Configuration Settings Payload - Restrictions
Meraki is committed to providing an inclusive experience for our customers. The following section contains language that does not adhere to our standards for inclusivity. We are working with our partners to replace it.
Apple MDM Restrictions for iOS Devices
Cross-platform Restrictions:
Setting |
Functionality |
Supervised Enrollment Required? |
Minimum Supported OS |
Camera: |
|||
|
If disabled - Cameras are disabled and the Camera icon is removed from the Home Screen in iOS and iPadOS. Users can’t take photographs or videos. |
Yes |
iOS 5 or iPadOS 13.1 |
Device Functionality: |
|||
|
If disabled - App Store is disabled and its icon is removed from the Home Screen. Users can’t install or update apps. This applies to App Store apps, marketplace apps, and locally installed apps (using Configurator, Xcode, etc). **In iOS 10 or later, MDM app commands can still be used. |
Yes |
iOS 10 or iPadOS 13.1 |
|
When disabled - Users can’t save a screenshot or recording of the screen. |
No |
iOS 5 or iPadOS 13.1 |
|
When disabled - Siri can't be used. |
No |
iOS 5 or iPadOS 13.1 |
|
When disabled - Siri responds only when the device is unlocked. |
No |
iOS 5.1 or iPadOS 13.1 |
Apple Restrictions- iOS:
Setting |
Functionality |
Supervised Enrollment Required? |
Minimum Supported OS |
Device Functionality: |
|||
|
If disabled - the system disables voice dialing if the device is locked with |
No |
Only Supported on iOS versions iOS 4 - iOS 16. **This feature has been deprecated by Apple as of iOS 17. |
|
If disabled, Devices that are roaming sync only when an account is accessed by the user. |
No |
iOS 5 or iPadOS 13.1 |
|
If disabled, the system hides Passbook notifications from the lock screen. |
No |
iOS 6 + |
|
If disabled, the system prohibits in-app purchasing. |
Yes |
iOS 5 or iPadOS 13.1 |
|
If enabled, the system forces the user to enter their iTunes password for each transaction |
No |
Only Supported on iOS versions iOS 6 - iOS 16. **This feature has been deprecated by Apple as of iOS 17. |
|
If disabled, the system prevents the Control Center from appearing on the Lock screen. Users can’t swipe up to view Control Centre. |
No |
iOS 7 or iPadOS 13.1 |
|
Users can’t view the Notification history when the screen is locked; however, they can still view a Notification when it appears. |
No |
iOS 7 or iPadOS 13.1 |
|
If disabled, users can’t swipe down to see the Notification Centre using Today View in the Lock Screen. |
No |
iOS 7 or iPadOS 13.1 |
|
If disabled, the system disables remote screen observation by the Classroom app. |
Yes |
iOS 12+ |
|
Unmanaged apps will have access to work data and contacts |
No |
iOS 12+ |
|
Managed apps will have access to work data and contacts |
No |
iOS 12+ |
iOS can natively separate work and personal data and contacts. For more information, see our article on iOS containerization. |
|||
|
Helps control the pasting of content from an app that’s using Open In management by following the Managed Open In restrictions in force. Apple apps that work with the managed pasteboard include Calendar, Files, Mail and Notes. Third-party apps are controlled based on whether they’re managed. When a user attempts to paste content where it isn’t permitted, a Paste Not Allowed notice appears along with the organisation’s name (which can be changed using the Settings command). Apps also can’t request items from the pasteboard when this restriction is used and the content crosses the managed boundary. Default is off. |
No |
iOS 15 or iPadOS 15 |
|
Users can’t use Handoff with their Apple devices. |
No |
iOS 8 or iPadOS 13.1 |
|
If enabled, the system forces all devices receiving AirPlay requests from this device to use a pairing password. |
No |
iOS 7.1+ |
|
If enabled, the system forces all devices receiving AirPlay requests from this device to use a pairing password. |
No |
iOS 7.1+ |
|
If enabled, Apple Watch locks automatically when it’s removed from the user’s wrist. It can be unlocked with its passcode or the paired iPhone. Default is off. |
No |
iOS 8.2+ and iPadOS 13.1+ |
|
If disabled, users can’t add App Clips. Any existing App Clips are removed when this restriction is applied |
Yes |
iOS 14 and iPadOS 14 |
|
If enabled, the system considers AirDrop to be an unmanaged drop target |
No |
iOS 9 |
|
Managed Apps can edit contacts to unmanaged accounts, even if Managed Apps are prevented from editing unmanaged destinations Default is off |
No |
iOS 12 and iPadOS 13.1 |
|
Unmanaged apps can read contacts from managed accounts, even if unmanaged apps are prevented from reading to managed destinations Default is off |
No |
iOS 12 and iPadOS 13.1 |
|
if enabled, Allows Siri from logging to its server |
Yes |
iOS 12.2 |
|
If disabled, Shared iPad won’t allow a Temporary Session |
Yes |
iPadOS 13.4 |
|
If disabled, the system disables NFC. Prevents users from using built-in NFC (near–field communications) hardware in compatible devices. |
Yes |
iOS 14.2 |
|
If disabled, users’ data won’t be used by the Apple advertising platform to deliver personalized ads. |
No |
iOS 14 and iPadOS 14 |
|
If enabled, the system allows unpaired devices to boot devices into recovery. Previously, (iOS 14 and below) any external host computer was allowed to restart a connected iPhone or iPad into the recoveryOS (also known as Recovery Mode), completely erase it, restore iOS or iPadOS over a USB connection without any other physical interaction with the device. iOS 14.5 and iPadOS 14.5 or later, prevent this behaviour by default. |
Yes |
iOS 14.5 and iPadOS 14.5 |
|
Prevents dictated content from being sent to Siri servers for processing. Supported on the following devices.
Default is off. |
No |
iOS 14.5 and iPadOS 14.5 |
|
Won’t let the device connect to Siri servers for the purposes of translation. Default is off |
No |
iOS 14.5 and iPadOS 14.5 |
|
This Feature has been deprecated by Apple, Please use the restriction payload key "Force WiFi to Allowed Networks Only" Instead |
N/A |
N/A |
|
If enabled, the system limits the device to only join Wi-Fi networks set up through a configuration profile. Important: If the Wi-Fi network isn’t available, the device can’t be managed. |
Yes |
iOS 14.5 |
|
If disabled, the system disables Mail Privacy Protection on the device. |
Yes |
iOS 15.2 |
|
If enabled, the system preserves eSIM when it erases the device due to too many failed password attempts or the Erase All Content and Settings option in Settings > General > Reset The system doesn’t preserve eSIM if Find My initiates erasing the device. |
Yes |
iOS 17.2 and iPadOS 17.2 |
|
If disabled, prevents installation of apps directly from the web |
Yes |
iOS 17.4 |
|
If disabled, Prevents a device with a Tandem OLED screen from dimming. |
Yes |
iPadOS 17.4 |
|
If disabled , prevents the transfer of an eSIM from the device on which the restriction is installed to a different device. |
Yes |
iOS 18 and iPadOS 18 |
|
If disabled, prevents users from creating a Genmoji. |
Yes |
iOS 18 and iPadOS 18 |
|
If disabled, Prevents users from using Image Wand. |
Yes |
iOS 18 and iPadOS 18 |
|
If disabled, prevents Apple Intelligence writing tools. |
Yes |
iOS 18 and iPadOS 18 |
|
If disabled, prevents users from using Image Playground. |
Yes |
iOS 18 and iPadOS 18 |
|
If disabled, prevents the use of call recording on iPhone. |
Yes |
iOS 18 |
|
If disabled, Prevents iOS and iPadOS from generating text in the user’s handwriting. |
Yes |
iOS 18 and iPadOS 18 |
|
If disabled, On iPhone, prevents an iPhone from mirroring to a Mac. |
Yes |
iOS 18 |
|
If disabled, prevents users from hiding apps. |
Yes |
iOS 18 and iPadOS 18 |
|
If disabled, prevents users from locking apps. If this restriction is used, hiding apps is also prevented. |
Yes |
iOS 18 and iPadOS 18 |
|
If disabled Prevents the ability to create summaries of email messages manually. This doesn’t affect automatic summary generation. |
Yes |
iOS 18 and iPadOS 18 |
|
If disabled, prevents the use of RCS messaging. |
Yes |
iOS 18 and iPadOS 18 |
|
If disabled, prevents the use of external, cloud-based intelligence services with Siri. On iOS, this restriction is temporarily allowed on unsupervised and user enrollments. In a future release, this restriction will require supervision, and will be ignored on non-supervised devices. |
No |
iOS 18.2 and macOS 15.2 |
|
If false, forces external intelligence providers into anonymous mode. If a user is already signed in to an external intelligence provider, applying this restriction will cause them to be signed out when the next request is attempted. |
No |
iOS 18.2 and macOS 15.2 |
iCloud iOS: |
|
||
|
If disabled, users can’t use their iCloud Photos. |
Yes |
iOS 9 and IPadOS 13.1 |
|
If disabled, the system disables backup of Enterprise books. Users can’t back up books distributed by their organisation to iCloud, the Finder (macOS 10.15 or later) or in iTunes (macOS 10.14 or earlier). |
No |
iOS 8 and iPadOS 13.1 |
|
If disabled, the system disables sync of Enterprise books, notes, and highlights. users can’t sync notes or highlights to other devices using iCloud. |
No |
iOS 8 and iPadOS 13.1 |
|
If disabled, the system disables Photo Stream. |
No |
Only supported on iOS 5 through iOS 16. **This feature has been deprecated by Apple as of iOS 17. |
|
If disabled, the system disables Shared Photo Stream |
Yes |
iOS 6 |
|
If disabled, the system prevents managed apps from using iCloud sync |
No |
iOS 8 |
Security and privacy: |
|
||
|
If disabled, users can’t choose to send diagnostic information to Apple. |
No |
iOS 6 and iPadOS 13.1 |
|
If disabled, the system automatically rejects untrusted HTTPS certificates without prompting the user. |
No |
iOS 5 |
|
If enabled, the system encrypts all backups. |
No |
iOS 4 |
|
If disabled, Automatic updates to certificate trust settings can’t occur. |
No |
iOS 7 |
|
If enabled, the system limits ad tracking. Additionally, it disables app tracking and the Allow Apps to Request to Track setting. |
No |
iOS 7 |
|
If disabled, users must use a passcode to unlock the device. |
No |
iOS 7 and iPadOS 13.1 |
|
If disabled, the system prohibits installation of rapid security responses. |
No |
iOS 16 and macOS 13 |
|
If disabled, the system prohibits removal of rapid security responses |
No |
iOS 16 and macOS 13 |
Ratings region |
|||
|
This feature can not be disabled and the default by Apple is the United States.
|
No |
N/A |
Allowed Content Ratings |
|||
|
|
No |
iOS 5 or iPadOS 13.1 |
|
|
No |
iOS 5 or iPadOS 13.1 |
|
|
No |
iOS 5 or iPadOS 13.1 |
Software updates |
|||
|
If enabled, the system delays user visibility of software updates. In macOS, the system allows seed build updates without delay. The delay is 30 days unless you set another value under hid all software updates. |
Yes |
iOS 11.3 and macOS 10.13.4 and tvOS 12.2 |
|
Allows admins to determine how many days to delay a software update on the device. With this restriction in place, the user doesn’t see a software update until the specified number of days after the software update release date Max # of days is 90 |
Yes |
iOS 11.3 and macOS 10.13.4 and tvOS 12.2 |
Apple Supervised Restrictions- iOS:
These restrictions only have an effect when a device is in 'supervised' mode. This mode can only be enabled with ADE or Apple Configurator. Read more
Setting |
Functionality |
Supervised Enrollment Required? |
Minimum Supported OS |
Applications: |
|||
|
If disabled, the system disables removal of apps from an iOS device. This applies to App Store apps, marketplace apps, and locally installed apps (using Configurator, Xcode, etc) |
Yes |
iOS 4.2.1 |
|
If disabled, the iTunes Store is disabled and its icon is removed from the Home Screen. Users can’t preview, purchase, or download content. |
Yes |
iOS 4 |
|
If disabled, the system disables the Safari web browser app, and the system removes its icon from the Home screen. This setting also prevents users from opening web clips. |
Yes |
iOS 4 |
|
If enabled, the system enables Safari fraud warning. Also available for user enrollment. |
Yes |
iOS 4 |
|
If disabled, Safari doesn’t execute any JavaScript and ignores all JavaScript on websites |
Yes |
iOS 5 and iPadOS 13.1 |
|
If disabled, Safari doesn’t allow pop-up windows. Pop-ups are blocked in Safari. |
Yes |
iOS 4 |
|
If disabled, the system disables Safari AutoFill for passwords, contact info, and credit cards and also prevents using the Keychain for AutoFill. Safari doesn’t keep track of what users enter in web forms. |
Yes |
iOS 4, iPadOS iPadOS 13.1 and macOS 10.13 |
|
If disabled, users can’t place or receive FaceTime audio or video calls and the system hides the FaceTime app. |
Yes |
iOS 5 and iPadOS 13.1 |
|
If disabled, the system disables the use of iMessage on supervised devices. If the device supports text messaging, the user can still send and receive text messages. For Wi-Fi–only devices, the Messages app is hidden. |
Yes |
iOS 5 and iPadOS 13.1 |
|
If disabled, the Game Center app and its icon are removed. |
Yes |
iOS 6 and iPadOS 13.1 |
|
If disabled, the system removes the Book Store tab from the Books app. |
Yes |
iOS 6 and iPadOS 13.1 |
|
If disabled, the system prevents the user from downloading Apple Books media that’s tagged as erotica. |
Yes |
iOS 4.0, iPadOS 13.1, macOS 15, and tvOS 17 |
|
If disabled, the system disables podcasts |
Yes |
iOS 8 and iPadOS 13.1 |
|
If disabled , the system disables the App Store, and the systems removes its icon from the Home screen. However, users can continue to use host apps such as iTunes or Configurator to install or update their apps. In iOS 10 and later, MDM commands can override this restriction. |
Yes |
iOS 9 and iPadOS 13.1 |
|
If disabled, users can’t use the News app |
Yes |
iOS 9 and iPadOS 13.1 |
|
If disabled, users can’t use Apple Music |
Yes |
iOS 9.3 and iPadOS 13.1 |
|
If disabled, sers can’t listen to the radio with Apple Music. |
Yes |
iOS 9.3 and iPadOS 13.1 |
Allowed Single App Mode |
Apps listed here are allowed to place themselves in Single App Mode autonomously. It does not restrict which apps can be manually placed into Single App Mode. |
Yes |
iOS 7 and iPadOS 13.1 |
Show or hide apps |
Regardless of what is selected, the following apps are always allowed: Settings, Phone. Choose from the options below, please note that "only allow the following apps" will remove system apps from view/use except for settings and phone.
|
Yes |
N/A |
Device functionality: |
|
||
Supervised devices can be configured to not allow the installation of configuration profiles or certificates interactively. |
If disabled, the system prohibits the user from installing configuration profiles and certificates interactively. |
Yes |
iOS 6, iPadOS 13.1, and macOS 13 |
|
If disabled, the system prohibits adding friends to Game Center. |
Yes |
iOS 5, iPadOS 13.1 and macOS 10.13 |
|
If disabled, the system disables modification of accounts such as Apple IDs and Internet-based accounts such as Mail, Contacts, and Calendar. |
Yes |
iOS 7 and iPadOS 13.1 |
|
If disabled, users can’t use AirDrop. |
Yes |
iOS 7 and iPadOS 13.1 and macOS 10.13 |
|
If disabled, the system disables changing settings for cellular data usage for apps. |
Yes |
iOS 7 and iPadOS 13.1 |
|
If disabled, Siri can’t access content from sources that allow user-generated content, such as Wikipedia. |
Yes |
iOS 7 and iPadOS 13.1 |
|
If disabled, the system disables Find My Device in the Find My app |
Yes |
iOS 13, iPadOS 13.1 and macOS 10.15 |
|
If disabled, the system disables Find My Friends in the Find My app |
Yes |
iOS 13, iPadOS 13.1 and macOS 10.15 |
|
If disabled, the system disables changes to Find My Friends. |
Yes |
iOS 7, iPadOS 13.1 and macOS 10.15 |
|
If disabled, the system disables host pairing with the exception of the supervision host. If there’s no configured supervision host certificate, the system disables all pairing. Host pairing lets the administrator control if an iOS device can pair with a host Mac or PC. |
Yes |
iOS 7 or iPadOS 13.1 |
|
If disabled, Users can’t play multiplayer games in Game Center. |
Yes |
iOS 4 .1 and iPadOS 13.1 and MacOS 10.12 |
|
If enabled, the system prevents turning off Wi-Fi in Settings or Control Center, even by entering or leaving Airplane Mode. It doesn’t prevent selecting which Wi-Fi network to use. |
Yes |
iOS 13.0 |
|
If enabled, the system forces the use of the profanity filter assistant. |
Yes |
iOS 11 and iPadOS 13.1 and macOIS |
|
If disabled, the system prevents connecting to network drives in the Files app. |
Yes |
iOS 13.1 and iPadOS 13.1 |
|
If disabled, the system prevents connecting to any connected USB devices in the Files app |
Yes |
iOS 13.1 |
|
If disabled, the system disables the Enable Restrictions option in the Restrictions UI in Settings. In iOS 12 and later, the system disables the Enable ScreenTime option in the ScreenTime UI in Settings and disables ScreenTime if already enabled. |
Yes |
iOS 8 |
|
If disabled, the system disables the Erase All Content and Settings option in the Reset UI. |
Yes |
iOS 8, iPadOS 13.1 and macOS 12 |
|
If disabled, the system disables Spotlight Internet search results in Siri Suggestions. |
Yes |
iOS 8, iPadOS 13.1 and macOS 10.11 |
|
If disabled, the system disables keyboard autocorrection. |
Yes |
iOS 8.1.3, iPadOS 13.1 |
|
If disabled, the system disables the keyboard spell checker. |
Yes |
iOS 8.1.3, iPadOS 13.1 |
|
If disabled, the system disables definition lookup. |
Yes |
iOS 8.1.3, iPadOS 13.1 and macOS 10.11 |
|
If disabled, the system disables predictive keyboards. |
Yes |
iOS 8.1.3, iPadOS 13.1 and macOS 10.11 |
|
If disabled, the system disables QuickPath keyboard |
Yes |
iOS 13 and iPadOS 13.1 |
|
If disabled, the system disables keyboard shortcuts. |
Yes |
iOS 9 and iPadOS 13.1 |
|
If disabled, the system disables pairing with an Apple Watch, and the system unpairs any currently paired Apple Watch and erases its content. |
Yes |
iOS 9 and iPadOS 13.1 |
Do not disable this setting if there is a passcode policy pushed to the device. |
If disabled, the system prevents adding, changing, or removing the passcode. The system ignores this restriction on Shared iPad |
Yes |
iOS 9, iPadOS 13.1 and macOS 10.13 |
|
If disabled, the system prevents the user from changing the device name. |
Yes |
iOS 9, iPadOS 13.1, macOS 14 and tvOS 11.0 |
The device name cannot be set from Dashboard if "Allow modification of device name" is disabled. |
When enabled, the system allows the dashboard to push the currently configured hostname in the dashboard to the device. |
Yes |
iOS 9, tvOS 10.2 and macOS 15.1
|
|
If disabled, the system prevents changing the wallpaper. |
Yes |
iOS 9, iPadOS 13.1 and macOS 10.13 |
|
If disabled, the system prevents automatic downloading of apps purchased on other devices. This setting doesn’t affect updates to existing apps |
Yes |
iOS 9 and iPadOS 13.1 |
|
If disabled, the system removes the Trust Enterprise Developer button in Settings > General > Profiles & Device Management, which prevents provisioning apps by universal provisioning profiles. This restriction applies to free developer accounts. However, it doesn’t apply to enterprise app developers, because they’re trusted and the system installed their apps through MDM. It also doesn’t revoke previously granted trust. |
Yes |
iOS 9 and iPadOS 13.1 |
|
If disabled, the system disables modification of notification settings. |
Yes |
iOS 9.3 and iPadOS 13.1 |
|
If disabled, the system disables changing the diagnostic submission and app analytics settings in the Diagnostics & Usage UI in Settings. |
Yes |
iOS 9.3.2 and iPadOS 13.1 |
|
If disabled, the system prevents modification of Bluetooth settings |
Yes |
iOS 11 and iPadOS 13.1 |
|
If disabled, the system disallows dictation input. |
Yes |
iOS 10.3, iPadOS 13.1 and macOS 10.13 |
|
If disabled, the system disables AirPrint. |
Yes |
iOS 11 and iPadOS 13.1 |
|
If disabled, the system disables keychain storage of user name and password for AirPrint |
Yes |
iOS 11 and iPadOS 13.1 |
|
If enabled, the system requires trusted certificates for TLS printing communication. |
Yes |
iOS 11 and iPadOS 13.1 |
|
If disabled, the system disables iBeacon discovery of AirPrint printers, which prevents spurious AirPrint Bluetooth beacons from phishing for network traffic. |
Yes |
iOS 11 and iPadOS 13.1 |
|
If disabled, the system disables the removal of system apps from the device |
Yes |
iOS 11 and iPadOS 13.1 |
|
If disabled, the system disables the creation of VPN configurations |
Yes |
iOS 11 and iPadOS 13.1 |
|
If disabled, the system allows iOS devices to always connect to USB accessories while locked. On macOS, allows new USB and Thunderbolt accessories and SD cards to connect without authorization. If the system has Lockdown mode enabled, it ignores this value. |
Yes |
iOS 11.4.1, iPadOS 13.1 and macOS 13 |
|
If enabled, the system enables the Set Automatically feature in Date & Time and the user can’t disable it. The system updates the device’s time zone only when the device can determine its location using a cellular connection or Wi-Fi with location services enabled. |
Yes |
iOS 12, iPadOS 13.1 and tvOS 12.2 |
|
If disabled, the system disables:
However the system does not prevent autofill contact info and credit cards in safari |
Yes |
iOS 12, iPadOS 13.1 and macOS 10.14 |
|
If disabled, the system disables requesting passwords from nearby devices. |
Yes |
iOS 12, iPadOS 13.1, macOS 10.14 and tvOS 12 |
|
If disabled, the system disables sharing passwords with the Airdrop Passwords feature. |
Yes |
iOS 12, iPadOS 13.1 and macOS 10.14 |
|
If disabled, he system disables modifications to carrier plan related settings. |
Yes |
iOS 11 |
|
If disabled, the system disables modifications of the personal hotspot setting. |
Yes |
iOS 12.2 |
|
If disabled, the system disallows iPhone widgets on a Mac that has signed in the same Apple ID for iCloud. |
Yes |
iOS 17 |
|
If disabled, the system disables live voicemail on the device. |
Yes |
iOS 17.2 |
|
If disabled, the system prevents installation of alternative marketplace apps from the web and prevents any installed alternative marketplace apps from installing apps. |
Yes |
iOS 17.4 |
iCloud iOS: |
|
||
|
If disabled, the system disables document and key-value syncing to iCloud. |
Yes |
iOS 5, iPadOS 13.1 and macOS 10.11 |
|
If disabled, the system disables iCloud keychain synchronization. |
Yes |
iOS 7, iPadOS 13.1 and macOS 10.12 |
|
If disabled, the system disables backing up the device to iCloud. |
Yes |
iOS 5, iPadOS 13.1 |
Security and privacy: |
|
||
|
If disabled, the system prevents the user from modifying Touch ID or Face ID |
Yes |
iOS 8.3, iPadOS 13.1 and macOS 14 |
Content Ratings: |
|
||
|
If disabled, the system hides explicit music or video content purchased from the iTunes Store. The system marks explicit content as such by content providers, such as record labels, when sold through the iTunes Store. Explicit content in the News and Podcast apps is also hidden. |
Yes |
iOS 4.0, iPadOS 13.1, macOS 15 and tvOS 11.3 |
Apple Education |
|
||
If true, automatically gives permission to the teacher's requests without prompting the student. |
If Enabled, the system automatically gives permission to the teacher’s requests without prompting the student. |
Yes |
iOS 11, iPadOS 13.1 and macOS 10.14.4 |
|
If enabled, a student enrolled in an unmanaged course through Classroom needs to request permission from the teacher to leave the course. |
Yes |
iOS 11.3, iPadOS 13.1 and macOS 10.14.4 |
|
If enabled, the system allows the teacher to lock apps or the device without prompting the student. |
Yes |
iOS 11, iPadOS 13.1 and macOS 10.14.4 |
If true and Allow MDM to automatically approve screen observation is also true in the Education payload, a student enrolled in a managed course via the Classroom app automatically gives permission to that course teacher's requests to observe the student's screen without prompting the student. |
If enable and the setting for "ScreenObservationPermissionModificationAllowed" is also enabled in the Education payload, a student enrolled in a managed course through the Classroom app automatically gives permission to that course teacher’s requests to observe the student’s screen without prompting the student. |
Yes |
iOS 11, iPadOS 13.1 and macOS 10.14.4 |
Apple MDM Restrictions for macOS Devices
Cross-platform Restrictions
Setting |
Functionality |
Supervised Enrollment Required? |
Minimum Supported OS |
Camera: |
|||
|
If disabled - Cameras are disabled and the Camera icon is removed from the Home Screen in iOS and iPadOS. Users can’t take photographs or videos. |
Yes |
macOS 10.11+ |
Device Functionality: |
|||
|
When disabled - Users can’t save a screenshot or recording of the screen. |
No |
macOS 10.14.4+ |
|
When disabled - Siri/Cortana can't be used. |
No |
macOS 14 |
Apple Restrictions - macOS
Setting |
Functionality |
Supervised Enrollment Required? |
Minimum Supported OS |
Device Functionality: |
|||
|
If disabled, the system disables iTunes file sharing services. |
No |
macOS 10.13 |
|
If disabled, prevents modification of Media Sharing settings. |
Yes |
macOS 15.1 |
**Screenshot feature must be enabled for this. |
If disabled, the system disables remote screen observation by the Classroom app. |
Yes |
macOS 10.14.4 |
|
If enabled, helps control the pasting of content from an app that’s using Open In management by following the Managed Open In restrictions in force. Apple apps that work with the managed pasteboard include Calendar, Files, Mail and Notes. Third-party apps are controlled based on whether they’re managed. When a user attempts to paste content where it isn’t permitted, a Paste Not Allowed notice appears along with the organisation’s name (which can be changed using the Settings command). Apps also can’t request items from the pasteboard when this restriction is used and the content crosses the managed boundary. Default is off |
No |
macOS |
|
Users can’t use Handoff with their Apple devices. |
No |
iOS 8, iPadOS 13.1 and macOS 10.15 |
|
If disabled, the system disables Universal Control. |
No |
macOS 13 |
|
If disabled, prevents a user with the role of administrator from creating new users in Users & Groups. |
No |
macOS 14 |
|
If disabled, prevents the user from modifying remote Apple events settings. |
No |
macOS 14 |
|
If disabled, prevents the user from modifying Remote Desktop management settings. |
No |
macOS 14 |
|
If disabled, prevents the user from selecting a different startup disk. |
No |
macOS 14 |
|
If disabled, prevents the user from setting up and using a Time Machine backup. |
No |
macOS 14 |
|
If disabled, prevents the user from modifying Bluetooth® settings. |
No |
macOS 14 |
|
If disabled, revents the user from modifying file sharing settings. |
No |
macOS 14 |
|
If disabled, revents the user from modifying internet sharing settings. |
No |
macOS 14 |
|
If disabled, prevents the user from modifying printer sharing settings. |
No |
macOS 14 |
|
If disabled, prevents Apple Intelligence writing tools. |
Yes |
iOS 18 and iPadOS 18 and macOS 15 |
|
If disabled, prevents users from using Image Playground. |
Yes |
iOS 18, iPadOS 18 and macOS 15 |
|
If disabled, revents showing the screen capture alert dialogue. Default is off |
No |
macOS 15.1 |
|
If disabled, prevents the use of external, cloud-based intelligence services with Siri. On iOS, this restriction is temporarily allowed on unsupervised and user enrollments. In a future release, this restriction will require supervision, and will be ignored on non-supervised devices. Available in iOS 18.2 and later, and macOS 15.2 and later. |
No |
iOS 18.2 and macOS 15.2 |
|
If false, forces external intelligence providers into anonymous mode. If a user is already signed in to an external intelligence provider, applying this restriction will cause them to be signed out when the next request is attempted. Available in iOS 18.2 and later, and macOS 15.2 and later. |
No |
iOS 18.2 and macOS 15.2 |
iCloud iOS: |
|||
|
If disabled, users can’t use their iCloud Photos. |
Yes |
iOS 9 and IPadOS 13.1 and macOS 10.12 |
|
This feature was discontinued by Apple in 2019 and Apple recommends using iCloud Drive or Apple Remote Desktop in its place. |
||
|
If disabled, users can't use Find My Device services |
No |
iOS 13, iPadOS 13.1 and macOS 10.15 |
|
If disabled, the system disables iCloud Bookmark sync. Bookmarks won't be uploaded to the cloud |
No |
macOS 10.12 |
|
If disabled, the system disables iCloud Mail services. Mail won't be uploaded to the cloud |
No |
macOS 10.12 |
|
If disabled, the system disables iCloud Calendar services. Calendar won't be uploaded to the cloud |
No |
macOS 10.12 |
|
If disabled, the system disables iCloud Reminder services. Reminders won't be uploaded to the cloud |
No |
macOS 10.12 |
|
If disabled, the system disables iCloud Address Book services. Address Book won't be uploaded to the cloud |
No |
macOS 10.12 |
|
If disabled, the system disables iCloud Notes services. Notes won't be uploaded to the cloud |
No |
macOS 10.12 |
|
If disabled, the system disables iCloud Desktop and Document services. |
No |
macOS 10.12.4 |
|
If disabled, prevents the user from storing Freeform files in iCloud |
No |
macOS 14 |
Security and privacy: |
|||
|
If disabled, users can’t choose to send diagnostic information to Apple. |
No |
MacOS 10.13 |
|
If disabled, users must use a passcode to unlock the device. |
No |
iOS 7 and iPadOS 13.1 and mac OS 10.12.4 |
|
If disabled, the system prohibits installation of rapid security responses. |
No |
iOS 16 and macOS 13 |
|
If disabled, the system prohibits removal of rapid security responses |
No |
iOS 16 and macOS 13 |
Software Updates |
|||
In macOS, seed build updates are allowed, without delay. |
If enabled, the system delays user visibility of software updates. In macOS, the system allows seed build updates without delay. The delay is 30 days unless you set another value under hid all software updates. |
Yes |
iOS 11.3 and macOS 10.13.4 and tvOS 12.2 |
|
Allows admins to determine how many days to delay a software update on the device. With this restriction in place, the user doesn’t see a software update until the specified number of days after the software update release date Max # of days is 90 |
Yes |
iOS 11.3 and macOS 10.13.4 and tvOS 12.2 |
|
|
|
|
|
|
|
|
|
|
|
|
Apple Supervised Restrictions - macOS
Setting |
Functionality |
Supervised Enrollment Required? |
Minimum Supported OS |
Applications |
|||
|
If disabled, the system disables Safari AutoFill for passwords, contact info, and credit cards and also prevents using the Keychain for AutoFill. Safari doesn’t keep track of what users enter in web forms. |
Yes |
iOS 4, iPadOS iPadOS 13.1 and macOS 10.13 |
|
If disabled, the Game Center app and its icon are removed. |
Yes |
iOS 6 and iPadOS 13.1 and macOS 10.13 |
Device Functionality: |
|||
Supervised devices can be configured to not allow the installation of configuration profiles or certificates interactively. |
If disabled, the system prohibits the user from installing configuration profiles and certificates interactively. |
Yes |
iOS 6, iPadOS 13.1, and macOS 13 |
|
If disabled, the system prohibits adding friends to Game Center. |
Yes |
iOS 5, iPadOS 13.1 and macOS 10.13 |
|
If disabled, the system disables modification of accounts such as Apple IDs and Internet-based accounts such as Mail, Contacts, and Calendar. |
Yes |
iOS 7 and iPadOS 13.1 and macOS 14 |
|
If disabled, users can’t use AirDrop. |
Yes |
iOS 7 and iPadOS 13.1 and macOS 10.13 |
|
If disabled, Users can’t play multiplayer games in Game Center. |
Yes |
iOS 4 .1 and iPadOS 13.1 and MacOS 10.12 |
|
If disabled, the system disables Spotlight Internet search results in Siri Suggestions. |
Yes |
iOS 8, iPadOS 13.1 and macOS 10.11 |
|
If disabled, the system disables definition lookup. |
Yes |
iOS 8.1.3, iPadOS 13.1 and macOS 10.11 |
Do not disable this setting if there is a passcode policy pushed to the device. |
If disabled, the system prevents adding, changing, or removing the passcode. The system ignores this restriction on Shared iPad |
Yes |
iOS 9, iPadOS 13.1 and macOS 10.13 |
|
If disabled, the system prevents the user from changing the device name. |
Yes |
iOS 9, iPadOS 13.1, macOS 14 and tvOS 11.0 |
|
If disabled, the system prevents changing the wallpaper. |
Yes |
iOS 9, iPadOS 13.1 and macOS 10.13 |
|
If disabled, users can’t use dictation on their device. |
Yes |
macOS 10.13 |
|
If disabled, the system allows iOS devices to always connect to USB accessories while locked. On macOS, allows new USB and Thunderbolt accessories and SD cards to connect without authorization. If the system has Lockdown mode enabled, it ignores this value. |
Yes |
iOS 11.4.1, iPadOS 13.1 and macOS 13 |
|
If disabled, the system disables:
However the system does not prevent autofill contact info and credit cards in safari |
Yes |
iOS 12, iPadOS 13.1 and macOS 10.14 |
|
If disabled, the system disables requesting passwords from nearby devices. |
Yes |
iOS 12, iPadOS 13.1, macOS 10.14 and tvOS 12 |
|
If disabled, the system disables sharing passwords with the Airdrop Passwords feature. |
Yes |
iOS 12, iPadOS 13.1 and macOS 10.14 |
iCloud |
|||
|
If disabled, the system disables document and key-value syncing to iCloud. Shared iPad doesn’t support it. |
Yes |
iOS 5 and macOS 10.11 and later. |
|
If disabled, the system disables iCloud keychain synchronization |
Yes |
iOS 7, iPadOS 13.1 and macOS 10.12 |
Security and privacy: |
|||
|
If disabled, the system prevents the user from modifying Touch ID or Face ID |
Yes |
iOS 8.3, iPadOS 13.1 and macOS 14 |
Apple Education |
|||
If true, automatically gives permission to the teacher's requests without prompting the student. |
If Enabled, the system automatically gives permission to the teacher’s requests without prompting the student. |
Yes |
iOS 11, iPadOS 13.1 and macOS 10.14.4 |
|
If enabled, a student enrolled in an unmanaged course through Classroom needs to request permission from the teacher to leave the course. |
Yes |
iOS 11.3, iPadOS 13.1 and macOS 10.14.4 |
|
If enabled, the system allows the teacher to lock apps or the device without prompting the student. |
Yes |
iOS 11, iPadOS 13.1 and macOS 10.14.4 |
|
If enable and the setting for "ScreenObservationPermissionModificationAllowed" is also enabled in the Education payload, a student enrolled in a managed course through the Classroom app automatically gives permission to that course teacher’s requests to observe the student’s screen without prompting the student. |
Yes |
iOS 11, iPadOS 13.1 and macOS 10.14.4 |
Apple MDM Restrictions for tvOS Devices
Apple Restrictions - tvOS
Setting |
Functionality |
Supervised Enrollment Required? |
Minimum Supported OS |
Device Functionality: |
|||
|
If disabled, users can’t use the Apple TV Remote app to control the Apple TV. |
Yes |
tvOS 10.2 |
Ratings region |
|||
|
This feature can not be disabled and the default by Apple is the United States.
|
No |
N/A |
Allowed Content Ratings |
|||
|
|
No |
iOS 5 or iPadOS 13.1 and tvOS 11.3 |
|
|
No |
iOS 5 or iPadOS 13.1 and tvOS 11.3 |
|
|
No |
iOS 5 or iPadOS 13.1 and tvOS 11.3 |
Software updates |
|||
|
If enabled, the system delays user visibility of software updates. In macOS, the system allows seed build updates without delay. The delay is 30 days unless you set another value under hid all software updates. |
Yes |
iOS 11.3 iPadOS 13.1, macOS 10.13.4 and tvOS 12.2 |
|
Allows admins to determine how many days to delay a software update on the device. With this restriction in place, the user doesn’t see a software update until the specified number of days after the software update release date Max # of days is 90 |
Yes |
iOS 11.3, iPadOS 13.1, macOS 10.13.4 and tvOS 12.2 |
Apple Supervised Restrictions - tvOS
Setting |
Functionality |
Supervised Enrollment |
Minimum Supported OS |
Applications: |
|||
|
If disabled, the system prevents the user from downloading Apple Books media that’s tagged as erotica. |
Yes |
iOS 4.0, iPadOS 13.1, macOS 15, and tvOS 17 |
Device Functionality: |
|||
|
If disabled, the system prevents the user from changing the device name. |
Yes |
iOS 9, iPadOS 13.1, macOS 14 and tvOS 11.0 |
The device name cannot be set from Dashboard if "Allow modification of device name" is disabled. |
When enabled, the system allows the dashboard to push the currently configured hostname in the dashboard to the device. |
Yes |
iOS 9, tvOS 10.2 and macOS 15.1 |
|
If enabled, the Set Automatically is turned on and users can’t turn it off. |
Yes |
tvOS 12.2 |
|
If disabled, the system disables requesting passwords from nearby devices. |
Yes |
iOS 12, iPadOS 13.1, macOS 10.14 and tvOS 12 |
|
If disabled, the system disables sharing passwords with the Airdrop Passwords feature. |
Yes |
iOS 12, iPadOS 13.1 and macOS 10.14 |
|
If disabled, the system prevents the device from automatically sleeping. Requires a supervised device. |
Yes |
tvOS 13 |
Content Ratings: |
|||
|
If disabled, the system hides explicit music or video content purchased from the iTunes Store. The system marks explicit content as such by content providers, such as record labels, when sold through the iTunes Store. Explicit content in the News and Podcast apps is also hidden. |
Yes |
iOS 4.0, iPadOS 13.1, macOS 15 and tvOS 11.3 |
Android MDM Restrictions
Cross-platform Restrictions
Setting |
Functionality |
Minimum Supported OS |
Camera: |
||
Supported on Samsung KNOX |
||
Device Functionality: |
||
|
Windows MDM Restrictions
Cross-platform Restrictions
Setting |
Functionality |
Minimum Supported OS |
Camera |
||
|
||
Device Functionality: |
||
|
Windows MDM Restrictions
Setting |
Functionality |
Minimum Supported OS |
Device Functionality: |
||
|
||
|
||
|