# Legacy MDM to DDM Mapping

> For every Legacy MDM profile, restriction and command that Apple has deprecated or removed in OS 26 and OS 27, which DDM configuration type replaces it in CapaOne — and what stays on Legacy MDM.

Source: https://docs.capaone.com/capaone/mobile-manager/apple-ddm/legacy-to-ddm-mapping/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

Use this reference to plan which Legacy configurations to recreate in DDM, and in which order. It lists every Legacy MDM payload, restriction, and command that Apple has **deprecated** or **removed** in OS 26 and OS 27, and the DDM configuration type in CapaOne that replaces it.

- **Removed** — the Legacy setting no longer functions on that OS version. Devices silently ignore it. Recreate it in DDM *before* devices update.
- **Deprecated** — the Legacy setting still works, but Apple has named a DDM replacement and can remove the Legacy setting in a future release. Plan to recreate it.

:::note[Before you start]
- DDM configurations live under **Apple → Configurations → DDM**. Legacy configurations stay under **Apple → Configurations → Legacy**. See [Enable Apple DDM](/capaone/mobile-manager/apple-ddm/enable-apple-ddm/).
- The article covers the Legacy configuration types in CapaOne's **Legacy** picker: Accounts (LDAP), App Management (Kiosk Mode), Certificates, Custom, Mail (Exchange ActiveSync), Networking, Proxies, Restrictions, Security (Passcode), System Configuration, User Experience, VPN, and Web.
- Versions in this article are from Apple's device management schema, Release v27.0 (September 2026). Apple adds deprecations with each major release.
:::

## Priority 1: Removed in OS 27 — act before devices update

These no longer function on iOS, iPadOS, and macOS 27. A device that updates with only the Legacy setting in place has **no** policy for it.

### Software update commands

| Legacy MDM command in CapaOne | Deprecated | Removed | Replace with |
|---|---|---|---|
| **Update OS** request (Apple: `ScheduleOSUpdate`) | 26.0 | 27.0 (iOS, macOS, tvOS) | **Software Update Enforcement Specific** — see [Enforce a Specific OS Update](/capaone/mobile-manager/apple-ddm/enforce-a-specific-os-update/) |
| Available OS updates (`AvailableOSUpdates`) | 26.0 | 27.0 | DDM status: the device reports pending version and install state on its own |
| OS update status (`OSUpdateStatus`) | 26.0 | 27.0 | DDM status: install state, pending version, failure reason |
| Schedule OS update scan (`ScheduleOSUpdateScan`) — macOS | 26.0 | 27.0 | Not needed — DDM devices check for updates on their own |

The **Update OS** request is in **Request** on the device's actions menu. See [Apple Device Commands](/capaone/mobile-manager/apple-mdm/apple-device-commands/#update-os-options). CapaOne doesn't show the other three as separate requests.

### Software update restrictions

| Legacy restriction (Apple key) | Platforms | Deprecated | Removed | Replace with (Software Update Settings) |
|---|---|---|---|---|
| Delay software updates (`forceDelayedSoftwareUpdates`) | iOS, macOS, tvOS | 26.0 | 27.0 | **Deferrals** (Combined, Major, Minor, and System Period) |
| Software update delay in days (`enforcedSoftwareUpdateDelay`) | iOS, macOS, tvOS | 26.0 | 27.0 | **Deferrals → Combined Period (Days)** (iOS), **Deferrals → Minor Period (Days)** (macOS) |
| Delay major macOS updates (`forceDelayedMajorSoftwareUpdates`) | macOS | 26.0 | 27.0 | **Deferrals → Major Period (Days)** |
| Major macOS update delay (`enforcedSoftwareUpdateMajorOSDeferredInstallDelay`) | macOS | 26.0 | 27.0 | **Deferrals → Major Period (Days)** |
| Minor macOS update delay (`enforcedSoftwareUpdateMinorOSDeferredInstallDelay`) | macOS | 26.0 | 27.0 | **Deferrals → Minor Period (Days)** |
| Non-OS update delay (`enforcedSoftwareUpdateNonOSDeferredInstallDelay`) | macOS | 26.0 | 27.0 | **Deferrals → System Period (Days)** |
| Delay app updates (`forceDelayedAppSoftwareUpdates`) | macOS | 26.0 | 27.0 | No direct DDM equivalent |
| Allow Rapid Security Response installation (`allowRapidSecurityResponseInstallation`) | iOS, macOS | 26.0 | 27.0 | **Rapid Security Response → Enable** |
| Allow Rapid Security Response removal (`allowRapidSecurityResponseRemoval`) | iOS, macOS | 26.0 | 27.0 | **Rapid Security Response → Enable Rollback** |
| Recommended cadence — **Settings** command, `SoftwareUpdateSettings` → `RecommendationCadence` (supervised) | iOS | 26.0 | 27.0 | **Recommended Cadence** |

See [Software Update Settings](/capaone/mobile-manager/apple-ddm/software-update-settings/) for each DDM setting.

CapaOne marks these Legacy settings with a **Deprecated** badge. On a device's **Configurations** tab, under **Applied**, a Legacy software update restriction that a device on OS 27 ignores is still listed with the badge — there's no error.

![Apple device Applied configurations with Legacy software update delay restrictions marked Deprecated and DDM Passcode and Software Update Settings](/attachments/capaone/legacy-to-ddm-mapping--device-applied-deprecated.png)

## Priority 2: Deprecated in OS 27 — recreate during your migration

### Profile payloads

| Legacy payload | Platforms | Deprecated | Replace with in CapaOne DDM | Notes |
|---|---|---|---|---|
| **Passcode** (`com.apple.mobiledevice.passwordpolicy`) | iOS, macOS, watchOS, visionOS | 27.0 | **Passcode Settings** | See [DDM Passcode Settings](/capaone/mobile-manager/apple-ddm/ddm-passcode-settings/). |
| **DNS Settings** (`com.apple.dnsSettings.managed`) | iOS, macOS, visionOS | 27.0 | **Network DNS Settings** | DDM type requires OS 27. |
| **DNS Proxy** (`com.apple.dnsProxy.managed`) | iOS, macOS, visionOS | 27.0 | **Network DNS Proxy** | DDM type requires OS 27. |

:::caution[DDM network types need OS 27]
The DDM **Network** types only work on OS 27 and later. Keep the Legacy DNS Settings and DNS Proxy configurations for devices still on OS 26 or earlier, and assign the DDM versions to OS 27 devices. Don't send both to the same device unless you've confirmed they don't conflict.
:::

### Restrictions

| Legacy restriction (Apple key) | Platforms | Deprecated | Replace with in CapaOne DDM |
|---|---|---|---|
| Allowed apps list (`allowListedAppBundleIDs`) | iOS, tvOS, visionOS | 27.0 | **App Settings → Allowed apps** |
| Blocked apps list (`blockedAppBundleIDs`) | iOS, tvOS, visionOS | 27.0 | **App Settings → Denied apps** |
| Allow Siri AI (`allowSiriAI`) | iOS | 27.0 | Not available in CapaOne — neither as a DDM type nor in the Legacy **Restrictions** editor. Use a **Custom Configuration** profile if you need it. |

## Priority 3: Deprecated in OS 26.4 — Apple Intelligence, Siri and keyboard restrictions

Apple moved these restrictions out of the Legacy **Restrictions** payload into dedicated DDM types in iOS, iPadOS and macOS 26.4. All the DDM replacements require **Supervised** devices. In CapaOne's Legacy **Restrictions** editor, these restrictions carry a **Deprecated** badge.

![Legacy Restrictions editor with Apple Intelligence and external intelligence restrictions marked Deprecated](/attachments/capaone/legacy-to-ddm-mapping--legacy-restrictions-deprecated.png)

Some of the restrictions below aren't in CapaOne's Legacy **Restrictions** editor at all. For those, the table says so — use a **Custom Configuration** profile if you need them.

| Legacy restriction (Apple key) | Replace with in CapaOne DDM |
|---|---|
| `allowAssistant` (Siri) | **Siri Settings → Enabled** |
| `allowAssistantWhileLocked` | **Siri Settings → Allow While Locked** |
| `allowAssistantUserGeneratedContent` | **Siri Settings → Allow User-Generated Content** |
| `forceAssistantProfanityFilter` | **Siri Settings → Force Profanity Filter** |
| `allowWritingTools` | **Intelligence Settings → Allow Writing Tools** |
| `allowGenmoji` | **Intelligence Settings → Allow Genmoji** (not in CapaOne's Legacy Restrictions editor) |
| `allowImagePlayground` | **Intelligence Settings → Allow Image Playground** (not in CapaOne's Legacy Restrictions editor) |
| `allowImageWand` | Not available in CapaOne — neither as a DDM type nor in the Legacy **Restrictions** editor. Use a **Custom Configuration** profile. |
| `allowPersonalizedHandwritingResults` | Not available in CapaOne — neither as a DDM type nor in the Legacy **Restrictions** editor. Use a **Custom Configuration** profile. |
| `allowMailSummary`, `allowMailSmartReplies` | Not available in CapaOne — neither as a DDM type nor in the Legacy **Restrictions** editor. Use a **Custom Configuration** profile. |
| `allowSafariSummary` | Not available in CapaOne — neither as a DDM type nor in the Legacy **Restrictions** editor. Use a **Custom Configuration** profile. |
| `allowNotesTranscription`, `allowNotesTranscriptionSummary` | Not available in CapaOne — neither as a DDM type nor in the Legacy **Restrictions** editor. Use a **Custom Configuration** profile. |
| `allowAppleIntelligenceReport` | Not available in CapaOne DDM. Keep the Legacy restriction. |
| `allowVisualIntelligenceSummary` | Not available in CapaOne DDM. Keep the Legacy restriction. |
| `forceOnDeviceOnlyDictation` | Not available in CapaOne DDM. Keep the Legacy restriction. |
| `forceOnDeviceOnlyTranslation` | Not available in CapaOne DDM. Keep the Legacy restriction. |
| `allowExternalIntelligenceIntegrations` | **External Intelligence Settings → Allow External Intelligence** |
| `allowExternalIntelligenceIntegrationsSignIn` | Not available in CapaOne DDM. Keep the Legacy restriction. |
| `allowedExternalIntelligenceWorkspaceIDs` | Not available in CapaOne DDM. Keep the Legacy restriction. |
| `allowAutoCorrection` | **Keyboard Settings → Auto-Correct** |
| `allowSpellCheck` | **Keyboard Settings → Allow Spell Checking** |
| `allowPredictiveKeyboard` | **Keyboard Settings → Allow Predictive Text** |
| `allowContinuousPathKeyboard` | **Keyboard Settings → Allow Slide to Type** |
| `allowDefinitionLookup` | Not available in CapaOne DDM. Keep the Legacy restriction. |
| `allowDictation` | **Keyboard Settings → Allow Dictation** |
| `allowKeyboardShortcuts` | **Keyboard Settings → Allow Text Replacement** |

See [Apple Intelligence, Siri and External AI Controls](/capaone/mobile-manager/apple-ddm/apple-intelligence-and-siri-controls/).

## Has a DDM equivalent, but Legacy isn't deprecated

These Legacy payloads keep working. Move them to DDM when it's convenient — for example to benefit from status reporting — not because you have to.

| Legacy configuration type | DDM type in CapaOne | DDM minimum version |
|---|---|---|
| Mail → Exchange ActiveSync | **Account Exchange** | iOS 15 / macOS 13 |
| Accounts → LDAP | **Account LDAP** | iOS 15 / macOS 13 |
| Certificates → PEM Certificate, PKCS1 Certificate, Root Certificate | **Security Certificate** + **Asset Credential Certificate** | iOS 17 / macOS 14 |
| Certificates → PKCS12 Certificate, SCEP | **Security Identity** + **Asset Credential Identity / SCEP** | iOS 17 / macOS 14 |
| VPN → VPN | **Network VPN IKEv2 / IPSec / Plugin / Always On** | OS 27 |
| Web → Web Content Filter | **Web Content Filter Plugin** | OS 27 |
| User Experience → Home Screen Layout | **Home Screen Layout** (delivered as a legacy profile declaration) | iOS 15 |

## No DDM equivalent yet — stay on Legacy

Keep these as Legacy configurations. They work on a device that runs DDM.

- **Networking → Wifi**
- **Networking → Cellular**
- **Networking → Domains**
- **Networking → Network Usage Rules**
- **Restrictions** not listed above (for example camera, AirDrop, screenshots, App Store, iCloud, managed Open In)
- **App Management → Kiosk Mode**
- **VPN → App Layer VPN**
- **User Experience → Notifications** and **Wallpaper**
- **System Configuration → Lock Screen Message**
- **Custom → Custom Configuration**

## Good to know

- **Removed means silent** — a removed Legacy setting doesn't produce an error in CapaOne or on the device. Audit before the update; see [Audit devices before upgrading](/capaone/mobile-manager/apple-ddm/ios-27-and-software-update-management/#audit-devices-before-upgrading).
- **Deprecated isn't urgent, but plan for it** — the software update settings Apple deprecated in OS 26 stopped functioning one release later, in OS 27. Plan as if the OS 27 deprecations could follow the same pattern.
- **Legacy and DDM can apply the same setting at the same time** — the device merges them and enforces the strictest value. That's safe during migration, but remove the Legacy setting afterwards to avoid confusion.
- **A Legacy profile can be bridged into DDM** — Apple's legacy profile declaration can deliver a Legacy profile through DDM, and can take over a profile Legacy MDM already installed. See [How DDM Works](/capaone/mobile-manager/apple-ddm/how-ddm-works/#legacy-profiles-inside-ddm).
- **Source:** Apple's [device management schema](https://github.com/apple/device-management/tree/release) (`mdm/profiles`, `mdm/commands`, Release v27.0) and [Apple's iOS 27 enterprise release notes](https://support.apple.com/en-us/148828).
