Skip to content

How Multiple DDM Configurations Combine

A device often belongs to several groups, and each group can assign DDM configurations. When two or more configurations of the same type reach the same device, the device combines them using Apple’s rules. This article explains those rules so you can predict what a device ends up with.

Each DDM configuration type has one apply rule:

Apply rule What happens when several configurations of the type reach a device Configuration types in CapaOne
Combined The device merges all of them into one effective policy, setting by setting. App Settings, Audio Accessory Settings, External Intelligence Settings, Intelligence Settings, Keyboard Settings, Math Settings, Passcode Settings, Safari Bookmarks, Safari Extension Settings, Safari Settings, Siri Settings, Software Update Settings
Multiple Each configuration applies independently, side by side. Account CalDAV, Account CardDAV, Account Exchange, Account Google, Account LDAP, Account Mail, Extensible SSO, Network DNS Proxy, Network DNS Settings, Network Relay, Network VPN IKEv2, Network VPN IPSec, Network VPN Plugin, Security Certificate, Security Identity, Software Update Enforcement Specific, Web Content Filter Plugin, Home Screen Layout (legacy profile)
Single Only one configuration of the type can be active on a device. Network VPN Always On, Content Caching

For combined types, Apple gives every setting its own merge rule. In almost every case, the most restrictive value wins:

Merge rule Result Example
Boolean AND (Allow… settings) false wins. If any configuration disallows a feature, it’s disallowed. Two Siri Settings configurations: one sets Allow While Locked to Yes, one to No → Siri on the Lock Screen is off.
Boolean OR (Require…, Force… settings) true wins. If any configuration requires something, it’s required. One Passcode Settings sets Require Complex Passcode → the device requires a complex passcode, even if another configuration doesn’t.
Highest number The largest value wins. Minimum Length 6 and 8 → 8. Combined Period (Days) 14 and 30 → 30.
Lowest number The smallest value wins. Maximum Inactivity (Minutes) 5 and 2 → 2. Maximum Failed Attempts 10 and 6 → 6.
Set intersection (allow-lists) Only items in every list stay. App Settings → Allowed apps: list A has Mail and Teams, list B has Mail → only Mail is allowed.
Set union (deny-lists) Items in any list are included. App Settings → Denied apps: list A denies Camera, list B denies FaceTime → both are denied.
Append Entries from all configurations are added together. Safari Bookmarks from two configurations all appear in Safari.
Enum (first/last) One fixed value from Apple’s list wins, independent of which configuration CapaOne sent first. See the per-type notes below.
First One configuration’s value is used, and you can’t control which. Avoid sending conflicting values. The temporary pairing configuration in Audio Accessory Settings.
Setting Merge rule Effective result
Require Passcode OR Required if any configuration requires it.
Require Alphanumeric Passcode OR Required if any configuration requires it.
Require Complex Passcode OR Required if any configuration requires it.
Minimum Length Highest Longest minimum wins.
Minimum Complex Characters Highest Highest count wins.
Maximum Failed Attempts Lowest Fewest attempts wins.
Failed Attempts Reset (Minutes) (macOS) Lowest Shortest reset time wins.
Maximum Grace Period (Minutes) Lowest Shortest grace period wins.
Maximum Inactivity (Minutes) Lowest Shortest inactivity period wins.
Maximum Passcode Age (Days) Lowest Shortest age wins.
Passcode Reuse Limit Lowest As defined by Apple: the lowest history count wins.
Change At Next Auth (macOS) OR Forced if any configuration sets it.

Passcode rules from DDM and from a Legacy Passcode profile also merge, and the device enforces the strictest. See DDM Passcode Settings.

Setting Merge rule Effective result
Notifications AND If any configuration sets Notifications to No, the device only shows the one-hour warning and the restart countdown.
Deferrals: Combined, Major, Minor, and System Period (Days) Highest Longest deferral wins.
Recommended Cadence (iOS) Enum last Apple’s order is All → Oldest → Newest; the later value wins.
Automatic Actions: Download, Install OS Updates, Install Security Update Enum last Apple’s order is Allowed → Always On → Always Off; Always Off wins over Always On, which wins over Allowed.
Rapid Security Response: Enable, Enable Rollback AND No if any configuration sets it to No.
Allow Standard User OS Updates (macOS) AND No if any configuration sets it to No.
Beta: Program Enrollment Enum last Always Off wins.
Setting Merge rule Effective result
Allowed apps Intersection Only apps in every list are allowed.
Denied apps Union Apps in any list are denied.
Allowed binaries (macOS) Intersection Only binaries in every list can run.
Denied binaries (macOS) Union Binaries in any list are blocked.
Always allow managed apps (macOS) OR On if any configuration turns it on.
Privacy permission defaults (per app, per permission) Enum last The most permissive default listed last by Apple wins, for example Always over While using for Location.

Safari Settings, Safari Extension Settings, Safari Bookmarks

Section titled “Safari Settings, Safari Extension Settings, Safari Bookmarks”
Type Setting Merge rule Effective result
Safari Settings Accept cookies Enum first Apple’s order is Never → Current website → Visited websites → Always; Never wins.
Safari Settings Allow JavaScript, pop-ups, private browsing, history clearing, summary, disabling fraud warning AND Off if any configuration turns it off.
Safari Settings Website permission defaults (camera, microphone) Enum last Allow wins over None.
Safari Extension Settings Allowed domains / denied domains Union All lists are combined. If a domain is in both, Safari denies it.
Safari Extension Settings Extension state, private browsing Enum last As ordered by Apple.
Safari Bookmarks Bookmarks Append All managed bookmarks appear.

Intelligence Settings, External Intelligence Settings, Siri Settings, Keyboard Settings, Math Settings

Section titled “Intelligence Settings, External Intelligence Settings, Siri Settings, Keyboard Settings, Math Settings”

These types use the simple restrictive rule throughout:

  • Every Allow… and Enabled setting is AND — off if any configuration turns it off.
  • Every Force… setting (for example Force Profanity Filter) is OR — on if any configuration turns it on.

Disable temporary pairing is OR. The temporary pairing configuration itself is first — use one configuration per device.

For multiple types, there’s no merging. Two Account Mail configurations create two mail accounts. Two Security Certificate configurations install two certificates. Make sure you don’t assign the same account or certificate through two different groups, or the user sees it twice.

Software Update Enforcement Specific is also a multiple type: a device can hold several enforcement configurations at once, for example one per OS release. The device acts on each one whose target version is an available update. See Enforce a Specific OS Update.

For single types, a device can only have one active configuration. If a device receives two Network VPN Always On configurations, only one is applied and the other is reported with an error.

Design groups so the result is predictable

Section titled “Design groups so the result is predictable”
  1. One combined configuration per type, per device, where you can. Build a baseline (for example DDM - Passcode - Corporate) and assign it to one group that every device is in. Create stricter variants only for groups that need them, and remember that the stricter value always wins.
  2. Don’t split allow-lists across configurations. Put all allowed apps for a device in one App Settings configuration. Use denied-lists if different groups need to add restrictions — denied-lists combine safely.
  3. Assign multiple-type configurations from one place. An account or a certificate should come from one group only.
  4. Name configurations after scope and intent, for example DDM - SU Settings - All Supervised and DDM - SU Enforce - 27.0.1 - Pilot, so overlap is easy to spot in the assignment list.
  5. Check the result on a device. Open the device in Apple → Endpoints and select the Configurations tab. On Applied, check the settings the device received from each configuration. The merged result is calculated on the device, so it isn’t shown as one combined policy.
  • Combining happens on the device — the merged result exists only on the device.
  • Most restrictive wins, almost always — when in doubt, assume the strictest value across all configurations is the one in effect.
  • DDM and Legacy settings also merge — if a Legacy profile and a DDM configuration set the same thing, the device enforces the strictest. The exception is software updates, where DDM takes precedence over Legacy MDM commands.
  • Removing a configuration recalculates the result — unassigning a stricter configuration loosens the effective policy immediately, without any action on the remaining configurations.
  • Source: merge rules per setting from Apple’s device management schema (apply and combinetype fields, Release v27.0); precedence rules from Apple Platform Deployment: Use declarative device management to manage Apple devices.