Editor's note, October 2026: This article was first published in September 2021 and describes iOS 15 as it was then. Apple released iOS 27 on 14 September 2026. Declarative device management, introduced here, has since become the required route for software update management: legacy MDM update commands no longer work with iOS 27. Managed Apple IDs are now called Managed Apple Accounts, and since iOS 18 User Enrollment is account-driven only. For the current state, read iOS 27 for Enterprise: What Changes for Software Updates and Device Management.
At this summer's Worldwide Developers Conference (WWDC), Apple announced several new features for iOS 15, with an emphasis on communication and on-device intelligence. This article focuses on the enterprise features, which make device management easier and more capable while improving the user experience and privacy.
To give users a clear picture of how their organization manages their device, VPN and device management information is now combined in one new view, which shows VPN profiles, managed accounts and configuration profiles.
Enforcing specific apps on supervised, company-owned devices is straightforward. On unsupervised, personally owned devices, as typically used in BYOD programs, it has not been possible so far.
With the required app feature, an organization can now specify one app that is installed without prompting the user, although the user still gives consent once during enrollment. A managed app attribute can also prevent the user from removing it.
Use cases include the agent an organization's UEM uses to configure and manage devices, or a mission-critical app every employee needs.
Controlling data exchange between apps is a crucial part of data leak prevention (DLP). Managed Open In already controlled whether data could move between managed work apps and unmanaged private apps.
The managed pasteboard extends that control to copy and paste. The paste button stays available, but if a restriction blocks pasting at a specific location, the user sees a "Paste Not Allowed" notice that names the organization enforcing the restriction. System apps such as Calendar, Notes, Mail and Files apply the new restriction natively, and third-party apps do so without any changes.
The existing Apple MDM protocol, used to manage everything from iPhone and iPad to Mac and Apple TV, is reactive: every management action is triggered by the server, for example a UEM, and takes several exchanges between server and device before it completes.
The new declarative device management protocol makes devices more autonomous and proactive. A device reacts to changes in its own state, applies management logic to work out which actions are needed and carries them out itself. For example, it can prompt the user to remove an unapproved app that made the device non-compliant, without asking the server what to do. Once compliant again, the device reports this to the server through a new status channel, as it does whenever important status changes occur, such as an OS upgrade.
Both protocols coexist, so MDM vendors can adopt the new functions gradually without interrupting existing ones. With iOS 15, declarative device management is available for User Enrollment; Apple extended it to all enrollment types with iOS 16.
User Enrollment, used in BYOD deployments on personal devices, gets a simpler onboarding flow. Users no longer download a UEM agent; they sign in with the Managed Apple ID provided by their organization, using the "Sign in to Work or School Account" option in the new VPN & Device Management section.
Shared iPad, which lets several users share an iPad with their Managed Apple IDs, is now available for business as well. Users can also start a temporary session as a guest without signing in. When they sign out, all data from that session is removed from the device, such as Safari browsing history and user settings.
New restrictions let organizations allow only temporary sessions and set a maximum time a temporary session, or any user, can stay signed in.
How iOS compares with Android Enterprise and Samsung Knox is covered in Demystifying Apple, Android Enterprise and Samsung Knox. For the Android side of 2021, see Android 12 for Enterprise.
Planning an iOS rollout or an update of your Apple device management? Our Apple Enterprise Mobility Fundamentals training covers enrollment and management in depth, and our team supports endpoint management projects end to end. Contact us with any questions.