# Managed Web Domains Last updated: August 14, 2026 This page explains Managed Web Domains, an iOS MDM feature that secures documents downloaded from specified URLs so only managed apps can access them. Applicable exclusively to Safari on iOS 8.0 or later, it helps organizations prevent unauthorized data sharing between managed and unmanaged apps, restrict PDF saving of websites, and containerize corporate data on BYOD devices. Administrators can configure domain, subdomain, folder, and wildcard URL patterns to control exactly which downloads are protected. With organizations moving towards a mobile-only workforce, securing web browsers has become an imperative requirement with respect to securing corporate data access on mobile browsers. It is also to be ensured that not all apps can access downloaded corporate documents, preventing any unauthorized data access or leakage. With Managed Web Domains, you can secure documents downloaded from certain URLs and ensure only managed apps can access these documents. **Managed Web Domains is applicable only for Safari.** ## Advantages of Managed Web Domains - Prevent sharing of data from managed apps to unmanaged apps, by default. - Saving websites as PDF (available from iOS 8.0) is also completely restricted. - Use Managed Web Domains to containerize the corporate data on BYOD, without affecting the personal space. - Optionally provision the URLs configured in [Web Clips](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_webclips.html?mwd) through Managed Web Domains, to ensure documents downloaded from Web Clips can also be viewed securely through managed apps. - No need for a specific browser app to be installed on the device, for implementing browser security as Managed Web Domains is applied on Safari. It is recommended to use ManageEngine MDM Self Service app (previously ManageEngine MDM app) as the default document viewer app, as it ensures there is no back up of the corporate data. All the corporate documents are stored and viewed within Self Service app (previously ME MDM app), thereby ensuring complete corporate containerization. ## Pre-requisites The only pre-requisite is that the devices must be running **iOS 8.0 or later versions**. ## Policy Description | PROFILE SETTINGS | DESCRIPTION | |---|---| | URLs | Documents from the URLs specified here can be viewed securely only through managed apps. | ### Adding URLs in Managed Web Domains The following table explains the various scenarios where Managed Web Domains can be used. | SCENARIO | EXAMPLE URL | |---|---| | Securing any documents downloaded **from a website/domain**. | Using **example.com** secures documents downloaded from example.com and all its sub-folders such as example.com/folder, example.com/folder/sub-folder etc., **However, it doesn't secure downloads from sub-domain.example.com** | | Securing any documents downloaded from **a sub-domain of a website**. | Using **sub-domain.example.com** secures all documents downloaded from sub-domain.example.com and all its sub-folders such as sub-domain.example.com/folder, sub-domain.example.com/folder/sub-folder etc., **However, it doesn't secure downloads from example.com or different-sub-domain.example.com** | | Securing any documents downloaded from **all sub-domains of a website**. | Using **\*.example.com** secures all documents downloaded from any sub-domain of example.com as well as all its sub-folders such as sub-domain1.example.com/folder, sub-domain2.example.com/folder/sub-folder etc., **However, it doesn't secure downloads from example.com** | | Securing any documents downloaded from **a folder of a website**. | Using **example.com/folder** secures all documents downloaded from example.com/folder as well as all its sub-folders such as example.com/folder/sub-folder etc., **However, it doesn't secure downloads from example.com** | | Securing any documents downloaded from **a folder of a website sub-domain**. | Using **sub-domain.example.com/folder** secures all documents downloaded from sub-domain.example.com/folder as well as all its sub-folders such as example.com/folder/sub-folder etc., **However, it doesn't secure downloads from example.com, example.com/folder, sub-domain.example.com, different-sub-domain.example.com** | | Securing any documents downloaded from **a folder of any website sub-domain**. | Using **\*.example.com/folder** secures all documents downloaded from sub-domain1.example.com/folder, sub-domain2.example.com/folder as well as all its sub-folders such as sub-domain2.example.com/folder/sub-folder etc., **However, it doesn't secure downloads from example.com, sub-domain.example.com** | | Securing any documents downloaded from **a specific domain extension**. | Using **\*.com** secures all documents downloaded from example1.com, example2.com. **However, it doesn't secure downloads from example1.gov, example2.org** | ## Frequently Asked Questions 1. **Does Managed Web Domains require installing a specific browser app?** No. Managed Web Domains is applied on Safari, so there's no need to install a specific browser app on the device to implement this browser security. 2. **Can Managed Web Domains secure documents downloaded from Web Clips?** Yes. You can optionally provision the URLs configured in Web Clips through Managed Web Domains, so documents downloaded from those Web Clips can also be viewed securely through managed apps. 3. **What happens if I add a wildcard domain like \*.example.com to Managed Web Domains?** Using \*.example.com secures documents downloaded from any sub-domain of example.com, including its sub-folders. However, it doesn't secure downloads from example.com itself. 4. **Can users still save downloaded content as a PDF on managed devices?** No. Saving websites as a PDF, available from iOS 8.0, is completely restricted once Managed Web Domains is applied, preventing corporate data from being shared outside managed apps.