# Managing Apple Vision Pro (visionOS) Devices Mobile Device Manager Plus already supports comprehensive management of Apple devices across iOS, iPadOS, macOS, and tvOS platforms, enabling IT administrators to enroll, configure, secure, and monitor iPhones, iPads, Macs, and Apple TVs from a single console. With visionOS support, Apple Vision Pro devices can now be managed using the same familiar workflows. You can enroll Vision Pro devices, distribute configuration profiles, execute remote actions, manage apps, and track device inventory, all alongside your existing Apple fleet. This document covers all the management capabilities currently available for visionOS devices in Mobile Device Manager Plus. visionOS management leverages the same Apple Push Notification service (APNs) certificate and Apple Business Manager (ABM) integration that you already use for your iOS, iPadOS, macOS, and tvOS devices. No additional infrastructure setup is required to begin managing Vision Pro devices. ## Device Setup and Enrollment Apple Vision Pro devices can be enrolled and managed through the MDM console using the same enrollment methods available for other Apple platforms. The following enrollment methods are supported for visionOS devices: ### Apple Business Manager (ABM) Enrollment If your organization already uses [Apple Business Manager (ABM)](https://www.manageengine.com/mobile-device-management/help/enrollment/automated_device_enrollment.html) to enroll iPhones, iPads, Macs, or Apple TVs, the same integration now recognizes Vision Pro devices as well. When a Vision Pro device is purchased through authorized channels and linked to your ABM account, it is automatically assigned to your MDM instance. During the initial device setup, the device enrolls into Mobile Device Manager Plus without any manual configuration by the end user. This zero-touch enrollment process ensures that the device is corporate-managed and supervised from the moment it is unboxed, allowing policies and apps to be applied immediately. ### Account Driven Apple User Enrollment For organizations that allow employees to use personal Vision Pro devices for work (BYOD), [Account Driven Apple User Enrollment](https://www.manageengine.com/mobile-device-management/help/enrollment/mdm_apple_user_enrollment.html) is supported. Users can enroll their personal Vision Pro by signing in with their Managed Apple ID. This enrollment method creates a clear separation between personal and corporate data on the device. IT administrators can manage only the corporate partition, including distributing work apps and applying security policies, while the user's personal data, apps, and settings remain private and untouched. This is the same user enrollment workflow available for iPhones and iPads. ### Setup Assistant Customization When deploying Vision Pro devices at scale, you can streamline the out-of-box experience by choosing which setup screens to skip during initial device configuration. This is especially useful for corporate-owned devices where IT administrators want to minimize end-user interaction during setup. The skip settings system in Mobile Device Manager Plus has been redesigned to support a broader set of screens (up to 100), including visionOS-specific options such as: - Safety and Handling - Age Assurance - Camera Button - Action Button - Apple Intelligence - Spoken Language - OS Showcase In addition to these visionOS-specific screens, common setup screens such as Siri, Passcode, Apple ID, Privacy, Appearance, Screen Time, and others can also be configured to skip, similar to the setup assistant customizations available for [iOS, iPadOS, macOS, and tvOS devices](https://www.manageengine.com/mobile-device-management/help/enrollment/automated_device_enrollment.html). The redesigned setup assistant skip settings apply across all Apple platforms managed by Mobile Device Manager Plus, not only visionOS. ### Group Auto-Assignment Vision Pro devices can be automatically placed into specific [device groups](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_creating_groups.html) during enrollment, just like iPhones, iPads, and Macs. By defining group assignment rules based on device type or platform, you can ensure that Vision Pro devices are organized into the correct groups as soon as they enroll. This allows group-based policies, apps, and configurations to be applied immediately without requiring any additional manual intervention from the IT administrator. ## Configuration and Policies Mobile Device Manager Plus supports distributing configuration profiles to Vision Pro devices using the same [profile management](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_profile_management.html) workflow used for other Apple platforms. Profiles define the settings, restrictions, and configurations that are enforced on managed devices. ### Custom Configuration Profiles You can create, distribute, edit, and remove visionOS-specific custom configuration profiles to control device settings on Vision Pro devices. Custom profiles allow you to push Apple configuration payloads that are compatible with visionOS, giving you granular control over device behavior, network settings, security policies, and other system-level configurations. This follows the same approach used for [iOS/iPadOS custom profiles](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_custom_configuration_profiles.html) and [macOS custom profiles](https://www.manageengine.com/mobile-device-management/help/profile_management/mac/mdm_mac_custom_configuration_profiles.html). ### Personalized Profiles Profiles distributed to Vision Pro devices can automatically insert user-specific information using dynamic variables such as user name, email address, device name, and asset tag. This ensures each device receives a configuration tailored to its assigned user without requiring IT administrators to create separate profiles for each individual. For example, a Wi-Fi or VPN profile can automatically populate the user's credentials during distribution. ### Profile Compatibility Filtering When a visionOS-specific profile is distributed to a mixed group containing non-Vision Pro devices (such as iPhones, iPads, or Macs), Mobile Device Manager Plus automatically detects the incompatibility and skips those devices. A clear status message is displayed for each skipped device, ensuring that you have full visibility into which devices received the profile and which were excluded due to platform mismatch. ## Remote Device Actions IT administrators can perform remote actions on Apple Vision Pro devices directly from the MDM console, similar to the [remote management capabilities](https://www.manageengine.com/mobile-device-management/help/security_management/mdm_security_management.html) available for iPhones, iPads, and Macs. These actions help secure devices, troubleshoot issues, and manage the device lifecycle without requiring physical access. The following remote actions are supported for visionOS devices: | ACTION | DESCRIPTION | |---|---| | Remote View | Remotely view the screen of a Vision Pro device from the MDM console. This can be used for troubleshooting or verifying the device state without requiring the end user to describe what they see on the device. | | Passcode Reset | Remotely clear the device passcode to help end users who are locked out of their Vision Pro. Once the passcode is cleared, the user is prompted to set a new passcode on the device. | | Location Tracking | Request the current geographical location of a Vision Pro device. This is particularly useful for tracking corporate-owned shared devices or for locating a device that may be lost or misplaced. Location data is fetched using the same [geo-tracking](https://www.manageengine.com/mobile-device-management/help/security_management/location_tracking.html) framework used for other Apple devices. | | Return to Service | Remotely wipe the device and automatically re-enroll it into MDM in a single step. This is useful when re-provisioning or reassigning a Vision Pro to a new user. User-enrolled (BYOD) devices are excluded from this action. | | Device Rename | Remotely update the device name of a Vision Pro as it appears in the MDM console and on the device itself. This helps maintain consistent naming conventions across your managed device fleet. | | Device Identity Verification | Vision Pro devices support Apple's device attestation protocol, which allows the MDM console to cryptographically verify the identity and integrity of the device hardware. This helps confirm that a device reporting to the console is a genuine Apple device. | | Remote Wipe | Erase all content and settings on a Vision Pro device remotely. For ABM-enrolled supervised devices, a full device wipe is performed and the device returns to the setup assistant. For user-enrolled (BYOD) devices, only corporate data, apps, and profiles are removed, and personal data remains intact. | ## Declarative Device Management (DDM) Vision Pro devices running visionOS 1.1 or later support Apple's **Declarative Device Management (DDM)** protocol. DDM represents a shift from traditional MDM command-response workflows. In the traditional model, the MDM console sends commands and the device responds. With DDM, the device itself becomes proactive. It receives a set of declared configurations and autonomously applies them, monitors for changes, and reports its status back to the console without waiting for polling commands. This results in faster policy enforcement, reduced latency in configuration changes, and more reliable status reporting. Mobile Device Manager Plus supports DDM across Apple platforms including iOS 15+, iPadOS 15+, macOS 13+, and tvOS 16+. visionOS 1.1 and later extends this support to Vision Pro devices, ensuring consistent management behavior across your entire Apple fleet. ## App Management App management for Vision Pro follows the same workflow available for [iOS, iPadOS, and other Apple platforms](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_app_management.html) in Mobile Device Manager Plus. You can distribute, update, and manage apps on Vision Pro devices from the MDM console. ### App Distribution Apps available on the App Store that support the visionOS platform are automatically detected by Mobile Device Manager Plus and can be distributed to Vision Pro devices. When you add an app to the App Repository, the console identifies whether the app is compatible with visionOS and makes it available for distribution to Vision Pro device groups. Both free and Volume Purchase Program (VPP) licensed apps can be distributed using this workflow. ### Native Management App The ME MDM management app, which provides features such as location reporting, app catalog access, and device compliance checks on iPhones and iPads, is also distributed to Vision Pro devices. The app is automatically pushed to the device during enrollment and enables communication between the device and the MDM console for features that require an on-device agent. ## Inventory and Monitoring Vision Pro devices are fully integrated into the [asset management and inventory](https://www.manageengine.com/mobile-device-management/help/asset_management/mdm_asset_management.html) capabilities of Mobile Device Manager Plus. Device details, installed apps, applied restrictions, and compliance status are all tracked and accessible from the console. ### Automatic Device Identification When a Vision Pro device enrolls or reports in to the MDM console, it is automatically recognized and classified as a visionOS device. The device model, OS version, serial number, and other hardware attributes are captured during the initial device scan. No additional configuration is needed for Mobile Device Manager Plus to identify and categorize Vision Pro devices separately from iPhones, iPads, Macs, and Apple TVs. ### Installed App Inventory You can query and view all installed apps on Vision Pro devices from the device inventory page. The app inventory includes details such as app name, version, bundle identifier, and installation status. This is the same app inventory functionality available for iOS, iPadOS, and macOS devices, extended to support the visionOS platform. ### Device Restrictions Scanning Security restrictions applied to Vision Pro devices, such as passcode policies, app restrictions, and other configuration enforcements, are inventoried during periodic device scans. This allows IT administrators to verify that compliance policies are correctly applied and to identify any deviations across the managed Vision Pro fleet. ### Reports and Filters All device lists, enrollment views, and [reports](https://www.manageengine.com/mobile-device-management/help/reports/reports.html) in Mobile Device Manager Plus can be filtered by **visionOS** as a platform and **Vision Pro** as a device type. This enables you to generate platform-specific reports, view enrollment status for Vision Pro devices, and export device data for visionOS alongside or separately from your other Apple device reports. ## Dashboard and Analytics The Mobile Device Manager Plus dashboard provides a consolidated view of all managed devices, including Vision Pro. visionOS data is integrated into the existing dashboard charts and metrics, giving you a unified overview of your entire device fleet. ### Platform Breakdown Charts visionOS appears as its own category in device platform breakdown charts on the dashboard, displayed separately from iOS, iPadOS, macOS, tvOS, Android, Windows, and Chrome OS. This allows you to quickly see how many Vision Pro devices are managed relative to your total device count. ### Device Type Breakdown Vision Pro is shown as a distinct device type in device type breakdown charts, alongside phones, tablets, laptops, desktops, and TVs. This categorization helps you track the composition of your managed device fleet at a glance. ### Usage Tracking Key metrics for visionOS devices, including managed and unmanaged device counts, active device counts, and profile distribution status, are tracked on the dashboard. These metrics follow the same structure used for other platforms, ensuring that Vision Pro devices are included in your overall device management reporting and compliance monitoring workflows.