| Component | Description | Requirements | Notes |
|---|---|---|---|
| App Store Apps | Install apps using declarative device management and configure settings such as:
| ||
| Audio accessory settings | Configure settings for temporarily pairing audio accessories |
| Temporarily pair audio accessories without syncing pairing information with iCloud and automatically unpair audio accessories at a set time each day. |
| Configuration profile payloads | In the component library list, configuration profile payloads are identified by the label "Legacy payload". If you previously deployed a configuration profile to a device and then deploy a blueprint that contains conflicting keys, unexpected behavior may occur. For example, if keys within the Restrictions payload conflict, the most restrictive setting will take precedence. The configuration profiles delivered through the blueprints service are not signed by the Elevate built-in certificate authority (CA). This is by design, as the declarative device management protocol prevents declarative payload tampering within the network and on the device. To mitigate end user concerns that may be caused by the red "Unsigned" label, these payloads are now labeled as "Not signed" in gray text beginning with macOS 26, iOS 26, iPadOS 26, watchOS 26, visionOS 26, and tvOS 26. | ||
| Custom Declarations | Custom declarative device management configurations allow you to define advanced settings tailored to specific needs, offering unmatched flexibility and control. With these custom configurations, you can configure options beyond the standard blueprint capabilities, enabling advanced functionality that supports unique use cases. For more information, see Creating a Custom Declaration Blueprint. Important: Misconfigurations can lead to unintended behavior, affecting device performance and security. Jamf recommends only using custom declarations if you have an advanced understanding of Apple's declarative device management protocol and testing custom declarations in a sandbox environment before deploying to a production environment. For more information, see Use declarative device management to manage Apple devices in Apple Platform Deployment. | ||
| Disk management policy | Configure restriction levels for external storage and network storage | macOS 15 or later, supervised | Permit or deny the device to mount external USB or network drives |
| External Intelligence Settings | Configure interaction with external intelligence integrations |
| Disable external integrations entirely, prevent users from signing in to external intelligence services, or restrict usage to a specific approved workspace by specifying an allowed workspace ID. When a workspace ID is specified, users are required to sign in before making requests to that integration. Note: On macOS, the Allow External Intelligence Integrations and Allow External Intelligence Integrations Sign In settings are not applied in External Intelligence Settings declarations when using the default values. Other settings in the declaration are enforced as expected. This is a known Apple issue. |
| Intelligence Settings | Configure Apple Intelligence settings |
| Disable system-wide features individually, such as Writing Tools, Genmoji, Image Playground, Image Wand, and Visual Intelligence Summary. You can also restrict AI-powered features within specific apps, including Mail Smart Replies, Mail Summary, Notes Transcription, Notes Transcription Summary, and Safari Summary. Additionally, you can require that dictation and translation are processed on-device only, preventing data from being sent to external servers. |
| Keyboard Settings | Configure keyboard settings |
| Disable features individually, including auto-correction, predictive text, spell check, text replacement, slide to type, definition lookup, dictation, and math keyboard suggestions. |
| Math settings | Configure settings for the calculator app and system behavior |
| Configure calculator settings such as:
|
| Passcode policy | Configure passcode policy settings |
| Configure password settings such as:
|
| Safari bookmarks | Configure managed bookmarks for Safari |
| Configure managed bookmarks for Safari by creating a bookmark folder containing a list of bookmarks that cannot be edited or deleted by users. |
| Safari extensions | Configure the extensions end users can use with Safari |
| Manage which Safari extensions are allowed, always on, or always off. Managed extensions can also be allowed or denied access to specific domains. |
| Safari settings | Configure Safari settings on mobile devices |
| Configure Safari settings such as:
|
| Screen Sharing: Connection | Configure screen sharing connections on macOS | macOS 14 or later, supervised | Configure screen sharing connections on macOS by defining the remote host, connection details, credentials, and display behavior. This declarative configuration ensures secure and consistent screen sharing access across managed Mac computers. |
| Screen Sharing: Connection Group | Bundle multiple Screen Sharing: Connection configurations | macOS 14 or later, supervised | Bundle multiple Screen Sharing: Connection configurations into a single, named group that appears in the Screen Sharing app. |
| Screen Sharing: Host Settings | Configure screen sharing host behavior and restrictions | macOS 14 or later, supervised | Configure screen sharing host behavior and restrictions on managed Mac computers. You can limit the maximum number of virtual displays available to connecting clients, define the base UDP port for screen sharing connections, and restrict file transfer capabilities by preventing users from copying files to or from the host. You can also prevent clients from establishing high-performance connections to the host. |
| Service background tasks | Configure background task management on devices | macOS 15 or later, supervised | Control managed settings for background tasks and launch items in a tamper-resistant way. This configuration requires a ZIP archive file that exactly matches the target service's file structure. This file must be hosted on your trusted HTTPS delivery URL and the configuration must also include a SHA-256 hash of the file. |
| Service configuration files | Configure Apple built-in services on devices | macOS 14 or later, supervised | Control managed settings for system services in a tamper-resistant way. This configuration requires a ZIP archive file that exactly matches the target service's file structure. This file must be hosted on your trusted HTTPS delivery URL and the configuration must also include a SHA-256 hash of the file. Managed services are:
|
| Siri Settings | Configure Siri settings |
| Disable Siri entirely, prevent Siri from being used while a device is locked, disable user-generated content in Siri responses, and enforce a profanity filter for Siri output. Note: On macOS and iOS, Siri Settings declarations that include the Force Profanity Filter setting fail to apply. This is a known Apple issue. |
| Software Update Settings | Configure aspects of the software update process |
| Enable comprehensive software update management by allowing administrators to control user permissions, customize update presentations, manage beta program enrollment, configure deferral periods, and manage Background Security Improvements. For more information, see Configuring the Software Update Settings Component. Settings configured in this component will override equivalent settings in existing configuration profiles rather than merging with them. For example:
|
| Software Updates | Configure software update enforcement |
| Configure software update settings such as:
Note: When the enforcement type is set to Latest OS version, declarations for every available minor OS version are sent and the device incrementally upgrades through each version before it upgrades to the latest minor version it is eligible for. For more infomation, see Configuring the Software Updates Component. |
Blueprints that include the Math settings, Safari bookmarks, Safari extensions, or Safari settings components are installed on macOS devices via the declarative device management user channel and require a macOS user that is MDM-enabled. For more information, see MDM-Enabled Local User Accounts in the Jamf Pro Documentation.