Create a Device Level Mac Restrictions Policy

This policy allows administrators to manage and enforce specific device limitations on Mac computers to enhance organizational security and minimize distractions. By standardizing device capabilities, organizations can ensure a more productive work environment and protect sensitive data from unauthorized access or accidental exposure.

Note:

This is a device level policy that applies system-wide to the device and all of its users. You can bind this policy to individual devices or device groups. For policies that apply to a specific user's profile across devices, see Get Started: Policies and Learn More section of this article.

Prerequisites

  • Mac computers must be enrolled in Apple MDM with the following enrollment type:
    • Device-Enrolled Devices - These devices are owned by the corporation, and enrolled by the admin or by the user.
    • User-Enrolled Devices - These are personal devices used for work where the user enrolls the device to securely access corporate data while maintaining personal privacy.
    • Auto-Enrolled Devices - These devices are owned and enrolled by the corporation through Automated Device Enrollment.
      For more information, see MDM Enrollment Method.
  • Target devices must be running macOS 11 or later.

Considerations

  • The policy configuration settings are applied automatically and do not require a system restart.

Creating the Policy

To create a Restrictions policy for Mac computers , do the following:

Selecting the Policy Template

  1. Log in to the JumpCloud Admin portal.

Important:

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Device Management > Policy Management. The Policy Management page is displayed.
  2. On the Policy Management page, click +Add New.
  3. Select Device Policy to assign the policy to devices and device groups. On the New Device Policy page:
    • Select the macOS tab.
    • Search and select the required policy and click Configure. The Details tab of the policy is displayed.
    • On the Details tab, configure the required policy configuration settings.
    • (Optional) In the Policy Name field, enter a new name for the policy or keep the default. Policy names must be unique.
    • (Optional) In the Policy Notes field, enter details such as creation date of the policy, and information on testing and deployment of the policy.

Configuring the Policy

To configure the Restrictions policy settings, configure the following:

System Settings
Property NameMinimum OS VersionDescription
Allow Account Modification14Select this option to allow modification of accounts such as Apple Accounts Mail Contacts and Calendar.
Allow Device Name Modification14Allowed by default. Select this option to permit users to manually change the computer name in System Settings.
Allow Erase All Content and Settings12Toggle this on to allow the “Erase All Content and Settings” option in the device reset menu.
Allow Bluetooth Settings Modification13Enable this on to let users change Bluetooth configurations; if disabled, these settings are locked.
Allow User Creation in System Settings14Allowed by default. Select this option to permit users to create and configure new local accounts on the Mac.
Allow Manual Profile Installation in System Settings13Enable this to allow users to manually install configuration profiles and certificates.
Allow Definition Lookup10.11Enable this on to allow users to look up word definitions.
Allow Startup Disk Selection14Toggle this on to allow users to change the designated startup disk in System Settings.
Allow Time Machine Configuration14Enable this on to let users configure or change Time Machine backup settings.
Allow Wallpaper Modification10.13Enable this on to permit users to change their background image.
Allow File Sharing Modification14Toggle this on to allow users to adjust File Sharing settings in System Settings on macOS.
Allow Media Sharing Modification15.1Enable this to allow users to change Media Sharing configurations.
Allow Content Caching10.13Enable this to allow the system to store and speed up the download of software and data from Apple’s servers.
Allow Bluetooth Sharing Modification14Toggle this on to allow changes to Bluetooth Sharing in System Settings.
Allow Internet Sharing Modification14Enable this to allow users to change Internet Sharing settings.
Allow Printer Sharing Modification14Enable this on to permit changes to Printer Sharing configurations.
Allow Remote Management Sharing Modification14Enable this on to permit changes to the Remote Management Sharing setting.
Allow Remote Application Scripting (formerly Apple Events) Modification14Enable this on to permit changes to the Remote Application Scripting setting.
Passwords & Biometrics
Property NameMinimum OS VersionDescription
Allow Touch ID to Unlock Mac10.12.4Enable this to allow the use of Touch ID, Face ID, or Optic ID to unlock the device.
Allow Modifying Touch ID Fingerprints14Toggle this on to let users set up or change Touch ID, Face ID, or Optic ID.
Timeout Period before Fingerprint Unlock requires a Password to Authenticate12Set the number of seconds before the device requires a passcode instead of a fingerprint for authentication. Default is 172800 seconds / 48 hours.
Allow Modifying Password10.13Enable this to let users add, change, or remove their device passcode.
Allow Password AutoFill10.14Toggle this on to enable automatic password entry, strong password generation, and suggestions. Does not affect contact or credit card AutoFill.
Allow Requesting of Passwords From Devices In Proximity10.14Enable this on to allow the system to request passwords from nearby trusted devices.
Allow Sharing of Passwords With AirDrop or Passwords App10.14Enable this to allow users to share passwords with others via AirDrop or the Passwords app.
Privacy & Security
Property NameMinimum OS VersionDescription
Allow Camera10.11Enable this to allow the use of the camera; if disabled, the camera is deactivated and its icon is removed from the Home Screen.
Allow USB Restricted Mode13This option allows unrestricted communication with connected USB accessories without demanding a device unlock sequence.
Allow Screenshots and Screen Recording10.14.4Enable this on to let users capture or record their screens; if disabled, this also prevents the Classroom app from observing remote screens.
Suppress Screen Capture Alerts15.1Enable this on to stop the system from showing an alert when the screen is being captured.
Allow Auto Unlock with Apple Watch10.12Toggle this on to let users unlock their Mac with an Apple Watch or one iPhone with another.
Allow Diagnostic Submission10.13Toggle this on to allow the device to automatically send diagnostic and usage reports to Apple to help improve services.
Allow Apple Personalized Advertising12Enable this on to receive relevant ads based on your interests; Enabling it limits personalized ad tracking.
iCloud
Property NameMinimum OS VersionDescription
Allow iCloud Contacts10.12Enable this to allow the system to sync and access iCloud Contacts on macOS.
Allow iCloud Bookmarks10.12Toggle this on to keep your Safari bookmarks updated across devices.
Allow iCloud Calendars10.12Enable this to sync and manage iCloud Calendar events on your system.
Allow iCloud Desktop & Documents10.12.4Enable this on to automatically store and sync files from your Desktop and Documents folders to iCloud.
Allow iCloud Drive10.11Allowed by default. Select this option to authorize local document and data synchronization with iCloud Drive infrastructure.
Allow iCloud Freeform14Allowed by default. Select this option to permit the Freeform app to sync boards and data with iCloud. Deselect this option to prevent Freeform from using iCloud services, restricting canvases to local storage.
Allow iCloud Keychain Sync10.12Enable this to securely synchronize your passwords and credit card info across devices.
Note: Support for unsupervised devices and Managed Apple Accounts is deprecated.
Allow iCloud Mail10.12Enable this on to enable iCloud Mail services on macOS.
Allow iCloud Notes10.12Enable this to sync and access your iCloud Notes on macOS.
Allow iCloud Photos10.12Toggle this on to sync your photos with iCloud; if disabled, any photos not fully downloaded will be removed from local storage.
Note: Support for unsupervised devices and Managed Apple Accounts is deprecated.
Allow iCloud Private Relay12Enable this to hide your IP address and browsing activity in Safari.
Note: Support for unsupervised devices and Managed Apple Accounts is deprecated.
Allow iCloud Reminders10.12Enable this to sync and manage your iCloud Reminders.
Apple Intelligence & Siri
Property NameMinimum OS VersionDescription
Allow Siri14Allowed by default. Select this option to authorize local and cloud-based Siri assistance capabilities on the Mac.
Deprecated in macOS 26.4 and later versions
Allow Spotlight Internet Search Results in Siri Suggestions10.11Enable this to receive Spotlight internet search results within Siri Suggestions; if disabled, these search results are hidden.
Enable Profanity Filter for Siri and Dictation10.13Allowed by default. Select this option to allow Siri to query unrestricted user-generated resources.
Deprecated in macOS 26.4 and later versions
Allow Apple Intelligence Report15.4Enable this to allow the system to generate reports on Apple Intelligence activity.
Deprecated in macOS 26.4 and later versions.
Allow Dictation10.13Toggle this on to permit the use of dictation for voice-to-text input.
Force On-Device Only Dictation14Enable this to ensure all dictation is processed locally on the device; this prevents the system from connecting to Siri servers for dictation.
Allow Audio Transcription in Notes App15.4Toggle this on to transcribe audio recordings within the Notes app.
Allow Transcription Summary in Notes App15.3Enable this to generate summaries of audio transcriptions in the Notes app.
Allow Apple Intelligence Writing Tools15Enable this to use AI-powered writing assistance.
Allow Mail Smart Replies15.4Enable this on to allow the Mail app to suggest quick, context-aware replies.
Allow Mail Summary15.1Allowed by default. Select this option to display brief summaries of long email exchanges at the top of mail threads.
Allow Safari Summary15.4Enable this on to allow Safari to summarize web content.
Deprecated in macOS 26.4 and later versions.
Allow Genmoji Creation15Enable this to allow the creation of custom Genmoji.
Allow Image Playground15Toggle this on to allow the use of AI image generation features. (Requires a supervised device.)
Allow External AI Integrations15.2Enable this to allow Siri to connect with external, cloud-based AI services.
Allow External AI Integrations Sign-In15.2Toggle this on to allow users to sign in to external AI accounts; if disabled, all requests are handled anonymously and active users are signed out.
Allowed External Intelligence Workspace IDs15.3Deprecated in macOS 26.4 and later versions
Communication
Property NameMinimum OS VersionDescription
Allow Call Recording26Toggle this on to permit the recording of phone calls.
Allow Live Voicemail 26Select this option to allow the Live Voicemail feature which provides real-time transcriptions of incoming messages.
Network & Connectivity
Property NameMinimum OS VersionDescription
Allow to AirDrop10.13Toggle this on to allow wireless file sharing via AirPlay.
Allow Handoff10.15Select this option to allow Handoff (activity continuation) between devices.
Allow Incoming AirPlay Requests12.3Enable this to allow the device to receive content via AirPlay.
Allow iPhone Mirroring15Enable this on to permit mirroring between an iPhone and a Mac; if disabled, mirroring is blocked for both devices.
Allow Universal Control13Enable this to use a single keyboard and mouse across multiple Apple devices.
Apps & Media
Property NameMinimum OS VersionDescription
Allow Apple Books Store15Allowed by default. Select this option to grant users access to commercial downloads and store storefronts within the Books application.
Allow Books Categorized as Erotica15 Select this option to allow users to download Apple Books media tagged as erotica.
Allow Media with Explicit Content15Select this option to allow users to access explicit music podcasts or video content.
Allow iTunes File Sharing10.13Allowed by default. Select this option to authorize local content syncing and file transfers through Finder windows when external devices are connected.
Allow Apple Music 10.12This option allows the full use of the premium Apple Music service on the device.
Rating Region10.7Select a value from the dropdown menu to choose the specific geographic region that determines content rating standards.
App Ratings Limit15 Select a value from the dropdown menu to set the maximum age-based rating permitted for app downloads.
Movie Ratings Limit15 Select this option to set the maximum rating level permitted for movie content.
TV Shows Ratings Limit15 Select this option to set the maximum rating level permitted for TV show content.
Safari
Property NameMinimum OS VersionDescription
Allow Safari History Cleaning 26Select this option to allow user to delete their browsing history and website data in Safari.
Allow Safari Private Browsing26 Select this option to allow the users to use private tabs or windows in Safari.
Allow Autofill in Safari10.13Select this option to allow Safari to automatically fill forms with user information passwords or credit card details.
Find My
Property NameMinimum OS VersionDescription
Allow Find My Device in the Find My App10.15Allowed by default. Select this option to permit users to configure and track this Mac using the native Find My network.
Allow Find My Friends in the Find My App10.15Allowed by default. Select this option to authorize users to broadcast their real-time geographical coordinates to external contacts via the Find My app.
Game Center & Social
Property NameMinimum OS VersionDescription
Allow Game Center10.13Select this option to allow the Game Center service entirely.
Allow Adding Game Friends10.13Select this option to allow users to add friends in Game Center.
Allow Multiplayer Gaming10.13Select this option to permit users to participate in multiplayer games.
Education & Classroom
Property NameMinimum OS VersionDescription
Force Automatic Joining of Classroom Classes10.14.4 Select this option to force the device to join Apple Classroom classes without requiring a prompt for the user.
Require Permission to Leave Classes10.14.4Select this option to prevent students from leaving an Apple Classroom session without the teacher’s approval.
Force Unprompted App and Device Lock in Classroom10.14.4Select this option to allow a teacher to lock a student’s device or specific app without requesting permission.
Force Unprompted Screen Observation in Classroom10.14.4Select this option to allow a teacher to view a student’s screen in Apple Classroom without triggering a local notification or request.
Allow Screen Observation10.14.4 Select this option to prevent the device screen from being viewed remotely by authorized administrators or teachers.

Applying the Policy

  • (Optional) Select the Policy Groups tab. Select one or more policy groups where you want to add this policy. 
  • Select the Device Groups tab. Select one or more device groups where you want to apply this policy to. For device groups with multiple OS member types, the policy only applies when a user logs into a supported Windows device that is enrolled in MDM.
  • Or, select the Devices tab. Select one or more devices where you want to apply this policy.
  • Click Create Policy. A success message is displayed indicating the completion of policy creation.

Viewing Policy Status

  1. Select the Status tab.
  2. To see the last Result Log for a device where this policy is applied, click view.

Note:
  • If any errors occur, they're listed in Exit Status. If you have an Exit Status of 0, no errors occurred when applying or enforcing this policy.

Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case