iOS device non-compliant because native Apple apps are blocklistedSolved

Participant
Discussion
2 weeks ago Aug 03, 2026

One of our supervised iOS devices is failing Application compliance in Hexnode. In the device details, the Applications section shows multiple entries under Blocklisted Apps, and the Default iOS Compliance Policy is marked non-compliant.

Some of the apps listed are Apple apps like App Store, Health, Wallet, Podcasts, and Stocks. We already use a policy to hide these from users, so they are not visible on the device.

Should these apps stay in the blocklist and be auto-uninstalled somehow, or is there a better way to clear the compliance failure?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
2 weeks ago Aug 03, 2026
Marked SolutionPending Review

Hello @maatthew ,

For iOS devices, Application compliance fails when an app currently installed on the device matches an app configured in the blocklist. You can confirm the exact apps causing the failure from:

Manage > Devices > select the device > Applications > filter by Blocklisted Apps

For regular third-party apps, the device must no longer have those blocklisted apps installed or available according to your policy. You can either have the user remove them manually or enforce the app restriction through an iOS app blocklist policy.

However, native Apple system apps such as App Store, Health, Wallet, Podcasts, and Stocks cannot be auto-uninstalled through MDM. This is an Apple platform limitation. Hiding or restricting them can make them unavailable to users, but it does not remove them from the device inventory. If those native apps remain in the Hexnode blocklist, the device may continue to fail compliance because they are still detected as installed blocklisted apps.

Recommended approach:

  1. Go to Policies and open the active iOS policy applied to the device.
  2. Navigate to iOS > App Management > Blocklist/Allowlist.
  3. Remove native Apple system apps from the Blocklist section.
  4. Save the policy.
  5. Keep your existing restriction or visibility policy if the goal is only to hide those apps from users.
  6. Go to Manage > Devices > select the affected device.
  7. Run Actions > Scanning and Monitoring > Scan device.
  8. Also run Scan for apps to refresh the application inventory.

After the scan completes, the Application compliance status should update. If the only violations were native Apple apps, the compliance warning should clear.

Regards,
Simon Scott
Hexnode UEM

Save