# How to achieve containerization in iOS using restrictions? Last updated: July 24, 2026 Since Apple doesn't offer built-in containerization on iOS, this guide explains how to create a logical container-like setup using MDM restrictions. Administrators create a Restrictions profile and configure settings covering data sharing between managed and unmanaged apps, device wipe, unauthorized certificates/accounts, USB pairing, app installation, and Wi-Fi/VPN and iCloud controls (some requiring Supervised devices), isolating corporate data from personal use. ## Description Unlike Android which provides containerization by default when provisioned as [Profile Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Profile_Owner), Apple doesn't offer containerization on iOS devices by default. However, with more organizations adopting a mobile-only workforce containerization on mobile devices is increasingly becoming a necessity. Containerization isolates personal and corporate data through a logical container ensuring there's no unauthorized access of corporate data. Containerization further helps in case of personal devices, whereby it ensures enterprises can control only the corporate data and enterprise apps while having zero control over the personal space. Though Apple doesn't provide containerization by default, MDM lets you achieve iOS containerization with a logical container-like setup using multiple restrictions as explained below: ## Steps - On your MDM console, click on **Device Mgmt** and select **Profiles** from the left menu. - Click on **Create Profile** and select **Apple** from the dropdown. - Click on **Restrictions** from the policy list. You can know more about [Restrictions here](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_restrictions.html). - Configure below given restrictions to achieve a container-like setup on managed devices. This is thhe recommended setup though it can be modified based on the needs of your organization. Restrictions marked with * are applicable only [if the devices are Supervised](https://www.manageengine.com/mobile-device-management/how-to/mdm-supervised-devices.html). | AVAILABILE UNDER | PARAMETER TO BE RESTRICTED | PRE-REQUISITES | COMMENTS | |---|---|---|---| | **SECURITY** | Share data from managed apps to unmanaged apps | Applicable for devices running 7.0 or later versions | These restrictions prevent unauthorized access of corporate data by unapproved apps and also prevent users from removing the existing configurations by factory resetting the device. | | **SECURITY** | Share data from unmanaged apps to managed apps | Applicable for devices running 7.0 or later versions | These restrictions prevent unauthorized access of corporate data by unapproved apps and also prevent users from removing the existing configurations by factory resetting the device. | | **SECURITY** | Allow user to wipe device by erasing all content and settings* | Applicable for devices running 8.0 or later versions | These restrictions prevent unauthorized access of corporate data by unapproved apps and also prevent users from removing the existing configurations by factory resetting the device. | | **ADVANCED SECURITY** | Install configuration profiles and certificates interactively* | Applicable for devices running 6.0 or later versions | These restrictions prevent users from adding unauthorized certificates/profiles on the devices as well as prevent users from adding non-corporate accounts to the device or allow devices to be paired using iTunes or via USB, thereby preventing data from being shared through USB. | | **ADVANCED SECURITY** | Add/Modify iCloud, Mail and other accounts* | Applicable for devices running 7.0 or later versions | These restrictions prevent users from adding unauthorized certificates/profiles on the devices as well as prevent users from adding non-corporate accounts to the device or allow devices to be paired using iTunes or via USB, thereby preventing data from being shared through USB. | | **ADVANCED SECURITY** | Allow iTunes pairing and other USB connections* | Applicable for devices running 7.0 or later versions | These restrictions prevent users from adding unauthorized certificates/profiles on the devices as well as prevent users from adding non-corporate accounts to the device or allow devices to be paired using iTunes or via USB, thereby preventing data from being shared through USB. | | **APPLICATION** | Users can install unapproved apps* | N/A | Prevents unapproved apps from being installed on the device, thereby preventing these apps from accessing corporate apps or the data they work with. | | **NETWORK AND ROAMING** | Connect to Wi-Fi, only if distributed via MDM* | Applicable for devices running 10.3 or later versions | This prevents users from connecting to untrusted Wi-Fi connections as well as configure unauthorized VPN connections on the device, thus ensuring secure transmission of corporate data. | | **NETWORK AND ROAMING** | Allow users to configure VPN* | Applicable for devices running 11.0 or later versions | This prevents users from connecting to untrusted Wi-Fi connections as well as configure unauthorized VPN connections on the device, thus ensuring secure transmission of corporate data. | | **ICLOUD** | iCloud Device Backup | N/A | This prevents corporate data from being saved on iCloud, which is a third-party cloud service. | | **ICLOUD** | iCloud Sync Data and Documents of Managed Apps | Applicable for devices running 8.0 or later versions | This prevents corporate data from being saved on iCloud, which is a third-party cloud service. | - Now, Save and Publish this profile. Distribute it to [devices](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_associating_profiles_to_devices.html) and/or [groups](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_associating_profiles_to_groups.html). - On successful profile association, you would have a container-like setup on devices. ## Frequently asked questions ### Why doesn't iOS support containerization the way Android does? Apple doesn't provide built-in containerization on iOS the way Android does through Profile Owner mode, so MDM achieves an equivalent container-like setup using a combination of Restrictions instead. ### Which restrictions actually create this container-like isolation? Blocking data sharing between managed and unmanaged apps, preventing installation of unapproved apps, disallowing iTunes/USB pairing and unauthorized certificate or account installation, and restricting Wi-Fi/VPN configuration and iCloud backup/sync together isolate corporate data from personal use. ### Do all of these restrictions work on any iOS device? No, restrictions marked with an asterisk in the table require the device to be Supervised, and several also have minimum iOS version requirements such as 7.0 or 8.0 and later.