Managing iOS and macOS features with custom payload profiles

You can use custom payload profiles to control Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) features on iOS and macOS devices that existing BlackBerry UEM IT policy settings or profiles do not yet manage. For example, Apple offers certain DDM features, including Intelligence settings (com.apple.configuration.intelligence.settings), Keyboard settings (com.apple.configuration.keyboard.settings), and Siri settings (com.apple.configuration.siri.settings) that are not currently controlled by a UEM IT policy setting or profile. You can define a configuration for these settings using a custom DDM payload profile and assign it to users and devices.

Custom payload profiles are intended to support only iOS and macOS features that UEM does not already offer management controls for. If an Apple feature is supported by an existing UEM policy or profile, use the UEM mechanism to manage the feature. For example, UEM offers device SR requirements profiles and software update enforcement profiles to manage various iOS and macOS software update settings; those profiles should be used instead of a custom payload profile. If UEM already provides a control for an Apple feature, use that control instead of a custom payload profile. Do not configure both a UEM control and a custom payload profile for the same feature. Either approach can cause unpredictable behavior on devices.

UEM offers two types of custom payload profiles. The profile that you use depends on the Apple configuration that you want to manage:

Profile type

Description

Custom payload profile

  • Intended for Apple MDM settings.
  • You use Apple Configurator to create an Apple configuration profile for the feature that you want to control.
  • You copy the XML payload for the feature into the custom payload profile in UEM and assign the profile to users and groups.
  • Create a dedicated custom payload profile for each Apple MDM feature that you want to control.
  • See Create a custom payload profile.

Custom DDM payload profile

  • Intended for Apple Declarative Device Management (DDM) settings.
  • You copy the JSON payload for the feature into the custom DDM payload profile in UEM and assign the profile to users and groups.
  • Create a dedicated custom DDM payload profile for each Apple DDM feature that you want to control.
  • For macOS devices, only DDM settings that use the device channel are supported. User channel settings are not currently supported.
  • See Create a custom DDM payload profile.
Note: Custom payload profiles provide a mechanism to manage certain Apple features that are not currently supported by UEM. BlackBerry cannot guarantee that features managed with custom payload profiles will behave as expected. Test and evaluate custom payload profiles thoroughly before you implement them in your organization's production environment.