Skip to main content

June 23, 2025

Declarative Device Management (DDM)

Declarative Device Management (DDM) is a new device management paradigm that allows devices to be autonomous and proactive in their management state. DDM is built on top of Apple’s existing MDM protocol. For more information on Declarative Device Management, see the Tech Zone article A Primer on Declarative Device Management for Apple Devices.

Requirements

  • Devices must be running macOS 13 and later.
  • Omnissa Workspace ONE UEM modern architecture.

Work with your account teams to ensure your Workspace ONE UEM environment has modern architecture implemented. For more information on Workspace ONE UEM modern architecture, see the article here.

Status Channel

Workspace ONE UEM now supports the following status items via Declarative Device Management (DDM). For eligible devices, Workspace ONE UEM will automatically receive these attributes as they change on managed macOS devices.

  • OS Version (macOS 13+)
  • Build Version (macOS 13+)
  • OS Supplemental Build Version (macOS 13+)
  • OS Supplemental Build Version Extra (macOS 13+)
  • OS Family (macOS 13+)
  • Pending Version (macOS 14+) (Available only in Omnissa Intelligence)
  • Install State (macOS 14+) (Available only in Omnissa Intelligence)
  • Install Reason (macOS 14+) (Available only in Omnissa Intelligence)
  • Failure reason (macOS 14+) (Available only in Omnissa Intelligence)

Declarations

Declarations are payloads that are installed on managed devices. Declarations can be thought of as the successor to profiles. There are four declaration subtypes: Configurations, Assets, Activations, and Management properties. Omnissa Workspace ONE UEM currently supports both Configuration and Asset declaration subtypes.

Configurations

Configurations represent policies that are applied to the device. For example, there are declarative configurations for passcode policy, email, and accounts. Many configurations require assets, so it’s important to create assets prior to configurations.

Assets

Assets represent user ancillary data needed by configurations. Assets provide information specific to an end user. For example, there are assets for defining user identity, authentication credentials, and certificates. Assets are linked to configurations any time user identity is needed. Assets have a one-to-many relationship with configurations, meaning one asset can be linked to many configurations.

The following are the available declarations that Omnissa Workspace ONE UEM supports:

Configurations

  • Passcode - It enforces simplified passcode policy for macOS devices. The policy include specification for passcode complexity, length, and reset intervals.
  • Software Update Enforcement - Define policies to ensure devices are running the minimum required macOS version.

Administrators can streamline software update compliance without relying solely on legacy MDM commands.

Assets

  • User Identity (name and email address)

Configure a Configuration Declaration

Configurations are similar to the current profile payloads used to configure email accounts, passcodes, restrictions, etc. They refer to the policies to be applied to a device. Any number of Configurations can use Assets. For example, when the user of a device changes, only the Asset needs updating, and all connected configurations will automatically update.

To create a passcode configuration:

  1. On the UEM console, navigate to Resources > Profiles & Baselines > Profiles > ADD > Add a profile > macOS.
  2. In the Apple macOS window, select Declarative.
  3. Select the Declaration Type as Assets or Configurations.
  4. Select Configuration.
  5. Select Context as Device. Click Next. A page similar to profile creation is displayed.
  6. Name the Declaration and choose Passcode from the dropdown.
  7. Enter the passcode configurations and assign it to a smart group.
  8. Click Save and Publish.

Configure an Asset Declaration

Assets help you to provide reference data for configurations such as user information, passwords, or identities for email configurations, etc.

To create a User Identity asset:

  1. On the UEM console, navigate to Resources > Profiles & Baselines > Profiles > ADD > Add a profile > macOS.
  2. In the Apple macOS window, select Declarative.
  3. Select the Declaration Type as Assets. Click Next.
  4. Select Context as Device. Click Next. A page similar to profile creation is displayed.
  5. Name the User Identity asset.
  6. Enter the user identity configurations such as name and email and click Next.
  7. Assign it to a smart group.
  8. Click Save and Publish.

Create a Google Account Configuration

You can assign Asset and Configuration to the same smart group. For example, to create a Google Account declaration:

  1. On the UEM console, navigate to Resources > Profiles & Baselines > Profiles > ADD > Add a profile > macOS.
  2. In the Apple macOS window, select Declarative.
  3. Select the Declaration Type as Configuration. Click Next.
  4. Select Context as Device. Click Next.
  5. Select Account name and User Identity Asset Reference and select the asset you have created earlier.
  6. Click Next.
  7. Assign the smart group. You can view the referenced Asset and Smart groups in the preview.
  8. Click Save and Publish.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…