macOS Restrictions

License: Gold

macOS restrictions determine which restrictions are enabled on macOS devices.

You can set the following features to be enabled or disabled on macOS devices:

macOS Version Features
macOS 10.11+

 

  • Allow Camera
  • Allow iCloud Document Sync

Supervised only:

  • Allow Spotlight Internet Results

macOS 10.11.2+

 

  • Allow Definition Lookup

macOS 10.12+

 

  • Allow iCloud Keychain Sync
  • Allow Back to my Mac
  • Allow Find my Mac
  • Allow sharing to Notes, Reminders, or LinkedIn
  • Allow Bookmark Sync
  • Allow macOS mail iCloud Service
  • Allow macOS iCloud Calendar Service
  • Allow macOS iCloud Address Book Service
  • Allow iCloud Reminder Service
  • Allow Auto Unlock

Supervised only:

  • Allow Apple Music

macOS 10.12.4+

 

  • Allow Finger Print for Unlock

macOS 10.13+

 

  • Allow iTunes File Sharing
  • Allow Content Caching
  • Allow modification of Wallpaper

Supervised only:

  • Allow AirPrint
  • Allow AirPrint iBeacon Discovery
  • Force AirPrint Trusted TLS Requirement
  • Allow AirDrop

  • Allow Game Center

macOS 10.13.4+

 

Supervised only:

Defer software updates for a range of days (30 to 90 days)

Default: 30 days.

macOS 10.14+

 

Supervised only:

Allow nearby devices to share requests for a password

macOS 10.14.4+

 

  • Allow Screenshots
  • Allow remote screen observation

Supervised only:

  • Allow automatically to join classroom
  • Allow classroom to request permission to leave classes
  • Allow classroom to lock an app and lock the device without prompting
  • Allow force unprompted managed classroom screen observation

macOS 11.0+

Supervised only:

Allow to force delay App Software Updates

macOS 11.3+

Enforced Fingerprint timeout

Default: 48 hours

Prerequisite: Touch ID must be configured on the device

macOS 11.3+

Supervised only:
  • Enforced Software Update Major OS Deferred Install Delay
  • Enforced Software Update Minor OS Deferred Install Delay
  • Enforced Software Update Non OS Deferred Install Delay
  • Force Delayed Major Software Updates

macOS 12+

  • allowCloudPrivateRelay: If you set the Private Relay ON in a macOS device, the network traffic is encrypted so that the internet activity is private and secure. This restriction requires a supervised device.
  • Allow iCloud Photo Library

Supervised only:

  • Allow Erase Content and Settings
macOS 13.0+

 

  • Allow Rapid Security Response Installation: To disable the responses. The user cannot install rapid security responses.
  • Allow Rapid Security Response Remova: To block the user from being able to undo the responses. The user cannot remove rapid security responses.
  • Allow Universal Control:
    • If True, the configuration lets you use the input devices of the primary device to control the secondary display device.
    • If False, you can add a secondary display device but cannot control it with the primary input devices.

Supervised only:

  • Allow UI Configuration Profile Installation: If False, the configuration does not allow the installation of profile, configuration, or certificates on the macOS device.
  • Allow USB Restricted Mode: If True, the configuration locks the device from using remotely connected input devices. The Allow Accessories to Connect options are greyed out on the device.

macOS 14.0+

 

  • Allow ARD Remote Management Modification

    • If False, prevents modifying the Remote Management Sharing setting in System Settings.

    • Default: true

  • Allow Bluetooth Sharing Modification

    • If false, prevents modifying Bluetooth setting in System Settings.

    • Default: true

  • Allow Cloud Freeform

    • If false, disallows iCloud Freeform services.

    • Default: true

  • Allow File Sharing Modification

    • If false, prevents modifying File Sharing setting in System Settings.

    • Default: true

  • Allow Internet Sharing Modification

    • If false, prevents modifying Internet Sharing setting in System Settings.

    • Default: true

  • Allow Local User Creation

    • If false, prevents creating new users in System Settings.

    • Default: true

  • Allow Printer Sharing Modification

    • If false, prevents modifying Printer Sharing setting in System Settings.

    • Default: true

  • Allow Remote Apple Events Modification

    • If false, prevents modifying Remote Apple Events Sharing setting in System Settings.

    • Default: true

  • Allow Siri

    • Default: true

  • Allow Startup Disk Modification

    • If false, prevents modification of Startup Disk setting in System Settings.

    • Default: true

  • Allow Time Machine Backup

    • If false, prevents modification of Time Machine settings in System Settings.

    • Default: true

Supervised only:

  • Allow account modification

    • If false, prevents account modification.

    • Default: true

  • Allow modifying Device Name

    • If false, prevents changing the Device Name.

    • Default: true

  • Allow modifying TouchID fingerprints

    • If false, prevents from modifying Touch ID fingerprints.

    • Default: true

macOS 15.0+

 

Supervised only:

  • Allow Genmoji

    • Select to allow the creation of Genmojis.

    • Default: true

  • Allow Image Playground

    • Select to allow the use of image generation.

    • Default: true

  • Allow iPhone Mirroring

    • Select to allow the iPhone to mirror in a macOS device.

    • Default: true

  • Allow Writing Tools

    • Select to enable Apple Intelligence writing tools.

    • Default: true

macOS 15.1+

 

Supervised only:

  • Allow Mail Summary

    • Select to allow the creation of summaries of email messages manually.

    • Default: true

  • Allow Media Sharing Modification

    • Select to allow the modification of Media Sharing Settings.

    • Default: true

macOS 15.2+

 

Supervised only:

  • Allow External Intelligence Integrations

    • Select to enable the use of external cloud-based intelligence services with Siri.

    • Default: true

  • Allow External Intelligence Integrations Sign-In

    • Select to enable default browser preference modification. The Ivanti Neurons for MDM settings command to set the default browser preference will still work when this is applied.

    • Default: true