Skip to content

DDM Configuration Types Reference

This reference lists every configuration type available under Apple → Configurations → DDM → New, on the Configurations tab. For asset types (the Assets tab in the same picker), see DDM Assets.

Select a configuration type dialog showing the Configurations tab with DDM configuration types such as Account CalDAV, App Settings, Passcode Settings and Safari Settings

The picker itself lists every type alphabetically, in a single grid — the categories below are groupings for this reference, not a distinction CapaOne’s UI makes. The picker shows a Supervised only label on Home Screen Layout. Supervised only means the configuration has no effect on Unsupervised (BYOD) devices; see Endpoint Management Modes for the Supervised/Unsupervised split.

  • Minimum iOS — the oldest iOS or iPadOS version that supports the declaration. A device on an older version rejects the configuration. See DDM — Unknown Configuration Error or Cannot Be Applied.
  • Unsupervised — whether the declaration works on devices enrolled without supervision (device enrollment). No means it only works on supervised devices, even when the picker doesn’t show a Supervised only label.
  • Notes — what the type is for, and known limitations.

The minimum versions and limitations come from Apple’s device management schema, checked in September 2026.

Configuration type Minimum iOS Unsupervised Notes
Account CalDAV 15.0 Yes Configure a Calendar account.
Account CardDAV 15.0 Yes Configure a Contacts account.
Account Exchange 15.0 Yes Configure an Exchange account.
Account Google 15.0 Yes Configure a Google account.
Account LDAP 15.0 Yes Configure a Lightweight Directory Access Protocol (LDAP) account.
Account Mail 15.0 Yes Configure a Mail account.
Configuration type Minimum iOS Unsupervised Notes
Network DNS Proxy 27.0 Yes Configure a DNS proxy using a Network Extension app. Replaces the Legacy DNS Proxy payload, which Apple deprecated in iOS 27.
Network DNS Settings 27.0 Yes Configure encrypted DNS settings (DNS over HTTPS or TLS). Replaces the Legacy DNS Settings payload, which Apple deprecated in iOS 27. On unsupervised devices, the settings only apply to managed networks. On supervised devices, they apply to all networks.
Network Relay 27.0 Yes Configure network relay servers to route traffic for specific domains. Replaces the Legacy Relay payload, which Apple deprecated in iOS 27.
Network VPN Always On 27.0 Yes Configure an Always On VPN that keeps the device continuously connected.
Network VPN IKEv2 27.0 Yes Configure a VPN connection using the IKEv2 protocol.
Network VPN IPSec 27.0 Yes Configure a VPN connection using the IPSec protocol.
Network VPN Plugin 27.0 Yes Configure a VPN connection using a third-party VPN plugin or Network Extension provider.
Configuration type Minimum iOS Unsupervised Notes
Security Certificate 17.0 Yes Add a certificate to the device. Can be paired with an asset — see DDM Assets.
Security Identity 17.0 Yes Install an identity on the device.
Passcode Settings 15.0 Yes Configure passcode policy settings. Replaces the Legacy Passcode payload, which Apple deprecated in iOS 27. Assigning it makes the device ask the user to set a passcode.
Extensible SSO 27.0 Yes Configure Extensible Single Sign-On for apps and the platform.
Configuration type Minimum iOS Unsupervised Notes
Software Update Settings 18.0 Yes Configure software updates. Required on iOS 27 in place of Legacy MDM software update management — see iOS 27 and Software Update Management. Deferrals, automatic downloads and installs, Background Security Improvements, and beta enrollment only work on supervised devices.
Software Update Enforcement Specific 17.0 Yes A software update enforcement policy for a specific OS release. If the target version isn’t an available update, the configuration stays active but the device doesn’t update. A supplemental update, such as 16.1 (a), only installs on a device that already runs the base version.
Configuration type Minimum iOS Unsupervised Notes
External Intelligence Settings 26.4 No Configure External Intelligence Integrations settings. Controls third-party AI integrations in Apple Intelligence, such as ChatGPT. Maps to Apple’s com.apple.configuration.external-intelligence.settings.
Intelligence Settings 26.4 No Configure Apple Intelligence settings: Apple Intelligence, summarization, Writing Tools, Image Playground, Genmoji, and the ChatGPT integration.
Siri Settings 26.4 No Configure Siri settings: whether Siri is on, Siri while locked, user-generated content, and the profanity filter.
Configuration type Minimum iOS Unsupervised Notes
App Settings 27.0 No Configure app privacy permission defaults and allowed/denied app and binary lists. See App Settings limitations.
Content Caching Not supported on iOS — Configure the Content Caching service on macOS. Requires macOS 27.0.
Safari Bookmarks 26.0 Yes Configure managed bookmarks in Safari.
Safari Extension Settings 18.0 No Configure Safari Extensions. If a domain is in both the allowed and denied lists, Safari denies it.
Safari Settings 26.0 Yes Configure Safari settings. Most settings require a supervised device. On unsupervised devices, only the new-tab start page applies. Website privacy permission defaults, such as camera and microphone, only apply after the user accepts a consent prompt.
Web Content Filter Plugin 27.0 Yes Configure web content filtering using a third-party Network Extension plugin.
  • Privacy permissions are defaults, not grants. When the app starts, the device shows a consent prompt. The defaults only apply if the user selects Allow. If the user selects Not Now, the app asks for each permission in the normal way. The user can change the permissions later in Settings.
  • The prompt only covers permissions the user hasn’t seen. If the user has already seen all the configured permissions for the app, the prompt doesn’t appear.
  • Permissions available on iOS: Location (WhileUsing or Always), Location accuracy, Bluetooth, Camera, Dictation, Local network, and Microphone.
  • macOS-only settings: the Accessibility permission, the allowed and denied binaries lists, and Always allow managed apps don’t apply on iOS.
  • Several App Settings configurations are combined. If more than one allowed apps list applies to a device, only apps that are in every list stay allowed. Apps in any denied apps list stay denied.
  • Denying system apps can disable other features. For example, denying the App Store can stop users from accepting the terms for user-based Volume Purchase Program (VPP) apps.
Configuration type Minimum iOS Unsupervised Notes
Audio Accessory Settings 26.0 No Configure audio accessory settings. Turning off temporary pairing doesn’t stop users from pairing their own audio accessories.
Keyboard Settings 26.4 No Configure keyboard settings: auto-correct, auto-capitalization, dictation, math keyboard suggestions, predictive text, slide to type, spell checking, and text replacement.
Math Settings 18.0 No Configure the math and calculator apps.
Configuration type Minimum iOS Unsupervised Notes
Home Screen Layout 15.0 No Supervised only. Configure the Home Screen layout for the device — delivered as a legacy MDM profile declaration under the hood, a bridging mechanism for configurations without a native DDM equivalent yet.
  • This list reflects the picker as of today — Apple and CapaOne both add configuration types over time. If a type you expect isn’t listed here, check the live picker at Apple → Configurations → DDM → New.
  • Meeting the minimum iOS version doesn’t guarantee a configuration applies — if a supported device still rejects a configuration, see DDM — Unknown Configuration Error or Cannot Be Applied.
  • Not every configuration needs an asset — most types in this list are self-contained. Only reach for DDM Assets when a configuration needs to reference a credential, identity, or stored data.