PayloadKit

Restrictions (iOS)

com.apple.applicationaccess

The payload that configures restrictions on a device.

iOS 4.0+macOS 10.7+tvOS 9.0+watchOS 10.0+visionOS 1.1+
Apple schemacombined
97 of 218 settings are available in the Intune Settings Catalog. Remaining settings require a custom .mobileconfig profile.

DDM recommended — 97 of 218 settings support Declarative Device Management

Apple recommends DDM over legacy profiles. DDM declarations are autonomous — the device enforces them without server round-trips. In Intune, use Settings Catalog → Declarative Device Management to configure these settings.

Configuration Keys (219)

KeyTypeTitleDDM
PFC_SegmentedControl_0required
string—
allowCamera

iOS · macOS 10.11+ · tvOS 17.0+ · visionOS 2.0+ · not on watchOS

If 'false', the system disables the camera and removes its icon from the Home Screen, and users are unable to take photographs. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow camera use
allowedCameraRestrictionBundleIDs

iOS 26.0+ · not on macOS, tvOS, watchOS, visionOS

If present, the system exempts apps with bundle IDs in the array from the 'allowCamera' restriction. The system doesn't grant these apps access to the camera automatically; they're only exempted from the 'allowCamera' restriction. This key has no effect when the camera isn't restricted. Multiple payloads combine using an intersect operation. Requires a supervised device.

arrayAllowed exceptions to camera restriction
bundleIDException
stringBundle ID to be excepted
allowVideoConferencing

iOS · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', the system hides the FaceTime app. Requires a supervised device in iOS 13 and later.

Default: true

booleanAllow video conferencing
allowCloudBackup

iOS 5.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', the system disables backing up the device to iCloud. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow iCloud backup
allowCloudPhotoLibrary

iOS 9.0+ · macOS 10.12+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system disables iCloud Photo Library. The system removes any photos from local storage that aren't fully downloaded from iCloud Photo Library to the device. Support for this restriction on unsupervised devices and with Managed Apple Accounts is deprecated.

Default: true

booleanAllow iCloud photo library
allowPhotoStreamdeprecated

iOS 5.0+ · deprecated 17.0 · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables Photo Stream.

Default: true

booleanAllow Photo Stream
allowSharedStream

iOS 6.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables Shared Photo Stream. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow shared stream
allowPasswordAutoFill

iOS 12.0+ · macOS 10.14+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system disables: The AutoFill Passwords feature in iOS, with Keychain and third-party password managers Prompting the user to use a saved password in Safari or in apps Automatic strong passwords Suggesting strong passwords to users However, if 'false', the system doesn't prevent AutoFill for contact info and credit cards in Safari.

Default: true

booleanAllow password AutoFill
allowAutoUnlock

iOS 14.5+ · macOS 10.12+ · not on tvOS, watchOS, visionOS

If 'false', the system disallows auto unlock. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow Apple Watch to auto unlock device
allowFingerprintForUnlock

iOS 7.0+ · macOS 10.12.4+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system prevents Touch ID, Face ID, or Optic ID from unlocking a device. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow Touch ID to unlock device
allowBookstore

iOS 6.0+ · macOS 15.0+ · not on tvOS, watchOS, visionOS

If 'false', the system removes the Book Store tab from the Books app.

Default: true

booleanAllow Book Store
allowChat

iOS 5.0+ · visionOS 27.0+ · not on macOS, tvOS, watchOS

If 'false', the system disables the use of iMessage with supervised devices. If the device supports text messaging, the user can still send and receive text messages.

Default: true

booleanAllow use of iMessage
allowiTunes

iOS · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables the iTunes Music Store and removes its icon from the Home Screen. Users can't preview, purchase, or download content. Requires a supervised device in iOS 13 and later.

Default: true

booleanAllow use of iTunes
allowMusicService

iOS 9.3+ · macOS 10.12+ · not on tvOS, watchOS, visionOS

If 'false', the system disables the Music service, and the Music app reverts to classic mode.

Default: true

booleanAllow Apple Music
allowNews

iOS 9.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables News.

Default: true

booleanAllow use of News
allowPodcasts

iOS 8.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables podcasts.

Default: true

booleanAllow Podcasts
allowRadioService

iOS 9.3+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables Apple Music Radio.

Default: true

booleanAllow iTunes radio
allowYouTube

This key is ignored on iOS 6 and later because the YouTube app is no longer built in.

Default: true

booleanAllow Apple's YouTube
allowAppsToBeHidden

iOS 18.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', disables the ability for the user to hide apps. It doesn't affect the user's ability to leave it in the App Library, while removing it from the Home Screen.

Default: true

booleanAllow hiding apps
allowAppsToBeLocked

iOS 18.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', disables the ability for the user to lock apps. Because hiding apps also requires locking them, disallowing locking also disallows hiding.

Default: true

booleanAllow locking apps
allowCloudDocumentSync

iOS 5.0+ · macOS 10.11+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system disables document and key-value syncing to iCloud. Requires a supervised device in iOS 13 and later, and Shared iPad doesn't support it. Support for this restriction on unsupervised devices and with Managed Apple Accounts is deprecated.

Default: true

booleanAllow iCloud document sync
allowCloudKeychainSync

iOS 7.0+ · macOS 10.12+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system disables iCloud Keychain synchronization. Support for this restriction on unsupervised devices and with Managed Apple Accounts is deprecated.

Default: true

booleanAllow iCloud Keychain
allowDefinitionLookupdeprecated

iOS 8.1.3+ · deprecated 26.4 · macOS 10.11+ · deprecated 26.4 · not on tvOS, watchOS, visionOS

If 'false', the system disables definition lookup. Deprecated: use the declarative management 'com.apple.configuration.keyboard.settings' configuration.

Default: true

booleanAllow definition lookup
allowDeprecatedWebKitTLS

Allow websites that use TLS 1.0 and TLS 1.1 to be accessed using Safari.

Default: false

booleanAllow accessing websites using TLS 1.0 and 1.1
allowAirPrint

iOS 11.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables AirPrint.

Default: true

booleanAllow AirPrint
allowAirPrintiBeaconDiscovery

iOS 11.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables iBeacon discovery of AirPrint printers, which prevents spurious AirPrint Bluetooth beacons from phishing for network traffic.

Default: true

booleanAllow discovery of AirPrint printers using iBeacons
forceAirPrintTrustedTLSRequirement

iOS 11.0+ · not on macOS, tvOS, watchOS, visionOS

If 'true', the system requires trusted certificates for TLS printing communication.

Default: false

booleanDisallow AirPrint to destinations with untrusted certificates
allowScreenShot

iOS 3.1+ · macOS 10.14.4+ · visionOS 2.0+ · not on tvOS

If 'false', the system disables saving a screenshot of the display and capturing a screen recording. It also disables the Classroom app from observing remote screens.

Default: true

booleanAllow screenshots and screen recording
allowRemoteScreenObservation

iOS 9.3+ · macOS 10.14.4+ · not on tvOS, watchOS, visionOS

If 'false', the system disables remote screen observation by the Classroom app. Nest this key beneath 'allowScreenShot' as a subrestriction. If 'allowScreenShot' is 'false', the Classroom app doesn't observe remote screens. Requires a supervised device until iOS 13 and macOS 10.15. Allowed for user enrollments in macOS 12 and later.

Default: true

booleanAllow remote screen observation
forceClassroomUnpromptedScreenObservation

iOS 11.0+ · macOS 10.14.4+ · not on tvOS, watchOS, visionOS

If 'true' and 'ScreenObservationPermissionModificationAllowed' is also 'true' in the Education payload, a student enrolled in a managed course through the Classroom app automatically gives permission to that course teacher's requests to observe the student's screen without prompting the student.

Default: false

booleanAllow Classroom app to perform AirPlay and View Screen without prompting
forceUnpromptedManagedClassroomScreenObservation

Deprecated in iOS 11. Use forceClassroomUnpromptedScreenObservation instead.

Default: false

boolean—
allowVoiceDialingdeprecated

iOS · deprecated 17.0 · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables voice dialing if the device is locked with a passcode.

Default: true

booleanAllow voice dialing while device is locked
allowAssistantdeprecated

iOS 5.0+ · deprecated 26.4 · macOS 14.0+ · deprecated 26.4 · visionOS 2.0+ · deprecated 26.4 · not on tvOS, watchOS

If 'false', the system disables Siri. Deprecated: use the declarative management 'com.apple.configuration.siri.settings' configuration.

Default: true

booleanAllow Siri
allowAssistantWhileLockeddeprecated

iOS 5.1+ · deprecated 26.4 · watchOS · deprecated 26.4 · not on macOS, tvOS, visionOS

If 'false', the system disables Siri when the device is locked. The system ignores this restriction if the device doesn't have a passcode set. Deprecated: use the declarative management 'com.apple.configuration.siri.settings' configuration.

Default: true

booleanAllow Siri while locked
forceAssistantProfanityFilterdeprecated

iOS 5.0+ · deprecated 26.4 · macOS 10.13+ · deprecated 26.4 · not on tvOS, watchOS, visionOS

If 'true', the system forces the use of the profanity filter for Siri and dictation. Requires a supervised device in iOS. Deprecated: use the declarative management 'com.apple.configuration.siri.settings' configuration.

Default: false

booleanEnable Siri profanity filter
allowAssistantUserGeneratedContentdeprecated

iOS 7.0+ · deprecated 26.4 · watchOS · deprecated 26.4 · not on macOS, tvOS, visionOS

If 'false', the system prevents Siri from querying user-generated content from the web. Deprecated: use the declarative management 'com.apple.configuration.siri.settings' configuration.

Default: true

booleanShow user-generated content in Siri
allowSiriServerLogging

Allow server-side logging of Siri commands

Default: true

booleanAllow server-side logging of Siri commands
allowSpotlightInternetResults

iOS 8.0+ · macOS 10.11+ · not on tvOS, watchOS, visionOS

If 'false', the system disables Spotlight Internet search results in Siri Suggestions. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow Siri suggestions
allowAppInstallation

iOS · watchOS · visionOS 2.0+ · not on macOS, tvOS

If 'false', the system disables the App Store and removes its icon from the Home Screen. Users are unable to install or update their apps. This applies to App Store apps, marketplace apps, and locally installed apps (using Configurator, Xcode, and so forth). In iOS 10 and later, MDM commands can override this restriction. Requires a supervised device in iOS 13 and later.

Default: true

booleanAllow app installation
allowUIAppInstallation

iOS 9.0+ · watchOS · visionOS 2.0+ · not on macOS, tvOS

If 'false', the system disables the App Store and removes its icon from the Home Screen. However, users can continue to install or update their apps either locally (via Configurator, Xcode, and so forth), or using alternative marketplace apps. In iOS 10 and later, MDM commands can override this restriction.

Default: true

booleanAllow app installation from app store
allowAutomaticAppDownloads

iOS 9.0+ · watchOS · not on macOS, tvOS, visionOS

If 'false', the system prevents automatic downloading of apps purchased on other devices. This setting doesn't affect updates to existing apps.

Default: true

booleanAllow automatic app downloads
allowMarketplaceAppInstallation

iOS 17.4+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system prevents installation of alternative marketplace apps from the web and prevents any installed alternative marketplace apps from installing apps.

Default: true

booleanAllow app installation from alternative marketplaces
allowWebDistributionAppInstallation

iOS 17.5+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the device prevents installation of apps directly from the web.

Default: true

booleanAllow app installation from web sites
allowAppRemoval

iOS 4.2.1+ · watchOS · not on macOS, tvOS, visionOS

If 'false', the system disables removal of apps from an iOS device. This applies to App Store apps, marketplace apps, and locally installed apps (using Configurator, Xcode, and so forth).

Default: true

booleanAllow app removal
allowAppClips

iOS 14.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system prevents a user from adding any App Clips, and removes any existing App Clips on the device.

Default: true

booleanAllow App Clips
allowSystemAppRemoval

iOS 11.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', the system disables the removal of system apps from the device.

Default: true

booleanAllow removing system apps
allowInAppPurchases

iOS · not on macOS, tvOS, watchOS, visionOS

If 'false', the system prohibits in-app purchasing. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow in app purchases
forceITunesStorePasswordEntrydeprecated

iOS 6.0+ · deprecated 17.0 · not on macOS, tvOS, watchOS, visionOS

If 'true', the system forces the user to enter their iTunes password for each transaction.

Default: false

booleanRequire iTunes password for all purchases
allowManagedAppsCloudSync

iOS 8.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', the system prevents managed apps from using iCloud sync.

Default: true

booleanAllow iCloud sync for managed apps
allowEnterpriseBookBackup

iOS 8.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables backup of Enterprise books.

Default: true

booleanAllow enterprise books backup
allowEnterpriseBookMetadataSync

iOS 8.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables sync of Enterprise books, notes, and highlights.

Default: true

booleanAllow enterprise books notes and highlights sync
allowCloudPrivateRelay

iOS 15.0+ · macOS 12.0+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system disables iCloud Private Relay. Support for this restriction on unsupervised devices and with Managed Apple Accounts is deprecated.

Default: true

booleanAllow iCloud Private Relay
allowGlobalBackgroundFetchWhenRoaming

iOS · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables global background fetch activity when an iOS phone is roaming. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow automatic sync while roaming
forceEncryptedBackup

not on macOS, tvOS, watchOS, visionOS

If 'true', the system encrypts all backups.

Default: false

booleanForce encrypted backups
allowEraseContentAndSettings

iOS 8.0+ · macOS 12.0+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system disables the Erase All Content and Settings option in the Reset UI.

Default: true

booleanAllow erase all content and settings
forcePreserveESIMOnErase

iOS 17.2+ · not on macOS, tvOS, watchOS, visionOS

If 'true', the system preserves eSIM when it erases the device due to too many failed password attempts or the Erase All Content and Settings option in Settings > General > Reset. Note: The system doesn't preserve eSIM if Find My initiates erasing the device.

Default: false

booleanForce preserve ESIM on erase
allowUntrustedTLSPrompt

iOS 5.0+ · visionOS 1.1+ · not on macOS, tvOS, watchOS

If 'false', the system automatically rejects untrusted HTTPS certificates without prompting the user.

Default: true

booleanAllow user to accept untrusted TLS certificates
allowEnterpriseAppTrust

iOS 9.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', the system removes the Trust Enterprise Developer button in Settings > General > VPN & Device Management, which prevents provisioning apps by universal provisioning profiles. This restriction applies to free developer accounts and enterprise app developers that aren't implicitly trusted by apps that install through MDM. This restriction doesn't revoke previously granted trust.

Default: true

booleanAllow trusting enterprise apps
allowOTAPKIUpdates

iOS 7.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables over-the-air PKI updates. Setting this restriction to 'false' doesn't disable CRL and OCSP checks.

Default: true

booleanAllow automatic updates to certificate trust settings
allowUIConfigurationProfileInstallation

iOS 6.0+ · macOS 13.0+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system prohibits the user from installing configuration profiles and certificates interactively.

Default: true

booleanAllow UI configuration profile installation
allowVPNCreation

iOS 11.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', the system allows only managed apps to create VPN configurations. Prior to iOS 18, the system also allows unmanaged apps to create VPN configurations.

Default: true

booleanAllow adding VPN configurations (supervised devices only)
forceAutomaticDateAndTime

iOS 12.0+ · tvOS 12.2+ · visionOS 2.0+ · not on macOS, watchOS

If 'true', the system enables the Set Automatically feature in Date & Time and the user can't disable it. The system updates the device's time zone only when the device can determine its location using a cellular connection or Wi-Fi with location services enabled.

Default: false

booleanForce automatic date and time
forceClassroomUnpromptedAppAndDeviceLock

iOS 11.0+ · macOS 10.14.4+ · not on tvOS, watchOS, visionOS

If 'true', the system allows the teacher to lock apps or the device without prompting the student.

Default: false

booleanAllow Classroom to lock apps or the device without prompting
forceClassroomAutomaticallyJoinClasses

iOS 11.0+ · macOS 10.14.4+ · not on tvOS, watchOS, visionOS

If 'true', the system automatically gives permission to the teacher's requests without prompting the student.

Default: false

booleanAutomatically join Classroom classes without prompting
forceClassroomRequestPermissionToLeaveClasses

iOS 11.3+ · macOS 10.14.4+ · not on tvOS, watchOS, visionOS

If 'true', a student enrolled in an unmanaged course through Classroom needs to request permission from the teacher to leave the course.

Default: false

booleanRequire teacher permission to leave Classroom app unmanaged classes
allowAccountModification

iOS 7.0+ · macOS 14.0+ · watchOS · visionOS 2.0+ · not on tvOS

If 'false', the system disables modification of accounts, such as Apple Accounts, and internet-based accounts, such as Mail, Contacts, and Calendar.

Default: true

booleanAllow modifying account settings
allowBluetoothModification

iOS 11.0+ · macOS 13.0+ · visionOS 27.0+ · not on tvOS, watchOS

If 'false', the system prevents modification of Bluetooth settings.

Default: true

booleanAllow modifying Bluetooth settings
allowAppCellularDataModification

iOS 7.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables changing settings for cellular data usage for apps.

Default: true

booleanAllow modifying cellular data usage for apps settings
allowCellularPlanModification

iOS 11.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system prevents users from changing settings related to their cellular plan (available only on select carriers).

Default: true

booleanAllow modifying celluar plan settings
allowESIMModification

iOS 12.1+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables modifications of eSIMs. This also disables the phone number sharing setup on iPhones, in iOS 27 and later.

Default: true

booleanAllow eSIM modification
allowFindMyFriendsModification

iOS 7.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables changes to Find My Friends.

Default: true

booleanAllow modifying Find My Friends settings
allowNotificationsModification

iOS 9.3+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', the system disables modification of notification settings.

Default: true

booleanAllow modifying notifications settings
allowNFC

iOS 14.2+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables NFC.

Default: true

booleanAllow NFC
allowPasscodeModification

iOS 9.0+ · macOS 10.13+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system prevents adding, changing, or removing the passcode. The system ignores this restriction on Shared iPad.

Default: true

booleanAllow modifying passcode
allowFingerprintModification

iOS 8.3+ · macOS 14.0+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system prevents the user from modifying Touch ID or Face ID.

Default: true

booleanAllow modifying Touch ID / Face ID
allowEnablingRestrictions

iOS 8.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', the system disables the Enable Restrictions option in the Restrictions UI in Settings. If 'false' in iOS 12 and later, the system disables the Enable ScreenTime option in the ScreenTime UI in Settings and disables ScreenTime if already enabled.

Default: true

booleanAllow configuring restrictions or ScreenTime
allowWallpaperModification

iOS 9.0+ · macOS 10.13+ · not on tvOS, watchOS, visionOS

If 'false', the system prevents changing the wallpaper.

Default: true

booleanAllow modifying wallpaper
allowUSBRestrictedMode

iOS 11.4.1+ · macOS 13.0+ · not on tvOS, watchOS, visionOS

If 'false', the system allows iOS devices to always connect to USB accessories while locked. In macOS, allows new USB and Thunderbolt accessories, and SD cards to connect without authorization. If the system has Lockdown mode enabled, it ignores this value. This restriction isn't supported on the user channel.

Default: true

booleanAllow USB Restricted Mode
allowHostPairing

iOS 7.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables host pairing with the exception of the supervision host. If there's no configured supervision host certificate, the system disables all pairing. Host pairing lets the administrator control whether an iOS device can pair with a host Mac or PC.

Default: true

booleanAllow pairing with non-Configurator hosts
allowiPhoneWidgetsOnMac

iOS 17.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disallows iPhone widgets on a Mac that signs in with the same Apple Account for iCloud.

Default: true

booleanAllow iPhone widget on Mac
allowUnpairedExternalBootToRecovery

iOS 14.5+ · not on macOS, tvOS, watchOS, visionOS

If 'true', the system allows unpaired devices to boot devices into recovery.

Default: false

booleanAllow booting into recovery by unpaired devices
allowOpenFromManagedToUnmanaged

iOS 7.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', documents in managed apps and accounts open only in other managed apps and accounts.

Default: true

booleanEnable allow open from managed to unmanaged
allowOpenFromUnmanagedToManaged

iOS 7.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', documents in unmanaged apps and accounts open only in other unmanaged apps and accounts.

Default: true

booleanEnable allow open from unmanaged to managed
allowUnmanagedToReadManagedContacts

iOS 12.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'true', the system allows unmanaged apps to read from managed contacts accounts. If 'allowOpenFromManagedToUnmanaged' is 'true', this restriction has no effect. Important: Use MDM to install profiles that contain this restriction.

Default: false

booleanAllow unmanaged apps to read managed contacts accounts
allowManagedToWriteUnmanagedContacts

iOS 12.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'true', the system allows managed apps to write contacts to unmanaged accounts. If 'allowOpenFromManagedToUnmanaged' is 'true', this restriction has no effect. Important: Use MDM to install profiles that contain this restriction.

Default: false

booleanAllow managed apps to write to managed contacts accounts
requireManagedPasteboard

iOS 15.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'true', the 'allowOpenFromManagedToUnmanaged' and 'allowOpenFromUnmanagedToManaged' restrictions also limit copy-and-paste functionality.

Default: false

booleanRequire managed pasteboard
allowAirDrop

iOS 7.0+ · macOS 10.13+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system disables AirDrop.

Default: true

booleanAllow AirDrop
forceAirDropUnmanaged

iOS 9.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'true', the system considers AirDrop to be an unmanaged drop target.

Default: false

booleanTreat AirDrop as unmanaged destination
allowActivityContinuation

iOS 8.0+ · macOS 10.15+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system disables activity continuation. Support for this restriction on unsupervised devices and with Managed Apple Accounts is deprecated. In a future release, this restriction will begin requiring supervision and will apply to personal Apple Accounts only.

Default: true

booleanAllow handoff
allowDiagnosticSubmission

iOS 6.0+ · macOS 10.13+ · visionOS 2.0+ · not on tvOS

If 'false', the system prevents the device from automatically submitting diagnostic reports to Apple.

Default: true

booleanAllow diagnostic submission
allowDiagnosticSubmissionModification

iOS 9.3.2+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', the system disables changing the diagnostic submission and app analytics settings in the Diagnostics & Usage UI in Settings.

Default: true

booleanAllow modifying diagnostics settings
forceAuthenticationBeforeAutoFill

iOS 11.0+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'true', the user needs to authenticate before the system can autofill passwords or credit card information in Safari and apps. If this restriction isn't enforced, the user can toggle this feature in Settings. Only supported on devices with Face ID or Touch ID.

Default: false

booleanRequire Touch ID / Face ID authentication before Autofill
allowPairedWatch

iOS 9.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables pairing with an Apple Watch, and the system unpairs any currently paired Apple Watch and erases its content.

Default: true

booleanAllow pairing with Apple Watch
forceWatchWristDetection

iOS 8.2+ · not on macOS, tvOS, visionOS

If 'true', the system forces a paired Apple Watch to use Wrist Detection.

Default: false

booleanForce Apple Watch wrist detection
forceWiFiPowerOn

iOS 13.0+ · not on macOS, tvOS, watchOS, visionOS

If 'true', the system prevents turning off Wi-Fi in Settings or Control Center, even by entering or leaving Airplane Mode. It doesn't prevent selecting which Wi-Fi network to use. and later.

Default: false

booleanDisallow Wi-Fi from being turned off
forceWiFiToAllowedNetworksOnly

iOS 14.5+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'true', the system limits the device to only join Wi-Fi networks set up through a configuration profile.

Default: false

booleanJoin only Wi-Fi networks installed by a Wi-Fi payload
forceWiFiWhitelistingdeprecated

iOS 10.3+ · deprecated 14.5 · not on macOS, tvOS, watchOS, visionOS

Use 'forceWiFiToAllowedNetworksOnly' instead.

Default: false

booleanOnly join Wi-Fi networks installed by profiles
allowProximitySetupToNewDevice

iOS 11.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', disables the prompt to set up new devices that are nearby. Starting with iOS 26.3, this also prevents exporting iOS data to set up new Android devices.

Default: true

booleanAllow setting up new nearby iOS devices
allowPredictiveKeyboarddeprecated

iOS 8.1.3+ · deprecated 26.4 · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables predictive keyboards. Deprecated: use the declarative management 'com.apple.configuration.keyboard.settings' configuration.

Default: true

booleanAllow predictive keyboard
allowKeyboardShortcutsdeprecated

iOS 9.0+ · deprecated 26.4 · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables keyboard shortcuts. Deprecated: use the declarative management 'com.apple.configuration.keyboard.settings' configuration.

Default: true

booleanAllow keyboard shortcuts
allowAutoCorrectiondeprecated

iOS 8.1.3+ · deprecated 26.4 · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables keyboard autocorrection. Deprecated: use the declarative management 'com.apple.configuration.keyboard.settings' configuration.

Default: true

booleanAllow auto correction
allowContinuousPathKeyboarddeprecated

iOS 13.0+ · deprecated 26.4 · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables QuickPath keyboard. Deprecated: use the declarative management 'com.apple.configuration.keyboard.settings' configuration.

Default: true

booleanAllow continuous path keyboard
allowSpellCheckdeprecated

iOS 8.1.3+ · deprecated 26.4 · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables the keyboard spell checker. Deprecated: use the declarative management 'com.apple.configuration.keyboard.settings' configuration.

Default: true

booleanAllow spell check
allowSharedDeviceTemporarySession

iOS 13.4+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system makes temporary sessions unavailable on Shared iPad.

Default: true

booleanAllow Shared iPad temporary session
allowDictationdeprecated

iOS 10.3+ · deprecated 26.4 · macOS 10.13+ · deprecated 26.4 · not on tvOS, watchOS, visionOS

If 'false', the system disallows dictation input. Deprecated: use the declarative management 'com.apple.configuration.keyboard.settings' configuration.

Default: true

booleanAllow dictation
forceOnDeviceOnlyDictationdeprecated

iOS 14.5+ · deprecated 26.4 · macOS 14.0+ · deprecated 26.4 · watchOS · deprecated 26.4 · visionOS 2.0+ · deprecated 26.4 · not on tvOS

If 'true', the system disables connections to Siri servers for the purposes of dictation. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: false

booleanForce on-device only dictation
forceOnDeviceOnlyTranslationdeprecated

iOS 15.0+ · deprecated 26.4 · watchOS · deprecated 26.4 · not on macOS, tvOS, visionOS

If 'true', the device can't connect to Siri servers for the purposes of translation. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: false

booleanForce on-device only translation
allowPassbookWhileLocked

iOS 6.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system hides Passbook notifications from the Lock Screen.

Default: true

booleanAllow Wallet while locked
allowPersonalHotspotModification

iOS 12.2+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables modifications of the personal hotspot setting.

Default: true

booleanAllow modifying personal hotspot settings
allowLiveVoicemail

iOS 17.2+ · macOS 26.0+ · not on tvOS, watchOS, visionOS

If 'false', the system disables live voicemail on the device.

Default: true

booleanAllow live voicemail
allowLockScreenControlCenter

iOS 7.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system prevents Control Center from appearing on the Lock Screen.

Default: true

booleanShow Control Center on Lock screen
allowLockScreenNotificationsView

iOS 7.0+ · not on macOS, tvOS, visionOS

If 'false', the system disables the Notifications history view on the Lock Screen, so users can't view past notifications. However, they can still see notifications when they arrive.

Default: true

booleanShow Notification Center on Lock screen
allowLockScreenTodayView

iOS 7.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables the Today view in Notification Center on the Lock Screen.

Default: true

booleanShow Today view on Lock screen
forceAirPlayOutgoingRequestsPairingPassword

iOS 7.1+ · not on macOS, tvOS, watchOS, visionOS

If 'true', the system forces all devices receiving AirPlay requests from this device to use a pairing password.

Default: false

booleanRequire passcode on first AirPlay pairing
allowAirPrintCredentialsStorage

iOS 11.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables Keychain storage of user name and password for AirPrint.

Default: true

booleanAllow storage of AirPrint credentials in keychain
forceLimitAdTracking

iOS 7.0+ · not on macOS, tvOS, watchOS, visionOS

If 'true', the system limits ad tracking. Additionally, it disables app tracking and the Allow Apps to Request to Track setting.

Default: false

booleanForce limited ad tracking
allowApplePersonalizedAdvertising

iOS 14.0+ · macOS 12.0+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system limits Apple personalized advertising.

Default: true

booleanAllow Apple-personalized advertizing
allowMailPrivacyProtection

iOS 15.2+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables Mail Privacy Protection on the device.

Default: true

booleanAllow mail privacy protection
allowAutoDim

iOS 17.4+ · not on macOS, tvOS, watchOS, visionOS

If 'false', disables auto dim on iPads with OLED displays.

Default: true

booleanAllow auto dim
allowGameCenter

iOS 6.0+ · macOS 10.13+ · not on tvOS, watchOS, visionOS

If 'false', the system disables Game Center, and the system removes its icon from the Home Screen.

Default: true

booleanAllow Game Center
allowAddingGameCenterFriends

iOS 4.2.1+ · macOS 10.13+ · not on tvOS, watchOS, visionOS

If 'false', the system prohibits adding friends to Game Center. Requires a supervised device in iOS 13 and later.

Default: true

booleanAllow adding Game Center friends
allowMultiplayerGaming

iOS 4.1+ · macOS 10.13+ · not on tvOS, watchOS, visionOS

If 'false', the system prohibits multiplayer gaming.

Default: true

booleanAllow multiplayer gaming
allowSafari

iOS · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables the Safari web browser app, and the system removes its icon from the Home Screen. This setting also prevents users from opening web clips. Requires a supervised device in iOS 13 and later.

Default: true

booleanAllow use of Safari
safariAllowAutoFill

iOS · macOS 10.13+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system disables Safari AutoFill for passwords, contact info, and credit cards, and also prevents using the Keychain for AutoFill. Requires a supervised device in iOS 13 and later. Note: The system still allows third-party password managers, and apps can use AutoFill.

Default: true

booleanAllow AutoFill in Safari
safariForceFraudWarning

not on macOS, tvOS, watchOS, visionOS

If 'true', the system enables Safari fraud warning.

Default: false

booleanEnable fraud warning
safariAllowJavaScript

iOS · not on macOS, tvOS, watchOS, visionOS

If 'false', Safari doesn't execute JavaScript. This restriction will require supervision in a future release.

Default: true

booleanAllow JavaScript
safariAllowPopups

iOS · not on macOS, tvOS, watchOS, visionOS

If 'false', Safari doesn't allow pop-up windows. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow pop-ups
safariAcceptCookies

iOS · not on macOS, tvOS, watchOS, visionOS

Defines the conditions under which the device accepts cookies. The user-facing settings changed in iOS 11, although the possible values remain the same. Support for this restriction on unsupervised devices is deprecated. Allowed values: '0': Enables Prevent Cross-Site Tracking and Block All Cookies, and the user canʼt disable either setting. '1' or '1.5': Enables Prevent Cross-Site Tracking, and the user canʼt disable it. Doesn't enable Block All Cookies, but the user can enable it. '2': Enables Prevent Cross-Site Tracking, but doesn't enable Block All Cookies. The user can toggle either setting.

Default: 2

Range: Never / Prevent Cross-Site Tracking & Block All Cookies (User Restricted) (0), Allow from current website only / Prevent Cross-Site Tracking (User Restricted) (1), Allow from websites visited (iOS 10 & earlier) (1.5), Always / Prevent Cross-Site Tracking (2)

realAccept cookies in Safari
allowDeviceNameModification

iOS 9.0+ · macOS 14.0+ · tvOS 11.0+ · visionOS 2.0+ · not on watchOS

If 'false', the system prevents the user from changing the device name.

Default: true

booleanAllow modifying device name
blockedAppBundleIDsdeprecated

iOS 15.0+ · deprecated 27.0 · tvOS 15.0+ · deprecated 27.0 · visionOS 27.0+ · deprecated 27.0 · not on macOS, watchOS

If present, the system prevents showing or launching apps with bundle IDs in the array. Include the value 'com.apple.webapp' to restrict all webclips. This applies to App Store apps, marketplace apps, and locally installed apps (using Configurator, Xcode, and so forth). Deprecated: use the declarative management 'com.apple.configuration.app.settings' configuration. Note: Denying system apps may disable other functionality. For example, denying the App Store app may prevent users from accepting the terms and conditions for the user-based Volume Purchase Program (VPP).

arrayBlocked apps
appBlockedBundleID
stringBundle ID
blacklistedAppBundleIDsdeprecated

iOS 9.3+ · deprecated 15.0 · tvOS 11.0+ · deprecated 15.0 · not on macOS, watchOS, visionOS

Deprecated: use the declarative management 'com.apple.configuration.app.settings' configuration.

arrayRestrict App Usage - Denylist
appBlacklistedBundleID
stringiOS / tvOS Bundle ID
allowListedAppBundleIDsdeprecated

iOS 15.0+ · deprecated 27.0 · tvOS 15.0+ · deprecated 27.0 · visionOS 27.0+ · deprecated 27.0 · not on macOS, watchOS

If present, the system only shows or can launch apps with bundle IDs in the array. Include the value 'com.apple.webapp' to allow all webclips. This applies to App Store apps, marketplace apps, and locally installed apps (using Configurator, Xcode, and so forth). Deprecated: use the declarative management 'com.apple.configuration.app.settings' configuration.

arrayAllow listed apps
appAllowlistedBundleID
stringBundle ID
whitelistedAppBundleIDsdeprecated

iOS 9.3+ · deprecated 15.0 · tvOS 11.0+ · deprecated 15.0 · not on macOS, watchOS, visionOS

Deprecated: use the declarative management 'com.apple.configuration.app.settings' configuration.

arrayRestrict App Usage - Allowlist
appWhitelistedBundleID
stringiOS / tvOS Bundle ID
autonomousSingleAppModePermittedAppIDs

iOS 7.0+ · not on macOS, tvOS, watchOS, visionOS

If present, the system allows apps identified by the bundle IDs listed in the array to autonomously enter Single App Mode.

arrayAutonomous Single App Mode Permitted App IDs
appAutonomousSingleAppModePermittedID
stringApps allow list for autonomous single app mode
ratingRegion

not on watchOS, visionOS

The two-letter key that profile tools use to display the proper ratings for the given region. The client doesn't recognize or report this data.

Default: "us"

Range: United States (us), Australia (au), Canada (ca), Germany (de), France (fr), Ireland (ie), Japan (jp), New Zealand (nz), United Kingdom (gb)

stringRatings region
ratingApps

iOS · macOS 15.0+ · tvOS 11.3+ · not on watchOS, visionOS

The maximum level of app content allowed on the device. Starting with iOS 26.2, this rating may apply to certain system apps. Age bands and the number of discrete age values vary by region, but the values are consistent across regions. For example, in a region that defines rating level 14+, its value is guaranteed to be larger than 300 (12+) and smaller than 600 (17+). Also, the value of rating level 15+ is guaranteed to be larger than the assigned value of rating level 14+. For more information about age ratings, see Age ratings values and definitions (https://developer.apple.com/help/app-store-connect/reference/age-ratings-values-and-definitions). Below is the complete list of age rating values used across all App Store regions. '1000': All '621': 21+ '620': 20+ '619': 19+ '618': 18+ '600': 17+ '416': 16+ '415': 15+ '314': 14+ '313': 13+ '300': 12+ '211': 11+ '210': 10+ '200': 9+ '108': 8+ '107': 7+ '106': 6+ '105': 5+ '100': 4+ '3': 3+ '2': 2+ '1': 1+ '0': None This restriction will require supervision in a future release.

Default: 1000

Range: Allow All Apps (1000), 900 (900), 800 (800), 700 (700), 600 (600), 500 (500), 400 (400), 300 (300), 200 (200), 100 (100), Don't Allow Apps (0)

integerApps ranking number
ratingMovies

iOS · macOS 15.0+ · tvOS 11.3+ · not on watchOS, visionOS

The maximum level of movie content allowed on the device. Support for this restriction on unsupervised devices is deprecated. Possible values, with the U.S. description of the rating level: '1000': All '500': NC-17 '400': R '300': PG-13 '200': PG '100': G '0': None

Default: 1000

Range: Allow All Movies (1000), 900 (900), 800 (800), 700 (700), 600 (600), 500 (500), 400 (400), 300 (300), 200 (200), 100 (100), Don't Allow Movies (0)

integerMovies ranking number
ratingTVShows

iOS · macOS 15.0+ · tvOS 11.3+ · not on watchOS, visionOS

The maximum level of TV content allowed on the device. Support for this restriction on unsupervised devices is deprecated. Possible values, with the U.S. description of the rating level: '1000': All '600': TV-MA '500': TV-14 '400': TV-PG '300': TV-G '200': TV-Y7 '100': TV-Y '0': None

Default: 1000

Range: Allow All TV Shows (1000), 900 (900), 800 (800), 700 (700), 600 (600), 500 (500), 400 (400), 300 (300), 200 (200), 100 (100), Don't Allow TV Shows (0)

integerAllowed content ratings - TV Shows
allowExplicitContent

iOS · macOS 15.0+ · tvOS 11.3+ · not on watchOS, visionOS

If 'false', the system hides explicit music or video content purchased from the iTunes Store. The system marks explicit content as such by content providers, such as record labels, when sold through the iTunes Store. Explicit content in the News and Podcast apps is also hidden. Requires a supervised device in iOS 13 and later. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow explicit content
allowFilesUSBDriveAccess

iOS 13.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system prevents connecting to any connected USB devices in the Files app.

Default: true

booleanAllow Files USB Drive Access
allowBookstoreEroticadeprecated

iOS 6.0+ · macOS 15.0+ · tvOS 11.3+ · deprecated 17.0 · not on watchOS, visionOS

If 'false', the system prevents the user from downloading Apple Books media that's tagged as erotica. Support for this restriction on unsupervised devices is deprecated.

Default: true

booleanAllow Book Store erotica
allowPasswordSharing

iOS 12.0+ · macOS 10.14+ · visionOS 2.0+ · not on tvOS, watchOS

If 'false', the system disables sharing passwords with the AirDrop passwords feature, or with the Passwords app.

Default: true

booleanAllow password sharing
allowPasswordProximityRequestsdeprecated

iOS 12.0+ · macOS 10.14+ · tvOS 12.0+ · removed 26.4 · not on watchOS, visionOS

If 'false', the system disables requesting passwords from nearby devices.

Default: true

booleanAllow proximity based password sharing requests
forceDelayedSoftwareUpdatesdeprecated

iOS 11.3+ · removed 27.0 · macOS 10.13+ · removed 27.0 · tvOS 12.2+ · removed 27.0 · not on watchOS, visionOS

If 'true', the system delays user visibility of software updates. In macOS, the system allows seed build updates without delay. The delay is 30 days unless you set 'enforcedSoftwareUpdateDelay' to another value. Removed: use the declarative management 'com.apple.configuration.softwareupdate.settings' configuration.

Default: false

booleanDefer Software Updates
enforcedSoftwareUpdateDelaydeprecated

iOS 11.3+ · removed 27.0 · macOS 10.13.4+ · removed 27.0 · tvOS 12.2+ · removed 27.0 · not on watchOS, visionOS

How many days to delay a software update on the device. With this restriction in place, the user doesn't see a software update until the specified number of days after the software update release date. The restrictions 'forceDelayedAppSoftwareUpdates' and 'forceDelayedSoftwareUpdates' use this value. Removed: use the declarative management 'com.apple.configuration.softwareupdate.settings' configuration.

Default: 30

Range: 1 – 90

integerDeferred Software Updates Delay
allowRapidSecurityResponseInstallationdeprecated

iOS 16.0+ · removed 27.0 · macOS 13.0+ · removed 27.0 · not on tvOS, watchOS, visionOS

If 'false', the system prohibits installation of Background Security Improvements. Removed: use the declarative management 'com.apple.configuration.softwareupdate.settings' configuration.

Default: true

booleanAllow Background Security Improvements installation
allowRapidSecurityResponseRemovaldeprecated

iOS 16.0+ · removed 27.0 · macOS 13.0+ · removed 27.0 · not on tvOS, watchOS, visionOS

If 'false', the system prohibits removal of Background Security Improvements. Removed: use the declarative management 'com.apple.configuration.softwareupdate.settings' configuration.

Default: true

booleanAllow Background Security Improvements removal
allowFindMyDevice

iOS 13.0+ · macOS 10.15+ · not on tvOS, watchOS, visionOS

If 'false', the system disables Find My Device in the Find My app.

Default: true

booleanAllow Find My Devices
allowFindMyFriends

iOS 13.0+ · macOS 10.15+ · not on tvOS, watchOS, visionOS

If 'false', the system disables Find My Friends in the Find My app.

Default: true

booleanAllow Find My Friends
allowFilesNetworkDriveAccess

iOS 13.1+ · visionOS 2.0+ · not on macOS, tvOS, watchOS

If 'false', the system prevents connecting to network drives in the Files app.

Default: true

booleanAllow Files Network Drive Access
allowESIMOutgoingTransfers

iOS 18.0+ · not on macOS, tvOS, watchOS, visionOS

If 'false', prevents the transfer of an eSIM from the device on which the restriction is installed to a different device.

Default: true

booleanAllow eSIM outgoing transfers
allowGenmojideprecated

iOS 18.0+ · deprecated 26.4 · macOS 15.0+ · deprecated 26.4 · visionOS 2.4+ · deprecated 26.4 · not on tvOS, watchOS

If 'false', prohibits creating new Genmoji. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

booleanAllow Genmoji
allowImagePlaygrounddeprecated

iOS 18.0+ · deprecated 26.4 · macOS 15.0+ · deprecated 26.4 · visionOS 2.4+ · deprecated 26.4 · not on tvOS, watchOS

If 'false', prohibits the use of image generation. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

booleanAllow Image Playground
allowImageWanddeprecated

iOS 18.0+ · deprecated 26.4 · visionOS 2.4+ · deprecated 26.4 · not on macOS, tvOS, watchOS

If 'false', prohibits the use of Image Wand. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

booleanAllow Image Wand
allowiPhoneMirroring

iOS 18.0+ · macOS 15.0+ · not on tvOS, watchOS, visionOS

If 'false', prohibits the use of iPhone Mirroring. In macOS, this prevents the Mac from mirroring any iPhone. In iOS, this prevents the iPhone from mirroring to any Mac.

Default: true

booleanAllow iPhone mirroring
allowPersonalizedHandwritingResultsdeprecated

iOS 18.0+ · deprecated 26.4 · not on macOS, tvOS, watchOS, visionOS

If false, prevents the system from generating text in the user's handwriting. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

booleanAllow personalized handwriting results
allowWritingToolsdeprecated

iOS 18.0+ · deprecated 26.4 · macOS 15.0+ · deprecated 26.4 · visionOS 2.4+ · deprecated 26.4 · not on tvOS, watchOS

If 'false', disables Apple Intelligence writing tools. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

booleanAllow writing tools
allowCallRecording

iOS 18.1+ · macOS 26.0+ · not on tvOS, watchOS, visionOS

If 'false', disables call recording.

Default: true

booleanAllow call recording
allowMailSummarydeprecated

iOS 18.1+ · deprecated 26.4 · macOS 15.1+ · deprecated 26.4 · visionOS 2.4+ · deprecated 26.4 · not on tvOS, watchOS

If 'false', disables the ability to create summaries of email messages manually. This doesn't affect automatic summary generation. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

boolean—
allowMailSmartRepliesdeprecated

iOS 18.4+ · deprecated 26.4 · macOS 15.4+ · deprecated 26.4 · visionOS 2.4+ · deprecated 26.4 · not on tvOS, watchOS

If 'false', disables smart replies in Mail. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

boolean—
allowRCSMessaging

iOS 18.1+ · not on macOS, tvOS, watchOS, visionOS

If 'false', prevents the use of RCS messaging.

Default: true

boolean—
allowDefaultBrowserModification

iOS 18.2+ · not on macOS, tvOS, watchOS, visionOS

If 'false', disables default browser preference modification. The MDM Settings command to set the default browser preference still works when applying this.

Default: true

booleanAllow default browser modification
allowDefaultCallingAppModification

iOS 18.4+ · not on macOS, tvOS, watchOS, visionOS

If 'false', disables default calling app preference modification. The MDM Settings command to set the default calling app preference still works when applying this.

Default: true

booleanAllow default calling app modification
allowDefaultMessagingAppModification

iOS 18.4+ · not on macOS, tvOS, watchOS, visionOS

If 'false', disables default messaging app preference modification. The MDM Settings command to set the default messaging app preference still works when applying this.

Default: true

booleanAllow default messaging app modification
allowExternalIntelligenceIntegrationsdeprecated

iOS 18.2+ · deprecated 26.4 · macOS 15.2+ · deprecated 26.4 · visionOS 2.4+ · deprecated 26.4 · not on tvOS, watchOS

If 'false', disables the use of external, cloud-based intelligence services with Siri. In iOS, this restriction is temporarily allowed on unsupervised and user enrollments. In a future release, this restriction will require supervision, and will be ignored on unsupervised devices. Deprecated: use the declarative management 'com.apple.configuration.external-intelligence.settings' configuration.

Default: true

booleanAllow external intelligence integrations
allowExternalIntelligenceIntegrationsSignIndeprecated

iOS 18.2+ · deprecated 26.4 · macOS 15.2+ · deprecated 26.4 · visionOS 2.4+ · deprecated 26.4 · not on tvOS, watchOS

If 'false', forces external intelligence providers into anonymous mode. If a user is already signed in to an external intelligence provider, applying this restriction signs them out when attempting the next request. Deprecated: use the declarative management 'com.apple.configuration.external-intelligence.settings' configuration.

Default: true

booleanAllow external intelligence integrations sign-in
allowedExternalIntelligenceWorkspaceIDsdeprecated

iOS 18.3+ · deprecated 26.4 · macOS 15.3+ · deprecated 26.4 · visionOS 2.4+ · deprecated 26.4 · not on tvOS, watchOS

An array of strings, but currently restricted to a single element. If present, Apple Intelligence allows use of only the given external integration workspace ID, and requires a sign-in to make requests. The user is required to sign in to integrations that support signing in. Multiple payloads combine using an intersect operation. This means the allowed set of workspace IDs can become the empty set if multiple payloads specify conflicting values. Deprecated: use the declarative management 'com.apple.configuration.external-intelligence.settings' configuration.

arrayAllowed external intelligence workspace IDs
allowedWorkspaceID
stringAllowed workspace ID
allowNotesTranscriptionSummarydeprecated

iOS 18.3+ · deprecated 26.4 · macOS 15.3+ · deprecated 26.4 · not on tvOS, watchOS, visionOS

If 'false', disables transcription summarization in Notes. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

boolean—
allowNotesTranscriptiondeprecated

iOS 18.4+ · deprecated 26.4 · macOS 15.4+ · deprecated 26.4 · not on tvOS, watchOS, visionOS

If 'false', disables transcription in Notes. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

boolean—
allowVisualIntelligenceSummarydeprecated

iOS 18.3+ · deprecated 26.4 · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables visual intelligence summarization. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

booleanAllow visual intelligence summary
allowSatelliteConnection

iOS 18.2+ · not on macOS, tvOS, watchOS, visionOS

If 'false', the system prohibits the connection to and use of satellite services.

Default: true

booleanAllow use of satellite connectivity
allowAppleIntelligenceReportdeprecated

iOS 18.4+ · deprecated 26.4 · macOS 15.4+ · deprecated 26.4 · not on tvOS, watchOS, visionOS

If 'false', the system disables Apple Intelligence reports. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

booleanAllow Apple Intelligence report
allowSafariSummarydeprecated

iOS 18.4+ · deprecated 26.4 · macOS 15.4+ · deprecated 26.4 · visionOS 2.4+ · deprecated 26.4 · not on tvOS, watchOS

If 'false', the system disables the ability to summarize content in Safari. Deprecated: use the declarative management 'com.apple.configuration.intelligence.settings' configuration.

Default: true

boolean—
allowVideoConferencingRemoteControl

iOS 18.4+ · not on macOS, tvOS, watchOS, visionOS

If 'false', disables the ability for a remote FaceTime session to request control of the device.

Default: true

booleanAllow video conferencing remote control
allowSafariHistoryClearing

iOS 26.0+ · macOS 26.0+ · visionOS 26.0+ · not on tvOS, watchOS

If 'false', the system disables the ability to clear browsing history in Safari.

Default: true

boolean—
allowSafariPrivateBrowsing

iOS 26.0+ · macOS 26.0+ · visionOS 26.0+ · not on tvOS, watchOS

If 'false', the system disables the ability to use private browsing in Safari.

Default: true

boolean—
deniedICCIDsForiMessageFaceTime

iOS 26.0+ · not on macOS, tvOS, watchOS, visionOS

An array of strings representing ICCIDs of cellular plans. The device prevents use of any matching cellular networks in iMessage and FaceTime. The array must contain no more than 4 ICCID strings.

array—
deniedICCIDForiMessageFaceTime

An ICCID.

stringDenied ICCID for iMessage and FaceTime
deniedICCIDsForRCS

iOS 26.0+ · not on macOS, tvOS, watchOS, visionOS

An array of strings representing ICCIDs of cellular plans. The device prevents use of any matching cellular networks with RCS messaging. The array must contain no more than 4 ICCID strings.

array—
deniedICCIDForRCS

An ICCID.

stringDenied ICCID for RCS
ratingAppsExemptedBundleIDs

iOS 26.1+ · not on macOS, tvOS, watchOS, visionOS

If present, the system exempts apps with bundle IDs in the array from age-based rating restrictions. The system uses intersection combine rules to combine multiple payloads and any exceptions that parental control apps provide, including ScreenTime.

arrayApps exempted from rating restrictions
ratingAppsExemptedBundleID
stringExempted app
allowSiriAIdeprecated

iOS 27.0+ · deprecated 27.0 · not on macOS, tvOS, watchOS, visionOS

If 'false', the system disables Apple Intelligence integration in Siri. Deprecated: use the declarative management 'com.apple.configuration.siri.settings' configuration.

Default: true

booleanAllow Siri Apple Intelligence integration
allowAirPlayIncomingRequests

macOS 12.3+ · tvOS 10.2+ · not on iOS, watchOS, visionOS

If 'false', the system disables incoming AirPlay requests.

Default: true

booleanAllow incoming AirPlay requests
allowContentCaching

macOS 10.13+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disables content caching. This restriction is not supported on the user channel.

Default: true

booleanAllow Content Caching
allowPrinterSharingModification

macOS 14.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system prevents modifying Printer Sharing settings in System Settings.

Default: true

booleanAllow modifying Printer Sharing setting
allowUniversalControl

macOS 13.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disables Universal Control.

Default: true

booleanAllow Universal Control
allowiTunesFileSharing

macOS 10.13+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disables iTunes file sharing services.

Default: true

booleanAllow iTunes File Sharing
allowRemoteAppleEventsModification

macOS 14.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system prevents modifying Remote Apple Events Sharing settings in System Settings.

Default: true

booleanAllow modifying remote Apple Events Sharing setting
allowCloudBTMM

Default: true

booleanAllow iCloud Back to My Mac
allowCloudBookmarks

macOS 10.12+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disables iCloud Bookmark sync.

Default: true

booleanAllow iCloud Bookmarks
allowCloudCalendar

macOS 10.12+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disables iCloud Calendar services.

Default: true

booleanAllow iCloud Calendar
allowCloudAddressBook

macOS 10.12+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disables iCloud Contacts services.

Default: true

booleanAllow iCloud Contacts
allowCloudDesktopAndDocuments

macOS 10.12.4+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disables iCloud Desktop and Document services.

Default: true

booleanAllow iCloud Desktop & Documents
allowCloudFMM

Default: true

booleanAllow iCloud Find My Mac
allowCloudFreeform

macOS 14.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disallows iCloud Freeform services.

Default: true

booleanAllow Cloud Freeform
allowCloudMail

macOS 10.12+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disables iCloud Mail services.

Default: true

booleanAllow iCloud Mail
allowCloudNotes

macOS 10.12+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disables iCloud Notes services.

Default: true

booleanAllow iCloud Notes
allowCloudReminders

macOS 10.12+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system disables iCloud Reminder services.

Default: true

booleanAllow iCloud Reminders
allowFileSharingModification

macOS 14.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system prevents modifying File Sharing setting in System Settings.

Default: true

booleanAllow modifying file sharing setting
allowInternetSharingModification

macOS 14.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system prevents modifying the Internet Sharing setting in System Settings.

Default: true

booleanAllow modifying internet sharing setting
allowLocalUserCreation

macOS 14.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system prevents creating users in System Settings.

Default: true

booleanAllow creating users in System Settings
allowARDRemoteManagementModification

macOS 14.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system prevents modifying the Remote Management Sharing setting in System Settings.

Default: true

booleanAllow modifying Remote Management Sharing setting
allowBluetoothSharingModification

macOS 14.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system prevents modifying Bluetooth settings in System Settings.

Default: true

booleanAllow modifying Bluetooth sharing setting
allowStartupDiskModification

macOS 14.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system prevents modification of Startup Disk settings in System Settings.

Default: true

booleanAllow modifying startup disk settings
allowTimeMachineBackup

macOS 14.0+ · not on iOS, tvOS, watchOS, visionOS

If 'false', the system prevents modification of Time Machine settings in System Settings. This restriction isn't supported on the user channel.

Default: true

booleanAllow modifying Time Machine settings
enforcedSoftwareUpdateMinorOSDeferredInstallDelaydeprecated

macOS 11.3+ · removed 27.0 · not on iOS, tvOS, watchOS, visionOS

This restriction allows the administrator to set the number of days to delay a minor OS software update on the device. When this restriction is in place, the user sees a software update only after the specified delay after the release of the software update. This value controls the delay for 'forceDelayedSoftwareUpdates'. Removed: use the declarative management 'com.apple.configuration.softwareupdate.settings' configuration.

Default: 30

Range: 1 – 90

integerDeferred Minor Software Updates Delay
forceDelayedAppSoftwareUpdatesdeprecated

macOS 11.0+ · removed 27.0 · not on iOS, tvOS, watchOS, visionOS

If 'true', the system delays user visibility of non-OS software updates. Control visibility of operating system updates through 'forceDelayedSoftwareUpdates'. The delay is 30 days unless you set 'enforcedSoftwareUpdateDelay' to another value.

Default: false

booleanDefer non-OS Software Updates
enforcedSoftwareUpdateNonOSDeferredInstallDelaydeprecated

macOS 11.3+ · removed 27.0 · not on iOS, tvOS, watchOS, visionOS

This restriction allows the administrator to set the number of days to delay an app software update on the device. When this restriction is in place, the user sees a non-OS software update only after the specified delay after the release of the software. This value controls the delay for 'forceDelayedAppSoftwareUpdates'. Removed: use the declarative management 'com.apple.configuration.softwareupdate.settings' configuration.

Default: 30

Range: 1 – 90

integerDeferred non-OS Software Updates Delay
forceDelayedMajorSoftwareUpdatesdeprecated

macOS 11.3+ · removed 27.0 · not on iOS, tvOS, watchOS, visionOS

If 'true', the system delays user visibility of major OS updates. Removed: use the declarative management 'com.apple.configuration.softwareupdate.settings' configuration.

Default: false

booleanDefer Major OS Software Updates
enforcedSoftwareUpdateMajorOSDeferredInstallDelaydeprecated

macOS 11.3+ · removed 27.0 · not on iOS, tvOS, watchOS, visionOS

This restriction allows the administrator to set the number of days to delay a major software upgrade on the device. When this restriction is in place, the user sees a software upgrade only after the specified delay after the release of the software upgrade. This value controls the delay for 'forceDelayedMajorSoftwareUpdates'. Removed: use the declarative management 'com.apple.configuration.softwareupdate.settings' configuration.

Default: 30

Range: 1 – 90

integerDeferred Major Software Updates Delay
enforcedFingerprintTimeout

macOS 12.0+ · not on iOS, tvOS, watchOS, visionOS

The value, in seconds, after which the fingerprint unlock requires a password to authenticate. The default value is 48 hours.

Default: 172800

integerEnforced Fingerprint Timeout
allowMediaSharingModification

macOS 15.1+ · not on iOS, tvOS, watchOS, visionOS

If 'false', prevents modification of Media Sharing settings.

Default: true

booleanAllow modifying Media Sharing setting
forceBypassScreenCaptureAlert

macOS 15.1+ · not on iOS, tvOS, watchOS, visionOS

If 'true', then the system bypasses the presentation of a screen capture alert.

Default: false

boolean—
allowRosettaUsageAwareness

macOS 26.4+ · not on iOS, tvOS, watchOS, visionOS

If 'false', disables Rosetta usage awareness. When Rosetta usage awareness is active, the device displays a pop-up dialog to the user when launching an app that uses Rosetta. The pop-up dialog indicates that Rosetta will be removed in a future version of the operating system so that the user can contact the app vendor regarding a replacement for the current app.

Default: true

booleanAllow Rosetta Usage Awareness
allowAutomaticScreenSaver

tvOS 15.4+ · not on iOS, macOS, watchOS, visionOS

If 'false', the system disables Apple TV's automatic screen saver.

Default: true

booleanAllow Automatic Screen Saver
forceAirPlayIncomingRequestsPairingPassword

not on iOS, macOS, watchOS, visionOS

If 'true', the system forces all devices sending AirPlay requests to this device to use a pairing password. This key isn't supported in tvOS 10.2 and later. Use the AirPlay Security Payload instead.

Default: false

booleanRequire passcode on first AirPlay pairing
allowRemoteAppPairing

tvOS 10.2+ · not on iOS, macOS, watchOS, visionOS

If 'false', the system disables pairing Apple TV for use with the Control Center widget.

Default: true

booleanAllow pairing with Remote app
allowDeviceSleep

tvOS 13.0+ · not on iOS, macOS, watchOS, visionOS

If 'false', the system prevents the device from automatically sleeping.

Default: true

booleanAllow device sleep
allowMediaSharing

Controls whether media sharing is permitted on the device

Default: false

booleanAllow Media Sharing
Siri Data Sharing Opt-In Status

Manages the user's opt-in status for sharing data with Siri and related services

Default: 2

Range: Not Set (0), Opted In (1), Opted Out (2)

integerSiri Data Sharing Opt-In Status