# DDM Configuration Types Reference

> Every DDM configuration type available in CapaOne, grouped by category, with what it's for and its Beta or Supervised-only status.

Source: https://docs.capaone.com/capaone/mobile-manager/apple-ddm/ddm-configuration-types-reference/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

This reference lists every configuration type available under **Apple → Configurations → DDM →
New**, on the **Configurations** tab. For asset types (the **Assets** tab in the same picker), see
[DDM Assets](/capaone/mobile-manager/apple-ddm/ddm-assets/).

![CapaOne's Select a configuration type picker under Apple → Configurations → DDM → New, showing the Configurations tab](/attachments/capaone/apple-ddm-configuration-type-picker-configurations.png)

The picker itself lists every type alphabetically, in a single grid — the categories below are
groupings for this reference, not a distinction CapaOne's UI makes. **Beta** and **Supervised
only** tags are shown as-is in the picker. **Supervised only** means the configuration has no
effect on Unsupervised (BYOD) devices; see [Endpoint Management
Modes](/capaone/reference/endpoint-management-modes/) for the Supervised/Unsupervised split.

## Account

| Configuration type | Notes |
|---|---|
| Account CalDAV | Configure a Calendar account. |
| Account CardDAV | Configure a Contacts account. |
| Account Exchange | Configure an Exchange account. |
| Account Google | Configure a Google account. |
| Account LDAP | Configure a Lightweight Directory Access Protocol (LDAP) account. |
| Account Mail | Configure a Mail account. |

## Network

| Configuration type | Notes |
|---|---|
| Network DNS Proxy | Beta. Configure a DNS proxy using a Network Extension app. |
| Network DNS Settings | Beta. Configure encrypted DNS settings (DNS over HTTPS or TLS). |
| Network Relay | Beta. Configure network relay servers to route traffic for specific domains. |
| Network VPN Always On | Beta. Configure an Always On VPN that keeps the device continuously connected. |
| Network VPN IKEv2 | Beta. Configure a VPN connection using the IKEv2 protocol. |
| Network VPN IPSec | Beta. Configure a VPN connection using the IPSec protocol. |
| Network VPN Plugin | Beta. Configure a VPN connection using a third-party VPN plugin or Network Extension provider. |

## Security

| Configuration type | Notes |
|---|---|
| Security Certificate | Add a certificate to the device. Can be paired with an asset — see [DDM Assets](/capaone/mobile-manager/apple-ddm/ddm-assets/). |
| Security Identity | Install an identity on the device. |
| Passcode Settings | Configure passcode policy settings. |
| Extensible SSO | Beta. Configure Extensible Single Sign-On for apps and the platform. |

## Software Update

| Configuration type | Notes |
|---|---|
| Software Update Settings | Configure software updates. Required on iOS 27 in place of Legacy MDM software update management — see [iOS 27 and Software Update Management](/capaone/mobile-manager/apple-ddm/ios-27-and-software-update-management/). |
| Software Update Enforcement Specific | A software update enforcement policy for a specific OS release. |

## Intelligence & AI

| Configuration type | Notes |
|---|---|
| External Intelligence Settings | Configure External Intelligence Integrations settings. Restricts external AI features — Siri AI, Visual Intelligence, and third-party AI extensions such as ChatGPT. Maps to Apple's `com.apple.configuration.external-intelligence.settings`, introduced in iOS 27. |
| Intelligence Settings | Configure Apple Intelligence settings. |
| Siri Settings | Configure Siri settings. |

## Apps & content

| Configuration type | Notes |
|---|---|
| App Settings | Beta. Configure app privacy permission defaults and allowed/denied app and binary lists. |
| Content Caching | Beta. Configure the Content Caching service on macOS. |
| Safari Bookmarks | Configure managed bookmarks in Safari. |
| Safari Extension Settings | Configure Safari Extensions. |
| Safari Settings | Configure Safari settings. |
| Web Content Filter Plugin | Beta. Configure web content filtering using a third-party Network Extension plugin. |

## Device & input

| Configuration type | Notes |
|---|---|
| Audio Accessory Settings | Configure audio accessory settings. |
| Keyboard Settings | Configure keyboard settings. |
| Math Settings | Configure the math and calculator apps. |

## Legacy bridge

| Configuration type | Notes |
|---|---|
| Home Screen Layout | Supervised only. Configure the Home Screen layout for the device — delivered as a legacy MDM profile declaration under the hood, a bridging mechanism for configurations without a native DDM equivalent yet. |

## Good to know

- **This list reflects the picker as of today** — Apple and CapaOne both add configuration types
  over time. If a type you expect isn't listed here, check the live picker at **Apple →
  Configurations → DDM → New**.
- **Not every configuration needs an asset** — most types in this list are self-contained. Only
  reach for [DDM Assets](/capaone/mobile-manager/apple-ddm/ddm-assets/) when a configuration needs
  to reference a credential, identity, or stored data.
