We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Apple device management
  2. Supervised device restrictions
Supervised restrictions, UAE

You cannot turn off Apple Intelligence writing tools on an unsupervised iPhone.

Supervision denotes that the device is owned by the organisation, and it unlocks a set of restrictions that unsupervised management simply does not have. The Apple Intelligence controls are the newest and most consequential example.

Book a supervision reviewSee what supervision unlocks
Supervised Apple device restrictions for UAE organisations
  • Supervised onlyWhere the strongest restrictions live
  • iOS 18Where the Apple Intelligence controls start
  • AutomaticDevices enrolled through ADE are supervised
  • DisclosedThe user is told the device is supervised
The failure mode

A restriction policy that looks configured and enforces nothing.

This is an unusual kind of problem because everything appears correct from the management console. The only way to find it is to look at a device.

  • Somebody writes the policy, the management platform accepts it without complaint, and the console reports it as assigned. Every signal available from the administrative side says the control is in place, and none of those signals are checking the device.
  • On the device, nothing changes. The restriction is supervised only, the device is not supervised, and the setting is simply ignored. There is no error, no warning and no indication that a control the organisation believes it has does not exist.
  • The gap can persist for a long time, because nobody tests a restriction that was never expected to fail. It usually surfaces during an incident or an audit, which are the two worst moments to discover that a control was decorative.
  • The test takes five minutes. Pick one restriction you believe is applied, and check it on an actual device. If it is not enforced, supervision is almost always the reason, and the fix is an enrolment question rather than a policy one.
What supervision means

Eight things that decide whether your restrictions actually apply.

Organisations regularly configure a restriction, see no effect, and conclude the management platform is broken. The usual explanation is that the restriction is supervised only and the devices are not supervised.

Supervision means the organisation owns it

Apple states that supervision generally denotes that the device is owned by the organisation, which provides additional control over its configuration and restrictions. It is a statement about ownership first and a technical mode second.

Some restrictions exist only under supervision

Apple is explicit that certain restrictions are available only for Apple devices that enrol in a device management service and are supervised. A policy that assumes those settings will apply to an unsupervised device will silently fail to do anything.

The Apple Intelligence controls are supervised only

Allow writing tools and Allow Image Playground from iOS 18, and Allow Safari summary, Allow Mail smart replies and Allow Apple Intelligence reports from iOS 18.4. On macOS 15.2 there is also Allow external intelligence integrations, which prevents cloud based intelligence services with Siri.

Automated Device Enrolment supervises automatically

Devices enrolled that way become supervised without any additional step, from iOS 13, iPadOS 13.1, macOS 10.14.4, tvOS 13, visionOS 3 and watchOS 10. That is the cleanest route and the reason registration at procurement matters so much.

Apple Configurator supervises, but erases

You can also supervise iPhone, iPad and Apple TV manually using Apple Configurator for Mac. The device has to be physically connected and it is erased during the process, so retrofitting supervision onto devices already in use is disruptive rather than transparent.

The user is told, in plain language

Device settings show wording of the form: this device is supervised, and the named organisation can monitor your internet traffic and locate this device. Supervision is disclosed by design, which is worth knowing before it appears on somebody screen unannounced.

App usage can be restricted to a list

Restrict app usage, available from iOS 9.3, places any apps other than Settings or Phone on an approved list or a disapproved one. For single purpose and frontline devices that is the control that actually determines what the device is for.

Availability varies by management platform

Apple notes that not all restrictions are available in all device management services, and that services can change the default state for any restriction. What your platform exposes is therefore a question to answer against your platform, not against the Apple list.

The current question

Most UAE organisations asking about supervision this year are asking about Apple Intelligence.

The generative features on Apple devices raised a governance question, and the answer sits behind supervision.

  • Allow writing tools prevents Apple Intelligence writing tools, and Allow Image Playground prevents users from using Image Playground. Both are available from iOS 18 and both are supervised only, so an unsupervised estate has no way to apply them.
  • From iOS 18.4 there are three more: Allow Safari summary prevents the ability to summarise content in Safari, Allow Mail smart replies prevents smart replies in Mail, and Allow Apple Intelligence reports prevents Apple Intelligence reports.
  • On the Mac side, Allow external intelligence integrations from macOS 15.2 prevents the use of external, cloud based intelligence services with Siri. For organisations whose concern is corporate content reaching a third party model, that is the specific control.
  • None of this is a judgement about whether these features should be off. It is that the decision should be yours to make, and without supervision it is not a decision you are able to implement at all.
Ask us about the AI feature controls
How we approach it

Four things that stop a restriction policy being decorative.

The failure mode here is unusual: everything looks configured and nothing is enforced. Verification on a real device is the only thing that catches it.

We confirm supervision before writing policy

Certain restrictions are available only for devices that enrol in a device management service and are supervised. Establishing which devices are actually supervised, and how, is the first step, because it determines what the policy is even able to say.

We treat the Apple Intelligence decision as a governance one

Writing tools, Image Playground, Safari summaries, Mail smart replies, Apple Intelligence reports and external intelligence integrations with Siri are all controllable and all supervised only. The organisation should decide, deliberately, rather than inherit a default.

We verify on device, never in the console

Apple notes that not all restrictions are available in all device management services. A setting your platform does not expose, or a device version does not support, produces a policy that reads correctly and enforces nothing.

We are honest about the retrofit cost

Supervising an existing device through Apple Configurator requires a physical connection and erases it. Where a population is unsupervised and in daily use, the realistic plan is usually to supervise at the next refresh rather than to wipe working devices.

How an engagement runs

Three phases across roughly three to five weeks.

The length depends almost entirely on how many devices are currently unsupervised and in daily use, since supervising those through Apple Configurator erases them.
  1. 01
    Week 1

    Establish supervision state

    Which devices are supervised and which are not, and how each became so. Devices enrolled through Automated Device Enrolment are supervised automatically, and anything else needs either a re-enrolment or an erase through Apple Configurator.

    • Supervised and unsupervised populations identified
    • Enrolment route documented per population
    • Devices requiring erase to supervise listed
    • OS version distribution recorded against restriction floors
  2. 02
    Week 2

    Decide the restriction policy

    Which supervised only restrictions the organisation actually wants, with a reason recorded for each. The Apple Intelligence controls usually dominate this conversation, and they deserve a deliberate decision rather than a default.

    • Restriction policy drafted with rationale per setting
    • Apple Intelligence position decided explicitly
    • App usage approach agreed for frontline devices
    • Availability confirmed against your management platform
  3. 03
    Weeks 3 to 5

    Apply, verify and communicate

    Restrictions applied and then verified on a real device rather than in the console, because a setting that a platform does not expose or a device version does not support fails quietly. Users informed, since supervision is disclosed in device settings anyway.

    • Restrictions applied and verified on device
    • Version floor exceptions documented
    • User communication issued about supervision
    • Review cadence agreed as Apple adds restrictions
Where this matters

Six situations where supervision is the deciding factor.

Each of these is an organisation that wanted a specific control and found that the control existed but their devices could not receive it.

A regulated firm restricting generative features

Where policy or regulation requires control over what content reaches an AI feature, the relevant restrictions all sit behind supervision. Allow external intelligence integrations on macOS 15.2 specifically prevents cloud based intelligence services with Siri.

A retail estate locking devices to a task

Restrict app usage places any apps other than Settings or Phone on an approved or disapproved list. For a device that exists to run one or two applications, that restriction is the difference between a work tool and a general purpose device.

A school controlling what students can reach

Supervision is the norm in education for exactly this reason, and the supervised only list is where the meaningful controls live. Devices enrolled through Automated Device Enrolment arrive supervised, which is why registration at purchase matters.

An organisation that cannot prevent hidden apps

Allow apps to be hidden, from iOS 18, prevents users from hiding apps. Where support or compliance depends on being able to see what is installed and visible on a device, that restriction is only available under supervision.

A business wanting to prevent iCloud Private Relay

From iOS 15, the restriction prevents the user from turning on iCloud Private Relay. For organisations whose network controls depend on seeing and filtering traffic, this is a common requirement and a supervised only one.

A team whose restrictions appear to do nothing

The most common support case in this area. The configuration is right, the platform accepted it, and the device ignores it, because the setting is supervised only and the device is not supervised. Diagnosing that takes minutes once you know to look.

Three positions

What you can actually control, by device posture.

The middle column is the uncomfortable one, because it looks managed in the console while the strongest settings quietly do nothing.
Supervised only restrictions apply
Supervised, corporate ownedYes
Enrolled but not supervisedNo
UnmanagedNo
Apple Intelligence features controllable
Supervised, corporate ownedYes
Enrolled but not supervisedNo
UnmanagedNo
App usage restricted to a list
Supervised, corporate ownedYes
Enrolled but not supervisedNo
UnmanagedNo
iCloud Private Relay preventable
Supervised, corporate ownedYes
Enrolled but not supervisedNo
UnmanagedNo
Apps can be prevented from being hidden
Supervised, corporate ownedYes
Enrolled but not supervisedNo
UnmanagedNo
Configuration and app deployment
Supervised, corporate ownedYes
Enrolled but not supervisedYes
UnmanagedNo
Supervision disclosed to the user
Supervised, corporate ownedYes
Enrolled but not supervisedNot applicable
UnmanagedNot applicable
Appropriate for personally owned devices
Supervised, corporate ownedNo
Enrolled but not supervisedYes
UnmanagedYes
How it is achieved
Supervised, corporate ownedADE, or Configurator with an erase
Enrolled but not supervisedProfile or account enrolment
UnmanagedNothing
Suitable for frontline and shared devices
Supervised, corporate ownedYes
Enrolled but not supervisedPartially
UnmanagedNo
Feature
Supervised, corporate owned
Enrolled but not supervised
Unmanaged
Supervised only restrictions apply
YesNoNo
Apple Intelligence features controllable
YesNoNo
App usage restricted to a list
YesNoNo
iCloud Private Relay preventable
YesNoNo
Apps can be prevented from being hidden
YesNoNo
Configuration and app deployment
YesYesNo
Supervision disclosed to the user
YesNot applicableNot applicable
Appropriate for personally owned devices
NoYesYes
How it is achieved
ADE, or Configurator with an eraseProfile or account enrolmentNothing
Suitable for frontline and shared devices
YesPartiallyNo
A representative selection

Supervised only restrictions and where they start.

Taken from the published supervised restrictions documentation. This is a selection rather than the full list, and availability varies by management platform.
RestrictionFromWhat it does
Allow writing toolsiOS 18Prevents Apple Intelligence writing tools
Allow Image PlaygroundiOS 18Prevents users from using Image Playground
Allow Safari summaryiOS 18.4Prevents summarising content in Safari
Allow Mail smart repliesiOS 18.4Prevents smart replies in Mail
Allow Apple Intelligence reportsiOS 18.4Prevents Apple Intelligence reports
Allow external intelligence integrationsmacOS 15.2Prevents cloud based intelligence services with Siri
Allow apps to be hiddeniOS 18Prevents users from hiding apps
iCloud Private RelayiOS 15Prevents the user turning on iCloud Private Relay
Allow App ClipsiOS 14Users cannot add App Clips, existing ones are removed
Restrict app usageiOS 9.3Approved or disapproved list beyond Settings and Phone
How an engagement runs

Five steps, and the first one usually explains the problem.

Where somebody arrives saying restrictions are not applying, the supervision audit answers it in the first hour, before any policy work begins.
  1. 1

    Audit supervision across the estate

    Which devices are supervised and by which route. Automated Device Enrolment supervises automatically from iOS 13, iPadOS 13.1, macOS 10.14.4, tvOS 13, visionOS 3 and watchOS 10, and Macs on macOS 11 or later also supervise through account-driven or profile-based enrolment.

  2. 2

    Map required controls against the supervised list

    Every control the organisation wants, checked against whether it is supervised only, which OS version it starts at, and whether your management platform exposes it. Apple is explicit that availability varies between services.

  3. 3

    Take the Apple Intelligence decision deliberately

    Writing tools and Image Playground from iOS 18, Safari summary, Mail smart replies and Apple Intelligence reports from iOS 18.4, and external intelligence integrations from macOS 15.2. A recorded reason for each position is what makes this defensible later.

  4. 4

    Apply and verify on real devices

    Each restriction confirmed as actually enforced on a device of each platform and version in scope. This step is not optional, because the failure mode is silent and looks identical to success from the management console.

  5. 5

    Communicate and set a review cadence

    Users are told about supervision, which device settings disclose anyway. And a review each major release, since Apple adds supervised restrictions regularly and the useful ones tend to be the newest ones.

Straight answers

What organisations ask about supervised restrictions.

Apple states that supervision generally denotes that the device is owned by the organisation, which provides additional control over its configuration and restrictions. It is a posture that reflects ownership, and it unlocks a specific set of restrictions.

The most common reason is that it is supervised only and the device is not supervised. Apple states plainly that certain restrictions are available only for devices that enrol in a device management service and are supervised.

Automated Device Enrolment supervises automatically, from iOS 13, iPadOS 13.1, macOS 10.14.4, tvOS 13, visionOS 3 and watchOS 10. iPhone, iPad and Apple TV can also be supervised manually using Apple Configurator for Mac, and Macs on macOS 11 or later through account-driven or profile-based enrolment.

Through Apple Configurator, yes, but the device must be physically connected and it is erased during the process. For a population already in daily use that is disruptive, so supervising at the next refresh is often the more realistic plan.

Yes, on supervised devices. Allow writing tools and Allow Image Playground from iOS 18, Allow Safari summary, Allow Mail smart replies and Allow Apple Intelligence reports from iOS 18.4, and Allow external intelligence integrations from macOS 15.2.

It prevents the use of external, cloud based intelligence services with Siri, and it is available from macOS 15.2. For organisations whose concern is corporate content leaving for a third party model, that is the specific control to look at.

Yes. Device settings display wording of the form that the device is supervised and the named organisation can monitor your internet traffic and locate this device. Supervision is disclosed by design rather than hidden.

Yes, with Restrict app usage, available from iOS 9.3. Any apps other than Settings or Phone on iPhone can be placed on either an approved list or a disapproved one, which is the core control for single purpose devices.

Yes, from iOS 18, with Allow apps to be hidden, which prevents users from hiding apps. Where support or oversight depends on seeing what is present on a device, that restriction is worth applying, and it is supervised only.

From iOS 15 there is a supervised restriction that prevents the user from turning on iCloud Private Relay. Organisations whose network filtering or inspection depends on visibility of traffic commonly need this one.

They are removed. The published description is that users cannot add App Clips and any existing App Clips are removed when this restriction is applied. It is available from iOS 14 and, like the rest of this list, requires supervision.

Not necessarily. Apple states that not all restrictions are available in all device management services, and that services have the ability to change the default state for any restriction. What matters is what your platform exposes, verified on a device.

No. Supervision denotes organisational ownership of the device, so it belongs on corporate hardware. For personally owned devices the appropriate model is account-driven User Enrolment, which is designed for that ownership position.

Each major release. Apple has added meaningful supervised restrictions in recent versions, particularly around Apple Intelligence, and the useful ones are frequently the newest. A review at each release keeps the policy current rather than dated.

We scope by device population and how much of it is currently unsupervised. The free first step: pick one restriction you believe is applied and check it on an actual device. That single test tells you whether your policy is enforced or decorative.

No. Supervision provides additional control over configuration and restrictions on a device the organisation owns. The device settings disclose that the organisation can monitor internet traffic and locate the device, and that disclosure is what should be communicated rather than a broader claim.

Yes, and most estates end up mixed. Corporate hardware enrolled through Automated Device Enrolment is supervised, personally owned devices are not, and the restriction policy has to be written knowing which population each rule can actually reach.

Macs can be supervised, including through Automated Device Enrolment and, from macOS 11 or later, through account-driven or profile-based enrolment. Restriction availability differs by platform, so the Mac position should be checked separately rather than assumed from iOS.

Then do not turn it off. The point of this work is that the organisation makes the decision knowingly, with a recorded reason, rather than discovering after the fact that it never had the option because its devices were not supervised.

Re-enrolling through Automated Device Enrolment is the clean answer where the serial is registered. Apple Configurator supervises iPhone, iPad and Apple TV directly but erases the device, so for a device already in use that is a disruption to schedule rather than to spring on somebody.

Configuration persists, but new releases add new restrictions and occasionally change behaviour. That is the argument for reviewing the restriction set at each major release rather than treating the policy as something written once and left.

They can see that the device is supervised and by which organisation. Since the platform discloses that anyway, telling people in advance what has been restricted and why is usually the better position than letting them find it.

Somewhere a security reviewer can read it. A list of the restrictions applied, the reason for each and the date it was decided is far more useful in a review than a screenshot of the management console, and it survives staff changes.
Policy checklist

Twelve questions to answer before you write the restriction policy.

The first group is the one that determines whether any of the rest is achievable at all.

Supervision

  • Are corporate devices supervised?
    Otherwise the list does not apply.
  • Were they enrolled through ADE?
    That supervises automatically.
  • Would supervising require an erase?
    Configurator erases the device.
  • Are new devices registered at purchase?
    The clean route.

Apple Intelligence

  • Do we have a position on writing tools?
    iOS 18 and supervised only.
  • What about Safari summaries and Mail replies?
    iOS 18.4.
  • Do we want external Siri integrations off?
    macOS 15.2.
  • Is the estate on iOS 18 or later?
    The floor for these controls.

Operational

  • Does our platform expose these settings?
    Availability varies.
  • Have we verified on a device?
    Not just in the console.
  • Have users been told?
    Supervision is disclosed anyway.
  • Who reviews new restrictions?
    Apple adds them each release.
Related reading

The pages around this one.

Zero-touch deployment

The route that supervises devices automatically.

Learn more

Kiosk and shared devices

Locking a device to a single purpose.

Learn more

Account-driven User Enrolment

The right model for personally owned hardware.

Learn more
Next step

Pick one restriction you believe is applied, and check it on an actual device.

That single test tells you whether your Apple restriction policy is enforced or decorative. If it is not applying, supervision is almost always the reason.

Book a supervision reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Zero-Touch Deployment UAE

Sealed box to working device without IT touching it

Learn more

Kiosk and Shared Devices

Signage, terminals and handsets locked to the job they do

Learn more

Account-driven User Enrolment

Apple BYOD enrolment where the employee owns the device.

Learn more

Apple Configurator

Bring retail-bought Apple devices under management

Learn more

iPhone and iPad Management

Remove company data from a phone you do not own

Learn more

Apple Device Management

Mac and iPhone fleets, encryption, patching and the September cycle

Learn more

macOS Management Dubai

FileVault, admin rights, updates and the Rosetta deadline

Learn more

Device Enrolment

Which path, which reset, and what you can enforce after

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy