Category filter

iOS Device Supervision: Core Differences in Management (Supervised vs. Unsupervised)

Supervision is a critical device state for corporate-owned Apple devices. It grants the MDM solution (Hexnode UEM) extensive administrative control that is unavailable on default (unsupervised) devices or those enrolled via simpler methods like User Enrollment (BYOD).

This document outlines the key differences in security, restrictions, and remote actions based on the device’s supervision status.

Core Differences in Management Control

The primary difference lies in the level of control the organization maintains over the device and the management profile itself.

Control Aspect Unsupervised Device Supervised Device (Corporate-Owned)
MDM Profile Removal Users can manually remove the MDM profile via Settings at any time. MDM profile is non-removable by the user.
Enrollment Method Typically Profile Installation, Self-Enrollment, or User Enrollment. Must be enrolled via Automated Device Enrollment (ADE) or Apple Configurator.
Activation Lock Bypass MDM cannot manage or bypass Activation Lock. MDM can remotely clear the Activation Lock, ensuring the device remains manageable.
Restrictions Limited set of basic restrictions (e.g., passcode complexity). Unlocks an extensive set of advanced restrictions (e.g., disabling iMessage, AirDrop, etc.).

Remote Actions Comparison

The availability of Hexnode’s one-time remote actions on iOS devices vary based on its supervision status.

Listed below are the remote actions available for iOS devices in Hexnode UEM.

Category Feature Supervised Unsupervised (Device Enrollment) Unsupervised (User Enrollment)
Scanning & Monitoring Scan Device
Scan Device Location(if enabled)
Scan for Apps
Device Control Power off Device
✔ (iOS 10.3 or later)
Restart Device
✔ (iOS 10.3 or later)
Disenroll Device
Security Lock Device
Wipe Device
Clear Password
Remote Ring
✔(iOS 10.3 or later)
Enable Lost Mode
✔ (iOS 9.3 or later)
Disable Lost Mode
✔ (iOS 9.3 or later: only when lost mode is enabled)
Clear Activation Lock
✔(iOS 7.1 or later)
Updates Update OS
Note: On devices with versions prior to iOS 10.3, ADE enrollment and supervision are mandatory to execute this action. Update OS can be executed on supervised iOS devices running later versions even if they were not enrolled via ADE.
Applications Install Application
Uninstall Application
Deployments Initiate Automation
Edit Rename Device
✔ (iOS 5.0 or later)
Set Friendly Name
Edit Device Attributes
Change Owner
Change Ownership
Policies & Accounts Associate Policy
Groups & Domains Add devices to group/td>
Kiosk(only when the Kiosk policy is applied) Enable Kiosk mode
✔ (iOS 9.3 or later)
Disable Kiosk mode
✔ (iOS 9.3 or later)
Network Update eSIM (iOS 13.0 or later)
Enable Personal Hotspot
Disable Personal Hotspot
Enable Data Roaming
✔(iOS 5.0 or later)
Disable Data Roaming
✔(iOS 5.0 or later)
Others Broadcast Message
Hexnode App Logs
Delete Location History
Export Device Details
Clear media

Policies Comparison

The following policies are available to configure for iOS devices:

Category Feature Supervised Unsupervised (Device Enrollment) Unsupervised (User Enrollment)
Passcode
Hexnode Business Container Business Container
Hexnode Email
App Management Required Apps Installs silently Installs on user confirmation Installs on user confirmation
Application Blocklisting/Allowlisting (iOS 9.3+) Blocklisted apps which are already installed will be hidden. Device is marked as non-compliant if a blocklisted app is already installed on the device. Cannot blocklist apps
App Catalog
Web Clips
App Notifications
App Configurations
Network Wi-Fi
VPN (Except VPN Always On)
VPN Always On
Per- App VPN
VPN Always On
APN
Network Slicing (iOS 17+)
Network Relay (iOS 17+)
Security Extensible SSO (iOS 13+)
SCEP
Certificates
Global HTTP Proxy
Web Content Filtering
Unmarked Email Domains (Managed Domains)
Managed Web Domains (Managed Domains)
Managed Web Domains for Password Autofills on Safari (Managed Domains)
OS Updates
Accounts Email
Exchange ActiveSync
CardDav
Calendar
CalDav
Google Accounts
LDAP
Expense Management Network Usage Rules
Network Data Usage Management
Configurations Deploy Custom Configurations
Fonts
Wallpaper
AirPrint
AirPlay
Lock Screen Message
Home Screen Layout
Tracking and Fencing Location Tracking
Geofencing
Troubleshooting Hexnode app logs
Patches and Updates Software Update preferences (iOS 18+)
Customizations Hexnode App UI
Kiosk Lockdown Kiosk Mode

iOS Restrictions

The following restrictions can be configured on iOS devices.

Basic Restrictions
Category Feature Supervised Unsupervised (Device Enrollment) Unsupervised (User Enrollment)
Allow Device Functionality Camera(iOS 4+)
✔ (iOS 13+)
Facetime(iOS 4+)
✔ (iOS 13+)
Screen Capture
✔ (iOS 13.1+)
Allow Remote Screen Observation (when Screen Capture is enabled, iOS 12+)
Touch ID
Siri
✔(iOS 13.1+)
Allow Siri while device is locked
✔(iOS 13.1+)
Voice dialing
Automatic sync while roaming
Allow Application Settings Install apps
✔(iOS 13+)
iTunes Store(iOS 4+)
✔ (iOS 13+)
Force user to enter iTunes store password for each purchase
In-app purchases
Trust enterprise app
Users can modify enterprise app trust
Backup enterprise-deployed iBooks
✔(iOS 13.1+)
Sync managed app data with iCloud
✔(iOS 13.1+)
YouTube(below iOS 6)
Safari(iOS 4+)
✔(iOS 13+)
Autofill(iOS  4+)
✔(iOS 13+)
Fraud warning
✔(iOS 13.1+)
JavaScript
Block pop-ups
Accept cookies
Access Passbook when the device is locked
Add friends in Game Center(iOS 4.2.1+)
✔(iOS 13+)
Allow iCloud Settings Backup(iOS 5+)
✔(iOS 13+)
Sync documents(iOS 5+)
✔(iOS 13+)
Photo Stream
(disallowing might cause data loss)
Share photo streams
iCloud photo library
Sync enterprise book metadata across devices
Allow Security and Privacy Settings Lock screen notifications
✔(iOS 13.1+)
Today View on lock screen
✔(iOS 13.1+)
Control Center on lock screen
✔(iOS 13.1+)
Over the air PKI updates
Limit ad tracking
Send diagnostic data to Apple
✔(iOS 13.1+)
Accept untrusted TLS certificate
Force encrypted backup
✔(iOS 13.1+)
Show notification on Apple Watch if worn
Allow Explicit Content Explicit music, podcasts and iTunes U services
iBooks store erotica
Rating region
Content rating
Movies (region-based rating)
TV shows
(region-based rating)
App ratings

Advanced Restrictions

Advanced Restrictions are available only for supervised devices.

Category Feature Supported version
Allow Device Functionality AirDrop
iOS 7.0+
Apps can modify cellular data usage
iOS 7.0+
Add or remove TouchID
iOS 11.0+
iMessage
iOS 6.0+
RCS messaging
iOS 18.1+
Game Center
iOS 5.0+
Multiplayer gaming
iOS 5.0+
Install configuration profile
iOS 6.0+
Handoff
iOS 8.0+
Definition lookup
iOS 8.1.3+
Predictive keyboard
iOS 8.1.3+
Auto-correct words
iOS 8.1.3+
Suggest words on misspellings
iOS 8.1.3+
QuickPath Keyboard
iOS 13.0+
Keyboard shortcuts
iOS 9.0+
USB Drive Access in Files App
iOS 13.1+
Network Drive Access in Files App
iOS 13.1+
Pair with Apple Watch
iOS 9.0+
Modify diagnostic data submission settings
iOS 9.3.2+
Modify Bluetooth settings
iOS 10.0+
Use voice to type
iOS 10.3+
Force Wi-Fi ON
iOS 13.0+
Connect to MDM-configured Wi-Fi networks only
iOS 10.3+
Users can modify Personal Hotspot settings
iOS 12.2+
Create VPN configuration
iOS 11.0+
AirPrint
iOS 11.0+
Connect with iBeacon
iOS 11.0+
Store AirPrint credentials in Keychain
iOS 11.0+
Use trusted certificates for secured printing
iOS 11.0+
Modify cellular plan settings
iOS 11+
eSIM Modification
iOS 12.1+
Outgoing eSIM transfer
iOS 18.0+
Live Voicemail
iOS 17.2+
Force preserve eSIM on erase
iOS 17.2+
Auto dimming
iOS 17.4+
iPhone mirroring
iOS 18.0+
Call recording
iOS 18.0+
Allow App Settings Install app from App Store
iOS 13.0+
Install apps from third-party app marketplaces
iOS 17.4+
Install apps from web
iOS 17.5+
Remove apps
iOS 5.0+
Remove system apps
iOS 11.0+
iBooks Store
iOS 6.0+
Apple Music
iOS 9.3+
iTunes Radio
iOS 9.3+
News
iOS 9.0+
Podcasts
iOS 8.0+
Download all purchased apps automatically
iOS 9.0+
Lock apps
iOS 18.0+
Hide apps
iOS 18.0+
Allow App Settings Activation Lock
iOS 7.0+
Modify an account
iOS 7.0+
Erase content and settings
iOS 8.0+
Siri can access user-generated content
iOS 7.0+
Find My Friends
iOS 13.0+
Find My Device
iOS 13.0+
Modify Find My Friends
iOS 7.0+
Use profanity filter
iOS 5.0+
Show web results using Spotlight Search
iOS 8.0+
Modify Restrictions/ Screen Time
iOS 8.0+
Modify passcode
iOS 9.0+
Modify device name
iOS 9.0+
Modify wallpaper
iOS 9.0+
Users can modify default browser
iOS 18.2+
Users can turn notifications on/off
iOS 9.3+
Force Automatic Date and Time
iOS 12.0+
Autofill Passwords
iOS 12.0+
Request passwords from nearby devices
iOS 12.0+
Share passwords via AirDrop Passwords feature
iOS 12.0+
Allow USB accessories when locked
iOS 11.4.1+
Prevent pairing with non-Configurator hosts
iOS 7.0+
Shared iPad temporary session
iOS 13.4+
Allow Apple Intelligence Genmoji
iOS 18.0+
Image Playground
iOS 18.0+
Image Wand
iOS 18.0+
Personalized Handwriting Results
iOS 18.0+
Writing Tools
iOS 18.0+
Mail Summary
iOS 18.1+
ChatGPT integration
iOS 18.2+
ChatGPT user account sign-in
iOS 18.2+

Managing iOS Devices