Policies - Apple

Apple policies

Apple policies define management settings that Cerberus Enterprise applies to Apple devices via MDM. These settings are configured from the dashboard in the Apple policy editor.

Before you start

Apple device management requires Apple Management (APNs) to be configured. If needed, read the Apple Management setup (APNs) page.

Open the Apple Policy Editor

In the dashboard, open Policies and click Create new Apple policy. To edit an existing Apple policy, click its row in the policies table.

Editor layout

The Apple Policy Editor is organized as a set of expandable sections. At the top of the page you can always edit:

Policy sections

The sections below match the panels currently available in the Apple Policy Editor:

Many options in the Apple Policy Editor include a tooltip that documents requirements and supported OS versions.

Save, delete, and associated devices

Use Save policy to apply your changes. The button is disabled when there are no pending edits, or when the license is expired.

When editing an existing policy, the page also shows a Delete policy action. The editor can show an Associated devices list at the bottom, so you can see how many devices are currently using the policy.

Next pages

Apple policy: Passcode

The Passcode settings section controls device passcode requirements and related security rules (for example, minimum length and complexity).

Options

In the Apple Policy Editor, passcode options are configured using a mix of toggles and numeric fields. Many fields include tooltips that indicate supported OS versions and supervision requirements.

Passcode toggles

Numeric fields

Apple policy: Restrictions

The Restrictions sections control which OS features are allowed on managed Apple devices. In the Apple Policy Editor, these options are exposed as grouped panels with multiple toggles.

Many restrictions are only supported on specific OS versions and may require supervised devices. Use the tooltips in the dashboard for authoritative requirements.

Security

iCloud

Multimedia

Cellular

Networking

Accounts (restriction)

The Accounts panel contains both a restriction and (optionally) account configuration. The restriction toggle controls whether the user can modify system accounts.

Apple policy: Apps & profiles

This section documents how to configure managed applications and account payloads for Apple devices.

App management

The App management panel contains both general app-related restrictions and a list of managed apps.

General app restrictions

Managed apps

Use Add application to add an app to the policy. Each managed app is displayed as a card. You can expand the card to edit its settings and remove the app using the delete action.

Accounts

The Accounts panel lets you configure accounts that are applied to managed devices. It also includes a restriction toggle for account modification.

Restriction

Add accounts

Use Add Google account or Add mail account to add account payloads to the policy. Each account appears as a card with its configuration fields.

Account credentials from users

Both Google and Mail account cards provide a Account credentials from users toggle. When enabled, the system applies account credentials on a per-user basis. When disabled, you enter the account identity in the policy.

Google account fields

Mail account fields

Mail accounts include identity fields plus incoming/outgoing server configuration. Host names are required.

Incoming server

Outgoing server

S/MIME options

For Mail accounts, you can also configure S/MIME encryption and signing behavior.

Encryption

Signing

Account and restriction options include tooltips in the dashboard that document prerequisites and supported OS versions.