# Apple DDM FAQ

> Answers to common questions about Apple Declarative Device Management in CapaOne — migration, coexistence with Legacy MDM, user impact, unenrollment and supported devices.

Source: https://docs.capaone.com/capaone/mobile-manager/apple-ddm/apple-ddm-faq/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

Short answers to the questions admins ask most when moving Apple devices to Declarative Device Management (DDM). Each answer links to the article with the full details.

## Migration

### Does enabling DDM re-enroll or wipe the device?

No. **Enable Apple DDM** turns on DDM on top of the existing MDM enrollment. The device keeps its enrollment, apps, Legacy profiles, and data. See [Enable Apple DDM](/capaone/mobile-manager/apple-ddm/enable-apple-ddm/).

### Does the user notice anything when DDM is enabled?

Not from the switch itself — there's no prompt or restart. Users only notice the effect of new configurations, for example a request to set a passcode when **Passcode Settings** applies, or software update notifications from an enforcement.

### Do my Legacy configurations stop working when a device moves to DDM?

No. A device that runs DDM still accepts Legacy profiles and commands. Only Legacy settings that Apple has removed stop working — and that depends on the OS version, not on DDM. On iOS 27 and later, that's software update management. See [Legacy MDM to DDM Mapping](/capaone/mobile-manager/apple-ddm/legacy-to-ddm-mapping/).

### What if the same setting comes from both a Legacy profile and a DDM configuration?

The device merges them and enforces the strictest value, the same way it handles two overlapping profiles. For software updates, the DDM configuration takes precedence. See [How Multiple DDM Configurations Combine](/capaone/mobile-manager/apple-ddm/how-ddm-configurations-combine/).

### Can I move a device back from DDM to Legacy MDM?

No. Once a device runs DDM, it stays on DDM. This applies to every device: devices on iOS, iPadOS, or macOS 27 or later always run DDM, and on earlier versions DDM is your choice until you enable it for the device. A device on DDM can still receive Legacy configurations, so you can keep using Legacy configurations that Apple hasn't deprecated.

### Which devices move to DDM automatically?

Devices that report iOS, iPadOS, or macOS 27 or later — whether they enroll on version 27 or update to it later. Devices on earlier versions stay on Legacy MDM until you decide to enable DDM for them. Make sure their DDM configurations, especially software update policy, are assigned before they update. See [iOS 27 and Software Update Management](/capaone/mobile-manager/apple-ddm/ios-27-and-software-update-management/).

### Can I enable DDM on many devices at once?

**Enable Apple DDM** is a device-page action, so you enable one device at a time. Devices on version 27 switch automatically. To migrate a large fleet on older versions, the most practical path is often to let devices update to version 27 — after the DDM configurations are in place.

## Devices and enrollment

### Which devices support DDM in CapaOne?

iPhone and iPad on iOS or iPadOS 17 or later, and Mac on macOS 14 or later, enrolled in CapaOne — Supervised or Unsupervised. Individual configuration types have their own minimum versions. See [DDM Configuration Types Reference](/capaone/mobile-manager/apple-ddm/ddm-configuration-types-reference/).

CapaOne lists iPhone, iPad, and Mac endpoints under **Apple → Endpoints**. Other Apple platforms, such as Apple TV and Apple Vision Pro, have no endpoint list in CapaOne.

### Does DDM work on unsupervised (BYOD) devices?

Partly. Unsupervised devices accept many DDM types, such as accounts, certificates, passcode, and software update enforcement. Types such as **App Settings**, **Intelligence Settings**, **Siri Settings**, and **Keyboard Settings** need Supervised devices, and some types have individual settings that need supervision — for example, deferrals in **Software Update Settings**.

### How do I see whether a device runs DDM?

Open the device in **Apple → Endpoints**. The badge shows **Supervised DDM**, **Unsupervised DDM**, or **Kiosk Mode DDM** when DDM is active.

### What happens to DDM configurations when a device is unenrolled?

Removing the MDM enrollment removes everything delivered through it — DDM configurations, assets, and Legacy profiles alike. Settings return to the device's defaults, and certificates and accounts installed by CapaOne are removed.

### Do I need new network ports or firewall rules for DDM?

No new ports. DDM uses the same MDM connection to CapaOne and the same Apple Push Notification service as Legacy MDM. Software updates enforced through DDM download from Apple's servers as before. See Apple's [Use Apple products on enterprise networks](https://support.apple.com/101555).

## Configurations

### How fast does a DDM configuration apply?

When you assign or change a configuration, CapaOne notifies the device through Apple Push Notification service, and the device fetches only what changed. A connected device usually applies it within seconds to minutes. An offline device applies it the next time it connects.

### How do I know whether a configuration applied?

On the device page, select the **Configurations** tab. DDM configurations are marked **DDM** under **Assigned**. An error icon with a reason means the device rejected it — see [DDM Status Reason Codes](/capaone/troubleshooting/ddm-status-reason-codes/). **Applied** shows the settings the device received.

![Apple device Configurations tab with DDM-labelled configurations](/attachments/capaone/apple-ddm-faq--device-configurations-assigned.png)

### A configuration saves in CapaOne but doesn't apply. Why?

CapaOne can't know every device's capabilities when you save. The device decides whether it supports the configuration, based on its OS version and enrollment type. The most common cause is an OS version below the type's minimum. See [DDM — Unknown Configuration Error or Cannot Be Applied](/capaone/troubleshooting/ddm-unknown-configuration-error/).

### What's the difference between a configuration and an asset?

A configuration is policy that you assign. An asset is data — a certificate, identity, or credential — that a configuration points to. You never assign assets directly. See [DDM Assets](/capaone/mobile-manager/apple-ddm/ddm-assets/).

### What happens when I remove a configuration?

The device removes it and its settings. For types that combine several configurations, such as **Passcode Settings**, the device recalculates the effective policy from the configurations that remain.

### Is there a DDM equivalent for Wi-Fi?

Not yet. Wi-Fi stays a Legacy configuration, and it works on devices that run DDM.

## Software updates

### Do I still need Legacy software update policy?

For devices on iOS, iPadOS, or macOS 27 or later, no — it no longer functions. For older devices, it still works, but DDM software update configurations take precedence when both are present. Build new policy in DDM. See [Software Update Settings](/capaone/mobile-manager/apple-ddm/software-update-settings/) and [Enforce a Specific OS Update](/capaone/mobile-manager/apple-ddm/enforce-a-specific-os-update/).

### Can I force "always the latest version" automatically?

Apple's enforcement targets one specific version. To keep devices on the latest version, create a new **Software Update Enforcement Specific** configuration for each release, and combine it with **Software Update Settings** that turns on automatic downloads and installs on Supervised devices.

## Good to know

- **Still stuck?** Start with [DDM Status Reason Codes](/capaone/troubleshooting/ddm-status-reason-codes/) for configuration errors, and [DDM Software Update Not Installing](/capaone/troubleshooting/ddm-software-update-not-installing/) for update problems.
- **Background reading** — [How DDM Works](/capaone/mobile-manager/apple-ddm/how-ddm-works/) explains declarations, assets, and status reporting.
