How Multiple DDM Configurations Combine
A device often belongs to several groups, and each group can assign DDM configurations. When two or more configurations of the same type reach the same device, the device combines them using Apple’s rules. This article explains those rules so you can predict what a device ends up with.
The three apply rules
Section titled “The three apply rules”Each DDM configuration type has one apply rule:
| Apply rule | What happens when several configurations of the type reach a device | Configuration types in CapaOne |
|---|---|---|
| Combined | The device merges all of them into one effective policy, setting by setting. | App Settings, Audio Accessory Settings, External Intelligence Settings, Intelligence Settings, Keyboard Settings, Math Settings, Passcode Settings, Safari Bookmarks, Safari Extension Settings, Safari Settings, Siri Settings, Software Update Settings |
| Multiple | Each configuration applies independently, side by side. | Account CalDAV, Account CardDAV, Account Exchange, Account Google, Account LDAP, Account Mail, Extensible SSO, Network DNS Proxy, Network DNS Settings, Network Relay, Network VPN IKEv2, Network VPN IPSec, Network VPN Plugin, Security Certificate, Security Identity, Software Update Enforcement Specific, Web Content Filter Plugin, Home Screen Layout (legacy profile) |
| Single | Only one configuration of the type can be active on a device. | Network VPN Always On, Content Caching |
Combined types
Section titled “Combined types”For combined types, Apple gives every setting its own merge rule. In almost every case, the most restrictive value wins:
| Merge rule | Result | Example |
|---|---|---|
Boolean AND (Allow… settings) |
false wins. If any configuration disallows a feature, it’s disallowed. |
Two Siri Settings configurations: one sets Allow While Locked to Yes, one to No → Siri on the Lock Screen is off. |
Boolean OR (Require…, Force… settings) |
true wins. If any configuration requires something, it’s required. |
One Passcode Settings sets Require Complex Passcode → the device requires a complex passcode, even if another configuration doesn’t. |
| Highest number | The largest value wins. | Minimum Length 6 and 8 → 8. Combined Period (Days) 14 and 30 → 30. |
| Lowest number | The smallest value wins. | Maximum Inactivity (Minutes) 5 and 2 → 2. Maximum Failed Attempts 10 and 6 → 6. |
| Set intersection (allow-lists) | Only items in every list stay. | App Settings → Allowed apps: list A has Mail and Teams, list B has Mail → only Mail is allowed. |
| Set union (deny-lists) | Items in any list are included. | App Settings → Denied apps: list A denies Camera, list B denies FaceTime → both are denied. |
| Append | Entries from all configurations are added together. | Safari Bookmarks from two configurations all appear in Safari. |
| Enum (first/last) | One fixed value from Apple’s list wins, independent of which configuration CapaOne sent first. | See the per-type notes below. |
| First | One configuration’s value is used, and you can’t control which. Avoid sending conflicting values. | The temporary pairing configuration in Audio Accessory Settings. |
Merge rules per configuration type
Section titled “Merge rules per configuration type”Passcode Settings
Section titled “Passcode Settings”| Setting | Merge rule | Effective result |
|---|---|---|
| Require Passcode | OR | Required if any configuration requires it. |
| Require Alphanumeric Passcode | OR | Required if any configuration requires it. |
| Require Complex Passcode | OR | Required if any configuration requires it. |
| Minimum Length | Highest | Longest minimum wins. |
| Minimum Complex Characters | Highest | Highest count wins. |
| Maximum Failed Attempts | Lowest | Fewest attempts wins. |
| Failed Attempts Reset (Minutes) (macOS) | Lowest | Shortest reset time wins. |
| Maximum Grace Period (Minutes) | Lowest | Shortest grace period wins. |
| Maximum Inactivity (Minutes) | Lowest | Shortest inactivity period wins. |
| Maximum Passcode Age (Days) | Lowest | Shortest age wins. |
| Passcode Reuse Limit | Lowest | As defined by Apple: the lowest history count wins. |
| Change At Next Auth (macOS) | OR | Forced if any configuration sets it. |
Passcode rules from DDM and from a Legacy Passcode profile also merge, and the device enforces the strictest. See DDM Passcode Settings.
Software Update Settings
Section titled “Software Update Settings”| Setting | Merge rule | Effective result |
|---|---|---|
| Notifications | AND | If any configuration sets Notifications to No, the device only shows the one-hour warning and the restart countdown. |
| Deferrals: Combined, Major, Minor, and System Period (Days) | Highest | Longest deferral wins. |
| Recommended Cadence (iOS) | Enum last | Apple’s order is All → Oldest → Newest; the later value wins. |
| Automatic Actions: Download, Install OS Updates, Install Security Update | Enum last | Apple’s order is Allowed → Always On → Always Off; Always Off wins over Always On, which wins over Allowed. |
| Rapid Security Response: Enable, Enable Rollback | AND | No if any configuration sets it to No. |
| Allow Standard User OS Updates (macOS) | AND | No if any configuration sets it to No. |
| Beta: Program Enrollment | Enum last | Always Off wins. |
App Settings
Section titled “App Settings”| Setting | Merge rule | Effective result |
|---|---|---|
| Allowed apps | Intersection | Only apps in every list are allowed. |
| Denied apps | Union | Apps in any list are denied. |
| Allowed binaries (macOS) | Intersection | Only binaries in every list can run. |
| Denied binaries (macOS) | Union | Binaries in any list are blocked. |
| Always allow managed apps (macOS) | OR | On if any configuration turns it on. |
| Privacy permission defaults (per app, per permission) | Enum last | The most permissive default listed last by Apple wins, for example Always over While using for Location. |
Safari Settings, Safari Extension Settings, Safari Bookmarks
Section titled “Safari Settings, Safari Extension Settings, Safari Bookmarks”| Type | Setting | Merge rule | Effective result |
|---|---|---|---|
| Safari Settings | Accept cookies | Enum first | Apple’s order is Never → Current website → Visited websites → Always; Never wins. |
| Safari Settings | Allow JavaScript, pop-ups, private browsing, history clearing, summary, disabling fraud warning | AND | Off if any configuration turns it off. |
| Safari Settings | Website permission defaults (camera, microphone) | Enum last | Allow wins over None. |
| Safari Extension Settings | Allowed domains / denied domains | Union | All lists are combined. If a domain is in both, Safari denies it. |
| Safari Extension Settings | Extension state, private browsing | Enum last | As ordered by Apple. |
| Safari Bookmarks | Bookmarks | Append | All managed bookmarks appear. |
Intelligence Settings, External Intelligence Settings, Siri Settings, Keyboard Settings, Math Settings
Section titled “Intelligence Settings, External Intelligence Settings, Siri Settings, Keyboard Settings, Math Settings”These types use the simple restrictive rule throughout:
- Every Allow… and Enabled setting is AND — off if any configuration turns it off.
- Every Force… setting (for example Force Profanity Filter) is OR — on if any configuration turns it on.
Audio Accessory Settings
Section titled “Audio Accessory Settings”Disable temporary pairing is OR. The temporary pairing configuration itself is first — use one configuration per device.
Multiple and single types
Section titled “Multiple and single types”For multiple types, there’s no merging. Two Account Mail configurations create two mail accounts. Two Security Certificate configurations install two certificates. Make sure you don’t assign the same account or certificate through two different groups, or the user sees it twice.
Software Update Enforcement Specific is also a multiple type: a device can hold several enforcement configurations at once, for example one per OS release. The device acts on each one whose target version is an available update. See Enforce a Specific OS Update.
For single types, a device can only have one active configuration. If a device receives two Network VPN Always On configurations, only one is applied and the other is reported with an error.
Design groups so the result is predictable
Section titled “Design groups so the result is predictable”- One combined configuration per type, per device, where you can. Build a baseline (for example
DDM - Passcode - Corporate) and assign it to one group that every device is in. Create stricter variants only for groups that need them, and remember that the stricter value always wins. - Don’t split allow-lists across configurations. Put all allowed apps for a device in one App Settings configuration. Use denied-lists if different groups need to add restrictions — denied-lists combine safely.
- Assign multiple-type configurations from one place. An account or a certificate should come from one group only.
- Name configurations after scope and intent, for example
DDM - SU Settings - All SupervisedandDDM - SU Enforce - 27.0.1 - Pilot, so overlap is easy to spot in the assignment list. - Check the result on a device. Open the device in Apple → Endpoints and select the Configurations tab. On Applied, check the settings the device received from each configuration. The merged result is calculated on the device, so it isn’t shown as one combined policy.
Good to know
Section titled “Good to know”- Combining happens on the device — the merged result exists only on the device.
- Most restrictive wins, almost always — when in doubt, assume the strictest value across all configurations is the one in effect.
- DDM and Legacy settings also merge — if a Legacy profile and a DDM configuration set the same thing, the device enforces the strictest. The exception is software updates, where DDM takes precedence over Legacy MDM commands.
- Removing a configuration recalculates the result — unassigning a stricter configuration loosens the effective policy immediately, without any action on the remaining configurations.
- Source: merge rules per setting from Apple’s device management schema (
applyandcombinetypefields, Release v27.0); precedence rules from Apple Platform Deployment: Use declarative device management to manage Apple devices.