location of iOS devices

SR
Sue Richmond
Canadian Wireless Communications Inc (End User)

Hi - Am I misunderstanding the location tab for iOS devices? I've set the settings on the device for Location services always on, Permissions for Mobi Control app  Location to always but the locate options are still greyed out unless the app is in the forefront on the device. Does this not make the function useless? If I've lost the device and need to locate it I can't bring the app to the forefront.

Thanks

Sue

7 months ago
iOS
ANSWERS
RS
Rafael Schäfer
7 months ago

At least for Android you also need to provide a data collection rule for location to the relevant devices (for constant location tracking of a device).

Does Mobicontrol agent on the iOS device maybe need relevant permissions?

RC
Raymond Chan Diamond Contributor
7 months ago

Hi Sue,

Apple architected the whole MDM infrastructure on how to resolve your concerned issue on Apple devices consistently for all qualified MDM solutions.  Would you mind telling us whether or not your iOS devices have been enrolled as supervised mode devices?

RC
Raymond Chan Diamond Contributor
7 months ago

Assuming that your Apple devices are in supervised mode, then their location can be found by enabling the "MDM Lost Mode" of the device from web-console of MobiControl or other MDM solution even when the device does not have the GPS location normally enabled, or even when there is no device agent installed/running in the foreground.   However, the device screen is also locked such that anyone (including the actual owner) holding the device cannot use the device even if he/she can input the correct lockscreen password, not until the device MDM mode has been disabled via MDM.  If location information has been sent to the MDM server when the MDM lock mode is active, a message related to this location operation will be shown on the device screen to inform the device end-user when he/she unlock his/her device after the MDM lost mode has been disabled.      Hence, MDM administrator cannot SILENTLY get the device location without letting the owner of the supervised device knowing about it.

The above "intrusive" device-location task is only applicable to supervised Apple devices, and is implemented in the above-mentioned  way  because Apple takes privacy of the end-users of their devices very seriously.  For the same reason, location information outside MDM lost mode need consent by device end-user via his/her app permissions configurations in device's Settings on a per-app basis.  

Unsupervised mode devices are assumed to be non-enterprise-grade devices (likely) owned by device end-users.  Respecting the privacy of such personal device owners is of utmost importance,  and Apple thus does not allow MDM lost mode on such devices.

SR
Sue Richmond
7 months ago

The devices are supervised. I understand the device needs to be in Lost Mode but to do this the device has to be on. If a device is lost - the reason we are trying to locate it, the battery is likely dead and there is no way to put it in lost mode making the function useless (in my opinion).

Sue

RC
Raymond Chan Diamond Contributor
7 months ago

So IN YOUR OPINION,  when a powered-off device has been moved somewhere else for an unknown length of time,  what is the value of the location information reported to the MDM server when it was online previously?

H
HDMOD@SOTI.net
7 months ago

Hi Sue,

Thank you for posting on SOTI Pulse, and a big thanks to Raymond and Rafael for their valuable input—their expertise and willingness to help are greatly appreciated!

Were they able to resolve your issue? You can also refer to the article below for your reference:

Using MDM to Manage Lost Mode

If not, or if you have any further questions or concerns, please don’t hesitate to reach out. We're here to support you every step of the way.

Regards.