Skip to main content

August 26, 2026

Declarative Device Management (DDM)

Declarative Device Management (DDM) is a new device management paradigm that allows devices to be autonomous and proactive in their management state. DDM is built on top of Apple’s existing MDM protocol. For more information on Declarative Device Management, see the Tech Zone article A Primer on Declarative Device Management for Apple Devices.

Requirements

  • Devices must be running iOS 17 and later.
  • Omnissa Workspace ONE UEM modern architecture must be implemented.

Work with your account teams to ensure your Workspace ONE UEM environment has modern architecture implemented. For more information on Workspace ONE UEM modern architecture, see the article here.

Status Channel

The Status Channel provides the means for collecting information from managed devices via Declarative Device Management. The Status Channel is comprised of Status Items, which represent various device attributes. Once subscribed to a Status Item, any time its value changes, a managed device will automatically report the new value to Workspace ONE UEM in near real-time.

Workspace ONE UEM automatically subscribes to all supported Status Items for any managed devices that meet the minimum iOS version requirement. The following is a list of currently supported Status Items and their minimum iOS version requirements.

  • OS Version (iOS 16+)

  • Build Version (iOS 16+)

  • OS Supplemental Build Version (iOS 16.1+)

  • OS Supplemental Build Version Extra (iOS 16.1+)

  • OS Family (iOS 16+)

  • Pending Version (iOS 17+)

    • Will be available in Omnissa Intelligence
  • Install State (iOS 17+)

    • Will be available in Omnissa Intelligence
  • Install Reason (iOS 17+)

    • Will be available in Omnissa Intelligence
  • Failure reason (iOS 17+)

    • Will be available in Omnissa Intelligence
  • Battery Health (iOS 17+)

    • Will be available in Omnissa Intelligence
  • Passcode Presence (iOS 17+)

    • Available in Omnissa Intelligence
  • Passcode Compliance (iOS 17+)

    • Available in Omnissa Intelligence
  • Model Marketing Name (iOS 17+)

    • Available in Omnissa Intelligence

Declarative Device Management (DDM) App Status Subscriptions

Workspace ONE UEM collects managed application inventory and status information through DDM Status Subscriptions starting with UEM version 2604. Previously, app installation status was collected through the native MDM’s Managed Application List (MAL) sample. This enhancement provides real-time visibility into app installations, removals, and status changes on DDM-enabled iOS devices. The UEM console UI, UEM APIs and all the downstream services such as Intelligence and Freestyle also reflect the app information received through DDM Status.

Declarations

Declarations are payloads that are installed on managed devices. Declarations can be thought of as the successor to profiles. There are four declaration subtypes: Configurations, Assets, Activations, and Management properties. Omnissa Workspace ONE UEM currently supports both Configuration and Asset declaration subtypes.

Configurations

Configurations represent policies that are applied to the device. For example, there are declarative configurations for passcode policy, email, and accounts. Many configurations require assets, so it’s important to create assets prior to configurations.

Declarative Configurations integrate with Apple’s GitHub device management developer documentation. This integration enables Workspace ONE UEM to implement and update configurations significantly faster, and in many cases, without requiring a Workspace ONE UEM console upgrade. This integration will be enabled by phased rollout for Workspace ONE UEM 2410 environments deployed on UEM modern architecture.

The following are the available declarations that Omnissa Workspace ONE UEM supports:

  • Account: CalDAV
  • Account: CardDAV
  • Account: Exchange
  • Account: Google
  • Account: LDAP
  • Account: Mail
  • Account: Subscribed Calendar
  • Math Settings
  • Passcode: Settings
  • Software Update: Enforcement: Specific
  • Software Update: Settings
  • Safari: Bookmarks

Assets

Assets represent user ancillary data needed by configurations. Assets provide information specific to an end user. For example, there are assets for defining user identity, authentication credentials, and certificates. Assets are linked to configurations any time user identity is needed. Assets have a one-to-many relationship with configurations, meaning one asset can be linked to many configurations.

The following are the available assets that Omnissa Workspace ONE UEM supports:

  • User Identity (name and email address)
  • Data

Configure a Configuration Declaration

Creating and managing Declarative Configurations is similar to creating and managing Profiles. For example, to create and deploy a Passcode Configuration:

  1. On the UEM console, navigate to Resources > Profiles & Baselines > Profiles > ADD > Add a profile > iOS.
  2. In the Apple iOS window, select Declarative.
  3. Select the Declaration Type as Assets or Configurations.
  4. Select Configuration.
  5. Select Context as Device. Click Next. A page similar to profile creator is displayed.
  6. Name the Declaration and choose the Configuration from the dropdown.
  7. Complete the displayed fields and proceed to assign the Configuration to a Smart Group.
  8. Click Save and Publish.

Configure an Asset Declaration

Like Declarative Configurations, creating and managing Assets is similar to creating and managing Profiles. For example, to create and deploy the User Identity Asset:

  1. On the UEM console, navigate to Resources > Profiles & Baselines > Profiles > ADD > Add a profile > iOS.
  2. In the Apple iOS window, select Declarative.
  3. Select the Declaration Type as Assets. Click Next.
  4. Select Context as Device. Click Next. A page similar to profile creation is displayed.
  5. Name the User Identity asset.
  6. Complete the fields for Name and Email Address. Click Next.
  7. Assign a smart group.
  8. Click Save and Publish.

Configure a Credentials – Username and Password Asset Declaration

The Credentials – Username and Password asset allows IT administrators to securely and remotely provision username and password credentials to managed devices as DDM assets. These credentials can be used by DDM configurations to silently perform authentication without requiring manual user input.

  1. Navigate to Profiles > List View > Profile> Declaration > Assets.
  2. Select Add and choose Credentials – Username & Password as the asset type.
  3. Enter the Username and password.
  4. The dependent DDM configurations that use this asset automatically have the asset dependency injected at publish time — no manual linking step is required.
  5. Review the OS version tags (iOS/iPadOS 15+) to confirm device compatibility.
  6. Save the asset.

After saving, you can perform the following actions on a Credentials – Username and Password asset:

  • Edit or delete the asset
  • Assign or unassign the asset to devices or users
  • Track deployment status
  • Deactivate or copy the asset

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…