Skip to main content

Apple iOS/iPadOS Application Block Policy

Overview

The Apple iOS/iPadOS Application Block Policy controls which apps users can open and install on supervised iPhones and iPads. You can:

  • Block specific apps by bundle ID, so they're hidden and can't be opened

  • Turn off app installation, which removes the App Store and stops users from installing or updating apps themselves

A new policy with no changes doesn't block anything.

Important: This policy works only on supervised iPhones and iPads. Unsupervised devices ignore both settings. Devices are supervised when enrolled through Automated Device Enrollment or prepared with Apple Configurator.

Supported platforms and requirements

Item

Details

Platforms

iOS, iPadOS

Minimum OS

iOS 15.0, iPadOS 15.0

Device ownership

Company-owned devices

Supervision

Required

User Enrollment (BYOD)

Not supported. Apple doesn't allow these restrictions on User Enrollment.

This policy doesn't apply to Macs. To block apps on macOS, use the Apple Application Block Policy. To limit the Mac App Store, use the Apple App Store Policy.


Settings reference

Setting

What it does

Default

Blocked App Bundle IDs

Apps with these bundle IDs are hidden from the Home Screen and can't be opened. Add com.apple.webapp to block all web clips. Applies to App Store apps, marketplace apps, and apps installed with Apple Configurator or Xcode.

Empty

Allow App Installation

When off, the App Store is turned off and its icon is removed, and users can't install or update apps. This includes App Store apps, marketplace apps, and apps installed with Apple Configurator or Xcode. Apps that Swif installs still install, because MDM commands can override this restriction.

On

What blocking an app does

  • Blocked apps stay installed. They're hidden and can't be opened, but they aren't deleted. They come back when you remove them from the list.

  • Blocking a system app can affect other features. For example, blocking the App Store app can stop users from accepting the terms for user-based Volume Purchase Program (VPP) apps.

  • Turning off app installation also stops updates. Users can't update App Store apps themselves. Keep apps current through Swif.


Finding bundle IDs

Each app has a unique bundle ID. Some common ones:

App

Bundle ID

Safari

com.apple.mobilesafari

App Store

com.apple.AppStore

Messages

com.apple.MobileSMS

FaceTime

com.apple.facetime

YouTube

com.google.ios.youtube

Instagram

com.burbn.instagram

TikTok

com.zhiliaoapp.musically

All web clips

com.apple.webapp

For other Apple apps, see Apple's bundle IDs for iPhone and iPad apps. For third-party apps, ask the developer or look up the app's bundle ID before you add it. Bundle IDs must match exactly.


About iOS and iPadOS 27

In iOS and iPadOS 27, Apple deprecated the restriction behind Blocked App Bundle IDs. Apple recommends declarative app settings instead. The restriction still works on iOS 27, but Apple may remove it in a future release. This article will be updated when Swif supports the replacement.


Before you start

  1. Check that devices are supervised.

  2. Collect the bundle IDs of the apps you want to block.

  3. Plan how users will get apps. If you turn off Allow App Installation, deploy every needed app through Swif.

  4. Check for VPP dependencies before blocking the App Store.


Create the policy

  1. In Swif, go to Device Management > Policies > New Policy.

  2. Select Apple iOS/iPadOS Application Block Policy.

  3. Enter a clear name, such as iPhone – Block Social Apps.

  4. Add bundle IDs to Blocked App Bundle IDs, one per entry.

  5. Set Allow App Installation.

  6. Save the policy.

  7. Assign it to a device group of supervised iPhones and iPads.

  8. Test on a few devices before a wider rollout.


Example configurations

Example 1: Block social media on company iPhones

Setting

Value

Blocked App Bundle IDs

com.burbn.instagram, com.zhiliaoapp.musically, com.google.ios.youtube

Allow App Installation

On

Users can still install other apps, but the listed apps are hidden and can't be opened.

Example 2: Locked-down frontline iPads

Setting

Value

Blocked App Bundle IDs

com.apple.webapp

Allow App Installation

Off

The App Store is removed, users can't install apps, and web clips are blocked. Swif deploys and updates all required apps.

Example 3: Classroom iPads without messaging

Setting

Value

Blocked App Bundle IDs

com.apple.MobileSMS, com.apple.facetime

Allow App Installation

Off


Verify the policy

On the iPhone or iPad:

  1. Go to Settings > General > VPN & Device Management, open the Swif profile, and confirm that it lists Restrictions.

  2. Check that blocked apps no longer appear on the Home Screen or in the App Library.

  3. If Allow App Installation is off, confirm that the App Store icon is gone.

  4. Deploy a test app from Swif and confirm that it still installs.

In Swif, open the device and confirm that the policy shows as applied.


Troubleshooting

Blocked apps still open

  • Check that the device is supervised.

  • Check that the bundle ID is exact.

  • Check that the device runs iOS/iPadOS 15 or later.

Users can still install apps

  • Check that the device is supervised.

  • Check that Allow App Installation is off.

Apps deployed by Swif don't install

  • Check that the app is assigned to the device in Swif.

  • Check that it isn't on Blocked App Bundle IDs.

Users can't accept VPP terms

The App Store is blocked. Allow it temporarily so users can accept, or assign VPP apps to devices instead of users.

Apps aren't updating

With Allow App Installation off, users can't update apps. Update them through Swif.

Nothing applies on a personal device

User Enrollment doesn't support these restrictions.


Related resources

Swif

Apple

Did this answer your question?