Skip to main content

Apple iOS/iPadOS Content & Privacy Restrictions Policy

The Apple iOS/iPadOS Content & Privacy Restrictions Policy controls the content restrictions that iPhone and iPad show under Settings > Screen Time > Content & Privacy Restrictions. Use it to set:

  • the maximum age ratings for apps, movies, and TV shows

  • whether explicit music, podcasts, news, and books are allowed

  • access to the Book Store, Apple Music, and Apple Music Radio

  • Safari and web content filtering with Apple's built-in filter

  • whether users can turn on Screen Time

The restrictions apply whether or not Screen Time is on, and users can't loosen them in Screen Time. MDM can't turn on Screen Time for the user or set a Screen Time passcode.

Important: Web content filtering works only on supervised devices. If Web Content is set to anything other than Unrestricted, iOS and iPadOS reject the entire profile on unsupervised devices. The installation fails and none of this policy's restrictions apply, including the age ratings. Swif doesn't check whether a device is supervised when you assign this policy. Assign a policy that filters web content only to supervised devices. For unsupervised devices, create a separate policy with Web Content set to Unrestricted.


Supported platforms and requirements

Item

Details

Platforms

iOS, iPadOS

Minimum OS

iOS 12.0 or later, iPadOS 13.1 or later (some settings need a later version; see the settings table)

Device ownership

Company-owned devices

Supervision

Most settings require a supervised device. Devices are supervised when enrolled through Automated Device Enrollment or prepared with Apple Configurator.

User Enrollment (BYOD)

Not supported. Apple doesn't allow these restrictions on User Enrollment.

What applies on unsupervised devices

On unsupervised devices, such as those enrolled with a profile or through account-driven (SSO) enrollment, only these settings apply:

  • Apps, Movies, and TV Shows age ratings

  • Allow Explicit Books

Apple has deprecated even these restrictions on unsupervised devices and says the app rating will require supervision in a future release. All other settings in this policy require supervision. Plan to supervise devices where these restrictions matter.


Settings reference

All defaults leave the device unrestricted. A new policy with no changes doesn't restrict anything.

Age ratings

Setting

What it does

Options

Default

Supervision

Minimum OS

Apps

The highest app age rating allowed. The device hides installed apps rated above it and blocks installing them. Starting with iOS/iPadOS 26.2, this rating may also apply to certain system apps.

Don't Allow Apps, 4+, 9+, 13+, 16+, 18+, Allow All Apps

Allow All Apps

Not required yet (deprecated when unsupervised)

iOS 5.0, iPadOS 13.1

Apps Exempted From Age Rating

Bundle IDs of apps that stay available whatever the Apps rating is, such as your organization's own apps.

List of bundle IDs

Empty

Not required

iOS 26.1, iPadOS 26.1

Movies

The highest movie rating allowed. Labels use U.S. ratings.

Don't Allow Movies, G, PG, PG-13, R, NC-17, Allow All Movies

Allow All Movies

Not required (deprecated when unsupervised)

iOS 5.0, iPadOS 13.1

TV Shows

The highest TV rating allowed. Labels use U.S. ratings.

Don't Allow TV Shows, TV-Y, TV-Y7, TV-G, TV-PG, TV-14, TV-MA, Allow All TV Shows

Allow All TV Shows

Not required (deprecated when unsupervised)

iOS 5.0, iPadOS 13.1

About the app ratings. iOS and iPadOS 26 introduced the 13+, 16+, and 18+ app ratings. They replace 12+ and 17+ on the App Store. Apple stores each rating as a number, and the device allows apps at or below the number you choose. Devices running earlier versions still show the older ratings. Test your chosen rating on older devices in your fleet before a broad rollout.

About exempted apps. Apple combines the exemption lists from all installed profiles and from parental controls, including Screen Time. An app stays available only if every list exempts it. Devices running a version before 26.1 ignore this setting. To find an app's bundle ID, see Apple's bundle IDs for iPhone and iPad apps or ask the app's developer.

Explicit content, books, and music

Setting

What it does

Default

Supervision

Minimum OS

Allow Explicit Music, Podcasts and News

When off, the device hides explicit music and video from the iTunes Store and explicit content in Podcasts and News. Content providers, such as record labels, mark what's explicit.

On

Required (iOS 13 and later)

iOS 5.0, iPadOS 13.1

Allow Book Store

When off, the Book Store tab is removed from the Books app.

On

Required

iOS 6.0, iPadOS 13.1

Allow Explicit Books

When off, users can't download Apple Books content tagged as erotica.

On

Not required (deprecated when unsupervised)

iOS 6.0, iPadOS 13.1

Allow Apple Music

When off, Apple Music is turned off and the Music app reverts to classic mode.

On

Required

iOS 9.3, iPadOS 13.1

Allow Apple Music Radio

When off, Apple Music Radio is turned off. Swif shows this setting only while Allow Apple Music is on.

On

Required

iOS 9.3, iPadOS 13.1

Web content

Setting

What it does

Default

Supervision

Minimum OS

Web Content

Filters websites with Apple's built-in filter, which works like Web Content in Screen Time. See the modes below.

Unrestricted

Required for any mode except Unrestricted

iOS 7.0, iPadOS 13.1

Always Allowed Websites

URLs users can visit even if the automatic filter would block them. Shown only in Limit Adult Websites mode.

Empty

Required

iOS 7.0, iPadOS 13.1

Never Allowed Websites

URLs users can never visit, up to 500 entries. Shown only in Limit Adult Websites mode.

Empty

Required

iOS 14.5, iPadOS 14.5

Allowed Websites

The only websites users can visit. Each entry needs a Website URL (starting with http:// or https://) and a Title. Safari shows the entries as bookmarks. Required in Allowed Websites Only mode.

Empty

Required

iOS 14.5, iPadOS 14.5

Web Content modes

Mode

Behavior

Unrestricted

No filtering. This is the only mode that works on unsupervised devices.

Limit Adult Websites

Apple's filter automatically limits access to many adult websites. Use Always Allowed Websites to allow sites the filter blocks, and Never Allowed Websites to block more sites.

Allowed Websites Only

Users can visit only the sites in Allowed Websites. Everything else is blocked.

To block specific sites without restricting everything else, use Limit Adult Websites with a Never Allowed Websites list. This policy doesn't offer a mode that blocks only a list of sites without the adult filter.

Screen Time

Setting

What it does

Default

Supervision

Minimum OS

Allow Screen Time

When off, users can't turn on Screen Time, and Screen Time turns off if it's already on. Users can't set their own restrictions or a Screen Time passcode. The restrictions in this policy stay in effect. Shared iPad ignores this setting.

On

Required

iOS 12.0, iPadOS 13.1


How website matching works

These rules come from Apple and apply to every website list in this policy:

  • Start every URL with https:// or http://. If a site is reached both ways, add both.

  • Entries match as text. An entry matches every URL that contains it. For example, https://example.com/a also matches https://example.com/apple and https://example.com/a/b.

  • A trailing slash matches that path. https://example.com/a/ matches https://example.com/a and pages under it.

  • www. is ignored. example.com and www.example.com are treated the same.

  • Subdomains are separate. Allowing or blocking https://about.example.com doesn't affect https://example.com or https://blog.example.com.

  • Redirects need their own entries. If an allowed or blocked site redirects to another URL, add that URL too.

  • Block wins over allow. If an Always Allowed Websites entry conflicts with Never Allowed Websites, the device removes the allowed entry.

  • In Limit Adult Websites mode, Apple websites ending in .apple.com and .icloud.com are always reachable.

In Allowed Websites Only mode, many sites load pages, images, or sign-in screens from other domains. For example, a site may send users to your identity provider to sign in. Add those domains too, or parts of the site won't work.

For details, see Apple's Web Content Filter payload settings.


What users notice

  • Settings you restrict appear locked under Settings > Screen Time > Content & Privacy Restrictions. Users can't change them.

  • Apps above the Apps rating disappear from the Home Screen and can't be installed. They come back when you raise the rating or remove the policy.

  • When a web content filter is active, users can't clear Safari history and website data. This is Apple's behavior for any MDM-managed built-in filter.

  • On iOS and iPadOS 26 and later, Apple's filter also keeps browsing history by default, which also turns off Safari Private Browsing. This policy doesn't have a setting to change that.


Before you start

  1. Check supervision. In Swif, confirm which devices are supervised. Place supervised and unsupervised devices in separate device groups.

  2. Check OS versions. Devices ignore settings they don't support. For example, devices before 26.1 ignore Apps Exempted From Age Rating, and devices before 14.5 ignore Never Allowed Websites and Allowed Websites.

  3. Collect bundle IDs for any apps that must stay available under a strict Apps rating.

  4. Collect website lists if you plan to filter web content, including sign-in and content domains.


Create the policy

  1. In Swif, go to Device Management > Policies > New Policy.

  2. Select Apple iOS/iPadOS Content & Privacy Restrictions Policy.

  3. Enter a clear name, such as iOS Content Restrictions – Supervised.

  4. Set the age ratings: Apps, Movies, and TV Shows. Add bundle IDs to Apps Exempted From Age Rating if needed.

  5. Set the explicit content and media toggles.

  6. Choose a Web Content mode:

    • For Limit Adult Websites, optionally add Always Allowed Websites and Never Allowed Websites.

    • For Allowed Websites Only, add at least one entry in Allowed Websites, with a URL and title for each.

  7. Set Allow Screen Time.

  8. Save the policy.

  9. Assign it to the right device group. Assign a policy that filters web content only to supervised devices.

  10. Test on a small group of devices before a wider rollout.


Example configurations

Example 1: Company-owned supervised iPhones

For general corporate phones where you want to block adult content without limiting normal work.

Setting

Value

Apps

Allow All Apps

Movies / TV Shows

Allow All

Allow Explicit Music, Podcasts and News

Off

Allow Explicit Books

Off

Web Content

Limit Adult Websites

Never Allowed Websites

https://gambling-example.com/

Allow Screen Time

On

Example 2: Shared frontline iPads with a fixed set of websites

For supervised iPads used on a warehouse floor or in a store, where staff need only a few sites.

Setting

Value

Apps

4+

Apps Exempted From Age Rating

com.example.inventory (your in-house app)

Movies

Don't Allow Movies

TV Shows

Don't Allow TV Shows

Allow Book Store

Off

Allow Apple Music

Off

Web Content

Allowed Websites Only

Allowed Websites

https://intranet.example.com – Intranet; https://login.example-idp.com – Sign in; https://support.example.com – Support

Allow Screen Time

Off

The sign-in site is included so users can authenticate. Devices before 26.1 ignore the exemption. On those devices, the in-house app is hidden if its rating is above 4+.

Example 3: Unsupervised company devices

For devices enrolled with a profile or through account-driven enrollment, which can't be supervised.

Setting

Value

Apps

13+

Movies

PG-13

TV Shows

TV-14

Allow Explicit Books

Off

Web Content

Unrestricted (required)

All other settings

Defaults

Only the ratings and Allow Explicit Books apply here. Swif still sends the other settings, but the device doesn't enforce them. If you need web filtering on these devices, see Apple DNS Settings Policy or a third-party filtering solution.


Verify the policy

On the device:

  1. Go to Settings > General > VPN & Device Management, open the Swif management profile, and confirm that it lists the restrictions. If the profile is missing, it may have failed to install; see troubleshooting below.

  2. Go to Settings > Screen Time > Content & Privacy Restrictions and confirm that the restricted settings are locked.

  3. Test the ratings. Look for an app above the Apps rating. It should be hidden and can't be installed from the App Store.

  4. Test web filtering in Safari:

    • Open a site on your Never Allowed Websites list. Safari should block it.

    • In Allowed Websites Only mode, confirm that the bookmarks appear, the listed sites open, and other sites are blocked.

  5. If Allow Screen Time is off, confirm that users can't turn on Screen Time.

In Swif, open the device and confirm that the policy shows as applied.


Troubleshooting

None of the restrictions apply, and the profile isn't on the device The device is probably unsupervised while Web Content is set to something other than Unrestricted. iOS/iPadOS rejects the entire profile in that case. Assign a policy with Web Content set to Unrestricted to that device, or supervise it by re-enrolling through Automated Device Enrollment.

Only the age ratings work The device is unsupervised. On unsupervised devices, only the ratings and Allow Explicit Books apply. Other settings need supervision.

Nothing applies on a personal (BYOD) device User Enrollment doesn't support these restrictions.

An exempted app is still hidden

  • Check that the device runs iOS/iPadOS 26.1 or later.

  • Check that the bundle ID is exact.

  • Check other profiles and the user's Screen Time settings. An app is exempt only if every source exempts it.

A blocked site still opens

  • Add both http:// and https:// versions if needed.

  • Add any subdomains separately.

  • Add the URL the site redirects to.

  • Check that the device runs iOS/iPadOS 14.5 or later.

An allowed site doesn't load fully in Allowed Websites Only mode The site loads content, sign-in pages, or redirects from domains that aren't on the list. Add those domains to Allowed Websites.

A legitimate site is blocked in Limit Adult Websites mode Add it to Always Allowed Websites. Also make sure it doesn't match an entry in Never Allowed Websites, because blocked entries win.

Users can't clear Safari history or use Private Browsing This is expected while a web content filter is active. Set Web Content to Unrestricted if users need these features.

Screen Time turned off on a device This is expected when Allow Screen Time is off. Turn it on if users need their own Screen Time controls.

Apple's built-in filter isn't enough Apple recommends a global HTTP proxy or a third-party content filter for complex or legally required filtering. See Apple Global HTTP Proxy Policy.


Related resources

Swif

Apple

Did this answer your question?