Description
It is possible in Jamf School to set time restrictions on a profile, for example if you want to enforce a profile that disables the usage of certain apps during school hours.
How Timed Profiles Work
When a timed profile is active, Jamf School physically installs the profile on the device at the configured start time and removes it at the configured end time. This happens every day on the days you have selected.
Profile removal at the end time is handled natively by iOS — Jamf School writes a RemovalDate key into the .mobileconfig file, and iOS honors this automatically. This daily removal and reinstallation is expected behavior. If you observe a profile being removed at the end of the school day and reinstalled the following morning, this is working as designed.
Why a Profile May Not Apply at the Scheduled Start Time
The most common reason a timed profile does not install at the scheduled start time is that the device is passcode-locked at that moment.
Apple's MDM protocol does not permit an InstallProfile command to execute on a locked device. When this occurs, the device returns a NotNow response to Jamf School, and the command remains queued. The profile will install on the next MDM check-in after the device is unlocked.
Note: It can take up to 15 minutes for a profile to be pushed after the scheduled start time, and only if the device is awake, unlocked, and connected to the internet during that window. If the device is passcode-locked at the start time, the profile will remain queued and will install on the next MDM check-in after the device is unlocked.
Important Considerations
If your environment included BYOD (personally-owned devices), there are two additional factors to be aware of:
Date and time manipulation: If the date/time restriction is enforced only via the timed profile, students may change the device's date or time to circumvent the restriction. To prevent this, apply a permanent, always-on restriction that enforces Automatic Date and Time as a separate profile, independent of the timed profile.
Important Notes:
If Location Services are not enabled on the device at the time this restriction is applied, the device will be locked into its current timezone which may differ from the expected timezone. Location Services cannot be enabled via MDM and must be set manually on the device. While an MDM command exists to set the timezone, the Automatic Date and Time restriction must be disabled for the command to take effect. For full details, refer to Apple's MDM Settings Command documentation.
The Force Automatic Date & Time restriction requires a supervised device and cannot be applied to BYOD (personally-owned) devices, meaning users of unsupervised devices will always have the ability to manipulate the device time.
Delayed network connection: Devices may not be connected to a Wi-Fi network until after the scheduled start time. Since the device must be reachable by MDM to receive the
InstallProfilecommand, any delay in network connectivity will result in a corresponding delay in profile installation.
Setting Custom Time Restrictions
To start, you'll need to have a profile set up that you want to use. In the existing profile, navigate to General and select Use Time Filter shown below:
You can also configure what days this profile should be active. During these days and between the selected start and end time the profile will be installed on the device enforcing anything configured inside of it.
What to Do If a Profile Has Not Applied
If a timed profile has not installed on a device at the expected time:
Navigate to the device record in Jamf School.
Manually push the profile from the device record.
The profile will install on the next MDM check-in after the device is unlocked and connected to the network.
This is the recommended approach for individual devices where the profile has been missed. For large-scale delays affecting many devices simultaneously, consider whether devices are locked or offline at the scheduled start time.
