Skip to content

DDM Status Reason Codes

A DDM configuration or asset on a device’s Configurations tab shows an error icon, and the reason contains a code such as Error.ConfigurationNotSupported or Error.AssetCannotBeDownloaded.

When a device receives DDM declarations, it validates and applies each one, and reports a status for it:

  • Valid — valid, invalid, or unknown. An invalid declaration isn’t applied.
  • Active — whether the declaration is currently in effect.
  • Reasons — when something went wrong or needs attention, one or more reason codes with a description and details.

The reason codes are defined by Apple and are the same in every MDM product. Codes that start with Error. mean the declaration didn’t apply. Codes that start with Info. are informational — the declaration may still be partly or fully in effect.

Find the code in the tables below and follow the action.

Code What it means What to do
Error.ConfigurationNotSupported The configuration type isn’t supported on this platform, enrollment type, or scope. This is the most common error. Check the type’s minimum OS version and whether it needs a Supervised device in DDM Configuration Types Reference. Update the device or assign the configuration only to devices that meet the requirements.
Error.UnknownDeclarationType The device doesn’t recognize the declaration type at all — usually because the OS is older than the version that introduced it. Same as above. The configuration usually applies once the device updates.
Error.ConfigurationCannotBeApplied The device accepted the configuration but couldn’t apply it. The details include the underlying system error. Read the error text in the details. Check for a conflicting configuration — for example, a second single-type configuration, such as two Network VPN Always On — and for values the device can’t use, such as a host name that doesn’t resolve.
Error.ConfigurationIsInvalid The configuration’s values aren’t valid for applying to this device. Open the configuration and check required fields and value ranges — for example a Minimum Length above 16 in Passcode Settings, or a deferral above 90 days.
Error.ConfigurationCannotBeDeserialized The configuration couldn’t be read. Save the configuration again in CapaOne. If the error persists, contact CapaOne support with the configuration name.
Error.UnknownPayloadKeys The configuration contains settings the device doesn’t recognize. The details list them. Usually a setting introduced in a newer OS version than the device runs. Remove the listed settings, or update the device.
Error.InvalidPayload The declaration isn’t fully loaded on the device. Usually temporary. Wait for the device to sync, or send Request → Synchronize from the device page.
Error.MissingState The device is missing internal state for the declaration. Send Request → Synchronize. If it persists, unassign and reassign the configuration.
Error.ConfigurationFailed An asset couldn’t be activated because the configuration that references it failed. Fix the configuration’s own error first. The asset follows.
Error.Unknown The device reported an error that Apple’s protocol doesn’t map to a specific code. The details include an error domain and code. Note the domain and code and contact CapaOne support.
Code What it means What to do
Error.MissingAssets A configuration references an asset that isn’t on the device. The details list the missing asset identifiers. Open the configuration and check that the …Asset Reference field points to an asset that still exists. If you deleted and recreated an asset, select the new one. See DDM Assets.
Error.AssetCannotBeDownloaded The device couldn’t download the asset’s data. Check that the device has network access and that it can reach CapaOne. For SCEP or ACME assets, check that the device can reach the certificate authority.
Error.AssetCannotBeDeserialized The asset’s data isn’t in the expected format. Check the asset’s content — for example, that an Asset Credential Certificate contains a PEM or DER certificate, and that an Asset Credential Identity contains a PKCS #12 file with the correct password.
Error.AssetCannotBeVerified The downloaded asset data couldn’t be verified. Recreate the asset. If the error persists, contact CapaOne support.

CapaOne creates activations for you, so you rarely see these. They point to a problem with how the device received its assignments.

Code What it means What to do
Error.MissingConfigurations An activation references configurations that aren’t on the device. Send Request → Synchronize. If it persists, contact CapaOne support.
Error.ActivationFailed A configuration or asset couldn’t be activated because its activation failed. Look for another error on the same device — it’s usually the root cause.
Error.PredicateFailed, Error.UnableToEvaluatePredicate, Error.UnableToParsePredicate, Error.UnableToParsePredicateWithCustomOperator The device couldn’t evaluate the condition attached to an activation. Contact CapaOne support and include the full reason text.
Code What it means What to do
Info.UnsupportedSettings The configuration applied, but some of its settings aren’t supported on this device and were ignored. The details list them. Usually expected — for example, deferrals in Software Update Settings on an Unsupervised iPhone, or macOS-only settings in App Settings on iOS. Remove the settings if you want a clean status, or ignore the message.
Info.NotReferencedByActivation A configuration is on the device but no activation uses it, so it isn’t active. Check that the configuration is assigned to a group the device is a member of.
Info.NotReferencedByConfiguration An asset is on the device but no configuration uses it. Expected if you removed the configuration that used the asset.
Info.Predicate An activation’s condition evaluated to false, so its configurations aren’t active. Expected behavior when a condition isn’t met.

If the code doesn’t explain the problem, check the configuration type’s requirements and conflicts in DDM — Unknown Configuration Error or Cannot Be Applied.

When you contact CapaOne support, include:

  • The configuration’s name and type.
  • The affected devices, their OS version, and whether they’re Supervised.
  • The full reason code, description, and details the device reported.
  • One failed declaration doesn’t block the others — every other DDM configuration on the device still applies.
  • Info. isn’t a failure — an informational reason can appear on a configuration that is fully or partly in effect.
  • Version-related errors usually clear after an update — once the device runs a supported OS version, it reprocesses the configuration without you reassigning it.
  • Status can lag behind assignment — the device reports status when it has processed the change, so a new assignment can show no status for a short time.
  • Source: Apple’s declaration status reasons in the device management schema (Release v27.0).