Device ID changes on iOS devices when upgrading to Mobile Connect 5.0

Description

The SMA 1000 and SMA 100 series depend on device ID's to apply End Point Control (EPC) policies to end users. Device ID's are generated at the time an end user connects to an SMA appliance using Mobile Connect. Recently, Apple has changed security guidelines for third party apps. Apps can no longer pull or use device hardware ID's due to privacy concerns (https://developer.apple.com/reference/uikit/uidevice/1620059-identifierforvendor).

Because of this recent change end users with Mobile Connect 5 may no longer receive correct EPC policies. Any EPC profile based on equipment ID, device ID, or hardware ID will no longer be able match EPC profiles.Ā 

The following article provides a workaround for this issue for the SMA 1000 and SMA 100 series.

Cause

Apple has changed security guidelines for third party apps. Apps can no longer pull or use device hardware ID's due to privacy concerns (https://developer.apple.com/reference/uikit/uidevice/1620059-identifierforvendor).

Resolution

For SMA 1000 series products please use the following workaround:

  1. It is recommended to enable ā€œMatch Profile if user has no registered deviceā€. Navigate to End Point Control | Profiles | Edit select the profile related to DeviceID Matching:
    Image
  2. With this change the new information would be logged under Management Console | Logging | View Logs | Unregistered Device logs. This section will display the new identifier:
    Image
    In Active Directory open the properties of the Administrator account. In the comment field paste the new device ID. Click OK.
    Image

For SMA 100 series products please use the following workaround:

  1. When logged into the SMA 100 appliance administrators will see EPC failures in the log:
    Image
  2. Locate the new iOS device ID by navigating to Device Management | Devices and searching for the user. Copy the new device ID:
    Image
  3. An additional workaround is to disable EPC by navigating to End Point Control | Settings and un-checking Enable End Point Control:

Related Articles

  • SMA100 End of Support No-Charge Replacement FAQ
    Read More
  • SMA1000: Post upgrade to 12.5.0 on AWS and Azure, we show the error Could not retrieve the DNS settings once we log in to AMC/CMS console
    Read More
  • Firmware version required to upgrade to version 12.5.0.
    Read More
not finding your answers?