, which will launch the desired content on all selected devices within a few seconds. To exit Single App Mode, simply turn off the function and the iPads will be unlocked in a few seconds, allowing them to use their full potential.

In the supervision mode, the administrator can also delete applications, make changes to the settings, connect the iPad to another device (Apple Watch), change the background or log in to Apple Music and other services, among other things.

"MDM is an absolute foundation that you cannot do without if you are thinking about implementing iPads or iPhones in your company. Subsequently, the new VPP and DEP programs come into play, which Apple launched for the Czech Republic only last October," concludes Kučerík.

It is the device registration and bulk purchase programs that push the efficiency of using iPads within the corporate environment a significant step further. We will discuss these new Apple programs in more detail in the next part of our series.

.