Description
While our controls over "Find My" on mobile devices are limited, we have two options:
Stop use of "Find My" entirely by preventing Apple Account log in.
Disable the "Devices" section of "Find My" locally on the device and hide the app.
With this method, other devices logged in to that Apple Account can still see that device on a map, but the device with the restriction cannot see the other devices logged in to that Apple Account.
Limiting "Find My" on Your Devices
The only way to disable "Find My" entirely is to lock the user out of logging in with an Apple Account (personal or managed). That is accomplished by using a restrictions configuration profile that has Modifying account settings restricted under Restrictions > Functionality.
The user needs to not already be logged in to an Apple Account for this to be effective. If the user is already logged in to an Apple Account, this will lock their device in to that Apple Account until the configuration profile is removed.
if restricting the use of peronal Apple Accounts, end users will not be able to install their own apps.
If the user is already logged in to an Apple Account, our options are much more limited:
Restrict "Find My Device" under Restrictions > Functionality. This still allows "Find My" to be used on the device, but it is unable to see other devices tied to that Apple Account. However, other devices can still see that device on the map if they are logged in with an Apple Account.
Hide "Find My" on the device by using the same restriction profile under Restrictions > Apps > Some apps not allowed. The App name is "Find My" and Bundle ID is "com.apple.findmy."
In the end, if the admin is dead set on fully disabling "Find My", the only option is to make sure the user isn't logged in with an Apple Account, and then restrict their ability to log in to one.