Supervision is the single flag that separates a corporate iPhone from a personal one, and almost every iOS control worth having lives on the far side of it. The management reality of the platform is the subject of [9.4] iOS Management Reality. This is the narrower question that decides your architecture: what supervision actually unlocks, what it pointedly does not, and why the only sane way to get it is to have owned the device from the first power-on.
Supervision is a statement of ownership
Supervision is Apple’s device state that says the organization owns this device, and on the strength of that claim it grants a management surface that a personal device never exposes. The device itself is honest about it: the Settings screen reads that the iPhone is supervised and managed by your organization. There are two ways to reach that state, and only one of them belongs in a design. Automated Device Enrollment through Apple Business Manager makes the device supervised by default the moment it enrolls, with no touch and no wipe. The other way is Apple Configurator over USB, which supervises a device by erasing it first. That distinction is the whole reason supervision is a provisioning decision and not a setting you flip later.
What supervision unlocks
The list of supervised-only capabilities is long, but it clusters into a few themes, and seeing the themes is more useful than memorizing the settings. Supervision is what lets you decide which apps exist, force the device into a single task, filter the web at the OS level, route traffic the way you require, and lock the device’s own configuration so the user cannot quietly undo your work. None of these are available on an unsupervised device, which is precisely why an unsupervised corporate iPhone is so much less than people expect.
| Capability class | Representative controls |
|---|---|
| App control | Allow and block lists, hiding or requiring specific apps, blocking the App Store outright, removing built-in apps. |
| Single-purpose lockdown | Single App Mode and Autonomous Single App Mode, the foundation of an iPad kiosk. |
| Network and content | The built-in web content filter, a global HTTP proxy, and always-on VPN, which supervision specifically requires. |
| Device lockdown | Blocking name changes, wallpaper and account edits, configuration-profile removal, and erase-all-content, plus Activation Lock management so a wiped device is not bricked to your own org. |
| Data boundary | Disabling AirDrop, restricting managed open-in and the pasteboard, and controlling per-app notifications and the home screen layout. |
The one I would call out is Activation Lock management, because it is the difference between reclaiming a departed employee’s iPad and holding a locked brick. On a supervised device you can clear the lock; on an unsupervised one you are at the mercy of whoever knows the Apple Account password.
What it still cannot do
Supervision does not reach personal devices, and this is by design rather than by omission. The enrollment methods built for personally owned iPhones, account-driven user enrollment and its device-enrollment cousin, produce unsupervised devices on purpose, because they are meant for hardware the user owns. User enrollment keeps a hard privacy boundary: the person’s own Apple Account and personal data stay outside management entirely, and management touches only the work apps and the work data. That boundary is the feature, and supervision would break it.
Which leads to the trap worth naming plainly. There is no in-place upgrade from unsupervised to supervised; the only route on a device already in someone’s hands is to wipe it and re-enroll through Automated Device Enrollment, or to erase it with Configurator. So supervising a personally owned phone means wiping the owner’s device and asserting corporate ownership of it, which defeats the entire reason it was a personal device. The correct answer for personal iOS is not supervision. It is app protection and user enrollment, and the trade-offs there are laid out in [9.4.1] iOS: MAM-Only vs Full Management.
The one road to supervision at scale
Because Configurator wipes one device at a time over a cable, it is a bench tool, not a fleet strategy. Automated Device Enrollment through Apple Business Manager is the only path that scales: buy the hardware into your ABM tenant, or have the reseller add it, and every device that ships arrives supervised and enrolls itself on first power-on. The practical instruction that follows is simple and it governs procurement, not IT: corporate iOS devices must enter the estate through ABM, because a device bought retail and handed to an employee can never be cleanly supervised without wiping it. Getting supervision right is a purchasing discipline as much as a technical one.
Where Apple is taking this
Apple’s direction makes supervision more central, not less. Declarative Device Management is now the model the platform is built around, and the pieces that matter to administrators increasingly assume a supervised device underneath. Software updates are the clearest example: Apple is retiring the old MDM commands that pushed and deferred updates, and the operating systems arriving this fall no longer honor them, which forces the entire estate onto declarative update management, and declarative updates assume supervision. Intune has been moving its Apple update policies to the declarative model for the same reason, a shift covered in [11.7] Apple Software Update Management. The takeaway for design is that the gap between a supervised device and an unsupervised one is widening, and building a corporate Apple estate on anything other than ADE supervision is planning around a door that is closing.
Intune Deployment Guide · Phase 9: Mobile and BYOD
‹ Previous: [9.4.1] iOS: MAM-Only vs Full Management – There Is No Middle Ground
Next: [9.4.3] Building iOS BYOD Onboarding: Web Device Enrollment and Account-Driven User Enrollment ›




