You cannot turn off Apple Intelligence writing tools on an unsupervised iPhone.
Supervision denotes that the device is owned by the organisation, and it unlocks a set of restrictions that unsupervised management simply does not have. The Apple Intelligence controls are the newest and most consequential example.

- Supervised onlyWhere the strongest restrictions live
- iOS 18Where the Apple Intelligence controls start
- AutomaticDevices enrolled through ADE are supervised
- DisclosedThe user is told the device is supervised
A restriction policy that looks configured and enforces nothing.
This is an unusual kind of problem because everything appears correct from the management console. The only way to find it is to look at a device.
- Somebody writes the policy, the management platform accepts it without complaint, and the console reports it as assigned. Every signal available from the administrative side says the control is in place, and none of those signals are checking the device.
- On the device, nothing changes. The restriction is supervised only, the device is not supervised, and the setting is simply ignored. There is no error, no warning and no indication that a control the organisation believes it has does not exist.
- The gap can persist for a long time, because nobody tests a restriction that was never expected to fail. It usually surfaces during an incident or an audit, which are the two worst moments to discover that a control was decorative.
- The test takes five minutes. Pick one restriction you believe is applied, and check it on an actual device. If it is not enforced, supervision is almost always the reason, and the fix is an enrolment question rather than a policy one.
Eight things that decide whether your restrictions actually apply.
Supervision means the organisation owns it
Apple states that supervision generally denotes that the device is owned by the organisation, which provides additional control over its configuration and restrictions. It is a statement about ownership first and a technical mode second.
Some restrictions exist only under supervision
Apple is explicit that certain restrictions are available only for Apple devices that enrol in a device management service and are supervised. A policy that assumes those settings will apply to an unsupervised device will silently fail to do anything.
The Apple Intelligence controls are supervised only
Allow writing tools and Allow Image Playground from iOS 18, and Allow Safari summary, Allow Mail smart replies and Allow Apple Intelligence reports from iOS 18.4. On macOS 15.2 there is also Allow external intelligence integrations, which prevents cloud based intelligence services with Siri.
Automated Device Enrolment supervises automatically
Devices enrolled that way become supervised without any additional step, from iOS 13, iPadOS 13.1, macOS 10.14.4, tvOS 13, visionOS 3 and watchOS 10. That is the cleanest route and the reason registration at procurement matters so much.
Apple Configurator supervises, but erases
You can also supervise iPhone, iPad and Apple TV manually using Apple Configurator for Mac. The device has to be physically connected and it is erased during the process, so retrofitting supervision onto devices already in use is disruptive rather than transparent.
The user is told, in plain language
Device settings show wording of the form: this device is supervised, and the named organisation can monitor your internet traffic and locate this device. Supervision is disclosed by design, which is worth knowing before it appears on somebody screen unannounced.
App usage can be restricted to a list
Restrict app usage, available from iOS 9.3, places any apps other than Settings or Phone on an approved list or a disapproved one. For single purpose and frontline devices that is the control that actually determines what the device is for.
Availability varies by management platform
Apple notes that not all restrictions are available in all device management services, and that services can change the default state for any restriction. What your platform exposes is therefore a question to answer against your platform, not against the Apple list.
Most UAE organisations asking about supervision this year are asking about Apple Intelligence.
The generative features on Apple devices raised a governance question, and the answer sits behind supervision.
- Allow writing tools prevents Apple Intelligence writing tools, and Allow Image Playground prevents users from using Image Playground. Both are available from iOS 18 and both are supervised only, so an unsupervised estate has no way to apply them.
- From iOS 18.4 there are three more: Allow Safari summary prevents the ability to summarise content in Safari, Allow Mail smart replies prevents smart replies in Mail, and Allow Apple Intelligence reports prevents Apple Intelligence reports.
- On the Mac side, Allow external intelligence integrations from macOS 15.2 prevents the use of external, cloud based intelligence services with Siri. For organisations whose concern is corporate content reaching a third party model, that is the specific control.
- None of this is a judgement about whether these features should be off. It is that the decision should be yours to make, and without supervision it is not a decision you are able to implement at all.
Four things that stop a restriction policy being decorative.
We confirm supervision before writing policy
Certain restrictions are available only for devices that enrol in a device management service and are supervised. Establishing which devices are actually supervised, and how, is the first step, because it determines what the policy is even able to say.
We treat the Apple Intelligence decision as a governance one
Writing tools, Image Playground, Safari summaries, Mail smart replies, Apple Intelligence reports and external intelligence integrations with Siri are all controllable and all supervised only. The organisation should decide, deliberately, rather than inherit a default.
We verify on device, never in the console
Apple notes that not all restrictions are available in all device management services. A setting your platform does not expose, or a device version does not support, produces a policy that reads correctly and enforces nothing.
We are honest about the retrofit cost
Supervising an existing device through Apple Configurator requires a physical connection and erases it. Where a population is unsupervised and in daily use, the realistic plan is usually to supervise at the next refresh rather than to wipe working devices.
Three phases across roughly three to five weeks.
- 01Week 1
Establish supervision state
Which devices are supervised and which are not, and how each became so. Devices enrolled through Automated Device Enrolment are supervised automatically, and anything else needs either a re-enrolment or an erase through Apple Configurator.
- Supervised and unsupervised populations identified
- Enrolment route documented per population
- Devices requiring erase to supervise listed
- OS version distribution recorded against restriction floors
- 02Week 2
Decide the restriction policy
Which supervised only restrictions the organisation actually wants, with a reason recorded for each. The Apple Intelligence controls usually dominate this conversation, and they deserve a deliberate decision rather than a default.
- Restriction policy drafted with rationale per setting
- Apple Intelligence position decided explicitly
- App usage approach agreed for frontline devices
- Availability confirmed against your management platform
- 03Weeks 3 to 5
Apply, verify and communicate
Restrictions applied and then verified on a real device rather than in the console, because a setting that a platform does not expose or a device version does not support fails quietly. Users informed, since supervision is disclosed in device settings anyway.
- Restrictions applied and verified on device
- Version floor exceptions documented
- User communication issued about supervision
- Review cadence agreed as Apple adds restrictions
Six situations where supervision is the deciding factor.
A regulated firm restricting generative features
Where policy or regulation requires control over what content reaches an AI feature, the relevant restrictions all sit behind supervision. Allow external intelligence integrations on macOS 15.2 specifically prevents cloud based intelligence services with Siri.
A retail estate locking devices to a task
Restrict app usage places any apps other than Settings or Phone on an approved or disapproved list. For a device that exists to run one or two applications, that restriction is the difference between a work tool and a general purpose device.
A school controlling what students can reach
Supervision is the norm in education for exactly this reason, and the supervised only list is where the meaningful controls live. Devices enrolled through Automated Device Enrolment arrive supervised, which is why registration at purchase matters.
An organisation that cannot prevent hidden apps
Allow apps to be hidden, from iOS 18, prevents users from hiding apps. Where support or compliance depends on being able to see what is installed and visible on a device, that restriction is only available under supervision.
A business wanting to prevent iCloud Private Relay
From iOS 15, the restriction prevents the user from turning on iCloud Private Relay. For organisations whose network controls depend on seeing and filtering traffic, this is a common requirement and a supervised only one.
A team whose restrictions appear to do nothing
The most common support case in this area. The configuration is right, the platform accepted it, and the device ignores it, because the setting is supervised only and the device is not supervised. Diagnosing that takes minutes once you know to look.
What you can actually control, by device posture.
| Feature | Supervised, corporate owned | Enrolled but not supervised | Unmanaged |
|---|---|---|---|
Supervised only restrictions apply | Yes | No | No |
Apple Intelligence features controllable | Yes | No | No |
App usage restricted to a list | Yes | No | No |
iCloud Private Relay preventable | Yes | No | No |
Apps can be prevented from being hidden | Yes | No | No |
Configuration and app deployment | Yes | Yes | No |
Supervision disclosed to the user | Yes | Not applicable | Not applicable |
Appropriate for personally owned devices | No | Yes | Yes |
How it is achieved | ADE, or Configurator with an erase | Profile or account enrolment | Nothing |
Suitable for frontline and shared devices | Yes | Partially | No |
Supervised only restrictions and where they start.
| Restriction | From | What it does | |
|---|---|---|---|
| Allow writing tools | iOS 18 | Prevents Apple Intelligence writing tools | |
| Allow Image Playground | iOS 18 | Prevents users from using Image Playground | |
| Allow Safari summary | iOS 18.4 | Prevents summarising content in Safari | |
| Allow Mail smart replies | iOS 18.4 | Prevents smart replies in Mail | |
| Allow Apple Intelligence reports | iOS 18.4 | Prevents Apple Intelligence reports | |
| Allow external intelligence integrations | macOS 15.2 | Prevents cloud based intelligence services with Siri | |
| Allow apps to be hidden | iOS 18 | Prevents users from hiding apps | |
| iCloud Private Relay | iOS 15 | Prevents the user turning on iCloud Private Relay | |
| Allow App Clips | iOS 14 | Users cannot add App Clips, existing ones are removed | |
| Restrict app usage | iOS 9.3 | Approved or disapproved list beyond Settings and Phone |
Five steps, and the first one usually explains the problem.
- 1
Audit supervision across the estate
Which devices are supervised and by which route. Automated Device Enrolment supervises automatically from iOS 13, iPadOS 13.1, macOS 10.14.4, tvOS 13, visionOS 3 and watchOS 10, and Macs on macOS 11 or later also supervise through account-driven or profile-based enrolment.
- 2
Map required controls against the supervised list
Every control the organisation wants, checked against whether it is supervised only, which OS version it starts at, and whether your management platform exposes it. Apple is explicit that availability varies between services.
- 3
Take the Apple Intelligence decision deliberately
Writing tools and Image Playground from iOS 18, Safari summary, Mail smart replies and Apple Intelligence reports from iOS 18.4, and external intelligence integrations from macOS 15.2. A recorded reason for each position is what makes this defensible later.
- 4
Apply and verify on real devices
Each restriction confirmed as actually enforced on a device of each platform and version in scope. This step is not optional, because the failure mode is silent and looks identical to success from the management console.
- 5
Communicate and set a review cadence
Users are told about supervision, which device settings disclose anyway. And a review each major release, since Apple adds supervised restrictions regularly and the useful ones tend to be the newest ones.
What organisations ask about supervised restrictions.
Twelve questions to answer before you write the restriction policy.
Supervision
- Are corporate devices supervised?Otherwise the list does not apply.
- Were they enrolled through ADE?That supervises automatically.
- Would supervising require an erase?Configurator erases the device.
- Are new devices registered at purchase?The clean route.
Apple Intelligence
- Do we have a position on writing tools?iOS 18 and supervised only.
- What about Safari summaries and Mail replies?iOS 18.4.
- Do we want external Siri integrations off?macOS 15.2.
- Is the estate on iOS 18 or later?The floor for these controls.
Operational
- Does our platform expose these settings?Availability varies.
- Have we verified on a device?Not just in the console.
- Have users been told?Supervision is disclosed anyway.
- Who reviews new restrictions?Apple adds them each release.
Pick one restriction you believe is applied, and check it on an actual device.
That single test tells you whether your Apple restriction policy is enforced or decorative. If it is not applying, supervision is almost always the reason.
Related Services
Explore more solutions that work great with this service
Zero-Touch Deployment UAE
Sealed box to working device without IT touching it
Kiosk and Shared Devices
Signage, terminals and handsets locked to the job they do
Account-driven User Enrolment
Apple BYOD enrolment where the employee owns the device.
Apple Configurator
Bring retail-bought Apple devices under management
iPhone and iPad Management
Remove company data from a phone you do not own
Apple Device Management
Mac and iPhone fleets, encryption, patching and the September cycle
macOS Management Dubai
FileVault, admin rights, updates and the Rosetta deadline
Device Enrolment
Which path, which reset, and what you can enforce after