Overview
The Apple Security Access Control Policy applies core security restrictions to managed Macs, iPhones, and iPads. You can control:
the camera and biometric unlock (Touch ID, Face ID, and Apple Watch)
Apple Account and other account changes
USB accessories and pairing with computers
erasing the device
diagnostics, ad tracking, and Mail Privacy Protection
authentication before AutoFill
Important: Apple Account is off by default, and it blocks more than Apple Account sign-in. This setting uses Apple's account modification restriction. When it's off, users can't add, remove, or change any accounts. That includes Apple Accounts and internet accounts for Mail, Contacts, and Calendar. It applies to supervised iPhones and iPads and to Macs running macOS 14 or later. Turn it on if users need to add their own email or calendar accounts. Accounts that are already signed in stay signed in.
Supported platforms and requirements
Item | Details |
Platforms | macOS, iOS, iPadOS |
Minimum OS | macOS 10.11, iOS 4.0, iPadOS 4.0 (most settings need a later version; see the tables) |
Device ownership | Company-owned devices |
Supervision | Many settings require supervised iPhones and iPads, enrolled through Automated Device Enrollment or prepared with Apple Configurator. Macs don't need supervision. |
User Enrollment (BYOD) | Not supported. Apple allows only Allow Diagnostic Submission on User Enrollment. |
Unsupervised iPhones and iPads. Apple has deprecated Allow Camera, Allow Fingerprint for Unlock, and Allow Unlock with Apple Watch on unsupervised devices. They still work there today but will require supervision in a future release.
Settings reference
In the tables, Not set means Swif doesn't send the setting and the device keeps Apple's default (allowed). Supervised refers to iPhone and iPad.
Camera and biometric unlock
Setting | What it does | Default | Platforms and minimum OS | Supervised |
Allow Camera | When off, turns off the camera and removes its icon. Users can't take photos. | Not set | macOS 10.11, iOS/iPadOS 4.0 | Deprecated if not |
Allow Fingerprint for Unlock | When off, Touch ID and Face ID can't unlock the device. | Not set | macOS 10.12.4, iOS/iPadOS 7.0 | Deprecated if not |
Allow Unlock with Apple Watch | When off, users can't unlock the device with Apple Watch. Not supported on Shared iPad. | On | macOS 10.12, iOS/iPadOS 14.5 | Deprecated if not |
Allow Fingerprint Modification | When off, users can't add or change Touch ID fingerprints or Face ID. | Not set | macOS 14, iOS/iPadOS 8.3 | Required |
Enforced Fingerprint Timeout | Seconds after which Touch ID unlock requires the password. Range 0–172,800. | 172,800 (48 hours) | macOS 12 | — |
Accounts and device
Setting | What it does | Default | Platforms and minimum OS | Supervised |
Apple Account | When off, users can't add, remove, or change accounts, including Apple Accounts and Mail, Contacts, and Calendar accounts. Existing accounts aren't signed out. | Off | macOS 14, iOS/iPadOS 7.0 | Required |
Allow Erase All Content and Settings | When off, turns off Erase All Content and Settings, so users can't erase the device from Settings. | On | macOS 12, iOS/iPadOS 8.0 | Required |
USB and computer connections
Setting | What it does | Default | Platforms and minimum OS | Supervised |
Allow USB Restricted Mode | When off, iPhones and iPads always connect to USB accessories while locked. Macs let new USB and Thunderbolt accessories and SD cards connect without asking. Ignored when Lockdown Mode is on. | Not set | macOS 13, iOS/iPadOS 11.4.1 | Required |
Allow Files USB Drive Access | When off, the Files app can't access connected USB drives. | Not set | iOS/iPadOS 13.1 | Required |
Allow Host Pairing | When off, the device can't pair with a Mac or PC, except the supervision host. If no supervision host certificate is configured, all pairing is blocked. | Not set | iOS/iPadOS 7.0 | Required |
Keep Allow USB Restricted Mode on unless you have a specific accessory requirement. Turning it off lowers protection against attacks through the USB port.
Privacy
Setting | What it does | Default | Platforms and minimum OS | Supervised |
Force Limit Ad Tracking | When on, limits ad tracking and turns off app tracking and Allow Apps to Request to Track. | Not set | iOS/iPadOS 7.0 | Not required |
Allow Diagnostic Submission | When off, the device doesn't automatically send diagnostic reports to Apple. | On | macOS 10.13, iOS/iPadOS 6.0 | Not required |
Allow Mail Privacy Protection | When off, turns off Mail Privacy Protection. | On | iOS/iPadOS 15.2 | Required |
AutoFill
Setting | What it does | Default | Platforms and minimum OS | Supervised |
Force Authentication Before AutoFill | When on, users must authenticate with Face ID or Touch ID before passwords or credit cards autofill in Safari and apps. Only works on devices with Face ID or Touch ID. | Not set | iOS/iPadOS 11.0 | Required |
Swif recommends managing this setting in the Apple Safari Policy instead.
Using this policy with other Swif policies
Some of these settings also appear in the Apple Application Access Policy: camera, biometric unlock, Apple Watch unlock, the fingerprint timeout, USB Restricted Mode, diagnostics, Mail Privacy Protection, and Erase All Content and Settings. How Apple handles conflicts depends on the platform:
iPhone and iPad: the most restrictive value wins.
Mac: when two profiles set the same restriction to different values, the result is undefined.
Manage each setting in only one policy per device, especially on Macs.
Before you start
Decide on Apple Account. Leave it off to stop personal account sign-in, or turn it on if users add their own email or calendar accounts.
Check supervision for iPhones and iPads. Many settings don't apply to unsupervised devices.
Check for overlapping policies. Make sure the Application Access Policy doesn't set the same restrictions on the same Macs.
Plan for host pairing. Turning it off can block syncing and connecting the device to a computer.
Create the policy
In Swif, go to Device Management > Policies > New Policy.
Select Apple Security Access Control Policy.
Enter a clear name, such as
iOS Security Baseline – Supervised.Review Apple Account first, since it's off by default.
Set the camera, biometric, USB, privacy, and device settings you need.
Save the policy.
Assign it to a device group.
Test on a few devices of each platform before a wider rollout.
Example configurations
Example 1: Supervised company iPhones
Setting | Value |
Apple Account | Off |
Allow Erase All Content and Settings | Off |
Allow Host Pairing | Off |
Allow Files USB Drive Access | Off |
Force Limit Ad Tracking | On |
Allow Diagnostic Submission | Off |
All other settings | Defaults |
Users can't sign in with personal accounts, erase the device, pair it with a computer, or copy files to USB drives.
Example 2: Company Macs where users add their own email
Setting | Value |
Apple Account | On |
Allow Erase All Content and Settings | Off |
Enforced Fingerprint Timeout | 86400 (24 hours) |
Allow Diagnostic Submission | Off |
All other settings | Defaults |
Turning on Apple Account lets users add Mail, Contacts, and Calendar accounts.
Example 3: Supervised shared iPads in a clinic
Setting | Value |
Allow Camera | Off |
Apple Account | Off |
Allow Fingerprint Modification | Off |
Allow Erase All Content and Settings | Off |
Allow Files USB Drive Access | Off |
All other settings | Defaults |
Verify the policy
iPhone or iPad
Go to Settings > General > VPN & Device Management, open the Swif profile, and confirm that it lists Restrictions.
Test a restricted setting:
If Apple Account is off, try to add a mail account in the Mail settings. The option to add an account should be unavailable.
If Allow Erase All Content and Settings is off, check that the erase option is unavailable in Settings > General > Transfer or Reset iPhone.
Mac
Open System Settings > General > Device Management and open the Swif profile. Confirm that the restrictions appear.
Test a restricted setting:
If Apple Account is off, try to add an account in System Settings > Internet Accounts.
If Allow Camera is off, open an app that uses the camera.
In Swif, open the device and confirm that the policy shows as applied.
Troubleshooting
Users can't add email, contacts, or calendar accounts
This is expected when Apple Account is off. Turn it on if users need to add accounts.
A user is still signed in with a personal Apple Account
Turning off Apple Account blocks changes but doesn't sign out existing accounts. Have the user sign out before you apply the policy, or erase the device.
A setting has no effect on an iPhone or iPad
Check whether the setting requires supervision.
Check the OS version.
The device can't sync with or connect to a computer
Allow Host Pairing is off. Turn it on, or configure a supervision host certificate so the device can still pair with the supervising Mac.
USB accessories connect while the iPhone is locked
Allow USB Restricted Mode is off, or Lockdown Mode is on, which ignores this setting.
A Mac behaves inconsistently for a setting
Another profile, such as the Application Access Policy, may set the same restriction differently. On macOS, the result is undefined. Remove the setting from one policy.
Nothing applies on a personal device
User Enrollment supports only Allow Diagnostic Submission.
Related resources
Swif
Apple