Integrating Cisco Umbrella with Apple Profile Manager as MDM
Here is a step-by-step guide on how to push Cisco Umbrella to iOS devices wirelessly via Apple Profile Manager
Clearly Apple Server is on its way out when Cisco provides instructions for how to distribute Umbrella via Apple Configurator 2, but not Apple Profile Manager. Other supported MDMs include Jamf Pro, MobileIron, AirWatch and Meraki (no surprise on that last one!).
For those investigating MDMs and not yet committed, go to the cloud and avoid Apple Profile Manager. You have been warned!! Jamf Pro is generally recognized as the most user-friendly but requires 50 paid licenses at a minimum. Meraki provides the most devices for free. But if you’re at this page, chances are that you—like me—are using Apple Profile Manager.
I record this for posterity as the documentation is currently nonexistent on how to do this, and neither Cisco nor Apple have so far replied to my inquiries.
In what’s written below, I am assuming you have a trial/paid account with Cisco Umbrella, with policies in place and know how to make them active for devices you deploy to. I also assume that you have a fully operational Apple Server with Profile Manager, DEP and VPP configured, and devices already enrolled. If that’s not you, then just bookmark this page.
Here is how to push Cisco Umbrella to iOS devices wirelessly via Apple Profile Manager:
Step 1:
In Umbrella, go to Deployments – Configuration – Root Certificate and download the certificate that’s presented there.
Step 2:
Then go to Deployments — Core Identities — Mobile Devices and click the ‘Manage MDMs’ button at the top right and download the one for Jamf.¹ You may be prompted to enter in an IT support email that end-users can contact if they have problems
Step 3:
In a text editor, open up that xml file you just downloaded and find line 64, you want to change the value: $SERIALNUMBER to %SerialNumber%
Step 4:
In that same file, go back up to the top and delete lines 4–25 (from <dict> to the <!-Jamf comment line) and lines 66–81 (from the closing <!-Jamfcomment line to the closing </dict>.
Then ‘save as’ that edited file with the namemobileconfigDNS.plist
Step 5:
Using your VPP account, purchase more Cisco Security Connector apps than you think you’ll need. They are free, so splurge!
Step 6:
In Profile Manager, I would suggest creating either a device group or a user group to distribute your settings. I called mine the very original: Umbrella Devices. In that new group, click the ‘Apps’ tab first and then the ‘+’ symbol at the bottom. Add the Cisco Security Connector as an automatic app install to this group.
Step 7:
Now click the Settings tab and find the small ‘edit’ button in the first ‘settings’ box that appears below the tab. On the left side, click Certificates and then the ‘+’ in the top right corner. Now you can upload the Cisco Umbrella root certificate you downloaded earlier. Also add a passphrase of your own choosing.
Step 8:
Scroll down on the left side until you arrive at ‘DNS Proxy’. Go ahead and click the ‘+’ to add a configuration.
For App Bundle ID, enter com.cisco.ciscosecurity.app
For Provider Bundle ID, enter com.cisco.ciscosecurity.app.CiscoUmbrella
Then select the Upload File… button and upload the mobileconfigDNS.plistfile you created earlier.²
Step 9:
You are done! Press the ‘OK’ button at the bottom right corner. Then the ‘Save’ button that appears for the grou you’ve been editing. If you already have devices in the group you created, you will see the Active Tasks section light up as it pushes out the new configuration.
Step 10:
As devices adopt the new configuration, you will see them in Umbrella. Double check that your mobile devices have a policy assigned to them. On a properly configured iOS device, you can go into Cisco Security Connector and click the Status tab at the bottom. If you followed the above steps correctly, your managed iOS device will display a green shield there with the words, Protected by Umbrella.
I hope this short guide has been a help to you. I sure wish it had been around when I was trying to sort this out…
¹ In truth, any of them will work, but the Jamf one has comments that will prove helpful to you, segmenting out the information you need to pass into Profile Manager.
² How is it that Apple documentation doesn’t tell you anywhere the correct file extension that Profile Manager will require?! If you try to upload an XML into Profile Manager, it gives you a file type error. But what if you try a .mobileconfig that Apple Configurator 2 requires? Yeah, that gives an error also! Profile Manager wants .plist files, but NOWHERE do they tell you that!!