Overview
The Apple Multiple Wi-Fi Policy lets administrators deploy several managed Wi-Fi network configurations to Apple devices from one Swif policy.
The policy can configure:
Multiple office, school, branch, lab, or fallback Wi-Fi networks
Personal or enterprise authentication
Automatic joining and hidden SSIDs
EAP and certificate-based authentication
Manual or automatic proxy settings
Hotspot 2.0 and roaming settings
Cisco QoS marking
MAC address randomization behavior
Blocking of saved passwordless Wi-Fi networks on managed Macs
Apple permits more than one managed Wi-Fi payload on a device. Swif creates a separate Wi-Fi configuration for each network added to the policy. For more information, see Wi-Fi device management settings for Apple devices.
Important: Test the policy on a small device group before broad deployment. An incorrect SSID, password, certificate, EAP setting, or proxy can prevent a device from connecting to the intended network.
Supported Platforms
Capability | Supported platform |
Managed Wi-Fi configurations | macOS 10.7 or later |
Managed Wi-Fi configurations | iOS 4.0 or later |
Managed Wi-Fi configurations | iPadOS 4.0 or later |
Block Public Wi-Fi | macOS 10.7 or later |
Disable Association MAC Randomization | macOS 15 or later, iOS 14 or later, and iPadOS 14 or later |
The policy supports both company-owned and BYOD devices. Availability of individual advanced settings depends on the operating system version, enrollment method, network type, and Apple platform.
What This Policy Does
For every entry under Multiple Wi-Fi Payload Content, Swif sends a managed Wi-Fi payload containing that network’s settings.
When the policy is installed:
The device receives each configured network.
A network with Auto Join enabled becomes eligible for automatic connection.
The device selects among available eligible networks according to Apple’s network-selection behavior, signal conditions, frequency band, security, and prior connection state.
Enterprise networks use the configured EAP credentials, trusted certificates, and server-name validation.
Proxy, Hotspot 2.0, and QoS settings apply only to the network entry in which they are configured.
The order of network entries in Swif is not a configurable Wi-Fi priority list. Apple decides which eligible network to join. When the same network is broadcast on multiple bands, Apple may prefer 5 GHz or 6 GHz when signal conditions meet its thresholds. See How Apple devices join Wi-Fi networks.
This policy does not:
Create or modify the wireless access point.
Guarantee that a device always selects the first network listed in Swif.
Supply certificates that are not included in the applicable configuration profile.
Validate RADIUS, proxy, DNS, captive portal, or internet availability.
Block all unapproved Wi-Fi networks on iPhone or iPad.
Prevent cellular networking, Ethernet, personal hotspots, or other network interfaces.
Block Public Wi-Fi on macOS
Block Public Wi-Fi is a Swif agent action for managed Macs.
When enabled, the Swif agent:
Scans the Mac’s preferred Wi-Fi networks.
Identifies saved networks that do not have a stored password.
Removes those passwordless networks from the preferred network list.
Disconnects the Mac if it is currently connected to one of those networks.
This setting is designed to reduce automatic or continued use of saved open Wi-Fi networks.
Important: This setting applies only to macOS. It is not an iOS or iPadOS Wi-Fi restriction, and it should not be treated as a complete network-access control or content-filtering solution.
Open Wi-Fi can include legitimate guest, hotel, airport, conference, onboarding, or captive-portal networks. Enable this setting only after confirming that affected users have another approved way to connect.
Before You Begin
Collect and verify the following information for every network:
Exact SSID, including capitalization and spaces
Network security type
Password, if using personal authentication
Whether the SSID is hidden
Whether devices should join automatically
EAP type and credential method for enterprise authentication
Trusted CA certificate and accepted RADIUS server names
Client identity certificate, if required
Proxy type, server, port, credentials, or PAC URL
Hotspot 2.0 roaming information, when applicable
Cisco QoS requirements, when applicable
Also confirm:
The target devices are enrolled in Swif and online.
At least one working network path remains available while testing.
Required certificates are available in the same profile when referenced by payload UUID.
The device clock is correct because certificate validation depends on time.
The network allows access to Apple services and Swif management endpoints.
The configuration has been tested with the operating-system versions and device models used in production.
For certificate-based networks, coordinate with the network or identity team before deployment. Do not weaken server-certificate validation simply to bypass a trust prompt.
Create the Policy
In the Swif Admin Dashboard, go to Device Management > Policies.
Create a new policy.
Select Apple Multiple Wi-Fi Policy.
Enter a descriptive policy name.
Configure Block Public Wi-Fi for Mac devices.
Under Multiple Wi-Fi Payload Content, select Add.
Enter the SSID and select the correct Encryption Type.
Configure the password, hidden-network behavior, and Auto Join setting.
Enable Advanced Network Configurations only when the network requires enterprise authentication, a proxy, Hotspot 2.0, QoS, or another advanced option.
Add another Wi-Fi entry for each additional network.
Assign the policy to one test device or a small test device group.
Verify every intended network before expanding the assignment.
Recommended Configuration
Standard Company Network
Setting | Recommended value |
Block Public Wi-Fi | Enabled for company-owned Macs when open Wi-Fi is prohibited |
SSID | Exact corporate network name |
Encryption Type |
|
Hidden Network | Disabled unless the SSID is intentionally hidden |
Auto Join | Enabled |
Advanced Network Configurations | Disabled unless required |
For an enterprise network, enable advanced settings and configure EAP, trusted certificates, and accepted server names.
BYOD Baseline
Setting | Recommended value |
Block Public Wi-Fi | Disabled unless required, disclosed, and appropriate for the enrollment model |
SSID | Work network only |
Auto Join | Enabled when automatic connection is expected |
Advanced settings | Configure only work-related authentication and routing |
Avoid deploying unrelated personal network credentials or a broad proxy configuration to personally owned devices.
Basic Policy Settings
Block Public Wi-Fi
Controls the Swif agent’s handling of saved passwordless networks on macOS.
Value | Behavior |
Enabled | Removes passwordless networks from the preferred list and disconnects an active passwordless Wi-Fi connection. |
Disabled | Swif does not perform this passwordless-network cleanup. |
The default value is Disabled.
Because some captive portals use open Wi-Fi before browser-based authentication, enabling this setting can interrupt legitimate travel or guest-network access.
Multiple Wi-Fi Payload Content
Contains one or more managed network entries. Add a separate entry for every SSID or roaming configuration that the device needs.
Avoid duplicate entries for the same SSID unless the configurations are intentionally different and have been tested. Conflicting payloads can produce unpredictable connection or authentication behavior.
Basic Network Settings
Service Set Identifier (SSID)
The exact name of the Wi-Fi network.
Example:
Swif-Corporate
SSID matching is case-sensitive. Include spaces and punctuation exactly as configured on the access point.
On iOS 7 and later and iPadOS, an SSID can be omitted for certain Hotspot 2.0 configurations when Domain Name is provided. For ordinary Wi-Fi networks, enter the SSID.
Password
The password for a personal Wi-Fi network.
Use this field for password-based WEP, WPA, WPA2, or WPA3 networks. If a protected network is deployed without a password, the device may prompt the user when it first connects.
Do not enter a shared Wi-Fi password when the network uses EAP or certificate-based enterprise authentication. Configure EAP Client Configuration instead.
Treat Wi-Fi passwords as sensitive credentials. Rotate them according to organizational policy and update the Swif policy before retiring the old password.
Encryption Type
Defines the network security types that the device may use.
Value | Intended use |
| Legacy WEP networks; avoid for production use |
| WPA or, on newer Apple operating systems, compatible WPA/WPA2 networks |
| WPA2 or, on newer Apple operating systems, compatible WPA2/WPA3 networks |
| WPA3-only networks |
| Allows supported WEP, WPA, WPA2, or WPA3 matching |
| Open network without password-based encryption |
The default value is Any.
On iOS 16 and later, iPadOS 16 and later, and macOS 13 and later:
WPAcan join WPA or WPA2 networks.WPA2can join WPA2 or WPA3 networks.WPA3joins WPA3 networks only.Anypermits compatible WEP, WPA, WPA2, and WPA3 networks.
Before macOS 13, an explicitly selected encryption type generally needed to match the network exactly.
Use the narrowest value compatible with the production network. Avoid WEP because it does not provide modern security. Apple documents its supported personal network settings in WEP, WPA, WPA2, and WPA2/WPA3 device management settings.
Hidden Network
Specifies whether the SSID is hidden.
Value | Behavior |
Enabled | The device actively looks for the configured hidden SSID. |
Disabled | The device expects the SSID to be broadcast normally. |
The default value is Disabled.
Enable this setting only when the access point is configured not to broadcast the SSID. Hiding an SSID is not a meaningful security control and can affect privacy and connection reliability.
Auto Join
Controls whether the device automatically joins the network when it is available.
Value | Behavior |
Enabled | The network is eligible for automatic connection. |
Disabled | The user must select the network to connect. |
The default value is Enabled.
Auto Join does not establish a strict priority among the networks in this policy. Apple’s operating system chooses among available eligible networks.
Advanced Network Configurations
Shows settings for enterprise authentication, certificates, proxies, Hotspot 2.0, Cisco QoS, and other specialized network behavior.
The default value is Disabled.
Leave it disabled for a standard personal WPA2 or WPA3 network that requires only an SSID and password.
Enterprise Authentication Settings
Certificate UUID
The payload UUID of the client identity certificate used for network authentication.
The referenced certificate payload must be present in the same configuration profile. A certificate’s display name, serial number, or file name is not a substitute for its payload UUID.
Use this field for certificate-based authentication such as EAP-TLS. Confirm that the certificate contains the required identity, private key, key usage, and certificate chain.
EAP Client Configuration
Configures 802.1X enterprise authentication.
Apple devices support commonly deployed EAP methods including EAP-TLS, EAP-TTLS, EAP-FAST, PEAP, EAP-SIM, EAP-AKA, and LEAP. Configure only methods supported by the organization’s RADIUS service.
Accept EAP Types
Enter one or more EAP type numbers:
Value | EAP method |
| EAP-TLS |
| LEAP |
| EAP-SIM |
| EAP-TTLS |
| EAP-AKA |
| PEAP |
| EAP-FAST |
EAP-TLS with a device or user identity certificate is generally preferred when the organization can operate the required certificate infrastructure.
Certificate Anchor UUID
A list of certificate payload UUIDs that identify trusted CA certificates for the authentication server.
Use certificate anchors with Trusted Server Certificate Names to prevent devices from trusting an unauthorized RADIUS server. If anchors are configured incorrectly or the server certificate chain changes, authentication can fail.
Trusted Server Certificate Names
A list of accepted common names for the RADIUS server certificate.
Example:
radius01.example.com radius02.example.com
A wildcard can be used when necessary:
radius*.example.com
Use the narrowest verified names possible. When server names or anchors are configured, dynamic trust prompts may be disabled. This protects users from accepting an unexpected authentication server, but it also means certificate renewal and server-name changes must be planned.
Username
The username used for enterprise authentication. If omitted, the device may prompt the user when credentials are required.
Do not place one employee’s credential in a policy assigned to multiple users.
User Password
The password used with the enterprise username. If omitted, the device may prompt the user.
For scalable deployments, prefer certificate-based authentication or a supported per-user credential workflow instead of embedding a shared enterprise password.
System Profile Credentials Source
Enter ActiveDirectory to use the Active Directory computer name and password for supported system-mode authentication.
Do not configure this setting together with Use OpenDirectory System Profile Credentials.
Use OpenDirectory System Profile Credentials
When enabled, system-mode authentication attempts to use Open Directory credentials.
Do not configure this setting together with System Profile Credentials Source.
EAP Setup Modes
Determines the macOS connection contexts to which the 802.1X configuration attaches.
Available values:
System
Loginwindow
Use System when the Mac must establish network access without depending on a signed-in user. Use Loginwindow when network authentication is required at the macOS login window. Test FileVault, login-window, local-account, and offline behavior before broad deployment.
Certificate Required
Controls certificate requirements for applicable EAP methods.
Use this setting only when it matches the organization’s RADIUS design. Certificate requirements differ among EAP-TLS, EAP-TTLS, PEAP, and EAP-FAST. An incorrect setting can cause authentication failure or weaken the intended authentication model.
For more details, see EAP device management settings for Apple devices.
Proxy Settings
Proxy Type
Determines whether the network uses no proxy, a manually configured proxy, or a proxy auto-configuration file.
Value | Behavior |
| No managed proxy for this network |
| Uses a specified proxy server and port |
| Uses a PAC URL |
Proxy settings apply to the corresponding Wi-Fi network entry.
Manual Proxy
When Proxy Type is Manual, configure:
Proxy Server: Hostname or IP address of the proxy
Proxy Server Port: Integer from
0through65535Proxy Username: Optional username
Proxy Password: Optional password
Example:
Setting | Example |
Proxy Server |
|
Proxy Server Port |
|
Confirm that the proxy permits access to Apple activation, push notification, certificate, software update, and Swif management services.
Automatic Proxy
When Proxy Type is Auto, configure:
Proxy PAC URL: HTTPS or HTTP URL of the proxy auto-configuration file
Allow direct connect if proxy PAC is unreachable: Whether the device can bypass the proxy when the PAC file cannot be retrieved
Enabling direct fallback improves availability but may allow traffic to bypass required inspection or routing. Disabling fallback preserves enforcement but can leave the device without network access when the PAC service is unavailable.
Privacy and Captive Network Settings
Captive Bypass
On iOS 10 and later and iPadOS 10 and later, bypasses Apple’s captive-network detection for the configured network.
Enable this only when the network does not require a captive portal. If enabled on a portal-based network, users may not receive the page needed to accept terms or complete authentication.
Disable Association MAC Randomization
When enabled, the device uses a nonprivate MAC address while associated with the configured network.
Supported by this Swif policy on:
macOS 15 or later
iOS 14 or later
iPadOS 14 or later
Disabling MAC randomization can help networks that rely on stable hardware addresses for access control, inventory, or troubleshooting. It also reduces a privacy protection, and Apple displays a privacy warning in Settings.
Use this setting only when a documented network dependency requires a stable MAC address. Prefer identity- or certificate-based access controls where possible.
Hotspot 2.0 and Roaming Settings
The following settings are intended for Hotspot 2.0, Passpoint, or service-provider roaming deployments. Do not configure them for an ordinary SSID unless instructed by the network provider.
Provider Display Name
The operator name displayed when the device connects to the Hotspot 2.0 network.
Domain Name
The primary domain used to identify the Hotspot 2.0 service.
For applicable iOS and iPadOS configurations, this can identify the service when no SSID is specified.
Is Hotspot
Marks the network as a hotspot on supported Mac devices.
Realm Names
A list of Network Access Identifier realm names used during Hotspot 2.0 negotiation.
Example:
example.com wifi.example.com
Roaming OIs
A list of Roaming Consortium Organization Identifiers used for Hotspot 2.0 negotiation.
Enter each identifier exactly as supplied by the roaming provider.
Connect to Roaming Partner Passpoint Networks
Allows the device to connect to compatible roaming service providers.
Enabling this can expand the networks to which a device is eligible to connect. Confirm the roaming consortium, authentication, cost, and data-handling requirements before deployment.
Interface
Specifies the interface selection used by applicable advanced network configurations.
Available Swif values include:
NoValue
AnyEthernet
FirstEthernet
FirstActiveEthernet
SecondEthernet
SecondActiveEthernet
ThirdEthernet
ThirdActiveEthernet
Leave this unset unless the network design specifically requires one of these interface modes. Test it on the target Apple platform because interface behavior is configuration-dependent.
Cisco QoS Marking Policy
The QoS Marking Policy controls which applications can use Layer 2 and Layer 3 traffic marking on a compatible Cisco Fastlane network.
Allow QoS Marking
Controls QoS marking for the configured network.
Enable it only when the wireless infrastructure is configured for Cisco Fastlane and the organization has verified the intended traffic treatment.
Allow List App Identifiers
A list of application bundle identifiers permitted to benefit from QoS marking.
Example:
com.example.voice com.example.meetings
When the QoS dictionary is present but the allowlist is absent, Apple behavior can differ from a configuration in which the entire QoS dictionary is omitted. Test the effective result before deployment.
QoS Marking for Audio/Video Calls
Adds traffic from built-in Apple audio and video services, such as FaceTime and Wi-Fi Calling, to the QoS allowlist.
Enable it only when those services are permitted and should receive prioritized treatment on the managed network.
Example Configurations
Example 1: Two Office Networks
Setting | Primary office | Backup office |
SSID |
|
|
Encryption Type |
|
|
Password | Organization-managed value | Organization-managed value |
Hidden Network | Disabled | Disabled |
Auto Join | Enabled | Enabled |
Advanced Network Configurations | Disabled | Disabled |
Apple decides which eligible network to use. The entry order does not force the primary network to win.
Example 2: Corporate and Guest Networks
Setting | Corporate | Guest |
SSID |
|
|
Encryption Type |
| Match actual guest security |
Auto Join | Enabled | Disabled |
Advanced Network Configurations | EAP as required | Captive behavior as required |
Use Auto Join: Disabled for the guest network if it should remain a manual fallback.
If the guest network is passwordless, enabling Block Public Wi-Fi on macOS conflicts with the intended fallback because Swif removes saved passwordless networks and disconnects from them.
Example 3: EAP-TLS Enterprise Network
Setting | Example value |
SSID |
|
Encryption Type | Match the enterprise WLAN |
Auto Join | Enabled |
Advanced Network Configurations | Enabled |
Accept EAP Types |
|
Certificate UUID | Client identity certificate payload UUID |
Certificate Anchor UUID | Organizational CA certificate payload UUID |
Trusted Server Certificate Names |
|
EAP Setup Modes |
|
Test certificate issuance, renewal, revocation, and RADIUS server rollover before production deployment.
Example 4: Network With a PAC Proxy
Setting | Example value |
SSID |
|
Encryption Type |
|
Auto Join | Enabled |
Proxy Type |
|
Proxy PAC URL |
|
Allow direct connect if PAC is unreachable | Disabled when proxy bypass is prohibited |
Confirm that the PAC URL is reachable before the proxy configuration is required.
Company-Owned and BYOD Considerations
Company-Owned Devices
For company-owned Apple devices:
Deploy only approved production and fallback networks.
Enable Auto Join for required networks.
Use WPA2, WPA3, or enterprise EAP rather than WEP or open Wi-Fi.
Enable Block Public Wi-Fi on Macs when organizational policy prohibits saved passwordless networks.
Use certificate-based enterprise authentication when practical.
Validate RADIUS server names and CA anchors.
Avoid embedding shared user credentials.
Review proxy fallback and MAC-randomization decisions with the security team.
Remove obsolete SSIDs, certificates, and credentials promptly.
BYOD Devices
For personally owned devices:
Limit the policy to work-related networks.
Tell users when the device will join automatically.
Disclose certificate, proxy, MAC-address, and public-Wi-Fi controls.
Avoid blocking open Wi-Fi on Macs unless the requirement is appropriate and clearly communicated.
Avoid routing unrelated personal traffic through an organizational proxy.
Confirm that the enrollment model supports the intended payload behavior.
Remove work network access and credentials during unenrollment or offboarding.
The policy configures networking on the device. It does not create a separate physical Wi-Fi interface for work traffic.
Verify the Policy
macOS
Confirm that the policy reports as installed in Swif.
Open System Settings > Wi-Fi.
Confirm that the expected managed networks appear.
Move the Mac within range of each test SSID.
Verify Auto Join behavior.
Confirm that the device receives an IP address, DNS, routing, and internet access.
Test internal resources and the configured proxy.
For enterprise Wi-Fi, verify the certificate identity and RADIUS server trust.
If Block Public Wi-Fi is enabled, confirm during a controlled test that a saved passwordless network is removed and an active passwordless connection is disconnected.
To view the current Wi-Fi connection:
networksetup -getairportnetwork en0
The Wi-Fi service may use a different hardware port on some Macs. To list ports:
networksetup -listallhardwareports
To inspect installed configuration profiles:
sudo profiles show -type configuration
Profile output can contain SSIDs, account names, server addresses, and other sensitive configuration. Redact it before sharing.
iPhone and iPad
Confirm that the device received the policy in Swif.
Open Settings > Wi-Fi.
Confirm that the expected network is available or connected.
Select the network’s information button and review applicable managed behavior.
Test automatic joining, authentication, captive behavior, and proxy routing.
Repeat the test after a restart and after moving between access points.
Block Public Wi-Fi verification is not applicable to iPhone or iPad.
Troubleshooting
The Policy Is Installed but the Device Does Not Join
Confirm that the SSID is within range.
Verify the exact spelling and capitalization of the SSID.
Confirm that Encryption Type matches the access point and operating-system behavior.
Re-enter the password.
Confirm that Hidden Network matches the access point configuration.
Verify that Auto Join is enabled.
Check for a conflicting Wi-Fi payload for the same SSID.
Confirm that the device can reach DHCP and DNS services.
Test without optional proxy or advanced settings on a separate test profile.
Do not remove the device’s only working network profile until another management path is available.
The Device Joins the Wrong Managed Network
The list order in Swif is not a strict priority.
Disable Auto Join for networks intended only as manual fallbacks.
Remove obsolete or overlapping SSIDs.
Check whether multiple payloads configure the same SSID.
Review signal strength and access-point coverage.
Confirm that the preferred network uses the intended security and frequency band.
The Device Repeatedly Requests a Password
Confirm that the network uses personal rather than enterprise authentication.
Verify the stored password.
Confirm that the encryption type matches.
Check whether the access point password recently changed.
Remove duplicate or conflicting payloads for the same SSID.
For enterprise Wi-Fi, inspect the EAP settings rather than entering the shared Wi-Fi password field.
Enterprise Authentication Fails
Confirm the selected EAP type.
Verify that the client identity certificate and private key are present.
Confirm that referenced certificate UUIDs belong to payloads in the same profile.
Verify the certificate validity period and device clock.
Confirm that the trusted CA anchors match the RADIUS server chain.
Confirm that the server certificate name matches Trusted Server Certificate Names.
Verify the username format and credential source.
Review RADIUS logs for the exact rejection reason.
Test certificate renewal and intermediate CA delivery.
Never tell users to accept an unexpected RADIUS certificate as a routine workaround.
The Hidden Network Does Not Connect
Confirm that Hidden Network is enabled.
Verify the SSID exactly.
Confirm that the access point is configured as hidden.
Test whether the same authentication settings work when the SSID is temporarily broadcast.
Review access-point logs for probe and authentication attempts.
Hidden SSIDs can be less reliable and do not provide meaningful protection against network discovery.
The Proxy Prevents Network Access
Confirm the proxy hostname and port.
Verify proxy credentials.
Confirm that the PAC URL is reachable without first requiring the proxy.
Validate the PAC file syntax and MIME type.
Check whether direct fallback is allowed.
Confirm that required Apple and Swif services are permitted.
Test DNS resolution and certificate trust.
If proxy bypass is prohibited, maintain redundant PAC and proxy infrastructure before disabling direct fallback.
Block Public Wi-Fi Does Not Disconnect the Mac
Confirm that the device is a Mac and the Swif agent is running.
Confirm that Block Public Wi-Fi is enabled and the policy is assigned.
Confirm that the active network is actually passwordless.
Trigger a device or policy sync.
Review the policy command history and Swif agent logs.
Check whether the network uses Opportunistic Wireless Encryption or another configuration that does not appear as a simple passwordless preferred network.
The feature operates on saved passwordless networks detected by the Mac agent. It is not a packet filter or a universal ban on every possible open network.
A Required Guest Network Is Removed
If the guest network is passwordless, this is expected when Block Public Wi-Fi is enabled on macOS.
Choose one of the following:
Disable Block Public Wi-Fi for the affected device group.
Provide a protected guest network.
Supply an approved alternative connection.
Assign a different policy to users who require public or captive-portal access.
MAC-Based Access Control Stops Working
Confirm whether the network expects a stable hardware MAC address.
On supported operating systems, evaluate Disable Association MAC Randomization.
Confirm that the device has re-associated after the policy change.
Update the network access-control record if needed.
Disabling MAC randomization reduces privacy. Prefer certificate- or identity-based access control when possible.
Hotspot 2.0 Roaming Does Not Work
Verify the domain name, realm names, and roaming OIs.
Confirm that the provider supports the device and credentials.
Confirm that service-provider roaming is enabled.
Review certificate and EAP requirements.
Test with the provider’s production Passpoint profile values.
Security and Compliance Impact
Managed Wi-Fi profiles help organizations standardize network authentication, reduce credential-entry errors, and apply network-specific proxy and trust settings.
For a secure deployment:
Prefer WPA3, WPA2, or enterprise EAP over WEP or open Wi-Fi.
Use unique certificate identities where possible.
Validate RADIUS server certificates with trusted CA anchors and server names.
Avoid shared enterprise usernames and passwords.
Protect Wi-Fi and proxy credentials in administrator workflows.
Keep certificate renewal and revocation processes documented.
Review every Auto Join network.
Treat proxy fallback as a security decision.
Disable MAC randomization only for a documented requirement.
Test policy changes before rotating passwords, certificates, SSIDs, or RADIUS servers.
Maintain an alternate management path during network migrations.
Block Public Wi-Fi can reduce exposure to saved passwordless networks on Macs, but it does not replace a firewall, VPN, DNS security service, web filter, zero-trust access control, or user security training.
This policy supports network security and configuration management objectives, but it does not independently make an organization compliant with a particular framework.
Notes
Each network entry becomes a separate managed Wi-Fi configuration.
Apple supports multiple Wi-Fi payloads on one device.
The order of entries does not create a strict network priority.
Auto Join is enabled by default.
Hidden Network is disabled by default.
Encryption Type defaults to
Any.Block Public Wi-Fi is disabled by default and applies only to macOS.
A passwordless captive-portal network may be removed when Block Public Wi-Fi is enabled.
Certificate UUIDs must reference the applicable certificate payload in the same profile.
Proxy, EAP, Hotspot 2.0, QoS, and privacy settings apply per network entry.
Feature availability varies by Apple platform and operating-system version.
Removing the policy can remove managed network configuration and may disconnect the device.
Summary
The Apple Multiple Wi-Fi Policy deploys several managed Wi-Fi networks to Mac, iPhone, and iPad devices from one policy.
For most organizations:
Add a separate entry for each approved SSID.
Use the narrowest correct encryption type.
Enable Auto Join only for preferred production networks.
Configure enterprise EAP with trusted CA anchors and RADIUS server names.
Use proxies, Hotspot 2.0, QoS, and MAC-address settings only when required.
Enable Block Public Wi-Fi only for Mac groups that should not retain or use passwordless networks.
Test every network and operating-system combination before broad deployment.
Maintain an alternate connection path during policy changes.
