Device security guidance
Guidance for organisations on how to choose, configure and use devices securely.
Pages
Page 5 of 37
iOS
iOS is the operating system which powers the Apple iPhone. Whilst this guide does not apply to any specific version of iOS, it was last tested on iOS 18.3.1 in February 2025.
-
Download iOS configurations
You can download the NCSC's recommended settings for this platform from our GitHub repository. These configurations are recommended to ensure that the device is in a state that aligns with the NCSC’s Device Security Principles.
As Apple releases new features, configurations may be made available which manage or restrict additional functionality. The NCSC will not necessarily have reviewed all these new features or updated our recommended configurations, so IT admins should make their own risk assessment when managing such features.
Please note these configurations are designed for a supervised device, for maximum control of the device. Depending on your organisation’s implementation of Apple IDs, some features may already be restricted or disabled.
General recommendations
- Decide which iOS devices your organisation will use. Apple does not state how long a device will receive updates, but iOS devices typically receive software updates for around 6 years after first release. Once a device is vintage or obsolete, it no longer receives updates. At this point you should purchase newer devices.
- Devices should be configured in supervised mode by your organisation to ensure you have the most control over which policies to enforce on your devices.
- If possible, use Apple Business Manager (ABM) to supervise, enrol and provision devices using zero touch enrolment. This prevents users from un-enrolling devices, once deployed. If this is not possible, use Apple Configurator to manually supervise devices before provisioning to enable more control.
- Once placed in supervised mode, iOS devices should be managed using a Mobile Device Management (MDM) service, to enforce technical controls.
- Configure the logging and monitoring capabilities of the MDM.
- Use one of our recommended network architectures to enable remote access to enterprise services.
- If a virtual private network (VPN) is required, use the built-in IKEv2 VPN, as this provides a high-performance, always-on mode and strong cryptography.
- Third-party apps for work use ("managed apps") should be approved centrally into an enterprise app catalogue and delivered via MDM, to keep data separate from non-work apps.
- Decide how you will implement Apple IDs (managed, personal or blocked), as this will greatly impact what features can be configured.
- Antivirus and other security software are not required on iOS.
- Ensure appropriate authentication is enforced on the device - we recommend use of biometrics.
- Apple has designed lockdown mode for users who might be targeted personally by the most sophisticated digital threats. You may wish to use lockdown mode for users who face higher threat due to their role or location. Lockdown mode cannot be configured through an MDM and must be turned on using the device. Most users will not require the use of lockdown mode.
Work applications
Most organisations will want to offer their users a range of productivity and business applications so they can consume, create and collaborate remotely.
If you are using third-party apps for work, we recommend using an enterprise application catalogue of approved apps that users can choose to install at will, delivered through MDM. Apps deployed in this way will be 'managed' apps and have access to work data. Apps installed through the App Store will be 'unmanaged' and will not have access to the same data. See our third-party applications guidance for more information on this approach.
We recommend that care is taken with high-privilege applications, such as third-party keyboard apps and network extensions. These types of application might be able to access large amounts of work data, so present a higher risk to your organisation.
Device configuration
Once you have chosen your MDM service, architecture and approach to applications, you should then configure your devices following our recommended configurations. You may wish to differ from these recommendations to meet your specific business needs or enforce your desired technical controls.
In particular, you should include policies that manage:
- External interfaces, including wired and wireless peripherals (e.g. disabling USB accessories when the device is locked).
- The use of biometrics, which is the recommended method of authentication, but you may also wish to consider the passcodes, authentication policies and other credentials.
- The cloud services that you want to enable for your users
- Device OS and application updates, including automatic updates
See also
- Managing Devices and Corporate Data on iOS, Apple (PDF)
- iOS Security, Apple (PDF)
- MDM restrictions, Apple
- Guidance provided by your MDM vendor


