Skip to content

Apple DDM

Apple Declarative Device Management (DDM) is Apple’s modern device management protocol. Instead of CapaOne sending a command and waiting for the device to respond, the device evaluates a set of declarations locally and reports status changes back on its own.

Apple is phasing out the traditional command-and-response MDM protocol in favor of DDM, starting with devices running iOS 17 and later.

  • Faster, more reliable configuration — declarations apply and reconcile on the device itself, without waiting on a round trip to the server.
  • Software update management moves to DDM on iOS 27 — as of iOS 27, Legacy MDM’s software update commands, software update queries, recommended cadence settings, and restrictions like deferrals and Background Security Improvements (BSI) no longer function. These commands don’t error — they silently stop applying. Move software update policy to DDM’s Software Update Settings and Software Update Enforcement Specific configuration types before deploying iOS 27 to your fleet. See iOS 27 and Software Update Management.
  • Runs alongside Legacy MDM during the transition — CapaOne supports both protocols, so you can migrate devices at your own pace instead of all at once.
  • iOS 27 devices move to DDM automatically — CapaOne automatically switches a device from Legacy MDM to DDM once it reports iOS, iPadOS, or macOS 27 or later, whether it’s already on version 27 today or updates to it later. You don’t need to request Enable Apple DDM for these devices — but this also means any DDM configuration you rely on (especially software update policy) must be in place before the device updates, not after.

CapaOne’s DDM tab supports both Supervised and Unsupervised (BYOD) Apple devices running iOS or iPadOS 17 or later, or macOS 14 or later — the same management-mode split as Legacy MDM. DDM is only partially available on Unsupervised devices: which declarations apply depends on the device’s iOS version and the specific declaration, not on management mode alone. See Apple’s declarative configurations guide for the full breakdown of which declarations need Supervised mode.

Configurations built for DDM live under their own DDM tab in Apple → Configurations, separate from your existing Legacy configurations — so nothing changes for devices you haven’t migrated yet.

Clicking New under Apple → Configurations → DDM opens the Select a configuration type picker, listing every available type as a flat, alphabetically sorted grid — CapaOne doesn’t group them by category in the picker itself. The table below groups them by category for reference, so you can check whether a configuration type exists without opening the picker. For setup details on any individual type, see DDM Configuration Types Reference.

Select a configuration type dialog showing the Configurations tab with DDM configuration types such as Account CalDAV, App Settings, Passcode Settings and Safari Settings

Category Configuration types
Account Account CalDAV, Account CardDAV, Account Exchange, Account Google, Account LDAP, Account Mail
Network Network DNS Proxy, Network DNS Settings, Network Relay, Network VPN Always On, Network VPN IKEv2, Network VPN IPSec, Network VPN Plugin
Security Security Certificate, Security Identity, Passcode Settings, Extensible SSO
Software Update Software Update Settings, Software Update Enforcement Specific
Intelligence & AI External Intelligence Settings, Intelligence Settings, Siri Settings
Apps & content App Settings, Content Caching, Safari Bookmarks, Safari Extension Settings, Safari Settings, Web Content Filter Plugin
Device & input Audio Accessory Settings, Keyboard Settings, Math Settings
Legacy bridge (Supervised only) Home Screen Layout

The Network types, Extensible SSO, App Settings, Content Caching, and Web Content Filter Plugin require iOS, iPadOS, or macOS 27 or later. See the minimum versions in the DDM Configuration Types Reference.

External Intelligence Settings controls third-party AI integrations in Apple Intelligence, such as ChatGPT. To restrict Siri, use Siri Settings. To restrict Apple Intelligence features, use Intelligence Settings. See Apple Intelligence, Siri and External AI Controls for every setting, and Apple’s iOS 27 enterprise release notes for the platform-level behavior.

Assets: a second category alongside configurations

Section titled “Assets: a second category alongside configurations”

Apple → Configurations → DDM → New has two tabs: Configurations and Assets. An asset isn’t a configuration by itself — it’s a reference to a credential, identity, or piece of data that a configuration can point to. For example, a Security Identity configuration references an Asset Credential Identity or Asset Credential SCEP asset instead of embedding certificate material directly.

Select a configuration type dialog showing the Assets tab with the seven DDM asset types

The Assets tab includes:

  • Asset Credential ACME — a reference to an ACME identity.
  • Asset Credential Certificate — a reference to a PKCS #1 or PEM encoded certificate.
  • Asset Credential Identity — a reference to a PKCS #12 password-protected identity.
  • Asset Credential SCEP — a reference to a SCEP identity. See SCEP in CapaOne for background on how SCEP issues certificates.
  • Asset Credential User Name And Password — a reference to data that describes a credential representing a username and password.
  • Asset Data — a reference to arbitrary data with a specific media type.
  • Asset User Identity — the user-identity data.

See DDM Assets for what each asset type is for and how to reference one from a configuration.

  • DDM and Legacy MDM can coexist — a device runs under one protocol at a time, but your organization can have devices on both while you migrate.
  • Not every configuration needs to move immediately — Legacy configurations that Apple hasn’t deprecated keep working. Prioritize recreating configurations that are deprecated or unsupported under DDM. See Legacy MDM to DDM Mapping for the list.
  • Legacy configurations can be delivered as declarative assets — Apple can bridge a Legacy MDM profile into DDM by delivering it as a declarative asset, without a native DDM equivalent existing yet. Home Screen Layout is a live example in CapaOne: it’s labeled Supervised only and is delivered as a legacy MDM profile declaration under the hood.
  • Set up Apple MDM first — DDM builds on the same push certificate, Apple Business Manager (DEP), and enrollment already configured for Apple MDM. See that section if you haven’t enrolled Apple devices in CapaOne yet.
  • Seeing an unexpected error on a DDM configuration? See DDM — Unknown Configuration Error or Cannot Be Applied, DDM Status Reason Codes, or DDM Software Update Not Installing.