为共享 iPad 设备配置 Intune 教育设置Configure Intune education settings for shared iPad devices

备注

Intune 目前不支持配置 Classroom 应用。Intune doesn't currently support configuring the Classroom app. 本文仅适用于 Intune 中使用现有 iOS/iPadOS 教育版配置文件的用户。This article is only applicable for users with existing iOS/iPadOS education profiles in Intune.

Intune 支持 iOS/iPadOS Classroom 应用,可帮助教师在课堂上指导学习以及控制学生设备。Intune supports the iOS/iPadOS Classroom app that helps teachers to guide learning, and control student devices in the classroom. 此外,对于 Classroom 应用,Apple 支持对学生 iPad 设备进行配置的功能,以便多名学生可以共享单台设备。In addition, to the Classroom app, Apple supports the ability for student iPad devices to be configured such that multiple students can share a single device. 本文档指导如何通过 Intune 实现此目标。This document guides you to achieve this goal with Intune.

有关配置专用 (1:1) iPad 设备以使用 Classroom 应用的信息,请参阅如何为 iOS/iPadOS Classroom 应用配置 Intune 设置For information about configuring dedicated (1:1) iPad devices to use the Classroom app, see How to configure Intune settings for the iOS/iPadOS Classroom app.

开始之前Before you start

使用共享 iPad 功能的先决条件是:The prerequisites to use the shared iPad capabilities are:

步骤 1 - 将学校数据导入 Azure Active DirectoryStep 1 - Import your school data into Azure Active Directory

使用 Microsoft 的学校数据同步 (SDS) 将现有学生信息系统 (SIS) 中的学校记录导入 Azure Active Directory (Azure AD)。Use Microsoft's School Data Sync (SDS) to import school records from an existing Student Information System (SIS) to Azure Active Directory (Azure AD). SDS 将同步 SIS 中的信息并将其存储在 Azure AD 中。SDS synchronizes information from your SIS and stores it in Azure AD. Azure AD 是帮助你组织用户和设备的 Microsoft 管理系统。Azure AD is a Microsoft management system that helps you organize users and devices. 使用此数据有助于管理学生和班级。You can then use this data to help you manage your students and classes. 了解有关如何部署 SDS 的详细信息Learn more about how to deploy SDS.

如何使用 SDS 导入数据How to import data using SDS

可以使用以下任一方法将信息导入 SDS:You can import information into SDS by using one of the following methods:

  • CSV 文件 - 手动导出并编译逗号分隔值 (.csv) 文件CSV files - Manually export and compile comma-separated value (.csv) files
  • PowerSchool API - 一个 SIS 提供程序,可以简化与 Azure AD 的同步操作PowerSchool API - An SIS provider that simplifies syncing with Azure AD
  • OneRoster - 一种 CSV 格式,可以导出和转换以用于与 Azure AD 同步OneRoster - A CSV format that you can export and convert to sync with Azure AD

查看详细信息Find out more

步骤 2 - 在 Intune 中创建和分配 iOS/iPadOS 教育配置文件Step 2 - Create and assign an iOS/iPadOS Education profile in Intune

配置常规设置Configure general settings

  1. 登录到 IntuneSign in to Intune.
  2. 在“Intune”窗格上,选择“设备配置” 。On the Intune pane, choose Device configuration.
  3. 在“管理”部分的“设备配置”窗格上,选择“配置文件” 。On the Device configuration pane under the Manage section, choose Profiles.
  4. 在“配置文件”窗格上,选择“创建配置文件” 。On the profiles pane, choose Create profile.
  5. 在“创建配置文件”窗格上,输入 iOS/iPadOS 教育配置文件的“名称”和“说明” 。On the Create profile pane, enter a Name and Description for the iOS/iPadOS education profile.
  6. 在“平台” 下拉列表中,选择“iOS” 。From the Platform drop-down list, choose iOS.
  7. 在“配置文件类型” 下拉列表中,选择“教育” 。From the Profile type drop-down list, choose Education.
  8. 选择“设置” > “配置” 。Choose Settings > Configure.

接下来,需要使用证书在教师和学生 iPad 之间建立信任关系。Next, you need certificates to establish a trust relationship between teacher and student iPads. 证书用于在无提示情况下对设备间的连接进行无缝式身份验证,而无需输入用户名和密码。Certificates are used to seamlessly and silently authenticate connections between devices without having to enter user names and passwords.

重要

所使用的教师和学生证书必须由不同的证书颁发机构 (CA) 颁发。The teacher and student certificates you use must be issued by different certificate authorities (CAs). 必须创建两个新的连接到你的现有证书基础结构的从属 CA;一个用于教师,一个用于学生。You must create two new subordinate CAs connected to your existing certificate infrastructure; one for teachers, and one for students.

iOS 教育配置文件仅支持 PFX 证书。iOS education profiles support only PFX certificates. 不支持 SCEP 证书。SCEP certificates are not supported.

除用户身份验证以外,所创建的证书还必须支持服务器身份验证。Certificates you create must support server authentication in addition to user authentication.

配置教师证书Configure teacher certificates

在“教育” 窗格上,选择“教师证书” 。On the Education pane, choose Teacher certificates.

配置教师根证书Configure teacher root certificate

在“教师根证书” 下,选择浏览按钮以选择扩展名为 .cer(DER 或 Base64 编码)或 .P7B(不一定包含完整链路)的教师根证书。Under Teacher root certificate, choose the browse button to select the teacher root certificate with the extension .cer (DER, or Base64 encoded), or .P7B (with or without full chain).

配置教师 PKCS#12 证书Configure teacher PKCS#12 certificate

在“教师 PKCS#12 证书” 下,配置下列值:Under Teacher PKCS#12 certificate, configure the following values:

  • 使用者名称格式 - 对于教师证书,Intune 将自动在证书公用名称上添加前缀“主持人” ,对于学生证书则添加“成员” 。Subject name format - Intune automatically prefixes the certificate common name with leader, for the teacher certificate, and member, for the student certificate.
  • 证书颁发机构 - 在 Windows Server 2008 R2 企业版或更高版本上运行的企业证书颁发机构 (CA)。Certification authority - An Enterprise Certification Authority (CA) that runs on an Enterprise edition of Windows Server 2008 R2 or later. 不支持独立 CA。A Standalone CA is not supported.
  • 证书颁发机构名称 - 输入你的证书颁发机构的名称。Certification authority name - Enter the name of your certification authority.
  • 证书模板名称 - 输入已添加到发证 CA 的证书模板的名称。Certificate template name- Enter the name of a certificate template that has been added to an issuing CA.
  • 续订阈值(%) - 指定设备请求证书续订之前剩余的证书有效期限的百分比。Renewal threshold (%) - Specify the percentage of the certificate lifetime that remains before the device requests renewal of the certificate.
  • 证书有效期 - 指定距离证书过期的剩余时间量。Certificate validity period - Specify the amount of remaining time before the certificate expires. 你可以指定比指定证书模板中的有效期小的值,但不能指定较大的值。You can specify a value that is lower than the validity period in the specified certificate template, but not higher. 例如,证书模板中的证书有效期为 2 年,则你可以指定值 1 年,但不能指定值 5 年。For example, if the certificate validity period in the certificate template is two years, you can specify a value of one year but not a value of five years. 该值还必须小于发证 CA 证书的剩余有效期。The value must also be lower than the remaining validity period of the issuing CA certificate.

完成教师证书配置后,选择“确定” 。When you have finished configuring teacher certificates, choose OK.

配置学生证书Configure student certificates

  1. 在“教育” 窗格上,选择“学生证书” 。On the Education pane, choose Student certificates.
  2. 在“学生证书” 窗格的“学生设备证书类型” 列表中,选择“共享 iPad” 。On the Student certificates pane, from the Student device certificates type list, choose Shared iPad.

配置学生根证书Configure student root certificate

在“设备根证书” 下,选择浏览按钮以选择扩展名为 .cer(DER 或 Base64 编码)或 .P7B(不一定包含完整链路)的学生根证书。Under Device root certificate, choose the browse button to select the student root certificate with the extension .cer (DER, or Base64 encoded), or .P7B (with or without full chain).

配置设备 PKCS#12 证书Configure device PKCS#12 certificate

在“学生 PKCS#12 证书” 下,配置下列值:Under Student PKCS#12 certificate, configure the following values:

  • 使用者名称格式 - 对于教师证书,Intune 将自动在证书公用名称上添加前缀“主持人”,对于设备证书则添加“成员”。Subject name format - Intune automatically prefixes the certificate common name with leader, for the teacher certificate, and member, for the device certificate.
  • 证书颁发机构 - Windows Server 2008 R2 企业版或更高版本上运行的企业证书颁发机构 (CA)。Certification authority - An Enterprise Certification Authority (CA) that runs on an Enterprise edition of Windows Server 2008 R2 or later. 不支持独立 CA。A Standalone CA is not supported.
  • 证书颁发机构名称 - 输入你的证书颁发机构的名称。Certification authority name - Enter the name of your certification authority.
  • 证书模板名称 - 输入已添加到发证 CA 的证书模板的名称。Certificate template name - Enter the name of a certificate template that has been added to an issuing CA.
  • 续订阈值(%) - 指定设备请求证书续订之前剩余的证书有效期限的百分比。Renewal threshold (%) - Specify the percentage of the certificate lifetime that remains before the device requests renewal of the certificate.
  • 证书有效期 - 指定距离证书过期的剩余时间量。Certificate validity period - Specify the amount of remaining time before the certificate expires. 你可以指定比指定证书模板中的有效期小的值,但不能指定较大的值。You can specify a value that is lower than the validity period in the specified certificate template, but not higher. 例如,证书模板中的证书有效期为 2 年,则你可以指定值 1 年,但不能指定值 5 年。For example, if the certificate validity period in the certificate template is two years, you can specify a value of one year but not a value of five years. 该值还必须小于发证 CA 证书的剩余有效期。The value must also be lower than the remaining validity period of the issuing CA certificate.

完成证书配置后,选择“确定” 。When you are finished configuring certificates, choose OK.

完成证书设置Complete Certificate Setup

  1. 在“教育” 窗格上,选择“确定” 。On the Education pane, choose OK.
  2. 在“创建配置文件” 窗格上,选择“创建” 。On the Create profile pane, choose Create.

配置文件随即创建并显示在“配置文件列表”窗格中。The profile is created and appears on the profiles list pane.

步骤 3 - 创建设备类别Step 3 - Create a device category

  1. 登录到 IntuneSign in to Intune.
  2. 在“Intune” 窗格上,选择“设备注册” 。On the Intune pane, choose Device enrollment.
  3. 在“设备注册 - 概述”窗格中,选择“设备类别” 。On the Device enrollment - Overview pane, choose Device categories.
  4. 在“设备注册 - 设备类别” 窗格上,选择“创建” 。On the Device enrollment - Device Categories pane, choose Create.
  5. 在“创建设备类别” 窗格上,输入类别的“名称” 和“说明” 。On the Create device category pane, enter a Name and Description for the category.
  6. 在“创建设备类别” 窗格上,选择“创建” 。On the Create device category pane, choose Create.

设备类别创建在“注册 – 设备类别” 窗格中。The device category is created in the Enrollment – Device Categories pane.

步骤 4 – 创建动态组Step 4 – Create a dynamic group

  1. 登录到 IntuneSign in to Intune.
  2. 在“Intune”窗格上,选择“组” 。On the Intune pane, choose Groups.
  3. 在“用户和组 - 所有组” 窗格上,选择“新建组” 。On the Users and Groups – All Groups pane, choose New group.
  4. 在“组”窗格上,选择“组类型”,然后输入组的“名称”和“说明” 。On the Group pane, choose a Group type and then enter a Name and Description for the group.
  5. 从“成员身份类型” 下拉列表中,选择“动态设备” 。From the Membership type drop-down list, choose Dynamic Device.
  6. 选择“动态设备成员” ,创建成员身份规则。Choose Dynamic device members to create membership rules.
  7. 在“动态成员身份规则” 窗格上:On the Dynamic membership rules pane:
  8. 从“添加设备位置” 下拉列表中选择“deviceCategory” 。Select deviceCategory from the Add devices where drop-down list.
  9. 选择“等于” 。Choose Equals.
  10. 在空白的文本框中输入创建的设备类别。Enter the device category you created in the blank text box.
  11. 在“动态成员身份规则” 窗格上,选择“添加查询” 。On the Dynamic membership rules pane, choose Add query.
  12. 在“组” 窗格上,选择“创建” 。On the Group pane, choose Create.

动态组创建在“用户和组 - 所有组” 窗格中。The dynamic group is created in the Users and Groups – All Groups pane.

步骤 5 - 将设备分配到类别 (Cart)Step 5 – Assign a device to a category (Carts)

  1. 登录到 IntuneSign in to Intune.
  2. 在“Intune”窗格上,选择“设备” 。On the Intune pane, choose Devices.
  3. 在“设备”窗格上,选择“所有设备” 。On the Devices pane, choose All devices.
  4. 在“设备 - 所有设备” 窗格上,选择一台设备。On the Devices – All devices pane, choose a device.
  5. 在“设备”窗格上,选择“属性” 。On the device pane, choose Properties.
  6. 在设备“属性”窗格的“设备类别” 文本框中输入设备类别。On the device's properties pane, enter the device category in the Device category text box.
  7. 在“设备”窗格上,选择“保存” 。On the device pane, choose Save.

设备现已关联到设备类别。The device is now associated to the device category. 请对所有希望关联到创建的设备类别的设备重复此过程。Repeat this process for all the devices you want to associate to the device category you created.

步骤 6 – 创建 Classroom 配置文件Step 6 – Create classroom profiles

  1. 登录到 IntuneSign in to Intune.
  2. 在“Intune”窗格上,选择“设备配置” 。On the Intune pane, choose Device configuration.
  3. 在“设备配置” 窗格上,选择“管理” > “Cart 配置文件” 。On the Device configuration pane, choose Manage > Cart Profiles.
  4. 在“配置文件”窗格上,选择“创建配置文件” 。On the profiles pane, choose Create Profile.
  5. 在“创建关联” 窗格上,输入“名称” 和“说明” 。On the Create Association pane, enter a Name and Description.
  6. 选择“选择类” > “配置” ,将组关联到 Cart 配置文件。Choose Select Classes > Configure to associate groups to the Cart Profile.
  7. 选择要包括到 Cart 配置文件的类,然后选择“选择” 。Choose the classes to include to the Cart Profile then choose Select.
  8. 选择“选择 Cart” > “配置” ,将组关联到 Cart 配置文件。Choose Select Carts > Configure to associate groups to the Cart Profile.
  9. 选择要包括到 Cart 配置文件的组,然后选择“选择” 。Choose the groups to include to the Cart Profile then choose Select.
  10. 在“创建关联” 窗格上,选择“保存” 以保存 Cart 配置文件。On the Create Association pane, choose Save to save the Cart Profile.

配置文件随即创建并显示在“配置文件列表”窗格中。The profile is created and appears on the profiles list pane.

步骤 7 - 将 Cart 配置文件分配到类Step 7 - Assign the Cart Profile to Classes

  1. 登录到 IntuneSign in to Intune.
  2. 在“Intune”窗格上,选择“设备配置” 。On the Intune pane, choose Device configuration.
  3. 在“设备配置” 窗格上,选择“监视” > “分配状态” 。On the Device configuration pane, choose Monitor > Assignment status.
  4. 在“分配状态” 窗格上,选择所创建的“Cart 配置文件” 。On the Assignment status pane, select the Cart Profile you created.
  5. 在“Cart 配置文件” 窗格上,选择“分配” ,然后在“包括” 下选中“选择要包括的组” 。On the Cart Profile pane choose Assignments and then, under Include choose Select groups to include.
  6. 选择希望作为 Cart 配置文件目标的类(请勿选择组),然后选择“选择” 。Select the classes you want the cart profile to target (do not select a group), then choose Select.
  7. 完成后,请选择“保存” 。When you are finished, choose Save.

分配完成,Intune 会基于教室分配将 Classroom 配置文件部署到目标设备。The assignment completes, and Intune deploys the Classroom profile to the targeted devices based on the classroom assignment.

后续步骤Next Steps

现在学生之间可以共享设备,并且可以在教室里拿起任何 iPad,使用 PIN 登录并根据自己的内容进行个性化设置。Now students can share devices between students, and students can pick up any iPad in a classroom, log in with a PIN and have it personalized with their content. 有关共享 iPad 的详细信息,请参阅 Apple 网站For more information about Shared iPads, see the Apple website.