Mac Restrictions

Restrictions lets you force enable/disable essential device functionality settings, security settings, iCloud settings, and Classroom settings on managed mac machines, according to your organization's requirements. This is to achieve higher productivity, without compromising on data security.

The status of restrictions imposed using Endpoint Central will be shown under 'Device Details' view. When no restrictions are set on a mobile device using Endpoint Central, then by default, the status will be displayed as 'Allowed'.

Configuration Description

Configuration SettingsSupported macOS VersionDescription
DEVICE FUNCTIONALITY
Camera10.11 and aboveCamera can be completely restricted along with FaceTime.
Screenshot and Screen Recording10.14.4 and aboveAllowing users to capture the screenshot of the display.
Spotlight Internet Search10.11 and aboveAllowing users to use Spotlight Search to find content directly from internet.
Airdrop10.13 and aboveAllow/Restrict sharing of documents, media etc., using AirDrop to other devices. If Bluetooth is disabled via restrictions, AirDrop gets automatically disabled as well.
Content caching10.13 and aboveAllow content caching to be setup for downloading the content from the nearest machines instead of the Apple Services
Dictionary word lookup10.11.2 and aboveAllowing the built-in mac dictionary to retrieve words.
Music10.12 and aboveDisabling Apple Music on user's Mac
Auto unlock devices with Apple Watch10.12 and abovePrevent users from using their paired Apple Watch to automatically unlock their Mac.
Handoff10.12 and aboveEnabling this option will allow you to resume an existing work/access a content from any device which is logged in using the same icloud account.
Siri11 and aboveAllow/Restrict the usage of Siri.
Allow user to modify wallpaper10.13 and aboveAllow/Restrict the user from modifying the wallpaper of the device.
Universal Control13 and aboveBy Restricting Universal Control, users cannot work with the same accessories like keyboard, mouse etc for multiple devices.
SECURITY
Use bio-metric methods such as TouchID and/or FaceID to unlock devices10.12.4 and aboveAllowing user to unlock the device using fingerprints/facial recognition
iTunes File Sharing10.13 and abovePrevent users from using iTunes to share content between their Apple devices.
Autofill passwords in Safari and apps10.14 and abovePrevent autofill in browsers and apps.
Share passwords with devices in proximity10.14 and aboveRestricting this setting will ensure that the device is not notified to share it's passwords with devices in proximity.
Request passwords from devices in proximity10.14 and aboveRestricting this setting will ensure that the device cannot request devices in proximity to share their passwords.
Configure Gatekeeper to allow downloads only from10.8 and aboveGatekeeper is a security feature that verifies downloaded apps before running them on Mac machines. Admin can select the type of apps that should be allowed to run on the Mac. Admins can choose from App Store, App Store and identified developer, or even unidentified sources.
Allow users to override Gatekeeper settings10.8 and aboveRestricting this setting will ensure the users do not override Gatekeeper settings configured by the admin.
Allow users to wipe device by erasing all content and settings (supported only on devices with Apple Silicon or T2 security chip)12 and aboveRestricting this will prevent users from resetting the devices.
iCLOUD
Sync data & documents from managed apps10.11 and aboveEnabling the syncing of all managed apps.
Sync Keychain10.12 and aboveEnabling Keychain data such as accounts, passwords and credit card information on a device to be synced and kept up-to-date.
Sync Desktop & Documents10.12.4 and aboveAllowing users to sync the files on their Desktops and Documents folders
Sync Bookmarks10.12 and aboveAllowing users to sync their browser Bookmarks with iCloud
Sync Mail10.12 and aboveAllowing users to sync their mails with iCloud
Sync Notes10.12 and aboveAllowing users to sync their notes with iCloud
Sync Calender10.12 and aboveAllowing users to sync their calender with iCloud
Sync Reminders10.12 and aboveAllowing users to sync their reminders with iCloud
Sync Contacts10.12 and aboveAllowing users to sync their contacts with iCloud
Sync Photo Library10.12 and aboveAllow users to sync their photos with iCloud
Allow iCloud in Private Relay12 and aboveAllowing Private relay hides IP address and Safari browsing activity of users from websites, network providers and Apple.
CLASSROOM (Applicable if Classroom 2.0 app is installed on the Teacher devices)
Automatically join classes without prompting10.14.4 and aboveEnabling this ensures the student devices mandatorily auto-join the classes, without any notification/prompt on the device.
Allow teachers device to lock apps and devices without prompting10.14.4 and aboveEnabling this ensures the teacher can either fully lock the student device or lock specific apps on the device, without any notification/prompt on the device.
Allow AirPlay and screen viewing by teachers device10.14.4 and aboveEnabling this allows the teacher to view the student device screen, after notifying/requesting permission s to do the same from the user.
Allow teachers device to AirPlay and view screen without prompting10.14.4 and aboveEnabling this allows the teacher to view the student device screen, without any notification/prompt on the device.
Teacher's permission required before leaving a classroom10.14.4 and aboveA student must request permission from the teacher before leaving a classroom.
APPLICATIONS
Game Center10.13 and aboveAllow/Restrict the usage of Game Center.
Download iBooks Content11 and aboveAllow/Restrict users from downloading content from iBooks Store.
Erotic Content11 and aboveAllow/Restrict users from downloading media which is tagged as erotic from iBooks. To configure this, Download iBooks content should be enabled.
NETWORK AND ROAMING
Modify Bluetooth-Allow/Restrict users from modifying Bluetooth. If Bluetooth is disabled via restrictions, AirDrop gets automatically disabled as well.
Set Bluetooth on Devices10.13.4 and aboveBluetooth can be restricted to always On/Off state. To configure this, Modify Bluetooth should be enabled.
PRIVACY
Find my friends11 and aboveAllow/Restrict users from configuring Find My Friends in the Find My app.
Find my device11 and aboveAllow/Restrict users from configuring Find My Device in the Find My app.
CONTENT RATINGS
Enable ratings by region-Enable/Disable ratings by region.
KEYBOARD SETTINGS
Dictation10.13 and aboveAllow/Restrict use of Dictation from the keyboard(s).

Trusted by