This policy allows administrators to manage and enforce specific device limitations on Mac computers to enhance organizational security and minimize distractions. By standardizing device capabilities, organizations can ensure a more productive work environment and protect sensitive data from unauthorized access or accidental exposure.
This is a device level policy that applies system-wide to the device and all of its users. You can bind this policy to individual devices or device groups. For policies that apply to a specific user's profile across devices, see Get Started: Policies and Learn More section of this article.
Prerequisites
- Mac computers must be enrolled in Apple MDM with the following enrollment type:
- Device-Enrolled Devices - These devices are owned by the corporation, and enrolled by the admin or by the user.
- User-Enrolled Devices - These are personal devices used for work where the user enrolls the device to securely access corporate data while maintaining personal privacy.
- Auto-Enrolled Devices - These devices are owned and enrolled by the corporation through Automated Device Enrollment.
For more information, see MDM Enrollment Method.
- Target devices must be running macOS 11 or later.
Considerations
- The policy configuration settings are applied automatically and do not require a system restart.
Creating the Policy
To create a Restrictions policy for Mac computers , do the following:
Selecting the Policy Template
- Log in to the JumpCloud Admin portal.
If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.
- Go to Device Management > Policy Management. The Policy Management page is displayed.
- On the Policy Management page, click +Add New.
- Select Device Policy to assign the policy to devices and device groups. On the New Device Policy page:
- Select the macOS tab.
- Search and select the required policy and click Configure. The Details tab of the policy is displayed.
- On the Details tab, configure the required policy configuration settings.
- (Optional) In the Policy Name field, enter a new name for the policy or keep the default. Policy names must be unique.
- (Optional) In the Policy Notes field, enter details such as creation date of the policy, and information on testing and deployment of the policy.
Configuring the Policy
To configure the Restrictions policy settings, configure the following:
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Allow Account Modification | 14 | Select this option to allow modification of accounts such as Apple Accounts Mail Contacts and Calendar. |
| Allow Device Name Modification | 14 | Allowed by default. Select this option to permit users to manually change the computer name in System Settings. |
| Allow Erase All Content and Settings | 12 | Toggle this on to allow the “Erase All Content and Settings” option in the device reset menu. |
| Allow Bluetooth Settings Modification | 13 | Enable this on to let users change Bluetooth configurations; if disabled, these settings are locked. |
| Allow User Creation in System Settings | 14 | Allowed by default. Select this option to permit users to create and configure new local accounts on the Mac. |
| Allow Manual Profile Installation in System Settings | 13 | Enable this to allow users to manually install configuration profiles and certificates. |
| Allow Definition Lookup | 10.11 | Enable this on to allow users to look up word definitions. |
| Allow Startup Disk Selection | 14 | Toggle this on to allow users to change the designated startup disk in System Settings. |
| Allow Time Machine Configuration | 14 | Enable this on to let users configure or change Time Machine backup settings. |
| Allow Wallpaper Modification | 10.13 | Enable this on to permit users to change their background image. |
| Allow File Sharing Modification | 14 | Toggle this on to allow users to adjust File Sharing settings in System Settings on macOS. |
| Allow Media Sharing Modification | 15.1 | Enable this to allow users to change Media Sharing configurations. |
| Allow Content Caching | 10.13 | Enable this to allow the system to store and speed up the download of software and data from Apple’s servers. |
| Allow Bluetooth Sharing Modification | 14 | Toggle this on to allow changes to Bluetooth Sharing in System Settings. |
| Allow Internet Sharing Modification | 14 | Enable this to allow users to change Internet Sharing settings. |
| Allow Printer Sharing Modification | 14 | Enable this on to permit changes to Printer Sharing configurations. |
| Allow Remote Management Sharing Modification | 14 | Enable this on to permit changes to the Remote Management Sharing setting. |
| Allow Remote Application Scripting (formerly Apple Events) Modification | 14 | Enable this on to permit changes to the Remote Application Scripting setting. |
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Allow Touch ID to Unlock Mac | 10.12.4 | Enable this to allow the use of Touch ID, Face ID, or Optic ID to unlock the device. |
| Allow Modifying Touch ID Fingerprints | 14 | Toggle this on to let users set up or change Touch ID, Face ID, or Optic ID. |
| Timeout Period before Fingerprint Unlock requires a Password to Authenticate | 12 | Set the number of seconds before the device requires a passcode instead of a fingerprint for authentication. Default is 172800 seconds / 48 hours. |
| Allow Modifying Password | 10.13 | Enable this to let users add, change, or remove their device passcode. |
| Allow Password AutoFill | 10.14 | Toggle this on to enable automatic password entry, strong password generation, and suggestions. Does not affect contact or credit card AutoFill. |
| Allow Requesting of Passwords From Devices In Proximity | 10.14 | Enable this on to allow the system to request passwords from nearby trusted devices. |
| Allow Sharing of Passwords With AirDrop or Passwords App | 10.14 | Enable this to allow users to share passwords with others via AirDrop or the Passwords app. |
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Allow Camera | 10.11 | Enable this to allow the use of the camera; if disabled, the camera is deactivated and its icon is removed from the Home Screen. |
| Allow USB Restricted Mode | 13 | This option allows unrestricted communication with connected USB accessories without demanding a device unlock sequence. |
| Allow Screenshots and Screen Recording | 10.14.4 | Enable this on to let users capture or record their screens; if disabled, this also prevents the Classroom app from observing remote screens. |
| Suppress Screen Capture Alerts | 15.1 | Enable this on to stop the system from showing an alert when the screen is being captured. |
| Allow Auto Unlock with Apple Watch | 10.12 | Toggle this on to let users unlock their Mac with an Apple Watch or one iPhone with another. |
| Allow Diagnostic Submission | 10.13 | Toggle this on to allow the device to automatically send diagnostic and usage reports to Apple to help improve services. |
| Allow Apple Personalized Advertising | 12 | Enable this on to receive relevant ads based on your interests; Enabling it limits personalized ad tracking. |
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Allow iCloud Contacts | 10.12 | Enable this to allow the system to sync and access iCloud Contacts on macOS. |
| Allow iCloud Bookmarks | 10.12 | Toggle this on to keep your Safari bookmarks updated across devices. |
| Allow iCloud Calendars | 10.12 | Enable this to sync and manage iCloud Calendar events on your system. |
| Allow iCloud Desktop & Documents | 10.12.4 | Enable this on to automatically store and sync files from your Desktop and Documents folders to iCloud. |
| Allow iCloud Drive | 10.11 | Allowed by default. Select this option to authorize local document and data synchronization with iCloud Drive infrastructure. |
| Allow iCloud Freeform | 14 | Allowed by default. Select this option to permit the Freeform app to sync boards and data with iCloud. Deselect this option to prevent Freeform from using iCloud services, restricting canvases to local storage. |
| Allow iCloud Keychain Sync | 10.12 | Enable this to securely synchronize your passwords and credit card info across devices. Note: Support for unsupervised devices and Managed Apple Accounts is deprecated. |
| Allow iCloud Mail | 10.12 | Enable this on to enable iCloud Mail services on macOS. |
| Allow iCloud Notes | 10.12 | Enable this to sync and access your iCloud Notes on macOS. |
| Allow iCloud Photos | 10.12 | Toggle this on to sync your photos with iCloud; if disabled, any photos not fully downloaded will be removed from local storage. Note: Support for unsupervised devices and Managed Apple Accounts is deprecated. |
| Allow iCloud Private Relay | 12 | Enable this to hide your IP address and browsing activity in Safari. Note: Support for unsupervised devices and Managed Apple Accounts is deprecated. |
| Allow iCloud Reminders | 10.12 | Enable this to sync and manage your iCloud Reminders. |
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Allow Siri | 14 | Allowed by default. Select this option to authorize local and cloud-based Siri assistance capabilities on the Mac. Deprecated in macOS 26.4 and later versions |
| Allow Spotlight Internet Search Results in Siri Suggestions | 10.11 | Enable this to receive Spotlight internet search results within Siri Suggestions; if disabled, these search results are hidden. |
| Enable Profanity Filter for Siri and Dictation | 10.13 | Allowed by default. Select this option to allow Siri to query unrestricted user-generated resources. Deprecated in macOS 26.4 and later versions |
| Allow Apple Intelligence Report | 15.4 | Enable this to allow the system to generate reports on Apple Intelligence activity. Deprecated in macOS 26.4 and later versions. |
| Allow Dictation | 10.13 | Toggle this on to permit the use of dictation for voice-to-text input. |
| Force On-Device Only Dictation | 14 | Enable this to ensure all dictation is processed locally on the device; this prevents the system from connecting to Siri servers for dictation. |
| Allow Audio Transcription in Notes App | 15.4 | Toggle this on to transcribe audio recordings within the Notes app. |
| Allow Transcription Summary in Notes App | 15.3 | Enable this to generate summaries of audio transcriptions in the Notes app. |
| Allow Apple Intelligence Writing Tools | 15 | Enable this to use AI-powered writing assistance. |
| Allow Mail Smart Replies | 15.4 | Enable this on to allow the Mail app to suggest quick, context-aware replies. |
| Allow Mail Summary | 15.1 | Allowed by default. Select this option to display brief summaries of long email exchanges at the top of mail threads. |
| Allow Safari Summary | 15.4 | Enable this on to allow Safari to summarize web content. Deprecated in macOS 26.4 and later versions. |
| Allow Genmoji Creation | 15 | Enable this to allow the creation of custom Genmoji. |
| Allow Image Playground | 15 | Toggle this on to allow the use of AI image generation features. (Requires a supervised device.) |
| Allow External AI Integrations | 15.2 | Enable this to allow Siri to connect with external, cloud-based AI services. |
| Allow External AI Integrations Sign-In | 15.2 | Toggle this on to allow users to sign in to external AI accounts; if disabled, all requests are handled anonymously and active users are signed out. |
| Allowed External Intelligence Workspace IDs | 15.3 | Deprecated in macOS 26.4 and later versions |
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Allow Call Recording | 26 | Toggle this on to permit the recording of phone calls. |
| Allow Live Voicemail | 26 | Select this option to allow the Live Voicemail feature which provides real-time transcriptions of incoming messages. |
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Allow to AirDrop | 10.13 | Toggle this on to allow wireless file sharing via AirPlay. |
| Allow Handoff | 10.15 | Select this option to allow Handoff (activity continuation) between devices. |
| Allow Incoming AirPlay Requests | 12.3 | Enable this to allow the device to receive content via AirPlay. |
| Allow iPhone Mirroring | 15 | Enable this on to permit mirroring between an iPhone and a Mac; if disabled, mirroring is blocked for both devices. |
| Allow Universal Control | 13 | Enable this to use a single keyboard and mouse across multiple Apple devices. |
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Allow Apple Books Store | 15 | Allowed by default. Select this option to grant users access to commercial downloads and store storefronts within the Books application. |
| Allow Books Categorized as Erotica | 15 | Select this option to allow users to download Apple Books media tagged as erotica. |
| Allow Media with Explicit Content | 15 | Select this option to allow users to access explicit music podcasts or video content. |
| Allow iTunes File Sharing | 10.13 | Allowed by default. Select this option to authorize local content syncing and file transfers through Finder windows when external devices are connected. |
| Allow Apple Music | 10.12 | This option allows the full use of the premium Apple Music service on the device. |
| Rating Region | 10.7 | Select a value from the dropdown menu to choose the specific geographic region that determines content rating standards. |
| App Ratings Limit | 15 | Select a value from the dropdown menu to set the maximum age-based rating permitted for app downloads. |
| Movie Ratings Limit | 15 | Select this option to set the maximum rating level permitted for movie content. |
| TV Shows Ratings Limit | 15 | Select this option to set the maximum rating level permitted for TV show content. |
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Allow Safari History Cleaning | 26 | Select this option to allow user to delete their browsing history and website data in Safari. |
| Allow Safari Private Browsing | 26 | Select this option to allow the users to use private tabs or windows in Safari. |
| Allow Autofill in Safari | 10.13 | Select this option to allow Safari to automatically fill forms with user information passwords or credit card details. |
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Allow Find My Device in the Find My App | 10.15 | Allowed by default. Select this option to permit users to configure and track this Mac using the native Find My network. |
| Allow Find My Friends in the Find My App | 10.15 | Allowed by default. Select this option to authorize users to broadcast their real-time geographical coordinates to external contacts via the Find My app. |
| Property Name | Minimum OS Version | Description |
|---|---|---|
| Force Automatic Joining of Classroom Classes | 10.14.4 | Select this option to force the device to join Apple Classroom classes without requiring a prompt for the user. |
| Require Permission to Leave Classes | 10.14.4 | Select this option to prevent students from leaving an Apple Classroom session without the teacher’s approval. |
| Force Unprompted App and Device Lock in Classroom | 10.14.4 | Select this option to allow a teacher to lock a student’s device or specific app without requesting permission. |
| Force Unprompted Screen Observation in Classroom | 10.14.4 | Select this option to allow a teacher to view a student’s screen in Apple Classroom without triggering a local notification or request. |
| Allow Screen Observation | 10.14.4 | Select this option to prevent the device screen from being viewed remotely by authorized administrators or teachers. |
Applying the Policy
- (Optional) Select the Policy Groups tab. Select one or more policy groups where you want to add this policy.
- Select the Device Groups tab. Select one or more device groups where you want to apply this policy to. For device groups with multiple OS member types, the policy only applies when a user logs into a supported Windows device that is enrolled in MDM.
- Or, select the Devices tab. Select one or more devices where you want to apply this policy.
- Click Create Policy. A success message is displayed indicating the completion of policy creation.
Viewing Policy Status
- Select the Status tab.
- To see the last Result Log for a device where this policy is applied, click view.
- If any errors occur, they're listed in Exit Status. If you have an Exit Status of 0, no errors occurred when applying or enforcing this policy.