Profile configuration in the Restrictions tab
Last adaptation to the version: 2.6
New:
- New option: Allow Apple Intelligence
- Explanations of the ranking values
This article refers to a Beta version
Partial configuration for profiles in the Mobile Security Portal.
Further information is displayed here:
- MS/deployment/profile (transclusion) (← links)
- MS/deployment/profile/reiter-einschraenkungen (transclusion) (← links)
- MS/deployment/profile-AppleTV (transclusion) (← links)
- MS/deployment/profile-shared-iPad (transclusion) (← links)
- MS/deployment/profile-Device (transclusion) (← links)
- MS/deployment/profile-User (transclusion) (← links)
| Restriction | Default | Explanation |
|---|---|---|
| Demo-Dev-Einschränkung | Sollte nur im devWiki angezeigt werden | |
| Allow automatic unlocking | When deactivated , the automatic unlocking is disabled | |
| Allow cloud address book | When deactivated , the cloud address book will be disabled | |
| Allow cloud bookmarks | When deactivated , cloud bookmarks will be disabled | |
| Allow cloud calendar | When deactivated , the cloud calendar will be disabled | |
| Allow cloud desktop & documents | When deactivated , cloud desktop and documents will be disabled | |
| Allow cloud mail | When deactivated , cloud mail will be disabled | |
| Allow cloud notes | When deactivated , cloud notes will be disabled | |
| Allow cloud reminders | When deactivated , cloud reminders will be disabled | |
| Allow content caching | When deactivated , content caching will be disabled | |
| Allow iTunes file sharing | When deactivated , iTunes file sharing will be disabled | |
| Allow automatic screen saver | When deactivated , automatic screen savers are not permitted | |
| Allow lock screen ControlCenter | When deactivated , the ControlCenter is disabled for the lock screen | |
| Allow lock screen notifications to display | When deactivated , the notification preview of the lock screen will be disabled | |
| Allow lock screen view today | When deactivated , today's lock screen view will be disabled | |
| Allow to write unmanaged contacts | When deactivated , writing unmanaged contacts will be disabled | |
| Allow unmanaged reading of managed contacts | When deactivated , unmanaged apps cannot access contacts of managed accounts and that managed apps do not save contacts in the local Contacts app | |
| Allow OTAPKI updates | When deactivated , OTAPKI updates are disabled | |
| Allow temporary session of the shared device | When deactivated , the temporary session of the shared device is disabled | |
| Force password for outgoing AirPlay requests | When activated , all devices receiving AirPlay requests from this device will be forced to use a pairing password | |
| Force encrypted backups | When activated , encrypted backups are enforced | |
| Limit ad tracking | When activated , ad tracking will be restricted | |
| Dictation only | When activated , connections to Siri servers for dictation are disabled | |
| Force WLAN Allowlist | Join Wi-Fi networks installed by profiles only | |
| Allow QuickPath keyboard | When deactivated , the QuickPath keyboard is disabled | |
| Allow network access for files | When deactivated , the connection to network drives is prevented in the file app | |
| Allow USB drive for files | When deactivated , it prevents the File app from connecting to connected USB devices | |
| Allow Find My Device | When deactivated , Find My Device is disabled in the Find my App | |
| Allow Find My Friends | When deactivated , Find My Friends is disabled in the Find My app | |
| Force WiFi activation | When activated it prevents Wi-Fi from being turned off in settings or control center, even by entering or leaving airplane mode.
It does not prevent selecting which Wi-Fi network to use. | |
| Allow trusting enterprise apps | When deactivated , Enterprise apps are not trusted | |
| Allow screenshots and screen recording | When deactivated , screenshots and screen recordings cannot be created | |
| Allow Apple Music | When deactivated , Apple Music will be disabled in the Music app | |
| Allow iTunes Radio | Allow iTunes Radio | |
| Allow shared stream | When deactivated , the shared stream is disabled | |
| Allow Wallet while locked | When deactivated , wallet notifications will not be shown on the lock screen | |
| Allow use of News | When deactivated no news can be used | |
| Allow modifying bluetooth settings | When deactivated , changes to the Bluetooth settings are not permitted | |
| Allow modifying cellular data usage for app settings | When deactivated , the mobile data uses for app settings cannot be changed | |
| Allow modifying device name | When deactivated , the device name cannot be changed | |
| Allow automatic sync while roaming | When deactivated , automatic synchronisation is deactivated during roaming | |
| Allow iCloud sync for managed apps | When deactivated , iCloud synchronisation is deactivated for managed apps | |
| Allow enterprise books backup | When deactivated , Enterprise books are not saved | |
| Allow enterprise books and highlights to sync | When deactivated , Enterprise books and highlights are not synchronised | |
| Allow email privacy | When activated , Apple's Mail Privacy Protection (AMPP) is activated | |
| Allow In App purchases | When deactivated no in-app purchases can be made | |
| Allow multiplayer gaming | When deactivated , multiplayer gaming is not allowed | |
| Allow voice dialing while device is locked | When deactivated , no voice dialling is allowed, even if the device is locked | |
| Force Apple Watch wrist detection | When activated , Apple Watch wrist detection is enforced | |
| Allow pairing with Apple Watch | When deactivated , pairing with Apple Watch is not permitted | |
| Allow Internet results in Spotlight | When deactivated , search results from the web will not be shown in Spotlight | |
| Allow user to accept untrusted TLS certificates | When deactivated , the user is not allowed to accept untrusted certificates in TLS | |
| Allow Photo Stream | When deactivated , the use of Photo-Stream is not permitted on the device | |
| Allow iCloud Photo Library | When deactivated , the use of the iCloud Photo Library on the device is not permitted | |
| Allow iCloud backup | When deactivated , the backup with the iCloud is not permitted | |
| Allow personalized advertising | When deactivated , restricts Apple's personalized advertising. Available in iOS 14 and later | |
| Requires iTunes password for all purchases | When activated , the user's iTunes password is required for all purchases | |
| Apps ranking number | 1000 | The value entered describes the maximum permitted level of apps relevant to youth protection on the device. |
| Movies ranking number | 1000 | The value entered describes the maximum permitted level of films relevant to youth protection on the device. |
| TV Shows ranking number | 1000 | The value entered describes the maximum permitted level of TV content relevant to youth protection on the device. |
| Region code | Germany | Two-character code for the region used to specify ratings |
| Accept cookies in Safari | Never | Accept cookies: Does not accept cookies |
| From current website only (iOS 8) or visited sites (pre-iOS 8) | Depending on iOS version: from iOS 8: Only from current website from iOS 8: Only from visited pages | |
| From websites I visited | Accepts cookies from all visited websites | |
| Always | Accepts all cookies | |
| Allow JavaScript | When deactivated , JavaScript is not allowed in Safari | |
| Allow Pop-ups | When deactivated , pop-ups are not allowed in Safari | |
| Enable fraud warning | When activated , the fraud warning in Safari is activated | |
| Force translation on the device only | When activated , the device does not connect to Siri servers for translation purposes | |
| Allow unmanaged documents in managed apps | When activated , it allows managed apps to access unmanaged documents | |
| Allow managed documents in unmanaged apps | When activated , allows unmanaged apps to access managed documents | |
| Managed clipboard required | When activated , the copy and paste feature follows the "Allow open from managed to unmanaged" and "Allow open from unmanaged to managed" constraints. | |
| Treat AirDrop as unmanaged destination | When activated , it prevents protected (managed) data from leaving the device without authorisation via Airdrop | |
| Allows Handoff | When deactivated , handoff is deactivated. Handoff allows you to continue an activity started on an iOS-device on another device. | |
| Allow Touch ID/Face ID for unlocking | When deactivated , Touch ID/Face ID is not allowed to unlock the device | |
| Fingerprint timeout | The time after which unlocking the fingerprint requires a password for authentication. Possible values: 1, 6, 12 hours, 1, 2, 3 days or 1 week | |
| Allow modifying notification settings | When deactivated , changing the notification settings is not allowed | |
| Allow incoming AirPlay requests | When deactivated , incoming AirPlay requests are not allowed | |
| Allow pairing with Remote app | When deactivated , pairing with remote app is not permitted | |
| Allow dictation | When deactivated , dictations are not allowed | |
| Allow camera use | When deactivated , the user is not allowed to use the camera | |
| Allow Siri | When deactivated , Siri is not allowed | |
| Allow Siri while locked | When deactivated , Siri is not allowed while the device is locked | |
| Allow Siri user generated content | When deactivated , it prevents Siri from querying requests with user-generated content | |
| Allow modifying Touch ID/Face ID | When deactivated , the user is not permitted to change the Touch ID/Face ID | |
| Allow diagnostic submission | When deactivated , diagnostic and usage data is not sent to Apple | |
| Allow modifying diagnostics settings | When deactivated , the user is not permitted to change the diagnostic settings | |
| notempty New as of: 2.6 |
When deactivated , the system deactivates the Apple Intelligence reports. Available in iOS 18.4 and higher. |


