# Restrictions Last updated: August 14, 2026 MDM lets you configure various restrictions on managed Apple devices according to your organization’s requirements. You can allow or restrict users from accessing device features, profile settings, application settings, iCloud settings, security settings, and privacy settings. **Note:** To view a detailed comparison of policies supported for specific OS versions, see [iOS feature comparison](https://www.manageengine.com/mobile-device-management/mdm-ios-feature-comparison.html). The status of restrictions imposed using MDM for a **particular device** is shown under **Inventory → Restrictions**. When no restrictions are imposed by MDM, the status is displayed as **Allowed** by default. ## Profile Creation To create a Restriction Profile: 1. On the Mobile Device Manager Plus console, navigate to **Device Management → Profiles → + Create Profile → Choose iOS/iPadOS Profile**. ![Create ios Profile](https://www.manageengine.com/mobile-device-management/help/images/iosres_1.png) 2. Provide the profile name and description, then continue. ![Create ios Profile description](https://www.manageengine.com/mobile-device-management/help/images/iosres_2.png) 3. Select the **Restrictions** tab and configure the restrictions as required. Save and publish the restriction, then associate the restriction profile with the required groups or devices. **Note:** When a restriction is applied through MDM, the corresponding setting on the user's device is disabled and cannot be modified until the restriction is removed. ## Profile Description ### Device Functionality 1. **Camera:** Camera(s) can be completely disabled and their icons removed from the Home Screen. This ensures users cannot take photos or use FaceTime. **Supported Management Type:** Supervised Devices ![Camera](https://www.manageengine.com/mobile-device-management/help/images/iosres_3.png) 2. **Camera — Exempted Apps:** Specify bundle IDs of apps that retain camera access even when Camera is restricted. Applies only to supervised devices with iOS 26+. **Supported Management Type:** Supervised Devices ![Camera Exempted Apps](https://www.manageengine.com/mobile-device-management/help/images/iosres_4.png) 3. **FaceTime:** Allow or restrict FaceTime video and audio calls. Camera must be allowed to enable FaceTime. **Supported Management Type:** Supervised Devices ![FaceTime](https://www.manageengine.com/mobile-device-management/help/images/iosres_5.png) 4. **Screenshot and Screen Recording:** Allow or restrict users from capturing screenshots and screen recordings. **Supported Management Type:** Supervised and Unsupervised Devices 5. **Spotlight Internet Search** (iOS 8 or later): Allow or restrict Spotlight Search from finding content directly on the internet. **Supported Management Type:** Supervised Devices ![Spotlight Internet Search](https://www.manageengine.com/mobile-device-management/help/images/iosres_6.png) 6. **AirDrop** (iOS 7 or later): Allow or restrict sharing documents and media through AirDrop. Disabling Bluetooth through restrictions also disables AirDrop. **Supported Management Type:** Supervised Devices 7. **iMessage** (iOS 6 or later): Allow or restrict iMessage. **Supported Management Type:** Supervised Devices ![iMessage](https://www.manageengine.com/mobile-device-management/help/images/iosres_7.png) 8. **Handoff** (iOS 8 or later): Lets users resume work or access content from devices signed in to the same iCloud account. **Supported Management Type:** Supervised Devices ![Handoff](https://www.manageengine.com/mobile-device-management/help/images/iosres_8.png) 9. **Allow user to modify device name:** Allow or restrict users from changing the device name. **Supported Management Type:** Supervised and Unsupervised Devices ![Allow user to modify device name](https://www.manageengine.com/mobile-device-management/help/images/iosres_9.png) 10. **Set device date and time:** Date and time can be automatically set based on network and location, configured by the user, or set to a specific timezone by the administrator. **Note:** If Screen Time Passcode is enabled, users cannot manually set date and time, and administrators cannot set a specific timezone. **Supported Management Type:** Supervised and Unsupervised Devices 11. **AirPrint** (iOS 11 or later): Allow or restrict managed devices from pairing with printers using AirPrint. **Supported Management Type:** Supervised Devices ![AirPrint](https://www.manageengine.com/mobile-device-management/help/images/iosres_10.png) 12. **Store AirPrint credentials on iCloud** (iOS 11 or later): Allow or restrict saving AirPrint credentials on iCloud. **Supported Management Type:** Supervised Devices 13. **Enforce TLS trusted certificates for AirPrint** (iOS 11 or later): Secure AirPrint communications by requiring TLS certificates on AirPrint printers. **Supported Management Type:** Supervised Devices 14. **Discover AirPrint printers using iBeacons** (iOS 11 or later): Enable or disable Bluetooth iBeacons for discovering AirPrint printers. **Supported Management Type:** Supervised Devices 15. **iPhone widgets on Mac:** Allow or restrict users from adding iPhone widgets on Mac devices. **Supported Management Type:** Supervised Devices 16. **Live voice mail:** Allow or restrict users from using live voicemail. **Supported Management Type:** Supervised Devices ![Live voice mail](https://www.manageengine.com/mobile-device-management/help/images/iosres_11.png) 17. **iPhone Mirroring** (iOS 18 or later): Prevents the iPhone from appearing in the iPhone Mirroring app on nearby Mac devices. **Supported Management Type:** Supervised Devices ![iPhone Mirroring](https://www.manageengine.com/mobile-device-management/help/images/iosres_12.png) #### Security: Share Data Between Managed and Unmanaged Apps 1. **Allow both ways:** Allow data sharing between managed and unmanaged apps. **Supported Management Type:** Supervised and Unsupervised Devices 2. **Restrict from unmanaged to managed:** Allow pasting cut or copied unmanaged-app data into managed apps. **Supported Management Type:** Supervised and Unsupervised Devices ![Restrict from unmanaged to managed](https://www.manageengine.com/mobile-device-management/help/images/iosres_13.png) 3. **Restrict from managed to unmanaged:** - Allow pasting cut or copied managed-app data into unmanaged apps. - Use AirDrop to share data from managed apps. - Allow managed apps to save contacts in unmanaged accounts. - Allow unmanaged apps to access managed contacts. **Supported Management Type:** Supervised and Unsupervised Devices 4. **Restrict both ways:** - Allow cut, copy, and paste between managed and unmanaged apps. - Use AirDrop to share data from managed apps. - Allow managed apps to save contacts in unmanaged accounts. - Allow unmanaged apps to access managed contacts. **Supported Management Type:** Supervised and Unsupervised Devices ![restrict both way](https://www.manageengine.com/mobile-device-management/help/images/iosres_16.png) 5. **Force Encrypted Backup:** Enable or disable forced encrypted backup of data. **Supported Management Type:** Supervised and Unsupervised Devices ![force encrypted](https://www.manageengine.com/mobile-device-management/help/images/iosres_17.png) 6. **Allow user to wipe device by erasing all content and settings** (iOS 8 or later): Allows users to erase all content and settings. **Note:** Restricting this option disables Erase All Content and Settings, which is equivalent to a factory reset. **Supported Management Type:** Supervised Devices ![allow user to wipe device](https://www.manageengine.com/mobile-device-management/help/images/iosres_18.png) 7. **Allow user to configure Screen Time/Restrictions on device** (iOS 8 or later): Enable or disable users from configuring Screen Time or device restrictions. **Note:** From iOS 12, Restrictions was renamed to Screen Time. If Screen Time restriction is enabled, Location Permission is set to Don't Change. **Supported Management Type:** Supervised Devices ![allow user to configure screen time](https://www.manageengine.com/mobile-device-management/help/images/iosres_19.png) 8. **Allow Passbook when device is locked** (iOS 6 or later): Enable or disable Passbook when the device is locked. **Supported Management Type:** Supervised and Unsupervised Devices ![Allow Passbook when device is locked](https://www.manageengine.com/mobile-device-management/help/images/iosres_20.png) 9. **Use biometric methods such as Touch ID and/or Face ID to unlock devices** (iOS 7 or later): Enable or disable fingerprints and facial recognition for unlocking devices. **Supported Management Type:** Supervised and Unsupervised Devices ![touch ID](https://www.manageengine.com/mobile-device-management/help/images/iosres_21.png) 10. **Allow user to add or modify Touch ID/Face ID** (iOS 8.3 or later): Allow users to add or modify fingerprints and faces. Biometric unlocking must be enabled. **Supported Management Type:** Supervised Devices ![Allow user to add or modify TouchID/FaceID](https://www.manageengine.com/mobile-device-management/help/images/iosres_22.png) ### Advanced Security 1. **Install configuration profiles and certificates interactively** (iOS 6 or later): Allow or restrict users from installing or modifying configurations and certificates. **Supported Management Type:** Supervised Devices ![Install configuration profiles and certificates interactively](https://www.manageengine.com/mobile-device-management/help/images/iosres_23.png) 2. **Add/Modify iCloud, Mail and other accounts** (iOS 7 or later): Allow or restrict users from adding or removing Apple accounts, email accounts, and other accounts. Once restricted, apps requiring an Apple ID cannot be installed, whether distributed by MDM or not. Apps can still be silently installed without an Apple ID as [explained here](https://www.manageengine.com/in/mobile-device-management/help/app_management/ios_app_management.html?iosrest#without_apple_id). After enabling this restriction, users cannot add or modify accounts, but administrators can add or modify them from the MDM console. Restricting iCloud and iMessage also restricts FaceTime. **Note:** iCloud sign-out is disabled if Screen Time is enabled. Turn off Screen Time from device settings to enable iCloud sign-out. **Supported Management Type:** Supervised Devices ![Add/Modify iCloud, Mail and other accounts](https://www.manageengine.com/mobile-device-management/help/images/iosres_24.png) 3. **Accept untrusted TLS certificates:** Allow or restrict untrusted Transport Layer Security certificates. **Supported Management Type:** Supervised and Unsupervised Devices ![TLS](https://www.manageengine.com/mobile-device-management/help/images/iosres_25.png) 4. **Automatic updates for trusted certificates** (iOS 7 or later): Allow or restrict trusted certificates from updating automatically. **Supported Management Type:** Supervised and Unsupervised Devices 5. **Allow iTunes pairing and other USB connections** (iOS 7 or later): Enable or disable pairing with Macs other than the one used to supervise the device through Apple Configurator. Restricting USB pairing also restricts iTunes pairing. **Supported Management Type:** Supervised Devices 6. **Allow USB connections when device is locked** (iOS 11.4.1 or later): Enable or disable USB data transfer while the device is locked. **Supported Management Type:** Supervised Devices 7. **USB flash drive** (iOS 13 or later): Allow or restrict users from connecting external storage drives. **Supported Management Type:** Supervised and Unsupervised Devices 8. **Allow unpaired computers to boot devices into recovery mode** (iOS 14.5 or later): Controls whether an unpaired computer can boot a connected iPhone or iPad into Recovery Mode. This is disabled by default on iOS/iPadOS 14.5 and later to prevent unauthorized erase or restore via USB. **Supported Management Type:** Supervised Devices 9. **Force password for iTunes and App Store downloads:** Enable or disable password prompts for every iTunes and App Store download. **Supported Management Type:** Supervised and Unsupervised Devices 10. **Force password for AirPlay outgoing requests** (iOS 7 or later): Enable or disable password prompts for outgoing AirPlay pairing requests. **Supported Management Type:** Supervised Devices 11. **Force password for AirPlay incoming requests** (iOS 7 or later): Enable or disable password prompts for incoming AirPlay pairing requests. **Supported Management Type:** Supervised Devices 12. **Restrict users from changing the passcode:** Enable or disable the ability to change the passcode. **Supported Management Type:** Supervised Devices 13. **Force Wrist Authentication to access notifications on Apple Watch** (iOS 8.3 or later): Enable or disable Wrist Authentication. **Supported Management Type:** Supervised Devices 14. **Pair with Apple Watch** (iOS 9 or later): Allow or restrict pairing with Apple Watch. **Supported Management Type:** Supervised and Unsupervised Devices 15. **Unlock with Apple Watch** (iOS 14.5 or later and watchOS 7.4 or later): Allow or restrict users from unlocking devices with Apple Watch. **Supported Management Type:** Supervised and Unsupervised Devices 16. **Set up other devices using proximity detection** (iOS 11 or later): Allow or restrict devices from detecting nearby devices to share settings, iCloud data, and Wi-Fi passwords. **Supported Management Type:** Supervised and Unsupervised Devices 17. **Autofill passwords in Safari and apps** (iOS 12 or later): Allow or restrict autofill in browsers and apps. **Supported Management Type:** Supervised Devices 18. **Authenticate Face ID/Touch ID before allowing autofill** (iOS 11 or later): Allow or restrict biometric authentication before password or credit-card details are entered. Autofill passwords in Safari and apps must be enabled. **Supported Management Type:** Supervised and Unsupervised Devices 19. **Share passwords with devices in proximity** (iOS 12 or later): Allow or restrict password-sharing notifications with nearby devices. **Supported Management Type:** Supervised Devices 20. **Request passwords from devices in proximity** (iOS 12 or later): Allow or restrict password requests from nearby devices. **Supported Management Type:** Supervised Devices ### Applications 1. **Users can install only approved apps** (iOS 9 or later): Allow or restrict users from installing apps through the App Store or iTunes. On iOS 9 and later, MDM-distributed apps can still be installed. With a Managed Apple ID, the GET option is disabled in the App Store by default. **Supported Management Type:** Supervised Devices 2. **Install alternative marketplace apps:** Allow or restrict apps from alternative marketplaces other than the App Store. This does not impact in-house, enterprise, or custom B2B app distribution through MDM. This restriction applies only to [EU regions](https://support.apple.com/en-gb/118110). **Supported Management Type:** Supervised Devices 3. **Install Apps Directly from Web:** Allow or restrict application installation directly from web sources. Available from iOS 17.5. **Supported Management Type:** Supervised Devices 4. **Deleting apps:** Allow or restrict users from removing apps. **Supported Management Type:** Supervised Devices 5. **Install unauthorized enterprise apps** (iOS 9 or later): Allow or restrict installation and use of enterprise apps that were not distributed through MDM. **Supported Management Type:** Supervised and Unsupervised Devices 6. **Automatically download apps on multiple devices with same Apple ID** (iOS 9 or later): Allow or restrict automatic app downloads on devices using the same Apple ID. **Supported Management Type:** Supervised Devices 7. **In-app purchase:** Allow or restrict in-app purchases. **Supported Management Type:** Supervised and Unsupervised Devices 8. **Game Center** (iOS 6 or later): Allow or restrict Game Center. **Supported Management Type:** Supervised Devices 9. **Multiplayer Gaming:** Allow or restrict multiplayer gaming. Game Center must be allowed. **Supported Management Type:** Supervised Devices 10. **Adding Game Center Friends:** Allow or restrict users from adding Game Center friends. Game Center must be allowed. **Supported Management Type:** Supervised Devices 11. **iTunes Store:** Allow or restrict iTunes Store. **Supported Management Type:** Supervised Devices 12. **Podcast app** (iOS 8 or later): Allow or restrict Podcasts. **Supported Management Type:** Supervised Devices 13. **News app** (iOS 9 or later): Allow or restrict News. **Supported Management Type:** Supervised Devices 14. **Remove system apps:** Allow or restrict users from removing system apps. **Supported Management Type:** Supervised Devices 15. **Modify Notification:** Allow or restrict users from modifying app-specific notifications. **Supported Management Type:** Supervised Devices 16. **Music Services** (iOS 9.3 or later): Allow or restrict music services in the default iOS Music app. **Supported Management Type:** Supervised Devices 17. **Radio Services** (iOS 9.3 or later): Allow or restrict radio services. **Supported Management Type:** Supervised Devices 18. **Download iBooks content** (iOS 6 or later): Allow or restrict downloading content from iBooks Store. **Supported Management Type:** Supervised Devices 19. **Erotic content** (iOS 6 or later): Allow or restrict downloading iBooks media tagged as erotic. Download iBooks content must be enabled. **Supported Management Type:** Supervised and Unsupervised Devices 20. **Lock Apps** (iOS 18 or later): Allows selected apps to be locked using App Lock. **Supported Management Type:** Supervised Devices 21. **Hide Apps** (iOS 18 or later): Hides selected apps from the device user interface. **Note:** If Lock Apps is restricted, Hide Apps is also restricted because apps can only be hidden if they are allowed to be locked. **Supported Management Type:** Supervised Devices ### Default Applications 1. **Default Browser Modification** (iOS 18.2 or later): Allows users to change the default web browser. **Supported Management Type:** Supervised and Unsupervised Devices 2. **Default Browser Setting** (iOS 18.2 or later): Sets the specified app as the default browser. If allowed, users can change the default browser from device settings. **Supported Management Type:** Supervised and Unsupervised Devices 3. **Default Calling App Modification** (iOS 18.4 or later): Allows users to modify the default calling app. **Supported Management Type:** Supervised Devices 4. **Default Calling App** (iOS 26 or later): Specify the app name or bundle identifier for the default calling app. **Note:** Removing the profile does not switch calling back to the original default app. **Supported Management Type:** Supervised and Unsupervised Devices 5. **Default Messaging App Modification** (iOS 18.4 or later): Allows users to modify the default messaging app. **Supported Management Type:** Supervised Devices 6. **Default Messaging App** (iOS 26 or later): Specify the app name or bundle identifier for the default messaging app. **Note:** Removing the profile does not switch messaging back to the original default app. **Supported Management Type:** Supervised and Unsupervised Devices ### Browser 1. **Safari:** Allow or restrict Safari. **Supported Management Type:** Supervised Devices #### Settings Available When Safari Is Allowed 1. **AutoFill:** Allow or restrict AutoFill in Safari. This does not apply to third-party password managers or app AutoFill. **Supported Management Type:** Supervised Devices 2. **Force fraudulent website warning:** Enable or disable fraudulent website warnings. **Supported Management Type:** Supervised Devices 3. **JavaScript:** Allow or restrict JavaScript in Safari. **Supported Management Type:** Supervised Devices 4. **Pop-ups:** Allow or restrict pop-ups in Safari. **Supported Management Type:** Supervised and Unsupervised Devices 5. **Cookies:** Allow or restrict cookies. **Supported Management Type:** Supervised Devices 6. **Private Browsing:** Allow or restrict private browsing in Safari. **Supported Management Type:** Supervised Devices 7. **History Clearing:** Allow or restrict users from clearing Safari browsing history. **Supported Management Type:** Supervised Devices ### Network and Roaming 1. **Automatic sync while roaming:** Permits apps to fetch background data when devices are roaming. **Supported Management Type:** Supervised and Unsupervised Devices 2. **Allow users to modify cellular data usage for apps** (iOS 7 or later): Allows users to restrict cellular data usage for specific apps. **Supported Management Type:** Supervised Devices 3. **Modify Bluetooth** (iOS 10 or later): Allow or restrict users from modifying Bluetooth. Restricting Bluetooth also disables AirDrop. **Supported Management Type:** Supervised Devices 4. **Set Bluetooth on devices** (iOS 11.3 or later): Restrict Bluetooth to always on or always off. Modify Bluetooth must be enabled. **Supported Management Type:** Supervised Devices 5. **Connect to Wi-Fi, only if distributed via MDM** (iOS 10.3 or later): Ensures devices connect only to Wi-Fi networks distributed through an MDM Wi-Fi profile. **Supported Management Type:** Supervised Devices 6. **Always on Wi-Fi** (iOS 13 or later): Forces Wi-Fi to remain enabled, or allows users to manage Wi-Fi themselves. **Supported Management Type:** Supervised and Unsupervised Devices 7. **Allow users to configure VPN** (iOS 11 or later): Allows users to configure VPN on managed iOS devices. **Supported Management Type:** Supervised Devices 8. **Modify Personal Hotspot** (iOS 12.2 or later): Allow or restrict Personal Hotspot. **Supported Management Type:** Supervised Devices 9. **Modify eSIM Settings:** Restricts users from adding or removing eSIMs. **Supported Management Type:** Supervised Devices 10. **Near Field Communication (NFC)** (iOS 14.2 or later): Restricts users from turning on NFC. **Supported Management Type:** Supervised Devices 11. **RCS Messaging** (iOS 18.1 or later): Allows enabling or disabling RCS messaging. **Supported Management Type:** Supervised Devices 12. **Call Recording** (iOS 18 or later): Allows or disallows phone-call recording. **Supported Management Type:** Supervised Devices ### iCloud 1. **Device backup:** Allow or restrict automatic photo and document backup when devices are connected to Wi-Fi. **Supported Management Type:** Supervised Devices 2. **Sync data and documents from managed apps** (iOS 8 or later): Allow or restrict syncing managed app data and documents. **Supported Management Type:** Supervised Devices 3. **Sync device data and documents:** Allow or restrict syncing device data and documents. **Supported Management Type:** Supervised Devices 4. **Sync Photo Stream:** Allow or restrict automatic photo backup when devices are connected to Wi-Fi. **Supported Management Type:** Supervised and Unsupervised Devices 5. **Sync Shared Stream** (iOS 6 or later): Allow or restrict users from creating iCloud shared photo and video albums. **Supported Management Type:** Supervised and Unsupervised Devices 6. **Sync Keychain** (iOS 8 or later): Allow or restrict syncing Keychain data, including passwords, credit-card information, and security notes. **Supported Management Type:** Supervised and Unsupervised Devices 7. **Sync iCloud Photo Library** (iOS 9 or later): Allow or restrict syncing photos from iCloud Photo Library onto devices. **Supported Management Type:** Supervised and Unsupervised Devices 8. **Enterprise books backup** (iOS 8 or later): Allow or restrict backing up data from organization-distributed books. **Supported Management Type:** Supervised and Unsupervised Devices 9. **Enterprise books metadata sync** (iOS 8 or later): Allow or restrict syncing notes and highlights from enterprise books. Enterprise books backup must be enabled. **Supported Management Type:** Supervised and Unsupervised Devices 10. **Allow iCloud Private Relay:** Private Relay hides users’ IP addresses and Safari browsing activity from websites, network providers, and Apple. **Supported Management Type:** Supervised and Unsupervised Devices ### Privacy 1. **Find My Friends** (iOS 13 or later): Allow or restrict users from configuring Find My Friends in the Find My app. **Supported Management Type:** Supervised Devices 2. **Modify Find My Friends settings** (iOS 7 or later): Allow or restrict users from modifying Find My Friends settings. Find My Friends must be allowed. **Supported Management Type:** Supervised Devices 3. **Find My Device** (iOS 13 or later): Allow or restrict users from configuring Find My Device in the Find My app. **Supported Management Type:** Supervised Devices 4. **Send diagnostics data to Apple** (iOS 6 or later): Allows diagnostic data to be sent to Apple. **Supported Management Type:** Supervised and Unsupervised Devices 5. **Modify Diagnostics & Usage pane settings** (iOS 9.3 or later): Allows users to enable or disable Diagnostics & Usage settings. **Supported Management Type:** Supervised and Unsupervised Devices 6. **Force limited ad tracking** (iOS 7 or later): Allow or restrict limited ad tracking. **Supported Management Type:** Supervised and Unsupervised Devices 7. **Enable lock screen settings** (iOS 7 or later): Allow or restrict access to Control Center, Notification Center, and Today View when the device is locked. **Supported Management Type:** Supervised and Unsupervised Devices #### Settings Available When Lock Screen Settings Are Allowed 1. **Control Center** (iOS 7 or later): Allow or restrict Control Center access while the device is locked. **Supported Management Type:** Supervised and Unsupervised Devices 2. **Notification Center** (iOS 7 or later): Allow or restrict Notification Center access while the device is locked. **Supported Management Type:** Supervised and Unsupervised Devices 3. **Today View** (iOS 7 or later): Allow or restrict Today View access while the device is locked. **Supported Management Type:** Supervised and Unsupervised Devices 4. **Mail Privacy Protection** (iOS 15.2 or later): Prevents users from enabling Mail Privacy Protection, which hides email activities and IP addresses from senders. **Supported Management Type:** Supervised and Unsupervised Devices 5. **Personalized Advertisement:** Allow or block personalized advertisements based on user activity. Available from iOS 14. **Supported Management Type:** Supervised and Unsupervised Devices ### Date/Time Settings 1. **Set date and time:** Configure device date and time automatically, manually, or through user control. Automatic configuration requires Location Services and prevents user modification. **Supported Management Type:** Supervised Devices 2. **Timezone:** Select a timezone manually that users cannot modify. **Supported Management Type:** Supervised Devices ### Content Ratings 1. **Explicit Music & Podcasts:** Allow or restrict explicit music and podcasts. **Supported Management Type:** Supervised Devices 2. **Enable ratings by region:** Enable or disable content ratings by region. **Supported Management Type:** Supervised and Unsupervised Devices #### Settings Available When Ratings by Region Are Allowed 1. **Specify the Region:** Choose the region used for content-rating standards. For example, United States uses MPAA movie ratings and United Kingdom uses BBFC standards. **Supported Management Type:** Supervised and Unsupervised Devices 2. **Maximum Allowable Ratings for Movies:** Set the maximum allowed movie rating. For example, when set to PG-13, R-rated and higher movies cannot be played. **Supported Management Type:** Supervised and Unsupervised Devices 3. **Maximum Allowable Ratings for TV shows:** Set the maximum allowed television rating. For example, when set to TV-14, TV-MA shows are blocked. **Supported Management Type:** Supervised and Unsupervised Devices 4. **Maximum Allowable Ratings for Apps:** Restrict apps based on their rating. Before iOS 26, an app that does not meet the allowed rating installs but its icon is hidden from the Home Screen. From iOS 26 onward, the app icon remains visible but the app is disabled and cannot be opened. **Supported Management Type:** Supervised and Unsupervised Devices ### Keyboard Settings 1. **Dictionary word lookup** (iOS 8.1.3 or later): Allow or restrict the built-in dictionary. **Supported Management Type:** Supervised Devices 2. **Predictive keyboard** (iOS 8.1.3 or later): Allow or restrict predictive keyboard. **Supported Management Type:** Supervised Devices 3. **Auto correction** (iOS 8.1.3 or later): Allow or restrict autocorrect. **Supported Management Type:** Supervised Devices 4. **Spellcheck** (iOS 8.1.3 or later): Allow or restrict spellcheck. **Supported Management Type:** Supervised Devices 5. **Shortcuts on external keyboards** (iOS 9 or later): Allow or restrict shortcuts from external keyboards. **Supported Management Type:** Supervised Devices 6. **Dictation** (iOS 10.3 or later): Allow or restrict keyboard dictation. **Supported Management Type:** Supervised Devices 7. **Process dictation on device:** Allow or restrict dictation content from being sent to Apple servers. **Supported Management Type:** Supervised and Unsupervised Devices 8. **Swipe keyboard** (iOS 13 or later): Allow or restrict QuickPath keyboard. **Supported Management Type:** Supervised Devices 9. **Process translation on device:** Allow or restrict translation content from being sent to Apple servers. **Supported Management Type:** Supervised and Unsupervised Devices ### Classroom Applicable if Classroom 2.0 is installed on teacher devices and student devices are supervised. 1. **Automatically join classes without prompting** (iOS 11 or later): Ensures student devices join classes without a prompt. **Supported Management Type:** Supervised Devices 2. **Allow teacher's device to lock apps and devices without prompting** (iOS 11 or later): Allows teachers to fully lock student devices or specific apps without prompts. **Supported Management Type:** Supervised Devices 3. **Allow AirPlay and screen viewing by teacher's device:** Allows teachers to view student screens after notification or permission. **Supported Management Type:** Supervised Devices 4. **Allow teacher's device to AirPlay and view screen without prompting:** Allows teachers to view student screens without notification or prompts. AirPlay and screen viewing must be enabled. **Supported Management Type:** Supervised Devices 5. **Teacher's permission required before leaving a classroom** (iOS 11.3 or later): Requires students to ask teacher permission before leaving a classroom. **Supported Management Type:** Supervised Devices ### Artificial Intelligence 1. **Image Playground:** Allow or restrict Image Playground. Available from iOS 18. **Supported Management Type:** Supervised Devices 2. **Writing Tools:** Allow or restrict AI-powered writing tools. Available from iOS 18. **Supported Management Type:** Supervised Devices 3. **System-generated text in User's Handwriting:** Allow or restrict AI-generated text in a user’s handwriting. Available from iOS 18. **Supported Management Type:** Supervised Devices 4. **Image Wand:** Allow or restrict Image Wand. Available from iOS 18. **Supported Management Type:** Supervised Devices 5. **Genmoji Creation:** Allow or restrict AI-powered Genmoji creation. Available from iOS 18. **Supported Management Type:** Supervised Devices 6. **Extends Apple Intelligence & Siri:** Allow or restrict extended AI integration with Siri and Apple Intelligence. Available from iOS 18.2. **Supported Management Type:** Supervised and Unsupervised Devices 7. **Sign-in to extensions** (iOS 18.2 or later): Allows users to sign in to Apple Intelligence tools, such as ChatGPT, that require authentication. **Supported Management Type:** Supervised Devices 8. **Allowed workspace ID** (iOS 18.3 or later): Enforces sign-in when accessing Apple Intelligence tools through an enterprise workspace. **Supported Management Type:** Supervised Devices 9. **Mail summary** (iOS 18.1 or later): Enables AI-generated email summaries in the Mail app. **Supported Management Type:** Supervised Devices 10. **Notes transcription summary** (iOS 18.3 or later): Allows Apple Intelligence transcription summaries in Notes. **Supported Management Type:** Supervised Devices 11. **Visual Intelligence Summary** (iOS 18.3 or later): Allows Apple Intelligence to summarize visual content. **Supported Management Type:** Supervised Devices 12. **Apple Intelligence Report** (iOS 18.4 or later): Generates a log showing how Apple Intelligence is used, including requests sent to Private Cloud Compute. The report can be customized by time range. **Supported Management Type:** Supervised Devices 13. **Mail Smart Reply** (iOS 18.4 or later): Allows the Mail app to suggest AI-powered replies. **Supported Management Type:** Supervised Devices 14. **Safari Web Page Summary** (iOS 18.4 or later): Allows Safari to generate Apple Intelligence summaries of web content. **Supported Management Type:** Supervised Devices ## Frequently Asked Questions ### How can users install App Store apps without admin approval? This can be enabled by configuring and associating an iOS/iPadOS restriction profile. 1. Create a restriction profile that allows **Add/modify iCloud, Mail and other accounts**. 2. Configure a restriction profile that allows users to install unapproved apps. 3. Associate the profile with the required devices. Once applied, users can sign in with their Apple ID and install apps directly from the App Store without administrator approval. ### Why can't a device be turned back to Allowed status for the Camera restriction after updating to iOS 13? For iOS 13 or later, the Camera restriction applies only to supervised devices. If the device was on an earlier iOS version when the restriction was configured, updating to iOS 13 has no effect until the profile is revoked and re-associated with the device. ### Does restricting iCloud account changes also block iMessage and FaceTime? Yes. Restricting **Add/Modify iCloud, Mail and other accounts** also restricts iMessage and FaceTime. Both appear disabled on the device. Accounts can still be added or modified from the MDM console. ### What changes when Maximum Allowable Ratings for Apps is applied on iOS 26 compared to earlier versions? Before iOS 26, an app that does not meet the permitted rating installs but its icon is hidden from the Home Screen. From iOS 26 onward, the app installs and remains visible, but is disabled and cannot be opened. ### Can end users change the default browser, calling app, or messaging app on a managed device? Users can change these apps only if **Default Browser Modification**, **Default Calling App Modification**, or **Default Messaging App Modification** is allowed. When **Default Browser Setting**, **Default Calling App**, or **Default Messaging App** is configured instead, administrators specify the app directly. Removing the profile does not restore the original default app.