Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Ivanti MDM Updates: Windows 11 eSIM, BitLocker Alerts & iOS Enhancements

Ivanti
08/26/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Windows eSIM configuration for Windows 11, Ivanti Neurons for VM now supports eSIM configuration for Windows 11 devices, and the customers must obtain a server number URL from their carrier for this. Once the profile is installed, the device connects the carrier URL to activate the eSIM, and the customers provide a file with the device details and should check requirements with the carrier. Another capability is about a notifying admin when BitLocker key is not saved. Saving the BitLocker key via MDM is supported, but external issues can prevent successful saving. Previously, admins had no visibility if a key was missing. Now, with the Ivanti NMDM will now notify admins in the console if it detects that the BitLocker key hasn't been saved. Those are the capabilities on the Neurons for MDM. Let's also talk about what are the new capabilities on the iOS and macOS on the on-prem EPMM. Starting with iOS improvements, new option to preserve the data plan during the device wipe operations. Basically, the preserve data plan checkbox is now enabled by default to avoid any accidental loss of cellular plans. Same as the Neurons for MDM, we have a network relays, FQDNS keys. As I mentioned earlier, Apple improved handling of FQDNS for better security between devices and network relays. It basically simplifies configuration and improves integration with enterprise networks and VPNs. Then we have the profile for Ethernet authentication for iPads. iOS 17 introduced 802.1X Ethernet support for iPads. Ivanti adds configuration support for certificate-based Ethernet authentication on iPads. Then we have software update enforcement to pick latest version. DDM now allows you to enforce updates to always install the latest OS version automatically. This basically helps organizations keep devices current with the controlling update timing and user experience. It fully automates a software update lifecycle. I think this is one of the key capability as well that can be leveraged to ASAP. Then ability to run a Mac OS scripts without the Mac agent. Apple DM or the device declarative management now allows pushing Mac OS scripts without needing an agent or a client. This is supported for Mac OS 15 plus. New scripts tab lets admin upload or write scripts and distribute them via configurations. Enhancements include adding roles for script management and renaming scripts in the backend. To highlight that earlier, we do have dependency on having a Mac agent to deploy the scripts on the device, but currently, that's not a dependency anymore. Without having an agent, you can still continue to use the scripts pushing the scripts onto the devices. Also touch basing on the mobile network, the client on the on-prem. Relocation of the notifications tab, where we are moving the notifications tab on the top right corner, and simplified enrollment flow for end-users. What does this mean is Apple's changes require users to manually download profiles during registration. Previously, users had to switch to Safari for download instructions. Now, Ivanti Go shows these instructions directly in the app, simplifying the process for the end-users. There is no switching between the Safari browser and switching back to the app. It's all completely embedded into the app. Again, the auto-launch of Ivanti Go at registration via automatic device enrollment. This is again as equally important both on-prem and on-Cloud, where we would want the users to be able to leverage the auto-launch of the app, which resolves a number of problems in terms of compliance. Basically, as you-all know that Ivanti Go and Ivanti Mobile Network requires the app to be launched at least once. Again, Apple does not allow MDM to auto-launch apps. We did come up with a solution where you can still use a single app mode during the automatic device enrollment to automatically launch Ivanti Go. Once its registration is completed, single app mode is removed and the device is ready for the user. It all happens in split seconds. That's on the overall Apple and macOS, both on-prem and on-Cloud.

TL;DR

  • Ivanti Neurons for MDM now supports eSIM configuration for Windows 11 devices, requiring only a carrier-provided server URL to activate cellular connectivity remotely.
  • Administrators receive console notifications when BitLocker recovery keys fail to save, addressing a previous visibility gap that could leave devices unrecoverable.
  • macOS 15+ devices can now receive scripts via Apple's declarative management without requiring the Mac agent installed, simplifying deployment workflows.
  • DDM software update enforcement automatically installs the latest OS version, giving organizations control over update timing while maintaining currency.

Windows 11 Management Enhancements

Ivanti Neurons for MDM introduces two significant Windows 11 capabilities. The first is eSIM configuration support, enabling administrators to remotely provision cellular connectivity on Windows 11 devices by obtaining a server number URL from their carrier and deploying profiles that automatically activate the eSIM. The second addresses a longstanding visibility gap with BitLocker key management—while MDM-based BitLocker key saving was already supported, external issues could silently prevent successful saves. Administrators now receive console notifications when BitLocker keys haven't been saved, eliminating the risk of discovering missing recovery keys during critical situations.

iOS and macOS Platform Improvements

The iOS and macOS updates span both cloud and on-premises deployments. For iOS, the preserve data plan option is now enabled by default during device wipes, preventing accidental loss of cellular plans. iPad administrators gain 802.1X Ethernet authentication support introduced in iOS 17, with Ivanti adding certificate-based configuration capabilities. Declarative Device Management (DDM) now enables automatic enforcement of the latest OS version, fully automating the software update lifecycle. Perhaps most notably for macOS 15+, Apple's declarative management framework now allows pushing scripts without requiring the Mac agent—a significant operational simplification. The Ivanti Go app improvements streamline enrollment by displaying profile download instructions directly in-app rather than requiring Safari switching, while a new single app mode workaround enables auto-launch during automatic device enrollment to address compliance requirements.

Chapters

0:00 - Windows 11 eSIM Configuration
0:29 - BitLocker Key Notifications
1:00 - iOS and macOS On-Prem Updates
1:56 - DDM Software Update Enforcement
2:22 - Agentless macOS Script Deployment
3:07 - Mobile Client and Enrollment Improvements

Key Quotes

0:41 "Previously, admins had no visibility if a key was missing."
2:17 "It fully automates a software update lifecycle."
2:56 "Currently, that's not a dependency anymore. Without having an agent, you can still continue to use the scripts pushing the scripts onto the devices."
4:13 "Apple does not allow MDM to auto-launch apps. We did come up with a solution where you can still use a single app mode during the automatic device enrollment to automatically launch Ivanti Go."

FAQ

What do I need from my carrier to configure eSIM on Windows 11 devices?

You need to obtain a server number URL from your carrier. Once you deploy the profile with this URL, the device automatically connects to the carrier to activate the eSIM. You'll also need to provide a file with device details and verify specific requirements with your carrier.

Do I still need the Mac agent to run scripts on macOS devices?

For macOS 15 and later, no—Apple's declarative device management now allows pushing scripts without an agent or client. For earlier macOS versions, the Mac agent dependency remains. The new scripts tab lets you upload or write scripts and distribute them via configurations.


Categories:
  • » Webinar Library » Ivanti
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Endpoint Management
  • Technical Deep Dive
  • Demo
  • Mobile Device Management
  • Windows 11 eSIM
  • BitLocker Key Management
  • iOS Device Management
  • macOS Script Deployment
  • Declarative Device Management
  • 802.1X Ethernet Authentication
  • Software Update Automation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Ivanti MDM Updates: Windows 11 eSIM, BitLocker Alerts & iOS Enhancements

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Sep
                        29

                        Embracing AI Adoption While Maintaining Robust Security Measures

                        09/29/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/29/2026
                          12:00 PM
                          09/29/2026
                          Embracing AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-maintaining-robust-security-measures/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version