Skip to content

Configure Accounts with DDM

The DDM Account configuration types set up accounts in Mail, Calendar, Contacts, Reminders, and Notes. Unlike Legacy account profiles, they don’t embed user details or passwords directly — they point to assets that hold them. This article shows which assets each account type uses, and walks through the most common setup: an Exchange account.

Account type User identity (name, email) Username and password Certificate identity
Account Exchange Asset User Identity Asset Credential User Name And Password Asset Credential Identity
Account Mail Asset User Identity Asset Credential User Name And Password (incoming and outgoing server, separately) —
Account Google Asset User Identity (required) — —
Account CalDAV — Asset Credential User Name And Password —
Account CardDAV — Asset Credential User Name And Password —
Account LDAP — Asset Credential User Name And Password —

Exchange and Mail can also use identity assets for S/MIME signing and encryption on iOS 17 and later.

To fill in per-user values, use macros in the configuration and asset values, such as $user.fullName$, $user.email$, and $user.userPrincipalName$. Point to Supported Macros in the editor to see the list. See Apple MDM Configuration Types.

This example creates an Exchange account that uses modern authentication (OAuth) with Exchange Online — the typical setup for Microsoft 365.

  1. Navigate to Apple → Configurations → DDM and click New.

  2. Switch to the Assets tab and select Asset User Identity.

  3. Enter the user’s Full Name and Email Address. Use macros, for example $user.fullName$ and $user.email$ or $user.userPrincipalName$, to fill them in per user.

    New Asset User Identity with the Full Name and Email Address fields

  4. Save the asset, for example as DDM - Asset - User Identity.

  1. Navigate to Apple → Configurations → DDM and click New.
  2. On the Configurations tab, select Account Exchange.
  3. Fill in the fields:
Field Value for Exchange Online Notes
Visible Name Work The account name users see.
Enabled Protocol Types (required) Exchange ActiveSync (EAS) Select Exchange ActiveSync (EAS) for iPhone and iPad. Mac uses Exchange Web Services (EWS). You can select both, in order of preference.
Host Name outlook.office365.com
User Identity Asset Reference DDM - Asset - User Identity Fills in the user’s name and email address.
OAuth → Enabled Yes Uses modern authentication. The user signs in once with their Microsoft account.
OAuth → Sign In URL Leave empty Only needed for custom identity providers. When set, the device doesn’t use autodiscovery.
Mail / Contacts / Calendar / Reminders / Notes Service Active Yes / Yes / Yes / Yes / No Which services the account syncs. All are on by default.
Lock Mail / Contacts / Calendar Service Yes Prevents the user from turning a service off. iOS only, EAS only.

New DDM Account Exchange configuration with asset references, service switches, Enabled Protocol Types and Host Name

  1. Save the configuration, select the Assignment tab, and assign it to your group.

The user sees a sign-in prompt for the account the first time they open Mail.

For on-premises Exchange with certificate authentication:

  1. Create an Asset Credential Identity with the user’s PKCS #12 file. Check that the asset is offered in Authentication Identity Asset Reference. SCEP and ACME assets aren’t offered for this field.
  2. In the Exchange configuration, leave OAuth off and set Authentication Identity Asset Reference to that asset.
  3. Set Host Name to your Exchange server.
  1. Create an identity asset for signing and, if needed, one for encryption.
  2. In the Exchange configuration, open S/MIME → Signing, set Enabled to Yes, and select the asset in Identity Asset Reference.
  3. Open S/MIME → Encryption, set Enabled to Yes, and select the asset in Identity Asset Reference. Set Per-Message Switch Enabled to Yes if users should be able to choose per message.

S/MIME in DDM is supported for EAS accounts on iPhone and iPad only.

Field Required What to enter
Visible Name No Account name users see.
User Identity Asset Reference No Asset User Identity with name and email.
Incoming Server → Server Type Yes IMAP or POP.
Incoming Server → Host Name Yes For example imap.example.com. The Port field can’t be set in CapaOne today, so the device uses the default port for the server type.
Incoming Server → Authentication Method Yes None, Password, CRAMMD5, NTLM, or HTTPMD5.
Incoming Server → Authentication Credentials Asset Reference Required unless the method is None Asset Credential User Name And Password. Leave it empty when Authentication Method is None.
Incoming Server → IMAP Path Prefix No IMAP only.
Outgoing Server → Host Name / Authentication Method Yes For example smtp.example.com. The Port field can’t be set in CapaOne today.
Outgoing Server → Authentication Credentials Asset Reference Required unless the method is None Can be the same asset as incoming.
Field Required What to enter
Visible Name No Account name users see.
Host Name Yes Server host name or IP address.
Port No For example 443.
Path No The principal URL path, if your server needs it.
Authentication Credentials Asset Reference No Asset Credential User Name And Password.
Field Required What to enter
Visible Name No Account name users see.
Host Name Yes LDAP server host name or IP address.
Port No For example 636 for LDAPS.
Authentication Credentials Asset Reference No Asset Credential User Name And Password, for servers that don’t allow anonymous binds.
Search Settings Recommended One or more search bases, for example ou=people,dc=example,dc=com, with a scope of Base, One level, or Subtree (default). macOS only uses the first one.
Field Required What to enter
Visible Name No Account name users see.
User Identity Asset Reference Yes Asset User Identity with the user’s Google email address. The user signs in to Google on the device.
  • Accounts apply side by side — Account types are multiple types, so two configurations create two accounts. Assign each account from one group only. See How Multiple DDM Configurations Combine.
  • Change the asset, not the account — updating a password or certificate asset updates every account that references it, without recreating the account.
  • Removing the configuration removes the account — including its locally synced mail, contacts, and calendars on the device. Data stays on the server.
  • EWS settings are Mac only — path and external host settings for EWS are ignored on iPhone and iPad. The Port and External Port fields can’t be set in CapaOne today.
  • Source: Apple’s Account declarations in the device management schema (Release v27.0).