Overview
The Apple App Store Policy controls how the Mac App Store behaves on managed Macs. You can use it to:
block the App Store app
stop users from adopting the Apple apps that came with the Mac
turn off software update notifications
This policy applies only to macOS. It doesn't affect the App Store on iPhone or iPad.
Important: Restrict Store Software Update Only blocks the App Store on current macOS. On macOS 10.14 and later, turning on Restrict Store Software Update Only stops the App Store app from opening at all. It doesn't limit the App Store to updates. The updates-only behavior applied only to macOS 10.10 through 10.13.
Supported platforms and requirements
Item | Details |
Platform | macOS |
Minimum OS | macOS 10.9 or later for the policy; each setting requires macOS 10.10 or later |
Device ownership | Company-owned devices |
Supervision | Not required |
User Enrollment (BYOD) | Not supported. Apple doesn't allow the App Store payload on User Enrollment. |
Settings reference
All settings are off by default. A new policy with no changes doesn't restrict the App Store.
Setting | What it does when turned on | Default | Minimum OS |
Disable Software Update Notifications | Turns off software update notifications for users. It doesn't stop updates from being available or installed. | Off | macOS 10.10 |
Restrict Store Disable App Adoption | Users can't adopt the Apple apps that shipped with the Mac, such as the iWork and iLife apps (for example, Pages, Numbers, Keynote, iMovie, and GarageBand). | Off | macOS 10.10 |
Restrict Store Software Update Only | macOS 10.14 and later: the App Store app can't open.<br>macOS 10.10–10.13: the App Store can install only software updates. | Off | macOS 10.10 |
About app adoption
Macs can come with Apple apps that weren't downloaded from the App Store under the user's Apple Account. Adoption lets a user claim these apps with their Apple Account so they can update them through the App Store. When Restrict Store Disable App Adoption is on, users can't adopt them.
This setting affects only those bundled Apple apps. It doesn't move apps into your organization's account. To manage Apple apps with your organization's licenses, assign them through Apple Business Manager or Apple School Manager and deploy them with Swif.
About update notifications
Apple describes Disable Software Update Notifications only as turning off software update notifications. It doesn't document which notifications are affected on current macOS. Test it on your macOS versions before relying on it.
Turning off notifications doesn't defer or block updates. To control when macOS updates install, use the Apple Software Update Policy.
What happens when the App Store is blocked
On macOS 10.14 and later, Restrict Store Software Update Only has these effects:
The App Store app won't open. Users can't browse, buy, download, or update apps from the App Store.
macOS updates aren't affected. Starting with macOS 10.14, macOS updates come from System Settings > General > Software Update (on older versions, System Preferences > Software Update), not the App Store.
Apps deployed by Swif still update. Apple updates device-assigned apps when your MDM sends an install command, not through the App Store. Keep apps current through Swif.
App Store apps users installed themselves stop updating. Users can't open the App Store to update them. Deploy those apps through Swif instead, or remove them.
Before you start
Decide how users will get apps. If you block the App Store, deploy every app users need through Swif.
Check macOS versions. Restrict Store Software Update Only behaves differently on macOS 10.13 and earlier.
Plan updates separately. This policy doesn't install or defer updates. Use the Apple Software Update Policy for that.
Create the policy
In Swif, go to Device Management > Policies > New Policy.
Select Apple App Store Policy.
Enter a clear name, such as
Mac App Store – Blocked.Turn on the settings you need.
Save the policy.
Assign it to a device group of Macs.
Test on a few Macs before a wider rollout.
Example configurations
Example 1: Block the App Store on company Macs
For organizations that deploy all apps through Swif.
Setting | Value |
Restrict Store Software Update Only | On |
Restrict Store Disable App Adoption | On |
Disable Software Update Notifications | Off |
Users can't open the App Store. Swif handles app deployment and updates. Leaving update notifications on means users still see macOS update prompts.
Example 2: Keep the App Store but stop personal adoption of bundled apps
For organizations that allow the App Store but license Apple's bundled apps centrally.
Setting | Value |
Restrict Store Software Update Only | Off |
Restrict Store Disable App Adoption | On |
Disable Software Update Notifications | Off |
Example 3: Reduce update prompts on shared or kiosk Macs
For Macs where update notifications would interrupt users. Pair this policy with the Apple Software Update Policy so the Macs still install updates.
Setting | Value |
Restrict Store Software Update Only | On |
Restrict Store Disable App Adoption | On |
Disable Software Update Notifications | On |
Verify the policy
On the Mac:
Open System Settings > General > Device Management (on older macOS, System Preferences > Profiles). Open the Swif profile and confirm that it includes the App Store settings.
Alternatively, run this in Terminal and look for the
com.apple.appstorepayload:sudo profiles show -type configuration
If Restrict Store Software Update Only is on, open the App Store. On macOS 10.14 and later, it shouldn't open.
If Restrict Store Disable App Adoption is on, confirm that the App Store doesn't offer to adopt bundled Apple apps.
In Swif, open the device and confirm that the policy shows as applied.
Troubleshooting
Users can't open the App Store at all
This is expected on macOS 10.14 and later when Restrict Store Software Update Only is on. Turn it off if users need the App Store.
Apps that users installed from the App Store aren't updating
The App Store is blocked, so users can't update them. Deploy these apps through Swif, or turn off Restrict Store Software Update Only.
macOS updates are still showing or installing
This policy doesn't control macOS updates. Disable Software Update Notifications affects only notifications, and Apple doesn't document its exact scope on current macOS. Use the Apple Software Update Policy to manage updates.
The policy doesn't apply to a personal Mac
User Enrollment doesn't support the App Store payload.
Related resources
Swif
Apple