If you are enforcing passcodes in your organization and using GroundControl, there’s some considerations to take in mind, specially when using check out workflows.
Unfortunately, GroundControl cannot automatically connect to passcode-locked devices or clear the device’s passcode. However, if the device has an active internet connection, we can use MDM to clear the passcode over the air.
We can do this in two ways that together address most scenarios.
- Clear Device Passcode via MDM when device is not pairing with a Launchpad
- Perform MDM Command workflow action to clear a device’s passcode
Both of these methods have some important things to know:
- Your MDM must install a profile on all shared devices to disable USB restricted mode.
- Clearing passcode does not work on rebooted devices unless they have a cellular connection.
- Clearing passcode does not work on devices without a wifi connection.
- If the passcode is not known, the device must be put into recovery mode and erased.
- Updating iOS on devices with passcodes is supported only when devices are erased.
- If enforcing passcode via MDM, we recommend setting this profile up during check out, not during check in.
Clear Device Passcode via MDM when device is not pairing
When enabled GroundControl will detect when a device connected to a Launchpad is connected but not pairing. When this condition occurs for 5 seconds, GroundControl will send an MDM command to clear a device’s passcode.
To enable navigate to Admin > Launchpads > Clear Device Passcode via MDM — when device is not pairing. The screen will display the MDMs you have set up with API support that also support this feature.
Enable the MDM or multiple MDMs to have GroundControl send the “Clear Passcode” API when devices are connected but not pairing.
Perform MDM Command workflow action to clear passcode
Under certain conditions, devices with passcodes will still pair with GroundControl. For example, your users may connect the device while it is unlocked. You must clear the passcode in your workflow in any of the following cases.
- You will check in the device for another user
- You will update iOS on this device (this feature may brick the device if it has a passcode)
- You are performing any actions other than Erase.
To clear a passcode without an erase action you can use the Perform MDM Command Workflow action with supported MDMs to enable a Pre-Enrollment action to clear a device’s Passcode. This action will be run before other Pre-Enrollment actions such as Delete Device from MDM.
If your automated workflow includes an Erase, you do not need to clear the passcode in the workflow. Erase will clear the passcode.