Resources
Supervised vs unsupervised iPhone and iPad: what changes
Two iPhones can enroll in the same MDM server and still behave very differently. The difference is supervision. It is a device state, separate from MDM enrollment, and it decides how much your organization can control. Getting it wrong is expensive, because a device that was not supervised at setup generally has to be erased before it can be. This article explains what supervision is, what it unlocks, what still works without it, and how to decide before you buy or deploy devices.
What supervision means
Apple describes supervision as a signal that the organization owns the device. In return, the organization gets additional control over configuration and restrictions. Supervision is not on by default: a new iPhone or iPad is unsupervised until something deliberately changes that.
It helps to think of two separate questions. First, is the device enrolled in an MDM server? Second, is it supervised? An unsupervised device can be fully enrolled and managed to a useful degree. A supervised device is enrolled and also carries the owner-level trust that unlocks the stricter controls.
How a device becomes supervised
For iPhone and iPad, Apple documents two routes. Enrolling in an MDM server by itself is not one of them.
- Automated Device Enrollment (ADE). Devices that are assigned to your organization in Apple Business Manager or Apple School Manager and enroll through ADE are supervised automatically. The requirement is iOS 13 or later on iPhone and iPadOS 13.1 or later on iPad. See when to use ADE for the decision.
- Apple Configurator for Mac. You connect the device by USB to a Mac and supervise it manually. This requires physical possession, and Apple notes that the process erases the device.
Both routes work at the same moment in a device's life: during initial setup, on a new or fully erased device, before Setup Assistant first appears. Apple's guidance is that supervision can only be turned on when a device is set up. That timing is the main reason supervision needs planning up front.
How to tell whether a device is supervised
On iPhone and iPad, open Settings. A message near the top of the main page, below the search field, states that the device is supervised and names the organization that manages it. Some organizations also show an ownership message on the Lock Screen. Apple also notes that the status text can mention that the organization may monitor internet traffic.
For fleet reporting, check what your MDM console shows about supervision state. Know it before any policy decision.
What supervision enables
Apple publishes a dedicated list of device management restrictions that apply only to supervised devices. It is long and changes with each OS release, so treat Apple's current page as the source of truth. These examples are confirmed in Apple's documentation:
- Restrictions such as turning off AirDrop and blocking App Store access.
- Controls over whether users can remove apps, including system apps, and whether they can hide or lock apps.
- Web usage filtering.
- Silent installation of managed apps. On supervised devices the app installs without a prompt, while on unsupervised devices the user is asked to approve it.
- Taking over management of an app the user already installed without any user interaction. On unsupervised devices the user must accept the management change.
- Managed Lost Mode, which locks the device and shows a message on the Lock Screen.
- Preventing the user from removing the management relationship. ADE offers a prevent-unenrollment option for supervised devices.
- Skipping selected Setup Assistant panes during ADE, so users reach the Home Screen faster.
Not every restriction is available in every MDM product, and a restriction can behave differently across OS versions. Check your product's documentation before promising a control to a security team.
What still works on unsupervised devices
Unsupervised does not mean unmanaged. An enrolled, unsupervised device can still receive configuration profiles for Wi-Fi, email, certificates, and many passcode and security settings. You can push apps, with a user prompt, and you can query inventory and send commands such as lock or erase. Many restrictions have no supervised-only requirement.
What you lose are the owner-grade controls: silent app deployment, the stricter restrictions, and the ability to make removal of management hard for the user. For a device carrying only a few work apps, that can be an acceptable tradeoff.
A restriction that is marked supervised only is ignored on a device that is not supervised. Build your policy against the least-capable device in the group, or split the group by supervision state, so a payload does not quietly fail to apply.
Trade-offs: who supervision is for
Supervision is intended for organization-owned devices. Do not supervise personal phones. It gives the organization broad control and visibility, and Apple's own user-facing documentation tells employees that a supervised device may let the organization monitor internet traffic. That is a reasonable expectation for a company laptop-style device and a poor one for a phone that also holds personal photos. See company-owned vs personal devices for the ownership side of this choice.
Employee expectations matter even on company devices. Before rollout, tell people what is restricted, what can be seen, and who to call when something is blocked. A restriction that is documented causes a ticket; one that is a surprise causes a complaint.
A simple rule: supervise by default for devices you buy, own, and assign, such as field handsets, shared devices, and kiosks. Leave supervision off where the device belongs to the employee and enrollment must stay limited.
Planning, and migrating an unsupervised device
Because supervision is set at initial setup, decide it when you buy. Have devices added to Apple Business Manager at purchase so they can go through ADE out of the box. That also keeps the path simple when a device is wiped and reissued.
If an existing device is unsupervised, there is no switch to flip. Apple states that an administrator has to completely erase it to set up supervision. The practical process looks like this:
- Inventory the fleet and identify unsupervised company-owned devices.
- Confirm ownership and, where the device qualifies, make sure it is in Apple Business Manager so it can use ADE.
- Schedule the work and tell users to back up. Erasing removes local data and apps.
- Erase the device and set it up again through ADE, or manually with Apple Configurator for Mac.
- Verify supervision in Settings, then confirm that policies applied.
The reverse is possible too. Unsupervising a device through Apple Configurator also erases it. Neither direction is a casual change.
AAMDM is in early access. Phase 1 is in development and covers workspaces, APNs connection, profile-based enrollment, inventory, remote commands, and an audit log. Apple Business Manager Automated Device Enrollment, which supervises devices, is planned for Phase 2. See the platform overview and the FAQ for current status.
Sources
- Apple Platform Deployment: About Apple device supervision
- Apple Platform Deployment: Device management restrictions for supervised Apple devices
- Apple Platform Deployment: Distribute managed apps to Apple devices
- Apple Platform Deployment: Automated Device Enrollment
AAMDM is not affiliated with Apple Inc. Apple documentation changes over time; check the linked pages for the latest details.
Related articles
Questions about your rollout?
Tell us about your devices. We will answer plainly and say what is available now.