The Apple restrictions you actually want are supervised only. Are your devices supervised?
Supervision denotes that the device is owned by the organisation, and it unlocks a set of restrictions that unsupervised management simply does not have: the Apple Intelligence controls, app allow-lists, iCloud Private Relay and more. Many Indian estates configure these settings, watch nothing happen, and blame the management platform. The real answer is almost always supervision. Remote-first from Gachibowli, Hyderabad.

- Supervised onlyWhere the strongest restrictions live
- iOS 18Where the Apple Intelligence controls start
- AutomaticADE-enrolled devices arrive supervised
- 30minManaged-client response SLA
A restriction policy that looks configured and enforces nothing.
This is an unusual kind of problem because everything appears correct from the management console. The only way to find it is to look at a device.
- Somebody writes the policy, the platform accepts it without complaint, and the console reports it assigned. Every administrative signal says the control is in place, and none of those signals check the device.
- On the device, nothing changes. The restriction is supervised only, the device is not supervised, and the setting is simply ignored. No error, no warning, no indication that a control the organisation believes it has does not exist.
- The gap persists for a long time, because nobody tests a restriction that was never expected to fail. It surfaces during an incident or an audit, which are the two worst possible moments to learn a control was decorative.
- The test takes five minutes. Pick one restriction you believe is applied and check it on an actual device. If it is not enforced, supervision is almost always the reason, and the fix is an enrolment question rather than a policy one.
Eight things that decide whether your restrictions actually apply.
Supervision reflects ownership
Apple states that supervision generally denotes that the device is owned by the organisation, which provides additional control over its configuration and restrictions. It is a statement about ownership first and a technical mode second, which is why it belongs on corporate hardware and not on employee phones.
Some restrictions exist only under supervision
Apple is explicit that certain restrictions are available only for devices that enrol in a device management service and are supervised. A policy assuming those settings will land on an unsupervised device will fail silently, with no error and no warning, which is the worst kind of gap to carry.
The Apple Intelligence controls are supervised only
Allow writing tools and Allow Image Playground from iOS 18, and Allow Safari summary, Allow Mail smart replies and Allow Apple Intelligence reports from iOS 18.4. On the Mac side, Allow external intelligence integrations from macOS 15.2 prevents cloud-based intelligence services with Siri. Without supervision, none of these are yours to decide.
Automated Device Enrollment supervises automatically
Devices enrolled through Automated Device Enrollment become supervised without any extra step, from iOS 13, iPadOS 13.1, macOS 10.14.4, tvOS 13, visionOS 3 and watchOS 10. That is the clean route, and it is why registering devices at the point of purchase matters so much.
Apple Configurator supervises, but erases
iPhone, iPad and Apple TV can be supervised manually using Apple Configurator for Mac, with the device physically connected and erased during the process. Retrofitting supervision onto devices already in daily use across Indian offices is therefore disruptive rather than transparent, and it usually gets scheduled for the next refresh instead.
The user is told, in plain language
Device settings show wording of the form: this device is supervised, and the named organisation can monitor your internet traffic and locate this device. Supervision is disclosed by design, which is worth knowing before it appears on somebody’s screen unannounced and becomes a HR conversation.
App usage can be restricted to a list
Restrict app usage, available from iOS 9.3, places any apps other than Settings or Phone on an approved or disapproved list. For frontline and single-purpose devices, delivery fleets, billing counters, survey tablets, this is the control that actually determines what the device is for.
Availability varies by management platform
Apple notes that not all restrictions are available in all device management services, and that services can change the default state for any restriction. Whether Intune, Jamf or another platform exposes a given setting is a question to answer against your platform and verify on a device, not against the Apple list alone.
Most Indian organisations asking about supervision this year are asking about Apple Intelligence.
Generative features on Apple devices raised a governance question, and the answer sits behind supervision.
- Allow writing tools prevents Apple Intelligence writing tools, and Allow Image Playground prevents Image Playground. Both arrive with iOS 18 and both are supervised only, so an unsupervised estate has no way to apply either.
- From iOS 18.4 there are three more: Allow Safari summary prevents summarising content in Safari, Allow Mail smart replies prevents smart replies in Mail, and Allow Apple Intelligence reports prevents Apple Intelligence reports.
- On the Mac, Allow external intelligence integrations from macOS 15.2 prevents the use of external, cloud-based intelligence services with Siri. For organisations whose concern under the DPDP Act is corporate or client content reaching a third-party model, that is the specific control to look at.
- None of this is a judgement about whether these features should be off. It is that the decision should be yours to make and record. Without supervision, it is not a decision you are able to implement at all.
Four things that stop a restriction policy being decorative.
We confirm supervision before writing policy
Certain restrictions are available only for devices that are enrolled in a management service and supervised. Establishing which devices are actually supervised, and by which route, is the first step, because it determines what the policy is even able to say.
We treat the Apple Intelligence decision as governance
Writing tools, Image Playground, Safari summaries, Mail smart replies, Apple Intelligence reports and external Siri integrations are all controllable and all supervised only. Under the DPDP Act, whether corporate content reaches a third-party model is a decision to make deliberately and record, not inherit as a default.
We verify on device, never in the console
Apple notes that not all restrictions are available in all device management services. A setting your platform does not expose, or an OS version does not support, produces a policy that reads correctly and enforces nothing. Every restriction we apply is checked on a real device.
Remote-first, and honest about the retrofit cost
Supervising an existing device through Apple Configurator requires a physical connection and erases it. Where a population is unsupervised and in daily use, the realistic plan is usually to supervise at the next refresh rather than wipe working devices. We deliver the whole engagement remotely from Gachibowli, Hyderabad, with a 30 minutes response SLA for managed clients.
Three phases across roughly three to five weeks.
- 01Week 1· Week 1
Establish supervision state
Which devices are supervised, which are not, and how each got there. Devices enrolled through Automated Device Enrollment are supervised automatically; anything else needs re-enrolment or an erase through Apple Configurator, and that difference shapes the whole plan.
- Supervised and unsupervised populations identified
- Enrolment route documented per population
- Devices requiring an erase to supervise listed
- OS version spread recorded against restriction floors
- 02Week 2· Week 2
Decide the restriction policy
Which supervised only restrictions the organisation actually wants, with a reason recorded for each. The Apple Intelligence controls dominate this conversation for most Indian clients right now, and they deserve a deliberate decision rather than a default.
- Restriction policy drafted with rationale per setting
- Apple Intelligence position decided explicitly
- App usage approach agreed for frontline devices
- Availability confirmed against your management platform
- 03Weeks 3-5· Weeks 3-5
Apply, verify and communicate
Restrictions applied and then verified on a real device rather than in the console, because a setting the platform does not expose or the OS version does not support fails quietly. Users informed, since supervision is disclosed in device settings anyway.
- Restrictions applied and verified on device
- Version floor exceptions documented
- User communication issued about supervision
- Review cadence agreed as Apple adds restrictions
Six situations where supervision is the deciding factor.
A regulated firm restricting generative features
Banks, NBFCs, insurers and firms bound by client confidentiality increasingly need control over what content reaches an AI feature. The relevant restrictions all sit behind supervision, and Allow external intelligence integrations on macOS 15.2 specifically prevents cloud-based intelligence services with Siri.
A retail estate locking devices to a task
Restrict app usage places any apps other than Settings or Phone on an approved or disapproved list. For a billing iPad or a store-survey device that exists to run one or two applications, that restriction is the difference between a work tool and a general-purpose device.
A school or ed-tech deployment
Supervision is the norm in education for exactly this reason: the supervised only list is where the meaningful student controls live. Devices enrolled through Automated Device Enrollment arrive supervised, which is why registration at purchase matters more than any classroom policy.
An organisation that cannot prevent hidden apps
Allow apps to be hidden, from iOS 18, prevents users from hiding apps. Where support or compliance depends on being able to see what is installed and visible on a device, that restriction is only available under supervision, and estates discover this the hard way.
A business that needs iCloud Private Relay off
From iOS 15, a supervised restriction prevents the user turning on iCloud Private Relay. For organisations whose network filtering, DLP or CERT-In logging obligations depend on seeing and attributing traffic, this is a common requirement and a supervised only one.
A team whose restrictions appear to do nothing
The most common support case in this area. The configuration is right, the platform accepted it, and the device ignores it, because the setting is supervised only and the device is not supervised. Diagnosing that takes minutes once you know to look at the device rather than the console.
What you can actually control, by device posture.
| Feature | Supervised, corporate owned | Enrolled but not supervised | Unmanaged |
|---|---|---|---|
Supervised only restrictions apply | Yes | No | No |
Apple Intelligence features controllable | Yes | No | No |
App usage restricted to a list | Yes | No | No |
iCloud Private Relay preventable | Yes | No | No |
Apps prevented from being hidden | Yes | No | No |
Configuration and app deployment | Yes | Yes | No |
Supervision disclosed to the user | Yes | Not applicable | Not applicable |
Appropriate for personally owned devices | No | Yes | Yes |
How it is achieved | ADE, or Configurator with an erase | Profile or account enrolment | Nothing |
Suitable for frontline and shared devices | Yes | Partially | No |
Supervised only restrictions and where they start.
| Restriction | From | What it does | |
|---|---|---|---|
| Allow writing tools | iOS 18 | Prevents Apple Intelligence writing tools | |
| Allow Image Playground | iOS 18 | Prevents users from using Image Playground | |
| Allow Safari summary | iOS 18.4 | Prevents summarising content in Safari | |
| Allow Mail smart replies | iOS 18.4 | Prevents smart replies in Mail | |
| Allow Apple Intelligence reports | iOS 18.4 | Prevents Apple Intelligence reports | |
| Allow external intelligence integrations | macOS 15.2 | Prevents cloud-based intelligence services with Siri | |
| Allow apps to be hidden | iOS 18 | Prevents users from hiding apps | |
| iCloud Private Relay | iOS 15 | Prevents the user turning on iCloud Private Relay | |
| Allow App Clips | iOS 14 | Users cannot add App Clips, existing ones are removed | |
| Restrict app usage | iOS 9.3 | Approved or disapproved list beyond Settings and Phone |
Five steps, and the first one usually explains the problem.
- 1
Audit supervision across the estate
Week 1
Which devices are supervised and by which route. Automated Device Enrollment supervises automatically from iOS 13, iPadOS 13.1, macOS 10.14.4, tvOS 13, visionOS 3 and watchOS 10, and Macs on macOS 11 or later also supervise through account-driven or profile-based enrolment.
- 2
Map required controls against the supervised list
Week 1-2
Every control the organisation wants, checked against whether it is supervised only, which OS version it starts at, and whether your management platform exposes it. Apple is explicit that availability varies between services, so nothing is assumed.
- 3
Take the Apple Intelligence decision deliberately
Week 2
Writing tools and Image Playground from iOS 18, Safari summary, Mail smart replies and Apple Intelligence reports from iOS 18.4, external intelligence integrations from macOS 15.2. A recorded reason for each position is what makes the policy defensible in a review later.
- 4
Apply and verify on real devices
Week 3-4
Each restriction confirmed as actually enforced on a device of each platform and version in scope. This step is not optional, because the failure mode is silent and looks identical to success from the management console.
- 5
Communicate and set a review cadence
Continuous
Users told about supervision, which device settings disclose anyway. Then a review each major release, since Apple adds supervised restrictions regularly and the useful ones tend to be the newest. Managed clients get this as part of ongoing operations with a 30 minutes response SLA.
What Indian organisations ask about supervised restrictions.
Twelve questions to answer before you write the restriction policy.
Supervision
- Are corporate devices supervised?Otherwise the supervised list does not apply.
- Were they enrolled through Automated Device Enrollment?That supervises automatically.
- Would supervising require an erase?Apple Configurator erases the device.
- Are new devices registered at purchase?The clean route for everything after.
Apple Intelligence
- Do we have a position on writing tools?iOS 18 and supervised only.
- What about Safari summaries and Mail replies?iOS 18.4.
- Do we want external Siri integrations off?macOS 15.2.
- Is the estate on iOS 18 or later?The floor for these controls.
Operational
- Does our platform expose these settings?Availability varies by service.
- Have we verified on a device?Not just in the console.
- Have users been told?Supervision is disclosed anyway.
- Who reviews new restrictions?Apple adds them each release.
The pages around this one.
Zero-touch Apple deployment
The route that supervises devices automatically, starting at the purchase order.
Learn moreAccount-driven User Enrolment
The right model for personally owned hardware, where supervision does not belong.
Learn moreiPhone and iPad management
The wider iOS and iPadOS management picture: enrolment models, BYOD and kiosk deployments.
Learn morePick one restriction you believe is applied, and check it on an actual device.
That single test tells you whether your Apple restriction policy is enforced or decorative. If it is not applying, supervision is almost always the reason, and we can tell you exactly what it would take to fix. Initial reply within 4 business hours.