DDM App Management Settings

In general, App Management includes the following settings:

  • Prevent backup to iCloud

  • Do not install app on newly enrolled devices

  • Cellular 5G

  • DNS Proxy

  • Managed app config

  • Business apps – Apps@Work, Email+, etc.

  • Per app VPN

  • Network relay

  • Webcontent filter

  • Allow Appstore updates

In addition to the above listed settings, DDM App Management introduces several capabilities that are available only for DDM-managed devices.

App Version Pinning

App Version Pinning allows administrators to deploy and maintain a specific application version across DDM-managed devices.

When Version Pinning is enabled:

  • Devices install the specified application version.

  • Automatic upgrades to newer versions are prevented.

  • Applications remain on the assigned version until a new version is explicitly selected by an administrator.

This capability enables tighter control over application version consistency and staged upgrade deployments.

Procedure

  1. Go to Apps > App Catalog.

  2. Click an app from the displayed list. The App Details page opens.

  3. Under the App Configurations tab, click Apple App Settings.

  4. Click on any of the listed existing settings.

  5. Click Edit.

  6. Under the Pin app version to a device section, select the Pin app version option.

  7. From the Select app version list, select the required app version.

    If the device has an existing version of the app, you cannot replace it with an older version.

  8. Click Update.

Automated App Store Update Controls (Automatic App Update)

Administrators can configure how App Store updates are handled for managed applications. This capability provides greater control over application update behaviour and helps organizations align updates with internal validation and rollout processes.

Allow Downloads via Cellular

DDM introduces a dedicated setting to control application downloads and updates over cellular networks.

Procedure

  1. Go to Apps > App Catalog.

  2. Click an app from the displayed list. The App Details page opens.

  3. Under the App Configurations tab, click Install on Device.

  4. Click on any of the listed existing settings.

  5. Click Edit.

  6. Under the Allowed downloads over cellular section, select one of the following options:

    • Store Settings – Default option. The device uses the settings for the corresponding store when downloading apps.

    • Always On – App download is allowed even if the device has no Wi-Fi connectivity.

    • Always Off – App download is not allowed if the device has no Wi-Fi connectivity.

  7. Click Update.

Application Installation Workflow

The process for distributing applications remains similar to traditional N-MDM app management.

Administrators can:

  • Assign apps

  • Distribute apps

  • Install apps

However, DDM changes how deployment status is communicated. Rather than relying on server pulling, devices report application state changes as soon as an action is completed. This provides more accurate and timely information about installation progress and deployment results.

Status Reporting and Monitoring

One of the primary benefits of DDM App Management is proactive status reporting.

With DDM:

  • Devices monitor application state locally.

  • Installation and update events are detected immediately.

  • State changes are automatically reported to the server.

  • Deployment information becomes available without waiting for scheduled polling intervals.

This provides administrators with faster visibility into:

  • Application installation progress

  • Successful installations

  • Application update completion

  • Application state changes

  • Deployment failures

Real-time reporting improves troubleshooting and provides a more responsive application management experience.

Requirements

DDM App Management is supported only on:

  • iOS 26 or later

  • iPadOS 26 or later

  • Managed Ivanti Go client 126 or later

Devices that do not meet these requirements continue to use traditional N-MDM app management.

Once a device is processed via DDM app management, disabling or updating this policy distribution does not revert the device to MDM app management. To return the device to MDM app management, remove the policy assignment and re-register the device.