Skip to content
Avanet

Plan iPhone and iPad device policies by supervision and management mode

A decision aid for choosing iOS/iPadOS device policies, not a validated rollout guide. Sophos Help describes the settings, but does not establish the suitability of every setting for every OS version and enrollment mode. No tenant, device, license, policy assignment, or rollback was tested for this article. First check the device and policy inventory, supervision status, iOS/iPadOS version, and availability indicators beside each specific setting in your own Sophos Mobile tenant. An iOS device policy configures iPhones and iPads; this does not mean all its settings require supervision or are available on every device.

Labels: Field names and actions here follow the English Sophos interface; descriptions in square brackets are selection hints to replace, not UI labels. Calculator and Convert are the English app/feature names; the explanations describe their purpose.

Before choosing settings: management mode and recovery path

Apple Device Enrollment manages the whole device; Automated Device Enrollment (ADE) is an enrollment method, not simply another name for a device policy. An iPhone or iPad enrolled through ADE is supervised; for manually prepared devices, check the actual supervision status. Apple User Enrollment for personal devices is not supervised; do not equate the separate iOS user policy with the device policies discussed here. Moving to supervision is not a harmless policy click: Apple’s manual Configurator route requires physical access and erases device data.

Choose an approved, expendable test device with a suitable OS version, a verifiable backup, and a documented restore/reactivation path. Record existing assignments, connectivity (cellular and alternative Wi-Fi), managed apps, mail/accounts, web and iCloud features, passcode, affected users, and the intended change. Neither concurrent policies nor successful delivery proves the effect on the device. For every proposed setting, read the OS/device-type note in the tenant and approve an observable positive and negative test and a recovery path; without a per-setting matrix, avoid blanket claims such as “supervised only.”

When a Password policies configuration is assigned to a device with a noncompliant passcode, Sophos says a 60-minute grace period begins. During this period, the device prompts for a passcode change every time the Home screen is opened; afterward, no apps, including internal apps, can launch until the passcode is changed. In particular, do not enable Number of failed attempts until device wipe without separate approval: exceeding the limit erases data and settings. According to Sophos, a delay starts only after the sixth failed attempt and increases with further failed attempts. If the limit is six or fewer, no preliminary delay applies. Do not test the limit by repeatedly guessing the passcode. Removing a policy does not restore erased data.

Classic device policy: select what is needed, not everything

Secure access and data against loss first

Restrictions covers app installation, Safari, iCloud, accounts, Wi-Fi, AirDrop, camera, eSIM, and separation of managed and unmanaged documents, among other settings. These distinctions are especially important when planning recovery:

  • Connectivity and unlocking: Force configured Wi-Fi networks permits only Wi-Fi networks configured through a Sophos Mobile policy and can therefore cut off connectivity. Force Wi-Fi on, by contrast, prevents Wi-Fi from being turned off; it stays on even in airplane mode. Allow account modification controls changes to accounts, while Allow password modification controls adding, changing, or removing the device passcode. Allow Touch ID and Face ID to unlock device separately controls biometric unlocking. Plan account changes, passcode changes, and biometric unlocking separately.
  • Backups: Force encrypted backups requires encrypted local backups in iTunes; Allow backup in the iCloud section, by contrast, permits device backups in iCloud. Before imposing a restriction, check which backup method is actually available and can be used for recovery. If the chosen local backup method requires USB pairing, first check Allow host pairing and the existing USB pairing requirements: when Allow host pairing is off, Sophos says the device can pair only with Macs configured for device supervision. In that case, document which approved Mac with the matching supervision identity is available, and test pairing for the backup method on the pilot device. This permission is not the same as Allow recovery mode from unpaired host, nor does it mean that every recovery method requires pairing. When Allow iCloud Keychain sync is disabled, Sophos says the keychain data remains locally on the device; turning off synchronization does not mean the data is deleted.
  • Erasure and recovery: According to Sophos, Allow recovery mode from unpaired host permits a USB-triggered factory reset without direct user interaction. Turning off Allow erase all contents and settings only removes the local erase option from the reset interface; it does not prevent every reset method. Preserve eSIM on erase retains the eSIM during Erase All Content and Settings and erasure caused by too many incorrect passcode attempts, but not during erasure through “Find My.” Clarify these differences before an approved recovery operation, rather than testing them through deliberate erasure or incorrect passcode attempts.

Do not take settings for the former My Photo Stream as evidence that streamed photos still exist today. Check the device- and version-specific indicators beside the particular setting in Restrictions; they do not establish a complete compatibility matrix. Shared iPad guest sessions and Apple Intelligence are outside the scope of this selection guide.

Passcode: composition, changes, and lock intervals

In Password policies, the rules serve different purposes. Allow simple value permits consecutive or repeated characters, such as 1111 or abcde. According to Sophos, Require alphanumeric value requires at least one letter or one number, not necessarily both. Minimum password length sets the minimum number of all characters; Minimum number of complex characters sets the minimum number of non-alphanumeric characters, such as & or !. Choose values based on your security requirements and device usability, not as supposed product defaults.

Maximum password age in days sets a change interval from 0 to 730 days; 0 means no periodic change is required. Password history determines how many previously used passcodes Sophos Mobile stores. A new passcode must not match any of those stored passcodes.

Maximum Auto-Lock (in minutes) limits the value users can choose for automatic locking after inactivity. Maximum grace period for device lock, by contrast, limits how long an already locked device can be unlocked without re-entering the passcode: None allows users to choose any interval available on the device; Immediately requires the passcode at every unlock. This unlock grace period is not the 60-minute period for a noncompliant passcode described above.

Choose apps and restrict installation methods

According to Sophos, clearing Allow app installation prevents installations and updates from the App Store, alternative app marketplaces, and Apple Configurator. Allow app installation from device UI, by contrast, only blocks App Store access on the device; alternative marketplaces and Apple Configurator remain available for installation and updates. Alternative distribution also has Allow alternative app marketplace and Allow app installation from a website. Marketplaces and website installation are available only in certain countries or regions; the website setting applies only to supervised devices. Turning off the marketplace option prevents users from installing alternative marketplaces and disables existing ones.

Even similar switches have different consequences: turning off Allow App Clips removes existing App Clips. Turning off Allow use of camera prevents FaceTime calls as well as photos and videos. Allow automatic app download concerns automatically downloaded apps purchased on other devices, not updates to apps already installed.

Under Filter type, choose the app group that matches your purpose: Forbidden apps blocks the listed apps; Allowed apps blocks all apps not listed, including system apps. Account for com.apple.webapp for Web Clips and com.apple.Sharing.AirDropUI for incoming AirDrop from iOS 18 onward, and test on the device; disabling Safari also prevents Web Clips from opening.

According to Sophos, users on some iOS devices can uninstall apps even when Allow app removal is disabled. Assignment therefore does not prove effective protection against app removal; test the actual behavior for the intended device scope on the approved test device. Sophos specifies no particular OS version, fix, or workaround for SMCIOS-897.

Control documents, contacts, and cloud access separately

Allow documents to be shared only within managed apps/accounts keeps managed documents within managed apps and accounts. If the device has a mail account managed by Sophos Mobile and managed apps, its attachments can then be opened only in managed apps. Allow documents to be shared only within unmanaged apps/accounts controls the opposite direction: when unmanaged apps are present, attachments from an unmanaged mail account stay within that area and cannot be opened in managed apps. Choose both directions according to the intended data flow.

Contacts need a separate decision: Allow managed apps to write contacts to unmanaged accounts permits writing from managed apps to unmanaged accounts; Allow unmanaged apps to read contacts from managed accounts permits unmanaged apps to read contacts from managed accounts. Turning off the rule that restricts document sharing to managed apps/accounts disables these two contact switches, and contacts from managed accounts can be shared with unmanaged apps.

Clipboard respects document sharing restrictions applies the selected document boundaries to the clipboard, for example from managed to unmanaged. If both document-sharing restrictions are off, this switch has no effect. Force AirDrop documents to be used as unmanaged documents treats AirDrop as an unmanaged destination; this is not the app allowlist for AirDrop reception described above. Allow managed apps to sync with iCloud is an additional permission for managed-app iCloud synchronization that must be checked separately.

Separate classic update restrictions from declarative settings

In Restrictions, iOS & iPadOS software update delay delays the offer of an OS update by 1 to 90 days from release; 0 offers available updates immediately. The delay does not apply to Background Security Improvements (BSI). Turn on Rapid Security Response controls whether BSI are offered; Allow removal of Rapid Security Response update controls whether BSI removal is offered. If either switch is off, the device does not offer BSI or their removal, respectively. This does not revert an already installed base OS.

For these three settings, the English Restrictions help refers to Software update settings in a declarative policy from iOS/iPadOS 27 onward. This is not a blanket prohibition on classic device policies from version 27. The guide to choosing managed iOS/iPadOS updates explains the declarative alternatives and the unresolved version conflict between the Sophos language editions; do not assume that conflict has been resolved.

Supervised devices: kiosk, filtering, and wallpaper

Kiosk/single app

According to Sophos, Single app mode applies only to supervised devices. Under Select source, choose the app list or a manual bundle ID, and select the target app under App identifier. The mode locks the device to that app and prevents switching to other apps. Assess this state on the pilot device separately from a successful task status.

Disable rotation, Disable volume buttons, and Disable ringer switch block screen rotation, volume buttons, and the ringer switch; Disable Auto-Lock, by contrast, turns off sleep after inactivity. Choose and test only the restrictions needed for the kiosk task. For accessibility, availability and user control are separate decisions: for example, Enable VoiceOver makes it available, while VoiceOver under User-editable options lets users turn it on or off. Not every available accessibility feature has such a second switch. Check both aspects for the required feature before restricting the device to one app.

According to Sophos, under known issue SMCIOS-896, changing the Single App Mode profile correctly updates only the Disable… options; all other options take effect only when the profile is first installed. Therefore, test the actual effect of every intended option change on the isolated test device. Sophos specifies no particular OS version or fix version. Removing and reinstalling the profile, as mentioned in the source, is not a blanket retry, but only a separately approved recovery change with proven MDM reachability and a tested exit path.

Test the exit path: Test only on the isolated test device with the app installed and launchable, working accessibility, MDM still reachable, and an exit path rehearsed in advance. A disabled touchscreen or sleep/wake button makes local recovery harder.

Browser filtering and wallpaper

  • Browser filtering: According to Sophos, Web content filter for Safari and other browsers applies only to supervised devices. Plugin, Blocked URLs (everything else allowed), and Allowed URLs (everything else blocked) are different models. Sophos says Safari ignores protocol, path, and subdomain in URL rules; example.com/a is not a precise path block.
    • Additional Apple filter: Both Blocked URLs and Allowed URLs offer Block adult content. If selected, Apple’s filter for unsuitable content can also block pages that the URL rules would allow. When a page is unexpectedly blocked, check this option as well as the URL rules; this does not mean it is enabled by default.
    • Plugin scope: Plugin uses a third-party filtering app. Filter browser traffic covers web pages in Safari and other browsers; Filter socket traffic covers app network traffic. If you choose this model, select the two traffic scopes separately and check them in the approved pilot. Selection alone proves neither filtering-app compatibility nor effective filtering, and does not replace the separate assignment route for individual managed apps.
    • Plugin connection: Filter name is a custom configuration name; Filter ID is the filtering app’s bundle ID, not that of the business app being filtered. Server contains the filtering service’s name, IP address, or URL. Enter Organization only if the service requires the organization name. User name, Password, and Certificate authenticate to that service; Third-party settings holds additional settings required by the provider. Confirm the endpoint, identity, certificate, and additional values with the filtering provider; do not borrow values from another service or copy secrets into the pilot record.
    • URL entry and bookmarks: In Blocked URLs, enter one URL per line. For Allowed URLs, URL holds the permitted address, Bookmark title the Safari bookmark name, and Bookmark folder its destination folder. An empty folder uses the default bookmarks folder. The bookmark fields do not change the broad Safari matching rules described above.
    • Check allowlist access: Before applying an allowlist, test access to identity providers, management, and emergency resources in particular. The separate filtering route for individual managed apps on unsupervised devices requires iOS 16 or later, or iPadOS 16.1 or later, and covers those apps’ network traffic. It is not permission to filter all browsers; these minimum versions apply to the separate app-filtering route, not to supervised browser filtering in general.

Separate app-filtering route: First check the scope of the app setting and all existing policy assignments; one app entry can affect more than the pilot device. For an unsupervised test device meeting the minimum versions above, Sophos documents Policies > iOS & iPadOS > Create > Device policy; for an existing isolated policy, choose Edit from its arrow. On Edit policy, use Add to add Web content filter, select Use web content filter for managed apps on non-supervised devices, enter confirmed filter values, and choose Apply > Save. Then open Apps > iOS & iPadOS > [test app] > [arrow] > Edit > Settings and VPN > Show. In Web content filter used by the app, select the policy; save with Apply on Edit settings and VPN, then Save on Edit iOS app. Assign the new policy only to the approved test device; update a changed existing policy with Update devices only after checking every assigned device. The app must be installed as a managed app. Alternatively, select Sophos Intercept X here, but only if Intercept X for Mobile is installed and managed by Sophos Mobile; this skips creation and assignment of this filter policy, not verification of the Intercept X filtering configuration. This alternative does not establish equivalent browser filtering. Before changing anything, record the previous app selection and policy assignment for the approved recovery path; afterward, observe allowed and blocked app traffic and MDM access. None of these actions was performed here.

  • Appearance: Wallpaper applies only to supervised devices; Apply to selects the lock screen, Home screen, or both, and Image accepts PNG/JPEG files up to 5 MB. According to Sophos, iOS crops and scales the image as needed, so its appearance can differ from the original file. In the approved pilot, check the image actually displayed on the selected screens. The Wallpaper help says users can change the wallpaper at any time. Separately, Allow wallpaper modification in Restrictions controls whether users may change it. Before assignment, check existing restrictions and this switch’s availability indicators in the tenant; in the pilot, observe whether users can change the image or are prevented from doing so as intended. The two field descriptions establish neither precedence between the settings nor permanently enforced branding.

Web Clip: check availability per setting

  • Quick access: Do not extend the supervision requirement for Wallpaper to Web Clip: Sophos Help for Web Clip does not state such a requirement. Check availability for the management mode, device, and OS version beside the specific setting in your own tenant. Set URL, Can be removed, Full screen, and Browser app. If Can be removed is off, the clip may not disappear until the policy that installed it is removed. Before the Web Clip pilot, check both fields in Restrictions: Filter type must be Allowed apps and App group must display a group name for an app allowlist to be in place. If com.apple.webapp is missing from that named group, add it there; otherwise, Web Clips are blocked. Test the browser fallback and destination URL.

Destination: According to Sophos, only a domain-only value such as www.example.com may omit the https:// prefix in URL. In all other cases, enter the full URL: https://www.example.com:8443 includes a port, while https://www.example.com/my-app includes a path. customapp://open, by contrast, is an example of a custom app scheme, not an HTTPS web address. These examples show only the accepted syntax; replace the destination, port, path, or app scheme to suit your approved purpose. The scheme alone does not prove that the intended app will launch on the device.

Browser selection: According to Sophos, Browser app offers all apps installed on the managed iPhones and iPads. This is not a list limited to suitable browsers, nor proof that the selected app is present on every target device. Device default opens the Web Clip in the default browser configured on the device. If the selected app cannot open web pages or is missing from a target device, Sophos says Safari opens instead. Before approval, check app availability on each device and observe both the intended launch and the case of a missing or unsuitable app on the approved pilot. Account for the Safari restriction and app allowlist described above rather than assuming the fallback will work.

Full screen and other pages: Full screen opens the URL as a full-screen web app. Show external pages in full-screen retains this mode when navigating from the Web Clip to other web pages; when the checkbox is cleared, the browser appears. In the approved pilot, open an approved link to another web page and observe whether full-screen or browser behavior matches the planned selection. This observation still needs to be performed; it is not device behavior demonstrated here.

Description and icon: Description describes the Web Clip. Icon accepts PNG, GIF, or JPEG up to 1 MB. The image is cropped square and scaled to the display resolution; Sophos recommends 180 × 180 pixels. Some pages may instead display the favicon defined in their HTML, depending on its configuration. Check the visible icon in the approved pilot; upload alone does not guarantee an unchanged appearance.

Network and managed apps

  • Cellular/migration: The old Access Point Name configuration determines how iPhones and iPads connect to the cellular network. It is deprecated; Sophos recommends Cellular. A Cellular configuration cannot be installed while the old APN configuration is installed. Plan APN, Authentication (PAP/CHAP), credentials, and proxy using only the carrier’s values. In both configurations, APN identifies the access point the device presents to the carrier when connecting. The older Sophos field description refers to a GPRS connection; this is not a recommendation to use GPRS. The entered APN must match one accepted by the carrier, or the connection will fail. For the proxy, Server contains the proxy server address and Port its port number. For the old APN configuration on iPhones and iPads, Sophos specifies a maximum of 64 characters for both User name for access point and Password for access point. In Cellular, these are also the fields for the access point user name and password; Sophos specifies a maximum of 64 characters for each on iOS.
    • Plan for outages: Incorrect APN values can interrupt cellular data; Sophos identifies policy removal as a way to revert changed APN settings. Secure alternative Wi-Fi and a recovery path before migrating; do not promise a disruption-free migration. Roaming/Hotspot turns voice/data roaming and Personal Hotspot on or off, but does not prevent users from changing roaming settings. According to Sophos, disabling voice roaming also disables data roaming; enabling data roaming also enables voice roaming. If the carrier does not support voice roaming, only that setting is ignored. Allow Personal Hotspot in Restrictions can prevent users on supervised devices from changing hotspot settings; this is distinct from administratively turning the hotspot on or off and does not make the entire Roaming/Hotspot configuration a supervised-only feature.
  • Managed domains: In Managed domains, Email domains lists the mail domains managed by the organization. Mail highlights messages from addresses that do not match any of these domains as external to the organization; the list does not block those messages. Web domains determines which downloaded files count as managed documents. These files can be opened only in managed apps if the Restrictions option Allow documents to be shared only within managed apps/accounts is enabled. Specifying a port limits matching to addresses with that exact port; without a port, Sophos says only HTTP port 80 and HTTPS port 443 apply. This is not a general web filter.
  • Managed app network use: Network usage rules set cellular/roaming rules for managed apps; Add exception > App group overrides the general rule, with at most one exception per app group. This is not a device-wide roaming switch. Under Rules for all managed apps, Allow cellular data permits cellular data and Allow data roaming permits data on a foreign cellular network. The same two fields in an exception apply to all managed apps in the selected App group. Record the general rule and exception separately, and test both an affected managed app and one outside the exception in the pilot.

Check accounts and services separately

  • Exchange account in Apple Mail: Email account adds an account for Exchange Online or Exchange Server. Account name names the account. Before using placeholders, check Exchange Login and Email Address in Sophos Fusion under My Environment > Users & Groups > Users > [user name]. If the account details are editable, select Edit in the left-hand account pane, enter the required values, and select Save. According to Sophos, these account details cannot be changed in Fusion for users imported from Active Directory; confirm the required values before using the placeholders rather than assuming they can be edited locally. Do not extend this restriction to every account imported from Microsoft Entra ID. The user assigned to the device is the one that matters: %_USERNAME_% uses that user’s Exchange Login, and %_EMAILADDRESS_% uses their email address; neither supplies a password or OAuth token.

    • Server and domain: Without OAuth, Server name contains outlook.office365.com for Exchange Online in the worldwide Microsoft 365 cloud; for other clouds, find the appropriate address in the current Microsoft cloud documentation rather than reusing this host. For Exchange Server, enter your own server URL, or the Sophos Mobile EAS proxy URL if you use that proxy. Leave Domain empty for Exchange Online; for Exchange Server, enter the domain of the user account.
    • Sign-in and account details: User is the sign-in name: for Exchange Online, usually the email address, with %_EMAILADDRESS_% taking it from the assigned user; for Exchange Server, %_USERNAME_% takes the assigned user’s Exchange Login. Email address is a separate field for the account address; %_EMAILADDRESS_% is replaced with the actual address. Password contains the account password; if it is empty, users must enter it on the device.
    • OAuth: Turn on OAuth 2.0 means users authenticate with their Microsoft credentials. With OAuth, normally leave Server name empty so the Exchange host is auto-discovered. OAuth authorization endpoint handles requests for user authentication; enter it only if your authentication provider requires it. Entering a value disables mail server auto-discovery: Server name must then contain the mail server URL. OAuth token endpoint handles requests for access tokens and should likewise be entered only if the provider requires it.
    • Time period and transport: Synchronization period limits synchronization with the device inbox to emails from the selected period. Sophos recommends enabling SSL/TLS to secure the Exchange connection as supported by the server; check which TLS settings are permitted and whether the server and device support them. This does not establish a default setting or a tested connection.
    • Data flow: Allow move permits moving emails to another account and replying to or forwarding them from another account. Allow recent address syncing includes the account in iCloud synchronization of recently used addresses with other devices. Use in Mail only limits selection of this account as the sender to the Mail app; it cannot be selected as the sending account for messages created in other apps.
    • Certificates and S/MIME: Identity certificate selects the certificate for the Exchange connection from the Client certificate configurations in the same policy. Enable S/MIME allows sending and receiving S/MIME-encrypted emails; this is separate from transport TLS and the Exchange identity certificate. Signing certificate and Encryption certificate select the certificates for signing and encryption, respectively. Before selecting one, upload the required certificate in the Client certificate configuration of the current policy: under File > Upload a file, select the PKCS-#12 file (.pfx). This certificate procedure is not a general requirement for every mail account. Allow user to send unencrypted emails lets users decide whether to encrypt each outgoing email.
    • Control synchronization separately: The following switches determine which Outlook data synchronizes with which Apple app. Each separate change permission lets users turn that specific synchronization on or off; do not equate synchronization with permission to change it.
      Synchronization switchDestination and dataSeparate user permission
      Synchronize calendarCalendar app: events, appointments, and meetingsUser can change calendar synchronization
      Synchronize contactsContacts app: Outlook contactsUser can change contacts synchronization
      Synchronize mailMail app: Outlook emailUser can change mail synchronization
      Synchronize notesNotes app: Outlook notesUser can change notes synchronization
      Synchronize tasksReminders app: Outlook tasks, not MDM tasksUser can change tasks synchronization
  • IMAP/POP: Plan incoming and outgoing servers and authentication separately. Assess Allow move, Allow recent address syncing, and Use in Mail only as distinct data-flow decisions.

    • Account details and placeholders: Account name is the display name of the mail account on the device. Account type selects IMAP or POP for incoming email. User display name is the sender display name for outgoing email; according to the IMAP/POP help, %_USERNAME_% here refers to the name of the user assigned to the device. Do not equate this display name with the Exchange sign-in name. Email address contains the account address; with %_EMAILADDRESS_%, the server replaces the placeholder with the actual email address. Both placeholders in IMAP/POP also have the prerequisite described in the Exchange section above, including the restriction for imported Active Directory accounts and Edit > Save: check the assigned user’s Exchange Login and Email Address in Sophos Fusion, and change them only if the account details are editable.
    • Data flow and Mail Drop: The effects described above for Exchange also apply to Allow move (moving to other accounts and replying or forwarding from another account), Allow recent address syncing (iCloud synchronization of recently used addresses with other devices), and Use in Mail only (using this account as the sender only in the Mail app, not for messages created in other apps). Allow Mail Drop permits Apple Mail Drop for this account.
    • S/MIME and certificates: Enable S/MIME allows sending and receiving S/MIME-encrypted emails. The upload procedure above also applies to Signing certificate and Encryption certificate: before selection, upload a PKCS-#12 file (.pfx) under File > Upload a file in the Client certificate configuration of the current policy. The certificate is available to other configurations in the same policy; if needed in another policy, it must be uploaded there again. Allow user to send unencrypted emails lets users decide whether to encrypt each outgoing email. S/MIME remains optional and separate from transport TLS; do not extend the Exchange Identity certificate field to IMAP/POP.
    • Incoming email: Server contains the incoming mail server’s host name or IP address, and Port its port number. User name is the sign-in name for that server, and Authentication type is the authentication method. Password contains the password for the connection, if required. According to Sophos, SSL/TLS secures the connection with SSL or TLS, depending on server support; before deployment, check which TLS settings are permitted and whether the server and device support them.
    • Outgoing email: Server separately contains the outgoing mail server’s host name or IP address, and Port its port number. User name and Authentication type specify the sign-in name and authentication method for that server; Password contains its connection password, if required. Use same password as for incoming email uses the password specified for incoming email. According to Sophos, SSL/TLS also secures this connection with SSL or TLS as supported by the server; check permitted TLS settings and actual server/device compatibility separately. These field descriptions establish neither default ports or authentication methods nor a tested connection.
  • Google account: Google account adds a Google account to the Mail app. When it is assigned, the user must enter their Google credentials; do not claim silent sign-in. Google email address contains the full address of the Google account. Account description is optional and appears in Mail and the device’s Settings app. User name here is the user’s name used as the sender name for outgoing emails, not a password or a guarantee of sign-in.

  • Calendars and contacts: CalDAV configures calendar data synchronization with a CalDAV server; CardDAV configures contact data synchronization with a CardDAV server. Both require suitable server-side URLs, ports, authentication, and TLS—sample principal URLs are not evidence of a currently working login.

    • Distinguish CardDAV fields: Account name is the display name of the CardDAV account on the device, not the login user name. Server contains the CardDAV server’s host name or IP address, and Port its port number. Principal URL separately identifies the contacts resource and should be entered only if the CardDAV server requires it. User name and Password are the CardDAV account’s login credentials. Sophos recommends selecting the SSL/TLS checkbox to secure the connection as supported by the server; check which TLS settings are permitted and whether the server and device support them.
    • Distinguish CalDAV fields: Account name is the display name on the device, not the login user name; User name and Password are the login credentials. Server contains the host name or IP address of the CalDAV server. The separate Principal URL identifies the calendar resource and should be entered only if the CalDAV server requires it. Sophos recommends selecting the SSL/TLS checkbox to secure the connection as supported by the server; before deployment, check which TLS settings are permitted and whether the server and device support them. Port separately contains the CalDAV server’s port number.

AirPrint: printers, permission, and trust

AirPrint adds printers with an IP address and resource path to the user’s AirPrint printer list. Sophos gives printers/<printer model> and ipp/print as examples of Resource path. These are printer-specific examples, not defaults: find the actual resource path for the intended printer; in the first example, <printer model> stands for that printer’s model. Before approval, check on the pilot device that the configured printer is reachable and a test print succeeds. Port is the port on which the printer accepts connections. The optional Force TLS setting secures AirPrint connections with TLS. Separately, Allow AirPrint in Restrictions permits printing at all. Allow iBeacon discovery of AirPrint printers enables printer discovery through iBeacon; Sophos warns of phishing attacks on network traffic by malicious AirPrint devices. Permit only the discovery methods you need. Force trusted certificates for AirPrint over TLS rejects connections when the printer certificate is untrusted. Force TLS alone therefore does not establish trust in the printer.

Kerberos SSO: identity and scope

Single sign-on configures Kerberos SSO for third-party apps and, according to Sophos, applies only through iOS/iPadOS 26 inclusive, not as a procedure for 27+. Name is the human-readable label for the SSO account, not the Kerberos sign-in name or realm. Kerberos principal name contains the Kerberos sign-in name; if left empty, the user must enter it. Realm identifies the Kerberos realm and must be entered in uppercase. Take both values from your own Kerberos environment, not from an example.

URLs contains prefixes whose matches cause this account to be used for Kerberos authentication over HTTP. An entry must start with http:// or https://; Sophos Mobile adds a trailing / if it is missing. A single asterisk * is allowed as a wildcard and, according to Sophos, represents any value at that position. For example, the prefix https://*.example.org/ matches both https://www.example.org/ and https://m.example.org/. Replace the example domain with your own approved domain; if only one specific host needs SSO, use its prefix without an asterisk. The example does not establish additional rules for the bare domain without a subdomain, the depth of nested subdomains, or arbitrary path wildcards. This syntax is not a recommendation to use unencrypted HTTP and must not be equated with the browser filter’s matching rules. App IDs selects apps by their bundle IDs: either an exact match or a prefix ending in .*. Plan URL and app scope separately, keeping each as narrow as the sign-in purpose requires.

Declarative policy: Math settings

Do not confuse this with OS updates: According to the English Sophos Help assigned in the source plan, the standalone Math settings configuration in an iOS/iPadOS declarative policy is available only on supervised iPhones/iPads running iOS/iPadOS 26 or later. The German Sophos Help page, however, says 18 or later. This version conflict is unresolved: do not use the lower threshold as authorization or roll out the feature without checking the actual version and tenant availability indicator. Under Calculator are Show square root button (square root instead of plus/minus in basic view; when off, available only in the scientific calculator), Allow unit conversion (allows “Convert” in the Calculator app, for example for lengths, weights, and currencies), Allow Math Notes mode, and Allow scientific mode. Under System are Show math solutions in keyboard suggestions and Allow Math Notes in other apps (for example, Notes). Check each option separately against the teaching/use objective and its actual effect on the device; a policy overview alone proves neither assignment nor effect. Math settings does not change an OS update strategy. The brief reference in the separate update article distinguishes the topics; it does not cover these six controls.

For network and certificate recovery independent of the changed policy, use the Apple connectivity planning guide; APN and Cellular fields remain explained in this article.

Verify the pilot and roll back changes

iPadOS boundary: The type overview names iOS/iPadOS together, whereas the direct instructions for Schedule task, Update devices, and Uninstall name only iOS device policies. Whether that term includes iPadOS remains unclear in the documentation. Do not transfer these click paths to iPadOS without checking; confirm the actual route in your tenant and pilot. The policy-assignment guide explains assignment scope, device inspection, and type-specific rollback.

Sophos documents Policies > [device platform] > Create > [policy type]; on Edit policy, enter a name, description, and—for iOS/iPadOS—the organization name, then Add configuration > [configuration] > Save. In the approved tenant, select only the options actually shown for iOS device policy or iOS declarative policy. Sophos describes assigning a classic policy under Policies > [platform] > [blue policy triangle] > Assign > [individual test device] > Schedule task > Finish. On Schedule task, select Now or an approved time (Date) for iOS device policies; Sophos says this page does not appear for declarative policies. Do not select a device group when only a single-device pilot is approved. Alternatively, Sophos shows the Status (management status), Device properties (OS version), Policies (assignments), and Declarative policy (declarative assignment with Assign) tabs under Devices > [device]. Then document policy identity, task status, actual function, and unexpected side effects separately. These paths come from official Help, not a verified interface in this tenant.

Prepare rollback before assignment: Use a dedicated pilot policy assigned only to the approved test device. Before any change or rollback, identify every assigned device, document the scope, and obtain approval: editing a shared policy may also affect other devices. For visible iOS device policies, Sophos documents Devices > [device] > Policies > Uninstall. However, iOS device policies containing only Roaming/Hotspot and/or Wallpaper do not appear on that tab; an absent entry therefore does not prove the policy is unassigned. Sophos also documents Uninstall policy as a task bundle and policy-wide Unassign under Policies > [platform] > [policy menu]—the latter affects all assigned devices and is not an isolated pilot rollback.

A policy change is not an isolated rollback: After changing a classic iOS device policy, Sophos requires Policies > [platform] > [blue policy triangle] > Update devices; that task covers every device assigned to the policy. Other policy types synchronize automatically the next time they connect to Sophos Mobile. According to Sophos, a declarative policy has no single-device “Uninstall” path equivalent to a classic iOS device policy: the alternatives it names are updating the policy or assigning a different one. Changes to a shared policy can likewise affect more devices at their next synchronization. Check assignment scope and approval beforehand; afterward, observe the effective settings and access on the pilot device rather than inferring successful rollback from assignment or task status.

Removing the assignment does not automatically restore erased data, lost connectivity, or lockouts that have already occurred. If results differ from expectations, stop the pilot, identify affected devices and users, use the previously approved alternative access path, and proceed only after observing the device functioning again. Release still requires a documented per-setting supervision/OS/enrollment matrix, tests of the actual tenant UI and license, authorized positive/negative tests, safe policy removal, and proven recovery from a backup. The macOS policy overview concerns Macs and their own device/user-policy coexistence; it is not evidence for iOS supervision requirements.