Skip to main content

Apple Multiple Wi-Fi Policy

Overview

The Apple Multiple Wi-Fi Policy lets administrators deploy several managed Wi-Fi network configurations to Apple devices from one Swif policy.

The policy can configure:

  • Multiple office, school, branch, lab, or fallback Wi-Fi networks

  • Personal or enterprise authentication

  • Automatic joining and hidden SSIDs

  • EAP and certificate-based authentication

  • Manual or automatic proxy settings

  • Hotspot 2.0 and roaming settings

  • Cisco QoS marking

  • MAC address randomization behavior

  • Blocking of saved passwordless Wi-Fi networks on managed Macs

Apple permits more than one managed Wi-Fi payload on a device. Swif creates a separate Wi-Fi configuration for each network added to the policy. For more information, see Wi-Fi device management settings for Apple devices.

Important: Test the policy on a small device group before broad deployment. An incorrect SSID, password, certificate, EAP setting, or proxy can prevent a device from connecting to the intended network.

Supported Platforms

Capability

Supported platform

Managed Wi-Fi configurations

macOS 10.7 or later

Managed Wi-Fi configurations

iOS 4.0 or later

Managed Wi-Fi configurations

iPadOS 4.0 or later

Block Public Wi-Fi

macOS 10.7 or later

Disable Association MAC Randomization

macOS 15 or later, iOS 14 or later, and iPadOS 14 or later

The policy supports both company-owned and BYOD devices. Availability of individual advanced settings depends on the operating system version, enrollment method, network type, and Apple platform.

What This Policy Does

For every entry under Multiple Wi-Fi Payload Content, Swif sends a managed Wi-Fi payload containing that network’s settings.

When the policy is installed:

  1. The device receives each configured network.

  2. A network with Auto Join enabled becomes eligible for automatic connection.

  3. The device selects among available eligible networks according to Apple’s network-selection behavior, signal conditions, frequency band, security, and prior connection state.

  4. Enterprise networks use the configured EAP credentials, trusted certificates, and server-name validation.

  5. Proxy, Hotspot 2.0, and QoS settings apply only to the network entry in which they are configured.

The order of network entries in Swif is not a configurable Wi-Fi priority list. Apple decides which eligible network to join. When the same network is broadcast on multiple bands, Apple may prefer 5 GHz or 6 GHz when signal conditions meet its thresholds. See How Apple devices join Wi-Fi networks.

This policy does not:

  • Create or modify the wireless access point.

  • Guarantee that a device always selects the first network listed in Swif.

  • Supply certificates that are not included in the applicable configuration profile.

  • Validate RADIUS, proxy, DNS, captive portal, or internet availability.

  • Block all unapproved Wi-Fi networks on iPhone or iPad.

  • Prevent cellular networking, Ethernet, personal hotspots, or other network interfaces.

Block Public Wi-Fi on macOS

Block Public Wi-Fi is a Swif agent action for managed Macs.

When enabled, the Swif agent:

  1. Scans the Mac’s preferred Wi-Fi networks.

  2. Identifies saved networks that do not have a stored password.

  3. Removes those passwordless networks from the preferred network list.

  4. Disconnects the Mac if it is currently connected to one of those networks.

This setting is designed to reduce automatic or continued use of saved open Wi-Fi networks.

Important: This setting applies only to macOS. It is not an iOS or iPadOS Wi-Fi restriction, and it should not be treated as a complete network-access control or content-filtering solution.

Open Wi-Fi can include legitimate guest, hotel, airport, conference, onboarding, or captive-portal networks. Enable this setting only after confirming that affected users have another approved way to connect.

Before You Begin

Collect and verify the following information for every network:

  • Exact SSID, including capitalization and spaces

  • Network security type

  • Password, if using personal authentication

  • Whether the SSID is hidden

  • Whether devices should join automatically

  • EAP type and credential method for enterprise authentication

  • Trusted CA certificate and accepted RADIUS server names

  • Client identity certificate, if required

  • Proxy type, server, port, credentials, or PAC URL

  • Hotspot 2.0 roaming information, when applicable

  • Cisco QoS requirements, when applicable

Also confirm:

  1. The target devices are enrolled in Swif and online.

  2. At least one working network path remains available while testing.

  3. Required certificates are available in the same profile when referenced by payload UUID.

  4. The device clock is correct because certificate validation depends on time.

  5. The network allows access to Apple services and Swif management endpoints.

  6. The configuration has been tested with the operating-system versions and device models used in production.

For certificate-based networks, coordinate with the network or identity team before deployment. Do not weaken server-certificate validation simply to bypass a trust prompt.

Create the Policy

  1. In the Swif Admin Dashboard, go to Device Management > Policies.

  2. Create a new policy.

  3. Select Apple Multiple Wi-Fi Policy.

  4. Enter a descriptive policy name.

  5. Configure Block Public Wi-Fi for Mac devices.

  6. Under Multiple Wi-Fi Payload Content, select Add.

  7. Enter the SSID and select the correct Encryption Type.

  8. Configure the password, hidden-network behavior, and Auto Join setting.

  9. Enable Advanced Network Configurations only when the network requires enterprise authentication, a proxy, Hotspot 2.0, QoS, or another advanced option.

  10. Add another Wi-Fi entry for each additional network.

  11. Assign the policy to one test device or a small test device group.

  12. Verify every intended network before expanding the assignment.


Recommended Configuration

Standard Company Network

Setting

Recommended value

Block Public Wi-Fi

Enabled for company-owned Macs when open Wi-Fi is prohibited

SSID

Exact corporate network name

Encryption Type

WPA2 or WPA3, matching the network design

Hidden Network

Disabled unless the SSID is intentionally hidden

Auto Join

Enabled

Advanced Network Configurations

Disabled unless required

For an enterprise network, enable advanced settings and configure EAP, trusted certificates, and accepted server names.

BYOD Baseline

Setting

Recommended value

Block Public Wi-Fi

Disabled unless required, disclosed, and appropriate for the enrollment model

SSID

Work network only

Auto Join

Enabled when automatic connection is expected

Advanced settings

Configure only work-related authentication and routing

Avoid deploying unrelated personal network credentials or a broad proxy configuration to personally owned devices.


Basic Policy Settings

Block Public Wi-Fi

Controls the Swif agent’s handling of saved passwordless networks on macOS.

Value

Behavior

Enabled

Removes passwordless networks from the preferred list and disconnects an active passwordless Wi-Fi connection.

Disabled

Swif does not perform this passwordless-network cleanup.

The default value is Disabled.

Because some captive portals use open Wi-Fi before browser-based authentication, enabling this setting can interrupt legitimate travel or guest-network access.

Multiple Wi-Fi Payload Content

Contains one or more managed network entries. Add a separate entry for every SSID or roaming configuration that the device needs.

Avoid duplicate entries for the same SSID unless the configurations are intentionally different and have been tested. Conflicting payloads can produce unpredictable connection or authentication behavior.


Basic Network Settings

Service Set Identifier (SSID)

The exact name of the Wi-Fi network.

Example:

Swif-Corporate

SSID matching is case-sensitive. Include spaces and punctuation exactly as configured on the access point.

On iOS 7 and later and iPadOS, an SSID can be omitted for certain Hotspot 2.0 configurations when Domain Name is provided. For ordinary Wi-Fi networks, enter the SSID.

Password

The password for a personal Wi-Fi network.

Use this field for password-based WEP, WPA, WPA2, or WPA3 networks. If a protected network is deployed without a password, the device may prompt the user when it first connects.

Do not enter a shared Wi-Fi password when the network uses EAP or certificate-based enterprise authentication. Configure EAP Client Configuration instead.

Treat Wi-Fi passwords as sensitive credentials. Rotate them according to organizational policy and update the Swif policy before retiring the old password.

Encryption Type

Defines the network security types that the device may use.

Value

Intended use

WEP

Legacy WEP networks; avoid for production use

WPA

WPA or, on newer Apple operating systems, compatible WPA/WPA2 networks

WPA2

WPA2 or, on newer Apple operating systems, compatible WPA2/WPA3 networks

WPA3

WPA3-only networks

Any

Allows supported WEP, WPA, WPA2, or WPA3 matching

None

Open network without password-based encryption

The default value is Any.

On iOS 16 and later, iPadOS 16 and later, and macOS 13 and later:

  • WPA can join WPA or WPA2 networks.

  • WPA2 can join WPA2 or WPA3 networks.

  • WPA3 joins WPA3 networks only.

  • Any permits compatible WEP, WPA, WPA2, and WPA3 networks.

Before macOS 13, an explicitly selected encryption type generally needed to match the network exactly.

Use the narrowest value compatible with the production network. Avoid WEP because it does not provide modern security. Apple documents its supported personal network settings in WEP, WPA, WPA2, and WPA2/WPA3 device management settings.

Hidden Network

Specifies whether the SSID is hidden.

Value

Behavior

Enabled

The device actively looks for the configured hidden SSID.

Disabled

The device expects the SSID to be broadcast normally.

The default value is Disabled.

Enable this setting only when the access point is configured not to broadcast the SSID. Hiding an SSID is not a meaningful security control and can affect privacy and connection reliability.

Auto Join

Controls whether the device automatically joins the network when it is available.

Value

Behavior

Enabled

The network is eligible for automatic connection.

Disabled

The user must select the network to connect.

The default value is Enabled.

Auto Join does not establish a strict priority among the networks in this policy. Apple’s operating system chooses among available eligible networks.

Advanced Network Configurations

Shows settings for enterprise authentication, certificates, proxies, Hotspot 2.0, Cisco QoS, and other specialized network behavior.

The default value is Disabled.

Leave it disabled for a standard personal WPA2 or WPA3 network that requires only an SSID and password.


Enterprise Authentication Settings

Certificate UUID

The payload UUID of the client identity certificate used for network authentication.

The referenced certificate payload must be present in the same configuration profile. A certificate’s display name, serial number, or file name is not a substitute for its payload UUID.

Use this field for certificate-based authentication such as EAP-TLS. Confirm that the certificate contains the required identity, private key, key usage, and certificate chain.

EAP Client Configuration

Configures 802.1X enterprise authentication.

Apple devices support commonly deployed EAP methods including EAP-TLS, EAP-TTLS, EAP-FAST, PEAP, EAP-SIM, EAP-AKA, and LEAP. Configure only methods supported by the organization’s RADIUS service.

Accept EAP Types

Enter one or more EAP type numbers:

Value

EAP method

13

EAP-TLS

17

LEAP

18

EAP-SIM

21

EAP-TTLS

23

EAP-AKA

25

PEAP

43

EAP-FAST

EAP-TLS with a device or user identity certificate is generally preferred when the organization can operate the required certificate infrastructure.

Certificate Anchor UUID

A list of certificate payload UUIDs that identify trusted CA certificates for the authentication server.

Use certificate anchors with Trusted Server Certificate Names to prevent devices from trusting an unauthorized RADIUS server. If anchors are configured incorrectly or the server certificate chain changes, authentication can fail.

Trusted Server Certificate Names

A list of accepted common names for the RADIUS server certificate.

Example:

radius01.example.com radius02.example.com

A wildcard can be used when necessary:

radius*.example.com

Use the narrowest verified names possible. When server names or anchors are configured, dynamic trust prompts may be disabled. This protects users from accepting an unexpected authentication server, but it also means certificate renewal and server-name changes must be planned.

Username

The username used for enterprise authentication. If omitted, the device may prompt the user when credentials are required.

Do not place one employee’s credential in a policy assigned to multiple users.

User Password

The password used with the enterprise username. If omitted, the device may prompt the user.

For scalable deployments, prefer certificate-based authentication or a supported per-user credential workflow instead of embedding a shared enterprise password.

System Profile Credentials Source

Enter ActiveDirectory to use the Active Directory computer name and password for supported system-mode authentication.

Do not configure this setting together with Use OpenDirectory System Profile Credentials.

Use OpenDirectory System Profile Credentials

When enabled, system-mode authentication attempts to use Open Directory credentials.

Do not configure this setting together with System Profile Credentials Source.

EAP Setup Modes

Determines the macOS connection contexts to which the 802.1X configuration attaches.

Available values:

  • System

  • Loginwindow

Use System when the Mac must establish network access without depending on a signed-in user. Use Loginwindow when network authentication is required at the macOS login window. Test FileVault, login-window, local-account, and offline behavior before broad deployment.

Certificate Required

Controls certificate requirements for applicable EAP methods.

Use this setting only when it matches the organization’s RADIUS design. Certificate requirements differ among EAP-TLS, EAP-TTLS, PEAP, and EAP-FAST. An incorrect setting can cause authentication failure or weaken the intended authentication model.


Proxy Settings

Proxy Type

Determines whether the network uses no proxy, a manually configured proxy, or a proxy auto-configuration file.

Value

Behavior

None

No managed proxy for this network

Manual

Uses a specified proxy server and port

Auto

Uses a PAC URL

Proxy settings apply to the corresponding Wi-Fi network entry.

Manual Proxy

When Proxy Type is Manual, configure:

  • Proxy Server: Hostname or IP address of the proxy

  • Proxy Server Port: Integer from 0 through 65535

  • Proxy Username: Optional username

  • Proxy Password: Optional password

Example:

Setting

Example

Proxy Server

proxy.example.com

Proxy Server Port

8080

Confirm that the proxy permits access to Apple activation, push notification, certificate, software update, and Swif management services.

Automatic Proxy

When Proxy Type is Auto, configure:

  • Proxy PAC URL: HTTPS or HTTP URL of the proxy auto-configuration file

  • Allow direct connect if proxy PAC is unreachable: Whether the device can bypass the proxy when the PAC file cannot be retrieved

Enabling direct fallback improves availability but may allow traffic to bypass required inspection or routing. Disabling fallback preserves enforcement but can leave the device without network access when the PAC service is unavailable.


Privacy and Captive Network Settings

Captive Bypass

On iOS 10 and later and iPadOS 10 and later, bypasses Apple’s captive-network detection for the configured network.

Enable this only when the network does not require a captive portal. If enabled on a portal-based network, users may not receive the page needed to accept terms or complete authentication.

Disable Association MAC Randomization

When enabled, the device uses a nonprivate MAC address while associated with the configured network.

Supported by this Swif policy on:

  • macOS 15 or later

  • iOS 14 or later

  • iPadOS 14 or later

Disabling MAC randomization can help networks that rely on stable hardware addresses for access control, inventory, or troubleshooting. It also reduces a privacy protection, and Apple displays a privacy warning in Settings.

Use this setting only when a documented network dependency requires a stable MAC address. Prefer identity- or certificate-based access controls where possible.

Hotspot 2.0 and Roaming Settings

The following settings are intended for Hotspot 2.0, Passpoint, or service-provider roaming deployments. Do not configure them for an ordinary SSID unless instructed by the network provider.

Provider Display Name

The operator name displayed when the device connects to the Hotspot 2.0 network.

Domain Name

The primary domain used to identify the Hotspot 2.0 service.

For applicable iOS and iPadOS configurations, this can identify the service when no SSID is specified.

Is Hotspot

Marks the network as a hotspot on supported Mac devices.

Realm Names

A list of Network Access Identifier realm names used during Hotspot 2.0 negotiation.

Example:

example.com wifi.example.com

Roaming OIs

A list of Roaming Consortium Organization Identifiers used for Hotspot 2.0 negotiation.

Enter each identifier exactly as supplied by the roaming provider.

Connect to Roaming Partner Passpoint Networks

Allows the device to connect to compatible roaming service providers.

Enabling this can expand the networks to which a device is eligible to connect. Confirm the roaming consortium, authentication, cost, and data-handling requirements before deployment.

Interface

Specifies the interface selection used by applicable advanced network configurations.

Available Swif values include:

  • NoValue

  • AnyEthernet

  • FirstEthernet

  • FirstActiveEthernet

  • SecondEthernet

  • SecondActiveEthernet

  • ThirdEthernet

  • ThirdActiveEthernet

Leave this unset unless the network design specifically requires one of these interface modes. Test it on the target Apple platform because interface behavior is configuration-dependent.

Cisco QoS Marking Policy

The QoS Marking Policy controls which applications can use Layer 2 and Layer 3 traffic marking on a compatible Cisco Fastlane network.

Allow QoS Marking

Controls QoS marking for the configured network.

Enable it only when the wireless infrastructure is configured for Cisco Fastlane and the organization has verified the intended traffic treatment.

Allow List App Identifiers

A list of application bundle identifiers permitted to benefit from QoS marking.

Example:

com.example.voice com.example.meetings

When the QoS dictionary is present but the allowlist is absent, Apple behavior can differ from a configuration in which the entire QoS dictionary is omitted. Test the effective result before deployment.

QoS Marking for Audio/Video Calls

Adds traffic from built-in Apple audio and video services, such as FaceTime and Wi-Fi Calling, to the QoS allowlist.

Enable it only when those services are permitted and should receive prioritized treatment on the managed network.


Example Configurations

Example 1: Two Office Networks

Setting

Primary office

Backup office

SSID

Swif-Corporate

Swif-Backup

Encryption Type

WPA3

WPA2

Password

Organization-managed value

Organization-managed value

Hidden Network

Disabled

Disabled

Auto Join

Enabled

Enabled

Advanced Network Configurations

Disabled

Disabled

Apple decides which eligible network to use. The entry order does not force the primary network to win.

Example 2: Corporate and Guest Networks

Setting

Corporate

Guest

SSID

Swif-Corporate

Swif-Guest

Encryption Type

WPA2 or WPA3

Match actual guest security

Auto Join

Enabled

Disabled

Advanced Network Configurations

EAP as required

Captive behavior as required

Use Auto Join: Disabled for the guest network if it should remain a manual fallback.

If the guest network is passwordless, enabling Block Public Wi-Fi on macOS conflicts with the intended fallback because Swif removes saved passwordless networks and disconnects from them.

Example 3: EAP-TLS Enterprise Network

Setting

Example value

SSID

Swif-Secure

Encryption Type

Match the enterprise WLAN

Auto Join

Enabled

Advanced Network Configurations

Enabled

Accept EAP Types

13

Certificate UUID

Client identity certificate payload UUID

Certificate Anchor UUID

Organizational CA certificate payload UUID

Trusted Server Certificate Names

radius01.example.com, radius02.example.com

EAP Setup Modes

System or Loginwindow, as required

Test certificate issuance, renewal, revocation, and RADIUS server rollover before production deployment.

Example 4: Network With a PAC Proxy

Setting

Example value

SSID

Swif-Filtered

Encryption Type

WPA2

Auto Join

Enabled

Proxy Type

Auto

Proxy PAC URL

https://proxy.example.com/company.pac

Allow direct connect if PAC is unreachable

Disabled when proxy bypass is prohibited

Confirm that the PAC URL is reachable before the proxy configuration is required.


Company-Owned and BYOD Considerations

Company-Owned Devices

For company-owned Apple devices:

  • Deploy only approved production and fallback networks.

  • Enable Auto Join for required networks.

  • Use WPA2, WPA3, or enterprise EAP rather than WEP or open Wi-Fi.

  • Enable Block Public Wi-Fi on Macs when organizational policy prohibits saved passwordless networks.

  • Use certificate-based enterprise authentication when practical.

  • Validate RADIUS server names and CA anchors.

  • Avoid embedding shared user credentials.

  • Review proxy fallback and MAC-randomization decisions with the security team.

  • Remove obsolete SSIDs, certificates, and credentials promptly.

BYOD Devices

For personally owned devices:

  • Limit the policy to work-related networks.

  • Tell users when the device will join automatically.

  • Disclose certificate, proxy, MAC-address, and public-Wi-Fi controls.

  • Avoid blocking open Wi-Fi on Macs unless the requirement is appropriate and clearly communicated.

  • Avoid routing unrelated personal traffic through an organizational proxy.

  • Confirm that the enrollment model supports the intended payload behavior.

  • Remove work network access and credentials during unenrollment or offboarding.

The policy configures networking on the device. It does not create a separate physical Wi-Fi interface for work traffic.


Verify the Policy

macOS

  1. Confirm that the policy reports as installed in Swif.

  2. Open System Settings > Wi-Fi.

  3. Confirm that the expected managed networks appear.

  4. Move the Mac within range of each test SSID.

  5. Verify Auto Join behavior.

  6. Confirm that the device receives an IP address, DNS, routing, and internet access.

  7. Test internal resources and the configured proxy.

  8. For enterprise Wi-Fi, verify the certificate identity and RADIUS server trust.

  9. If Block Public Wi-Fi is enabled, confirm during a controlled test that a saved passwordless network is removed and an active passwordless connection is disconnected.

To view the current Wi-Fi connection:

networksetup -getairportnetwork en0

The Wi-Fi service may use a different hardware port on some Macs. To list ports:

networksetup -listallhardwareports

To inspect installed configuration profiles:

sudo profiles show -type configuration

Profile output can contain SSIDs, account names, server addresses, and other sensitive configuration. Redact it before sharing.

iPhone and iPad

  1. Confirm that the device received the policy in Swif.

  2. Open Settings > Wi-Fi.

  3. Confirm that the expected network is available or connected.

  4. Select the network’s information button and review applicable managed behavior.

  5. Test automatic joining, authentication, captive behavior, and proxy routing.

  6. Repeat the test after a restart and after moving between access points.

Block Public Wi-Fi verification is not applicable to iPhone or iPad.


Troubleshooting

The Policy Is Installed but the Device Does Not Join

  1. Confirm that the SSID is within range.

  2. Verify the exact spelling and capitalization of the SSID.

  3. Confirm that Encryption Type matches the access point and operating-system behavior.

  4. Re-enter the password.

  5. Confirm that Hidden Network matches the access point configuration.

  6. Verify that Auto Join is enabled.

  7. Check for a conflicting Wi-Fi payload for the same SSID.

  8. Confirm that the device can reach DHCP and DNS services.

  9. Test without optional proxy or advanced settings on a separate test profile.

Do not remove the device’s only working network profile until another management path is available.

The Device Joins the Wrong Managed Network

The list order in Swif is not a strict priority.

  • Disable Auto Join for networks intended only as manual fallbacks.

  • Remove obsolete or overlapping SSIDs.

  • Check whether multiple payloads configure the same SSID.

  • Review signal strength and access-point coverage.

  • Confirm that the preferred network uses the intended security and frequency band.

The Device Repeatedly Requests a Password

  • Confirm that the network uses personal rather than enterprise authentication.

  • Verify the stored password.

  • Confirm that the encryption type matches.

  • Check whether the access point password recently changed.

  • Remove duplicate or conflicting payloads for the same SSID.

  • For enterprise Wi-Fi, inspect the EAP settings rather than entering the shared Wi-Fi password field.

Enterprise Authentication Fails

  • Confirm the selected EAP type.

  • Verify that the client identity certificate and private key are present.

  • Confirm that referenced certificate UUIDs belong to payloads in the same profile.

  • Verify the certificate validity period and device clock.

  • Confirm that the trusted CA anchors match the RADIUS server chain.

  • Confirm that the server certificate name matches Trusted Server Certificate Names.

  • Verify the username format and credential source.

  • Review RADIUS logs for the exact rejection reason.

  • Test certificate renewal and intermediate CA delivery.

Never tell users to accept an unexpected RADIUS certificate as a routine workaround.

The Hidden Network Does Not Connect

  • Confirm that Hidden Network is enabled.

  • Verify the SSID exactly.

  • Confirm that the access point is configured as hidden.

  • Test whether the same authentication settings work when the SSID is temporarily broadcast.

  • Review access-point logs for probe and authentication attempts.

Hidden SSIDs can be less reliable and do not provide meaningful protection against network discovery.

The Proxy Prevents Network Access

  • Confirm the proxy hostname and port.

  • Verify proxy credentials.

  • Confirm that the PAC URL is reachable without first requiring the proxy.

  • Validate the PAC file syntax and MIME type.

  • Check whether direct fallback is allowed.

  • Confirm that required Apple and Swif services are permitted.

  • Test DNS resolution and certificate trust.

If proxy bypass is prohibited, maintain redundant PAC and proxy infrastructure before disabling direct fallback.

Block Public Wi-Fi Does Not Disconnect the Mac

  • Confirm that the device is a Mac and the Swif agent is running.

  • Confirm that Block Public Wi-Fi is enabled and the policy is assigned.

  • Confirm that the active network is actually passwordless.

  • Trigger a device or policy sync.

  • Review the policy command history and Swif agent logs.

  • Check whether the network uses Opportunistic Wireless Encryption or another configuration that does not appear as a simple passwordless preferred network.

The feature operates on saved passwordless networks detected by the Mac agent. It is not a packet filter or a universal ban on every possible open network.

A Required Guest Network Is Removed

If the guest network is passwordless, this is expected when Block Public Wi-Fi is enabled on macOS.

Choose one of the following:

  • Disable Block Public Wi-Fi for the affected device group.

  • Provide a protected guest network.

  • Supply an approved alternative connection.

  • Assign a different policy to users who require public or captive-portal access.

MAC-Based Access Control Stops Working

  • Confirm whether the network expects a stable hardware MAC address.

  • On supported operating systems, evaluate Disable Association MAC Randomization.

  • Confirm that the device has re-associated after the policy change.

  • Update the network access-control record if needed.

Disabling MAC randomization reduces privacy. Prefer certificate- or identity-based access control when possible.

Hotspot 2.0 Roaming Does Not Work

  • Verify the domain name, realm names, and roaming OIs.

  • Confirm that the provider supports the device and credentials.

  • Confirm that service-provider roaming is enabled.

  • Review certificate and EAP requirements.

  • Test with the provider’s production Passpoint profile values.

Security and Compliance Impact

Managed Wi-Fi profiles help organizations standardize network authentication, reduce credential-entry errors, and apply network-specific proxy and trust settings.

For a secure deployment:

  • Prefer WPA3, WPA2, or enterprise EAP over WEP or open Wi-Fi.

  • Use unique certificate identities where possible.

  • Validate RADIUS server certificates with trusted CA anchors and server names.

  • Avoid shared enterprise usernames and passwords.

  • Protect Wi-Fi and proxy credentials in administrator workflows.

  • Keep certificate renewal and revocation processes documented.

  • Review every Auto Join network.

  • Treat proxy fallback as a security decision.

  • Disable MAC randomization only for a documented requirement.

  • Test policy changes before rotating passwords, certificates, SSIDs, or RADIUS servers.

  • Maintain an alternate management path during network migrations.

Block Public Wi-Fi can reduce exposure to saved passwordless networks on Macs, but it does not replace a firewall, VPN, DNS security service, web filter, zero-trust access control, or user security training.

This policy supports network security and configuration management objectives, but it does not independently make an organization compliant with a particular framework.

Notes

  • Each network entry becomes a separate managed Wi-Fi configuration.

  • Apple supports multiple Wi-Fi payloads on one device.

  • The order of entries does not create a strict network priority.

  • Auto Join is enabled by default.

  • Hidden Network is disabled by default.

  • Encryption Type defaults to Any.

  • Block Public Wi-Fi is disabled by default and applies only to macOS.

  • A passwordless captive-portal network may be removed when Block Public Wi-Fi is enabled.

  • Certificate UUIDs must reference the applicable certificate payload in the same profile.

  • Proxy, EAP, Hotspot 2.0, QoS, and privacy settings apply per network entry.

  • Feature availability varies by Apple platform and operating-system version.

  • Removing the policy can remove managed network configuration and may disconnect the device.

Summary

The Apple Multiple Wi-Fi Policy deploys several managed Wi-Fi networks to Mac, iPhone, and iPad devices from one policy.

For most organizations:

  1. Add a separate entry for each approved SSID.

  2. Use the narrowest correct encryption type.

  3. Enable Auto Join only for preferred production networks.

  4. Configure enterprise EAP with trusted CA anchors and RADIUS server names.

  5. Use proxies, Hotspot 2.0, QoS, and MAC-address settings only when required.

  6. Enable Block Public Wi-Fi only for Mac groups that should not retain or use passwordless networks.

  7. Test every network and operating-system combination before broad deployment.

  8. Maintain an alternate connection path during policy changes.

Related Resources

Did this answer your question?