Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Onboarding Options for IPADs that are district owned

This thread has been viewed 2 times
  • 1.  Onboarding Options for IPADs that are district owned

    Posted Feb 16, 2016 03:39 PM

    Hello,

    I am seeking ideas for how to stream line our onboarding registration for our school board owned IPADs.   Originally when we started out we had a handful of IPADs so it was manageable to provision each device / onboard it.  Then pull it into an MDM solution.  No biggie, we associated to an SSID and registered the device using a local user account in Clearpass (we are running 6.5 these days).  Auth method is EAP-TLS and auth source is localhost, authorization source is [Local User Repository].  The IPAD gets 2 profiles:  Clearpass onboard local and Device Enrollment as part of the process. Fast forward a couple years, now there are > 1,200 IPADs that will need to be re-onboarded.  They are getting re-onboarded for a couple reasons 1) our cert is expiring and 2) all the devices will be wiped and enrolled in the Apple DEP program (Device Enrollment Program - lets you quickly assign Apple devices to your mobile device management (MDM) servers so you can automate enrollment, wirelessly supervise devices, and skip basic setup steps.   We have not yet seen the DEP process real time in our environment... but I'm wondering if there are options to more streamline the re-onboarding of the device process for the IPADs themselves.  Does anyone out there have enterprise / system owned IPADs that you onboard to your internal network and manage in a better more effective way?

     

    Thanks for ideas,

    Sarah



  • 2.  RE: Onboarding Options for IPADs that are district owned

    EMPLOYEE
    Posted Feb 16, 2016 03:43 PM

    What are you using for MDM? ClearPass supports SCEP which can automagically Onboard them as part of MDM enforcement.



  • 3.  RE: Onboarding Options for IPADs that are district owned

    Posted Feb 16, 2016 03:46 PM

    airwatch is our MDM



  • 4.  RE: Onboarding Options for IPADs that are district owned
    Best Answer

    Posted Feb 16, 2016 04:28 PM

    Just FYI - In my CPPM MDM TechNote their is a section covering ClearPass & AirWatch SCEP setup, might be worth a read.

     

    Tech Note: ClearPass Enterprise Mobility Management Integration V5 



  • 5.  RE: Onboarding Options for IPADs that are district owned



  • 6.  RE: Onboarding Options for IPADs that are district owned

    Posted Feb 17, 2016 07:48 AM

    Thank you will give it a read.

     



  • 7.  RE: Onboarding Options for IPADs that are district owned

    Posted Feb 17, 2016 07:54 AM
    Thank you!