# DDM Status Reason Codes

> What each status reason a device reports for a DDM configuration or asset means — such as Error.ConfigurationNotSupported or Error.AssetCannotBeDownloaded — and what to do about it.

Source: https://docs.capaone.com/capaone/troubleshooting/ddm-status-reason-codes/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

## Problem

A DDM configuration or asset on a device's **Configurations** tab shows an error icon, and the reason contains a code such as `Error.ConfigurationNotSupported` or `Error.AssetCannotBeDownloaded`.

## Cause

When a device receives DDM declarations, it validates and applies each one, and reports a status for it:

- **Valid** — `valid`, `invalid`, or `unknown`. An `invalid` declaration isn't applied.
- **Active** — whether the declaration is currently in effect.
- **Reasons** — when something went wrong or needs attention, one or more reason codes with a description and details.

The reason codes are defined by Apple and are the same in every MDM product. Codes that start with `Error.` mean the declaration didn't apply. Codes that start with `Info.` are informational — the declaration may still be partly or fully in effect.

## Solution

Find the code in the tables below and follow the action.

### Configuration errors

| Code | What it means | What to do |
|---|---|---|
| `Error.ConfigurationNotSupported` | The configuration type isn't supported on this platform, enrollment type, or scope. This is the most common error. | Check the type's minimum OS version and whether it needs a Supervised device in [DDM Configuration Types Reference](/capaone/mobile-manager/apple-ddm/ddm-configuration-types-reference/). Update the device or assign the configuration only to devices that meet the requirements. |
| `Error.UnknownDeclarationType` | The device doesn't recognize the declaration type at all — usually because the OS is older than the version that introduced it. | Same as above. The configuration usually applies once the device updates. |
| `Error.ConfigurationCannotBeApplied` | The device accepted the configuration but couldn't apply it. The details include the underlying system error. | Read the error text in the details. Check for a conflicting configuration — for example, a second **single**-type configuration, such as two **Network VPN Always On** — and for values the device can't use, such as a host name that doesn't resolve. |
| `Error.ConfigurationIsInvalid` | The configuration's values aren't valid for applying to this device. | Open the configuration and check required fields and value ranges — for example a **Minimum Length** above 16 in **Passcode Settings**, or a deferral above 90 days. |
| `Error.ConfigurationCannotBeDeserialized` | The configuration couldn't be read. | Save the configuration again in CapaOne. If the error persists, contact CapaOne support with the configuration name. |
| `Error.UnknownPayloadKeys` | The configuration contains settings the device doesn't recognize. The details list them. | Usually a setting introduced in a newer OS version than the device runs. Remove the listed settings, or update the device. |
| `Error.InvalidPayload` | The declaration isn't fully loaded on the device. | Usually temporary. Wait for the device to sync, or send **Request → Synchronize** from the device page. |
| `Error.MissingState` | The device is missing internal state for the declaration. | Send **Request → Synchronize**. If it persists, unassign and reassign the configuration. |
| `Error.ConfigurationFailed` | An asset couldn't be activated because the configuration that references it failed. | Fix the configuration's own error first. The asset follows. |
| `Error.Unknown` | The device reported an error that Apple's protocol doesn't map to a specific code. The details include an error domain and code. | Note the domain and code and contact CapaOne support. |

### Asset errors

| Code | What it means | What to do |
|---|---|---|
| `Error.MissingAssets` | A configuration references an asset that isn't on the device. The details list the missing asset identifiers. | Open the configuration and check that the **…Asset Reference** field points to an asset that still exists. If you deleted and recreated an asset, select the new one. See [DDM Assets](/capaone/mobile-manager/apple-ddm/ddm-assets/). |
| `Error.AssetCannotBeDownloaded` | The device couldn't download the asset's data. | Check that the device has network access and that it can reach CapaOne. For SCEP or ACME assets, check that the device can reach the certificate authority. |
| `Error.AssetCannotBeDeserialized` | The asset's data isn't in the expected format. | Check the asset's content — for example, that an **Asset Credential Certificate** contains a PEM or DER certificate, and that an **Asset Credential Identity** contains a PKCS #12 file with the correct password. |
| `Error.AssetCannotBeVerified` | The downloaded asset data couldn't be verified. | Recreate the asset. If the error persists, contact CapaOne support. |

### Activation and predicate errors

CapaOne creates activations for you, so you rarely see these. They point to a problem with how the device received its assignments.

| Code | What it means | What to do |
|---|---|---|
| `Error.MissingConfigurations` | An activation references configurations that aren't on the device. | Send **Request → Synchronize**. If it persists, contact CapaOne support. |
| `Error.ActivationFailed` | A configuration or asset couldn't be activated because its activation failed. | Look for another error on the same device — it's usually the root cause. |
| `Error.PredicateFailed`, `Error.UnableToEvaluatePredicate`, `Error.UnableToParsePredicate`, `Error.UnableToParsePredicateWithCustomOperator` | The device couldn't evaluate the condition attached to an activation. | Contact CapaOne support and include the full reason text. |

### Informational reasons

| Code | What it means | What to do |
|---|---|---|
| `Info.UnsupportedSettings` | The configuration applied, but some of its settings aren't supported on this device and were ignored. The details list them. | Usually expected — for example, deferrals in **Software Update Settings** on an Unsupervised iPhone, or macOS-only settings in **App Settings** on iOS. Remove the settings if you want a clean status, or ignore the message. |
| `Info.NotReferencedByActivation` | A configuration is on the device but no activation uses it, so it isn't active. | Check that the configuration is assigned to a group the device is a member of. |
| `Info.NotReferencedByConfiguration` | An asset is on the device but no configuration uses it. | Expected if you removed the configuration that used the asset. |
| `Info.Predicate` | An activation's condition evaluated to false, so its configurations aren't active. | Expected behavior when a condition isn't met. |

If the code doesn't explain the problem, check the configuration type's requirements and conflicts in [DDM — Unknown Configuration Error or Cannot Be Applied](/capaone/troubleshooting/ddm-unknown-configuration-error/).

When you contact CapaOne support, include:

- The configuration's name and type.
- The affected devices, their OS version, and whether they're Supervised.
- The full reason code, description, and details the device reported.

## Good to know

- **One failed declaration doesn't block the others** — every other DDM configuration on the device still applies.
- **`Info.` isn't a failure** — an informational reason can appear on a configuration that is fully or partly in effect.
- **Version-related errors usually clear after an update** — once the device runs a supported OS version, it reprocesses the configuration without you reassigning it.
- **Status can lag behind assignment** — the device reports status when it has processed the change, so a new assignment can show no status for a short time.
- **Source:** Apple's declaration status reasons in the [device management schema](https://github.com/apple/device-management/blob/release/declarative/declarations/declarationbase.yaml) (Release v27.0).
