# Enable Apple DDM

> Migrate Apple devices running iOS 17 or later from Legacy MDM to Declarative Device Management.

Source: https://docs.capaone.com/capaone/mobile-manager/apple-ddm/enable-apple-ddm/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

This guide walks you through migrating Apple devices from Legacy MDM to Declarative
Device Management (DDM) in CapaOne.

:::note[Before you start]
- This guide applies to Apple devices running **iOS 17 or later**, enrolled in CapaOne — either
  Supervised or Unsupervised (BYOD).
- Don't enable DDM on all devices at the same time. Start with a single device to confirm your
  setup works as expected before rolling out to a larger group.
- DDM configurations live under their own **DDM** tab in **Apple → Configurations**. Some Legacy
  configurations continue to work alongside DDM — you don't need to recreate everything at once.
:::

## Step 1: Plan your migration

:::caution
As of iOS 27, Legacy MDM's software update management no longer functions — software update
commands, software update queries, recommended cadence settings, and restrictions like deferrals
and Background Security Improvements (BSI) all stop working. These commands don't error, they
silently stop applying. If your fleet includes devices on iOS 27 or later, move software update
policy to DDM before upgrading them.

CapaOne also switches a device to DDM automatically once it's running iOS 27 — whether it's
already on that version or updates to it while enrolled. You don't need to request **Enable Apple
DDM** for these devices, but it also means any DDM configuration they depend on must already be in
place: there's no window after the update to react before the device is under DDM management.
:::

1. **Check device eligibility.** The device must be running iOS 17 or later, whether it's
   Supervised or Unsupervised (BYOD). Verify the OS version before proceeding — devices that don't
   meet it can't be enabled for DDM. If you plan to use a declaration that requires Supervised
   mode, confirm the device's management mode as well.
2. **Check for Legacy software update policy.** Before migrating a group to iOS 27, confirm
   whether it currently relies on Legacy MDM for software update management — cadence settings,
   deferrals, or BSI restrictions. If it does, you need a **Software Update Settings** or
   **Software Update Enforcement Specific** DDM configuration in place first; see [iOS 27 and
   Software Update Management](/capaone/mobile-manager/apple-ddm/ios-27-and-software-update-management/)
   for how to audit and configure this.
3. **Communicate with your users.** Let them know their device management configuration is
   changing. No user action is required, but it's good practice to set expectations.
4. **Plan a phased rollout.** Start with a pilot group or a single test device, confirm that
   configurations apply correctly, then expand to the rest of your fleet.

## Step 2: Prepare configurations in DDM format

Before enrolling any devices, review your existing Legacy MDM configurations and identify which
ones need a DDM equivalent.

1. Navigate to **Apple → Configurations**.
2. Switch between the **Legacy** and **DDM** tabs to compare what already exists in each format.

![CapaOne Apple Configurations page showing the Legacy and DDM tabs, with a DDM configuration named password reuse policy](/attachments/capaone/apple-ddm-configurations-tab.png)

For each configuration that should be managed through DDM:

1. Navigate to **Apple → Configurations → DDM**.
2. Click **New**. This opens the **Select a configuration type** picker, with two tabs:
   - **Configurations** — every DDM configuration type, listed alphabetically. This is what you'll
     use for most migrations. See [DDM Configuration Types
     Reference](/capaone/mobile-manager/apple-ddm/ddm-configuration-types-reference/) for what
     each one does.
   - **Assets** — credentials, identities, and data that a configuration can reference, rather than
     configurations in their own right (for example, a certificate a Wi-Fi configuration points
     to). See [DDM Assets](/capaone/mobile-manager/apple-ddm/ddm-assets/) if the configuration
     you're recreating uses a certificate, identity, or stored credential.

   ![CapaOne's Select a configuration type picker showing the Configurations tab](/attachments/capaone/apple-ddm-configuration-type-picker-configurations.png)
   ![CapaOne's Select a configuration type picker showing the Assets tab](/attachments/capaone/apple-ddm-configuration-type-picker-assets.png)
3. Create a new configuration matching your existing Legacy configuration.
4. Save and verify the configuration.

:::note
Legacy configurations that Apple hasn't deprecated keep working alongside DDM. You don't need to
recreate all configurations immediately — prioritize any that are deprecated or flagged by Apple as
unsupported under DDM.

Some Legacy configurations don't have a native DDM equivalent yet. Apple can bridge these by
delivering the Legacy MDM profile as a declarative asset. **Home Screen Layout** works this way in
CapaOne today — it's tagged **Supervised only** and is delivered as a legacy MDM profile
declaration under the hood, even though it's created from the DDM tab.
:::

## Step 3: Prepare a new group for DDM

Create a dedicated device group for DDM migration before you link any DDM configurations to
devices. This keeps your rollout isolated from existing Legacy-managed groups and gives you a
clear, at-a-glance view of migration progress.

1. Navigate to **Management → Groups**.
2. Click **New** and give the group a descriptive name, for example `DDM - Pilot` or
   `DDM - Production`.
3. Save the group. Don't add devices yet.

Then link your DDM configurations to this group:

1. Navigate to **Apple → Configurations → DDM**.
2. Open each DDM configuration you prepared in Step 2.
3. Under **Group Assignment**, link the configuration to your new DDM group.
4. Save the configuration.

:::tip[Why a dedicated group?]
Linking DDM configurations to a dedicated group — rather than your existing groups — lets you
migrate devices one at a time simply by moving them into the DDM group. You can track exactly how
many devices have migrated without disrupting devices that haven't moved yet: devices in the DDM
group have migrated, devices that aren't are still on Legacy MDM.
:::

:::caution
Don't add a device to the DDM group until you've completed Step 4 and enabled DDM on it. Adding a
device early doesn't cause errors, but its DDM configurations won't apply until the device is
actually running under DDM management.
:::

## Step 4: Enroll and enable DDM on devices

Enroll the device as normal — see [Apple Enrollment](/capaone/enrollment/apple-enrollment/). The
device enrolls under Legacy MDM initially.

:::note
CapaOne automatically switches a device to DDM once it's running iOS 27 or later — you don't need
the manual step below for those devices; it happens on its own once the device is on iOS 27,
whether it's already there at enrollment or updates to it later.

Use the manual steps below to enable DDM early on a device that's still running an earlier iOS
version — for example, to pilot your migration ahead of the rest of your fleet.
:::

To enable DDM on an already-enrolled device:

1. Navigate to **Apple → Endpoints**.
2. Open the device page for the device you want to migrate.
3. Click the action menu (⋯) in the top right corner.
4. Select **Request → Enable Apple DDM**.

![Endpoint action menu in CapaOne with Enable Apple DDM highlighted](/attachments/capaone/apple-ddm-enable-endpoint-action.png)

The device now runs under DDM management.

## Step 5: Verify DDM enrollment

1. Open the device page in **Apple → Endpoints**. The device badge shows **Supervised DDM** or
   **Unsupervised DDM**, confirming DDM is active.
2. Navigate to **Apple → Configurations → DDM** and confirm your configurations are assigned and
   applied to the device.

If a configuration doesn't apply, check that the correct group is assigned to it and that the
device is a member of that group.
