Skip to content

DDM — Unknown Configuration Error or Cannot Be Applied

A DDM (Declarative Device Management) configuration is assigned to an iOS device, but the device reports one of these statuses:

  • Unknown DDM configuration error
  • Cannot be applied

The configuration saves without issue in CapaOne, but the device doesn’t apply it.

Each DDM configuration type in CapaOne maps to an Apple declaration. The device checks each declaration it receives and reports whether it’s valid. If the device rejects a declaration, the configuration doesn’t apply.

The most common cause is the iOS version. Each declaration has a minimum iOS version, and many only work on supervised devices. A device that doesn’t meet these requirements rejects the declaration.

The iOS version isn’t the only cause. A device can meet the minimum iOS version and still reject a configuration, for example because of the configuration’s settings or another configuration assigned to the same device.

Start by checking the requirements for the configuration type. If the device meets them, continue with The device meets the minimum iOS version but the configuration still fails.

Check the minimum iOS version and management mode

Section titled “Check the minimum iOS version and management mode”
  1. Identify which DDM configuration type the configuration uses, for example App Settings or Passcode Settings.
  2. Look up the type’s minimum iOS version and whether it works on unsupervised devices in DDM Configuration Types Reference.
  3. Open the affected device under Apple → Endpoints. Check its iOS version and whether it’s supervised.

If the device runs an older iOS version than required, the configuration usually applies once the device updates. You don’t need to reassign or recreate it. If it still fails after the update, continue with the next section.

If the configuration type needs a supervised device and the device is unsupervised, updating iOS doesn’t help. The device must be enrolled as supervised through Apple Business Manager. See Endpoint Management Modes.

The device meets the minimum iOS version but the configuration still fails

Section titled “The device meets the minimum iOS version but the configuration still fails”

If the device runs a supported iOS version and is supervised where required, check the following:

  1. The status reason reported by the device. When a device rejects a declaration, it can report an error code and a description that explain why. Note them down, because support needs them.
  2. Settings the device doesn’t support. Some settings in a declaration only work on some platforms. For example, the Accessibility permission and the allowed and denied binaries lists in App Settings are macOS only. Check the known limitations for the type in DDM Configuration Types Reference, and remove settings that don’t apply to iOS.
  3. Conflicting configurations. Check which other DDM and Legacy configurations are assigned to the device and control the same thing. Some declaration types are combined on the device. For example, if several App Settings configurations have an allowed apps list, only apps that are in every list stay allowed.
  4. Configuration priority. If several configurations cover the same device, check their priority values. See Configuration Priority.

If the configuration still fails, contact CapaOne support. Include:

  • The configuration’s name and type.
  • The affected devices, their iOS version, and whether they’re supervised.
  • The status and the status reason the devices reported.

The App Settings declaration requires iOS 27 or later, and it only works on supervised devices. Devices on iOS 26 or earlier reject it.

A supervised device on iOS 27 meets these requirements. If an App Settings configuration still fails on such a device, the iOS version isn’t the cause. Follow The device meets the minimum iOS version but the configuration still fails.

The Privacy settings in App Settings don’t grant permissions to an app on their own. They set permission defaults that the user must accept. According to Apple:

  • When the app starts, the device shows a consent prompt that lists the configured permissions and your organization’s justification.
  • If the user selects Allow, the device applies the defaults. If the user selects Not Now, the app asks for each permission in the normal way.
  • The prompt only lists permissions the user hasn’t seen before. If the user has already seen all of them, the prompt doesn’t appear.
  • The user can change the permissions later in Settings.

On iOS, you can set defaults for Location (WhileUsing or Always), Location accuracy, Bluetooth, Camera, Dictation, Local network, and Microphone. Source: Apple’s App Settings declaration.

  • The iOS version is the most common cause, not the only one — check the minimum iOS version first. If the device meets it, check the configuration’s settings and other assigned configurations.
  • Different declarations have different requirements — check the minimum iOS version and whether the type needs a supervised device before troubleshooting further.
  • Other configurations are unaffected — a DDM declaration that is unsupported on a device does not affect other configurations assigned to the same device.
  • Version-related errors usually clear after an update — once the device updates to a supported iOS version, the configuration usually applies without reassigning or recreating it.