# How Multiple DDM Configurations Combine

> What happens when two or more DDM configurations of the same type reach the same device — merge rules per setting, and how to design groups so the result is predictable.

Source: https://docs.capaone.com/capaone/mobile-manager/apple-ddm/how-ddm-configurations-combine/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

A device often belongs to several groups, and each group can assign DDM configurations. When two or more configurations of the **same type** reach the same device, the device combines them using Apple's rules. This article explains those rules so you can predict what a device ends up with.

:::note[Before you start]
- This article assumes you know the difference between a configuration and an asset. See [How DDM Works](/capaone/mobile-manager/apple-ddm/how-ddm-works/).
- For how CapaOne orders configurations, see [Configuration Priority](/capaone/reference/configuration-priority/).
:::

## The three apply rules

Each DDM configuration type has one apply rule:

| Apply rule | What happens when several configurations of the type reach a device | Configuration types in CapaOne |
|---|---|---|
| **Combined** | The device merges all of them into one effective policy, setting by setting. | App Settings, Audio Accessory Settings, External Intelligence Settings, Intelligence Settings, Keyboard Settings, Math Settings, Passcode Settings, Safari Bookmarks, Safari Extension Settings, Safari Settings, Siri Settings, Software Update Settings |
| **Multiple** | Each configuration applies independently, side by side. | Account CalDAV, Account CardDAV, Account Exchange, Account Google, Account LDAP, Account Mail, Extensible SSO, Network DNS Proxy, Network DNS Settings, Network Relay, Network VPN IKEv2, Network VPN IPSec, Network VPN Plugin, Security Certificate, Security Identity, Software Update Enforcement Specific, Web Content Filter Plugin, Home Screen Layout (legacy profile) |
| **Single** | Only one configuration of the type can be active on a device. | Network VPN Always On, Content Caching |

### Combined types

For combined types, Apple gives every setting its own merge rule. In almost every case, the **most restrictive** value wins:

| Merge rule | Result | Example |
|---|---|---|
| **Boolean AND** (`Allow…` settings) | `false` wins. If any configuration disallows a feature, it's disallowed. | Two **Siri Settings** configurations: one sets **Allow While Locked** to **Yes**, one to **No** → Siri on the Lock Screen is off. |
| **Boolean OR** (`Require…`, `Force…` settings) | `true` wins. If any configuration requires something, it's required. | One **Passcode Settings** sets **Require Complex Passcode** → the device requires a complex passcode, even if another configuration doesn't. |
| **Highest number** | The largest value wins. | **Minimum Length** 6 and 8 → 8. **Combined Period (Days)** 14 and 30 → 30. |
| **Lowest number** | The smallest value wins. | **Maximum Inactivity (Minutes)** 5 and 2 → 2. **Maximum Failed Attempts** 10 and 6 → 6. |
| **Set intersection** (allow-lists) | Only items in **every** list stay. | **App Settings → Allowed apps**: list A has Mail and Teams, list B has Mail → only Mail is allowed. |
| **Set union** (deny-lists) | Items in **any** list are included. | **App Settings → Denied apps**: list A denies Camera, list B denies FaceTime → both are denied. |
| **Append** | Entries from all configurations are added together. | **Safari Bookmarks** from two configurations all appear in Safari. |
| **Enum (first/last)** | One fixed value from Apple's list wins, independent of which configuration CapaOne sent first. | See the per-type notes below. |
| **First** | One configuration's value is used, and you can't control which. Avoid sending conflicting values. | The temporary pairing configuration in **Audio Accessory Settings**. |

:::caution
An allow-list combined by intersection can quickly shrink to nothing. If two **App Settings** configurations each have an **Allowed apps** list and the lists share no apps, the device allows none of the listed apps. Keep allow-lists in a single configuration per device.
:::

## Merge rules per configuration type

### Passcode Settings

| Setting | Merge rule | Effective result |
|---|---|---|
| Require Passcode | OR | Required if any configuration requires it. |
| Require Alphanumeric Passcode | OR | Required if any configuration requires it. |
| Require Complex Passcode | OR | Required if any configuration requires it. |
| Minimum Length | Highest | Longest minimum wins. |
| Minimum Complex Characters | Highest | Highest count wins. |
| Maximum Failed Attempts | Lowest | Fewest attempts wins. |
| Failed Attempts Reset (Minutes) (macOS) | Lowest | Shortest reset time wins. |
| Maximum Grace Period (Minutes) | Lowest | Shortest grace period wins. |
| Maximum Inactivity (Minutes) | Lowest | Shortest inactivity period wins. |
| Maximum Passcode Age (Days) | Lowest | Shortest age wins. |
| Passcode Reuse Limit | Lowest | As defined by Apple: the lowest history count wins. |
| Change At Next Auth (macOS) | OR | Forced if any configuration sets it. |

Passcode rules from DDM and from a Legacy **Passcode** profile also merge, and the device enforces the strictest. See [DDM Passcode Settings](/capaone/mobile-manager/apple-ddm/ddm-passcode-settings/).

### Software Update Settings

| Setting | Merge rule | Effective result |
|---|---|---|
| Notifications | AND | If any configuration sets **Notifications** to **No**, the device only shows the one-hour warning and the restart countdown. |
| Deferrals: Combined, Major, Minor, and System Period (Days) | Highest | Longest deferral wins. |
| Recommended Cadence (iOS) | Enum last | Apple's order is **All → Oldest → Newest**; the later value wins. |
| Automatic Actions: Download, Install OS Updates, Install Security Update | Enum last | Apple's order is **Allowed → Always On → Always Off**; **Always Off** wins over **Always On**, which wins over **Allowed**. |
| Rapid Security Response: Enable, Enable Rollback | AND | **No** if any configuration sets it to **No**. |
| Allow Standard User OS Updates (macOS) | AND | **No** if any configuration sets it to **No**. |
| Beta: Program Enrollment | Enum last | **Always Off** wins. |

:::caution
Two Software Update Settings with **Install OS Updates** set to **Always On** and **Always Off** don't average out — **Always Off** wins, and the device stops installing updates automatically. Keep exactly one Software Update Settings configuration per device. See [Software Update Settings](/capaone/mobile-manager/apple-ddm/software-update-settings/).
:::

### App Settings

| Setting | Merge rule | Effective result |
|---|---|---|
| Allowed apps | Intersection | Only apps in every list are allowed. |
| Denied apps | Union | Apps in any list are denied. |
| Allowed binaries (macOS) | Intersection | Only binaries in every list can run. |
| Denied binaries (macOS) | Union | Binaries in any list are blocked. |
| Always allow managed apps (macOS) | OR | On if any configuration turns it on. |
| Privacy permission defaults (per app, per permission) | Enum last | The most permissive default listed last by Apple wins, for example **Always** over **While using** for Location. |

### Safari Settings, Safari Extension Settings, Safari Bookmarks

| Type | Setting | Merge rule | Effective result |
|---|---|---|---|
| Safari Settings | Accept cookies | Enum first | Apple's order is **Never → Current website → Visited websites → Always**; **Never** wins. |
| Safari Settings | Allow JavaScript, pop-ups, private browsing, history clearing, summary, disabling fraud warning | AND | Off if any configuration turns it off. |
| Safari Settings | Website permission defaults (camera, microphone) | Enum last | **Allow** wins over **None**. |
| Safari Extension Settings | Allowed domains / denied domains | Union | All lists are combined. If a domain is in both, Safari denies it. |
| Safari Extension Settings | Extension state, private browsing | Enum last | As ordered by Apple. |
| Safari Bookmarks | Bookmarks | Append | All managed bookmarks appear. |

### Intelligence Settings, External Intelligence Settings, Siri Settings, Keyboard Settings, Math Settings

These types use the simple restrictive rule throughout:

- Every **Allow…** and **Enabled** setting is **AND** — off if any configuration turns it off.
- Every **Force…** setting (for example **Force Profanity Filter**) is **OR** — on if any configuration turns it on.

### Audio Accessory Settings

**Disable temporary pairing** is **OR**. The temporary pairing configuration itself is **first** — use one configuration per device.

## Multiple and single types

For **multiple** types, there's no merging. Two **Account Mail** configurations create two mail accounts. Two **Security Certificate** configurations install two certificates. Make sure you don't assign the same account or certificate through two different groups, or the user sees it twice.

**Software Update Enforcement Specific** is also a multiple type: a device can hold several enforcement configurations at once, for example one per OS release. The device acts on each one whose target version is an available update. See [Enforce a Specific OS Update](/capaone/mobile-manager/apple-ddm/enforce-a-specific-os-update/).

For **single** types, a device can only have one active configuration. If a device receives two **Network VPN Always On** configurations, only one is applied and the other is reported with an error.

## Design groups so the result is predictable

1. **One combined configuration per type, per device, where you can.** Build a baseline (for example `DDM - Passcode - Corporate`) and assign it to one group that every device is in. Create stricter variants only for groups that need them, and remember that the stricter value always wins.
2. **Don't split allow-lists across configurations.** Put all allowed apps for a device in one **App Settings** configuration. Use denied-lists if different groups need to add restrictions — denied-lists combine safely.
3. **Assign multiple-type configurations from one place.** An account or a certificate should come from one group only.
4. **Name configurations after scope and intent**, for example `DDM - SU Settings - All Supervised` and `DDM - SU Enforce - 27.0.1 - Pilot`, so overlap is easy to spot in the assignment list.
5. **Check the result on a device.** Open the device in **Apple → Endpoints** and select the **Configurations** tab. On **Applied**, check the settings the device received from each configuration. The merged result is calculated on the device, so it isn't shown as one combined policy.

## Good to know

- **Combining happens on the device** — the merged result exists only on the device.
- **Most restrictive wins, almost always** — when in doubt, assume the strictest value across all configurations is the one in effect.
- **DDM and Legacy settings also merge** — if a Legacy profile and a DDM configuration set the same thing, the device enforces the strictest. The exception is software updates, where DDM takes precedence over Legacy MDM commands.
- **Removing a configuration recalculates the result** — unassigning a stricter configuration loosens the effective policy immediately, without any action on the remaining configurations.
- **Source:** merge rules per setting from Apple's [device management schema](https://github.com/apple/device-management/tree/release/declarative/declarations/configurations) (`apply` and `combinetype` fields, Release v27.0); precedence rules from Apple Platform Deployment: [Use declarative device management to manage Apple devices](https://support.apple.com/guide/deployment/declarative-device-management-manage-apple-depc30268577/web).
