Profile: App Privacy Permissions

The "App Privacy Permissions" profile is a declarative configuration that lets admins pre-populate the default answer to macOS and iOS privacy consent prompts for specific apps, such as access to the camera, microphone, or location. When a configured app is first launched, the device shows its normal consent prompt to the user with the configured permission already set as the default response, helping reduce prompt fatigue and guesswork for end users.

Note: App Privacy Permissions sets the default response shown in the device's native consent prompt — it does not silently grant or deny access without the user seeing a prompt. To silently grant privacy permissions without a user-facing prompt on managed Macs, see Privacy Preferences Policy Control (PPPC) instead.

To create an App Privacy Permissions profile:

  1. Make sure the target devices are running macOS 27+ or iOS/iPadOS 27+, are supervised, and have DDM enabled.
  2. Go to Configs > Profiles and click "Create Profile".
  3. From the list, select "App Privacy Permissions".
  4. Click "Add Apps" to add one or more apps to the profile.
  5. For each app, enter the app's name, bundle identifier, and a justification explaining why the permission is needed, then configure the desired permissions.
  6. Assign the configuration to your devices/groups.

App Privacy Permissions settings explained

A single profile can contain multiple apps, each with its own permission configuration. For each app entry:

  • Name: A descriptive name for the app entry.
  • Bundle Identifier: The app's bundle identifier. Each bundle identifier can only appear once per profile.
  • Organization Justification: Text shown to the device user as part of the consent prompt, explaining why the app is requesting the permission.
  • Permissions: At least one permission must be configured per app. Available permissions:
    • Accessibility (macOS only): None or Allow.
    • Bluetooth: None or Allow.
    • Camera: None or Allow.
    • Dictation: None or Allow.
    • Local Network: None or Allow.
    • Microphone: None or Allow.
    • Location: None, WhileUsing, or Always.

      Note: The location consent prompt is only shown to the device user if Location Services is already enabled on the device.

    • Location Accuracy: None, Approximate, or Precise. This must be set if Location is set to anything other than "None".

Note: Accessibility is not supported on iOS/iPadOS and is excluded from the configuration sent to those devices.

Was this article helpful?