Apple makes big improvements in iOS management tools for enterprise and education — from by Matthew Panzarino (@panzer)

Excerpt:

Apple has been busy in the IT department. [Yesterday], it released a slew of improvements and alterations to its large-scale deployment tools for education and enterprise customers.

The changes are outlined in a series of documents Apple posted on its IT deployment page today. These include changes to its Device Enrollment Program, Volume Purchase Program and the Apple ID for Students service. A new iOS deployment technical reference guide and Device Enrollment Program guide have been issued, updating its older versions with new options for device management. A new overview document provides a quick cheat sheet for enterprise folks looking to utilize the tools Apple provides to mass purchase apps and roll out huge numbers of iOS devices at a time. And a new iOS Security Document has been posted that provides in-depth details on how Touch ID and the A7’s Secure Enclave work.

 

Addendum later on 3/3/14:

Why Apple’s new Device Enrollment Program is a game changer for IT — from citeworld.com

Excerpt:

What does supervision enable?
Apple has added several powerful management options over the past couple of years that can only be enabled on supervised devices. Here’s a list of those features.

  • Enable and manage Single App Mode (typical for kiosk devices).
  • Configure Accessibility settings.
  • Allow or disable access to iMessage.
  • Allow or disable access to Game Center.
  • Allow or or prevent users from deleting apps.
  • Allow or disable access to iBooks Store.
  • Prevent access to ebooks flagged erotica in the iBooks Store.
  • Enable or disable Siri’s Profanity Filter.
  • Allow or or prevent manual install of configuration profiles (including unauthorized or malicious profiles).
  • Configure a global proxy server for all installed web browsers.
  • Allow or prevent host pairing (iTunes).
  • Allow or or prevent pairing with computers for content sync.
  • Restrict AirPlay connections with a whitelist of acceptable device and enter a passcode for