Skip to main content

Apple Security Access Control Policy

Overview

The Apple Security Access Control Policy applies core security restrictions to managed Macs, iPhones, and iPads. You can control:

  • the camera and biometric unlock (Touch ID, Face ID, and Apple Watch)

  • Apple Account and other account changes

  • USB accessories and pairing with computers

  • erasing the device

  • diagnostics, ad tracking, and Mail Privacy Protection

  • authentication before AutoFill

Important: Apple Account is off by default, and it blocks more than Apple Account sign-in. This setting uses Apple's account modification restriction. When it's off, users can't add, remove, or change any accounts. That includes Apple Accounts and internet accounts for Mail, Contacts, and Calendar. It applies to supervised iPhones and iPads and to Macs running macOS 14 or later. Turn it on if users need to add their own email or calendar accounts. Accounts that are already signed in stay signed in.


Supported platforms and requirements

Item

Details

Platforms

macOS, iOS, iPadOS

Minimum OS

macOS 10.11, iOS 4.0, iPadOS 4.0 (most settings need a later version; see the tables)

Device ownership

Company-owned devices

Supervision

Many settings require supervised iPhones and iPads, enrolled through Automated Device Enrollment or prepared with Apple Configurator. Macs don't need supervision.

User Enrollment (BYOD)

Not supported. Apple allows only Allow Diagnostic Submission on User Enrollment.

Unsupervised iPhones and iPads. Apple has deprecated Allow Camera, Allow Fingerprint for Unlock, and Allow Unlock with Apple Watch on unsupervised devices. They still work there today but will require supervision in a future release.


Settings reference

In the tables, Not set means Swif doesn't send the setting and the device keeps Apple's default (allowed). Supervised refers to iPhone and iPad.

Camera and biometric unlock

Setting

What it does

Default

Platforms and minimum OS

Supervised

Allow Camera

When off, turns off the camera and removes its icon. Users can't take photos.

Not set

macOS 10.11, iOS/iPadOS 4.0

Deprecated if not

Allow Fingerprint for Unlock

When off, Touch ID and Face ID can't unlock the device.

Not set

macOS 10.12.4, iOS/iPadOS 7.0

Deprecated if not

Allow Unlock with Apple Watch

When off, users can't unlock the device with Apple Watch. Not supported on Shared iPad.

On

macOS 10.12, iOS/iPadOS 14.5

Deprecated if not

Allow Fingerprint Modification

When off, users can't add or change Touch ID fingerprints or Face ID.

Not set

macOS 14, iOS/iPadOS 8.3

Required

Enforced Fingerprint Timeout

Seconds after which Touch ID unlock requires the password. Range 0–172,800.

172,800 (48 hours)

macOS 12

—

Accounts and device

Setting

What it does

Default

Platforms and minimum OS

Supervised

Apple Account

When off, users can't add, remove, or change accounts, including Apple Accounts and Mail, Contacts, and Calendar accounts. Existing accounts aren't signed out.

Off

macOS 14, iOS/iPadOS 7.0

Required

Allow Erase All Content and Settings

When off, turns off Erase All Content and Settings, so users can't erase the device from Settings.

On

macOS 12, iOS/iPadOS 8.0

Required

USB and computer connections

Setting

What it does

Default

Platforms and minimum OS

Supervised

Allow USB Restricted Mode

When off, iPhones and iPads always connect to USB accessories while locked. Macs let new USB and Thunderbolt accessories and SD cards connect without asking. Ignored when Lockdown Mode is on.

Not set

macOS 13, iOS/iPadOS 11.4.1

Required

Allow Files USB Drive Access

When off, the Files app can't access connected USB drives.

Not set

iOS/iPadOS 13.1

Required

Allow Host Pairing

When off, the device can't pair with a Mac or PC, except the supervision host. If no supervision host certificate is configured, all pairing is blocked.

Not set

iOS/iPadOS 7.0

Required

Keep Allow USB Restricted Mode on unless you have a specific accessory requirement. Turning it off lowers protection against attacks through the USB port.

Privacy

Setting

What it does

Default

Platforms and minimum OS

Supervised

Force Limit Ad Tracking

When on, limits ad tracking and turns off app tracking and Allow Apps to Request to Track.

Not set

iOS/iPadOS 7.0

Not required

Allow Diagnostic Submission

When off, the device doesn't automatically send diagnostic reports to Apple.

On

macOS 10.13, iOS/iPadOS 6.0

Not required

Allow Mail Privacy Protection

When off, turns off Mail Privacy Protection.

On

iOS/iPadOS 15.2

Required

AutoFill

Setting

What it does

Default

Platforms and minimum OS

Supervised

Force Authentication Before AutoFill

When on, users must authenticate with Face ID or Touch ID before passwords or credit cards autofill in Safari and apps. Only works on devices with Face ID or Touch ID.

Not set

iOS/iPadOS 11.0

Required

Swif recommends managing this setting in the Apple Safari Policy instead.


Using this policy with other Swif policies

Some of these settings also appear in the Apple Application Access Policy: camera, biometric unlock, Apple Watch unlock, the fingerprint timeout, USB Restricted Mode, diagnostics, Mail Privacy Protection, and Erase All Content and Settings. How Apple handles conflicts depends on the platform:

  • iPhone and iPad: the most restrictive value wins.

  • Mac: when two profiles set the same restriction to different values, the result is undefined.

Manage each setting in only one policy per device, especially on Macs.


Before you start

  1. Decide on Apple Account. Leave it off to stop personal account sign-in, or turn it on if users add their own email or calendar accounts.

  2. Check supervision for iPhones and iPads. Many settings don't apply to unsupervised devices.

  3. Check for overlapping policies. Make sure the Application Access Policy doesn't set the same restrictions on the same Macs.

  4. Plan for host pairing. Turning it off can block syncing and connecting the device to a computer.


Create the policy

  1. In Swif, go to Device Management > Policies > New Policy.

  2. Select Apple Security Access Control Policy.

  3. Enter a clear name, such as iOS Security Baseline – Supervised.

  4. Review Apple Account first, since it's off by default.

  5. Set the camera, biometric, USB, privacy, and device settings you need.

  6. Save the policy.

  7. Assign it to a device group.

  8. Test on a few devices of each platform before a wider rollout.


Example configurations

Example 1: Supervised company iPhones

Setting

Value

Apple Account

Off

Allow Erase All Content and Settings

Off

Allow Host Pairing

Off

Allow Files USB Drive Access

Off

Force Limit Ad Tracking

On

Allow Diagnostic Submission

Off

All other settings

Defaults

Users can't sign in with personal accounts, erase the device, pair it with a computer, or copy files to USB drives.

Example 2: Company Macs where users add their own email

Setting

Value

Apple Account

On

Allow Erase All Content and Settings

Off

Enforced Fingerprint Timeout

86400 (24 hours)

Allow Diagnostic Submission

Off

All other settings

Defaults

Turning on Apple Account lets users add Mail, Contacts, and Calendar accounts.

Example 3: Supervised shared iPads in a clinic

Setting

Value

Allow Camera

Off

Apple Account

Off

Allow Fingerprint Modification

Off

Allow Erase All Content and Settings

Off

Allow Files USB Drive Access

Off

All other settings

Defaults


Verify the policy

iPhone or iPad

  1. Go to Settings > General > VPN & Device Management, open the Swif profile, and confirm that it lists Restrictions.

  2. Test a restricted setting:

    • If Apple Account is off, try to add a mail account in the Mail settings. The option to add an account should be unavailable.

    • If Allow Erase All Content and Settings is off, check that the erase option is unavailable in Settings > General > Transfer or Reset iPhone.

Mac

  1. Open System Settings > General > Device Management and open the Swif profile. Confirm that the restrictions appear.

  2. Test a restricted setting:

    • If Apple Account is off, try to add an account in System Settings > Internet Accounts.

    • If Allow Camera is off, open an app that uses the camera.

In Swif, open the device and confirm that the policy shows as applied.


Troubleshooting

Users can't add email, contacts, or calendar accounts

This is expected when Apple Account is off. Turn it on if users need to add accounts.

A user is still signed in with a personal Apple Account

Turning off Apple Account blocks changes but doesn't sign out existing accounts. Have the user sign out before you apply the policy, or erase the device.

A setting has no effect on an iPhone or iPad

  • Check whether the setting requires supervision.

  • Check the OS version.

The device can't sync with or connect to a computer

Allow Host Pairing is off. Turn it on, or configure a supervision host certificate so the device can still pair with the supervising Mac.

USB accessories connect while the iPhone is locked

Allow USB Restricted Mode is off, or Lockdown Mode is on, which ignores this setting.

A Mac behaves inconsistently for a setting

Another profile, such as the Application Access Policy, may set the same restriction differently. On macOS, the result is undefined. Remove the setting from one policy.

Nothing applies on a personal device

User Enrollment supports only Allow Diagnostic Submission.


Related resources

Swif

Apple

Did this answer your question?