Skip to content

Enable Apple DDM

This guide walks you through migrating Apple devices from Legacy MDM to Declarative Device Management (DDM) in CapaOne.

  1. Check device eligibility. The device must be running iOS 17 or later, whether it’s Supervised or Unsupervised (BYOD). Verify the OS version before proceeding — devices that don’t meet it can’t be enabled for DDM. If you plan to use a declaration that requires Supervised mode, confirm the device’s management mode as well.
  2. Check for Legacy software update policy. Before migrating a group to iOS 27, confirm whether it currently relies on Legacy MDM for software update management — cadence settings, deferrals, or BSI restrictions. If it does, you need a Software Update Settings or Software Update Enforcement Specific DDM configuration in place first; see iOS 27 and Software Update Management for how to audit and configure this.
  3. Communicate with your users. Let them know their device management configuration is changing. No user action is required, but it’s good practice to set expectations.
  4. Plan a phased rollout. Start with a pilot group or a single test device, confirm that configurations apply correctly, then expand to the rest of your fleet.

Step 2: Prepare configurations in DDM format

Section titled “Step 2: Prepare configurations in DDM format”

Before enrolling any devices, review your existing Legacy MDM configurations and identify which ones need a DDM equivalent.

  1. Navigate to Apple → Configurations.
  2. Switch between the Legacy and DDM tabs to compare what already exists in each format.

CapaOne Apple Configurations page showing the Legacy and DDM tabs, with a DDM configuration named password reuse policy

For each configuration that should be managed through DDM:

  1. Navigate to Apple → Configurations → DDM.

  2. Click New. This opens the Select a configuration type picker, with two tabs:

    • Configurations — every DDM configuration type, listed alphabetically. This is what you’ll use for most migrations. See DDM Configuration Types Reference for what each one does.
    • Assets — credentials, identities, and data that a configuration can reference, rather than configurations in their own right (for example, a certificate a Wi-Fi configuration points to). See DDM Assets if the configuration you’re recreating uses a certificate, identity, or stored credential.

    CapaOne’s Select a configuration type picker showing the Configurations tab CapaOne’s Select a configuration type picker showing the Assets tab

  3. Create a new configuration matching your existing Legacy configuration.

  4. Save and verify the configuration.

Create a dedicated device group for DDM migration before you link any DDM configurations to devices. This keeps your rollout isolated from existing Legacy-managed groups and gives you a clear, at-a-glance view of migration progress.

  1. Navigate to Management → Groups.
  2. Click New and give the group a descriptive name, for example DDM - Pilot or DDM - Production.
  3. Save the group. Don’t add devices yet.

Then link your DDM configurations to this group:

  1. Navigate to Apple → Configurations → DDM.
  2. Open each DDM configuration you prepared in Step 2.
  3. Under Group Assignment, link the configuration to your new DDM group.
  4. Save the configuration.

Enroll the device as normal — see Apple Enrollment. The device enrolls under Legacy MDM initially.

To enable DDM on an already-enrolled device:

  1. Navigate to Apple → Endpoints.
  2. Open the device page for the device you want to migrate.
  3. Click the action menu (⋯) in the top right corner.
  4. Select Request → Enable Apple DDM.

Endpoint action menu in CapaOne with Enable Apple DDM highlighted

The device now runs under DDM management.

  1. Open the device page in Apple → Endpoints. The device badge shows Supervised DDM or Unsupervised DDM, confirming DDM is active.
  2. Navigate to Apple → Configurations → DDM and confirm your configurations are assigned and applied to the device.

If a configuration doesn’t apply, check that the correct group is assigned to it and that the device is a member of that group.