# How to Setup Business Container for iOS Devices

The **Hexnode Business Container** for iOS separates corporate data from personal content by controlling how managed and unmanaged apps exchange documents, clipboard content, contacts, and AirDrop files. IT administrators use this Hexnode UEM policy to reduce data leakage on Device Enrolled and User Enrolled iOS devices while preserving user privacy on BYOD or corporate-owned devices. After deployment, managed corporate apps follow the configured data flow restrictions, and personal apps remain outside the managed container unless a setting explicitly permits interaction.

Managed apps are apps installed through the Hexnode UEM console. Unmanaged apps are apps installed directly by the user, such as apps downloaded from the App Store outside Hexnode UEM management.

What is the Hexnode Business Container for iOS?
-----------------------------------------------

The **Hexnode Business Container** for iOS is a policy-based security framework that limits the flow of corporate documents and information between managed and unmanaged apps. The container does not create a separate user space on the device. Instead, Hexnode UEM uses iOS management controls to define whether work data can move into personal apps and whether personal data can be opened inside managed work apps.

When configured, sensitive corporate data remains within managed apps unless the policy permits a specific type of data exchange. This model supports BYOD deployments because personal apps, photos, messages, and other unmanaged user data remain outside Hexnode UEM control.

Configure the Hexnode Business Container Policy for iOS
-------------------------------------------------------

Use the following workflow in the Hexnode UEM portal to set up Business Container restrictions for iOS devices:

1. Navigate to the **Policies** tab.
2. Click **New Policy** or select an existing policy.
3. Go to **iOS** > **Hexnode Business Container** > **Business Container**.
4. Configure the required data flow restrictions for documents, clipboard content, contacts, and AirDrop sharing.

Available Data Flow Configurations for iOS Business Container
-------------------------------------------------------------

[![Create business container policy for iOS devices.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/12/Set-up-Business-Container-on-iOS-devices-via-Hexnode-UEM.png "Set up Business Container on iOS devices via Hexnode UEM")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/12/Set-up-Business-Container-on-iOS-devices-via-Hexnode-UEM.png)

This table lists the Hexnode Business Container settings for iOS, explains what each setting controls, and shows the default state for document sharing, clipboard restrictions, contact access, and AirDrop sharing.

Hexnode Business Container data flow settings for iOS

SettingTechnical DescriptionDefault State**Open documents from managed apps in unmanaged apps**Controls whether files from work apps can be shared with personal apps. If unchecked, corporate data is confined to managed apps.Allowed**Open documents from unmanaged apps in managed apps**Controls whether personal files can be imported into managed work applications.Allowed**Manage Copy/Paste between managed/unmanaged apps**Restricts clipboard functionality across the managed and unmanaged app boundary. **Note:** This option requires at least one document-opening setting to be restricted.Disabled**Managed apps can write to Unmanaged Contact Accounts (iOS 12+)**Allows work applications to save contacts to the user’s personal contact list.Disabled**Unmanaged apps can read from Managed Contact Accounts (iOS 12+)**Allows personal apps, such as WhatsApp, to view contacts stored within the managed work container.Disabled**Block Sharing Managed Document using AirDrop**Disables AirDrop sharing for files that originate from a managed corporate application.DisabledDeploy the Business Container Policy to iOS Devices
---------------------------------------------------

After configuring the Business Container settings, navigate to Policy Targets and associate the policy with the required iOS devices or user groups. Click Save to deploy the restrictions to the selected targets.

Key Considerations for iOS Business Container Implementation
------------------------------------------------------------

#### Managed and unmanaged app definitions

- **Managed Apps:** Applications installed through the Hexnode UEM console.
- **Unmanaged Apps:** Applications installed directly from the App Store by the user.

#### Copy/Paste restriction enrollment support

The **Manage Copy/Paste between managed/unmanaged apps** restriction is supported on the following enrollment types:

- **Device Enrolled** devices.
- **User Enrolled (BYOD)** devices.

Troubleshoot Hexnode Business Container for iOS
-----------------------------------------------

1. **Copy/Paste setting is greyed out** If the **Manage Copy/Paste between managed/unmanaged apps** option is unavailable, check the two document-opening settings in the Business Container policy. Clipboard management becomes available only when at least one data flow direction is restricted. If both **Open documents from managed apps in unmanaged apps** and **Open documents from unmanaged apps in managed apps** are allowed, the Copy/Paste restriction cannot engage.
2. **AirDrop still works for managed documents** If users can still share managed documents through AirDrop, confirm that **Block Sharing Managed Document using AirDrop** is enabled in the policy. This setting is visible and active only when the policy initially allows managed documents to be opened in unmanaged apps.