From 2e6673873e71a8bba2516f915710e5bd50b81859 Mon Sep 17 00:00:00 2001 From: Cyrus Daboo Date: Tue, 28 Jan 2025 14:49:18 -0500 Subject: [PATCH] Release_iOS-18-3_macOS-15-3 --- LICENSE.txt | 2 +- README.md | 10 +-- mdm/commands/information.contentcaching.yaml | 8 +- mdm/commands/settings.yaml | 4 +- mdm/commands/system.update.schedule.yaml | 1 - .../com.apple.ADCertificate.managed.yaml | 6 +- .../com.apple.DirectoryService.managed.yaml | 2 +- mdm/profiles/com.apple.MCX(EnergySaver).yaml | 6 +- mdm/profiles/com.apple.SoftwareUpdate.yaml | 12 +-- ...pple.TCC.configuration-profile-policy.yaml | 2 +- mdm/profiles/com.apple.applicationaccess.yaml | 81 ++++++++++++++++++- .../com.apple.associated-domains.yaml | 2 +- mdm/profiles/com.apple.dock.yaml | 29 ++++--- .../com.apple.extensiblesso(kerberos).yaml | 2 +- mdm/profiles/com.apple.extensiblesso.yaml | 4 +- ...om.apple.familycontrols.contentfilter.yaml | 1 - mdm/profiles/com.apple.font.yaml | 1 - mdm/profiles/com.apple.loginwindow.yaml | 2 +- mdm/profiles/com.apple.networkusagerules.yaml | 1 - .../com.apple.notificationsettings.yaml | 2 - mdm/profiles/com.apple.systemuiserver.yaml | 1 - mdm/profiles/com.apple.universalaccess.yaml | 18 ++--- mdm/profiles/com.apple.vpn.managed.yaml | 14 +++- mdm/profiles/com.apple.wifi.managed.yaml | 1 - mdm/profiles/com.apple.xsan.yaml | 3 - 25 files changed, 144 insertions(+), 71 deletions(-) diff --git a/LICENSE.txt b/LICENSE.txt index 9faab6a..b899c1a 100644 --- a/LICENSE.txt +++ b/LICENSE.txt @@ -1,4 +1,4 @@ -Copyright © 2022-2024 Apple Inc. +Copyright © 2022-2025 Apple Inc. Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the diff --git a/README.md b/README.md index 9209928..aba6b5f 100644 --- a/README.md +++ b/README.md @@ -8,11 +8,11 @@ This release corresponds to the following OS versions | OS | Version | |----------|---------| -| iOS | 18.2 | -| macOS | 15.2 | -| tvOS | 18.2 | -| visionOS | 2.2 | -| watchOS | 11.2 | +| iOS | 18.3 | +| macOS | 15.3 | +| tvOS | 18.3 | +| visionOS | 2.3 | +| watchOS | 11.3 | ## Important Release Notes diff --git a/mdm/commands/information.contentcaching.yaml b/mdm/commands/information.contentcaching.yaml index a791e8d..965b1c1 100644 --- a/mdm/commands/information.contentcaching.yaml +++ b/mdm/commands/information.contentcaching.yaml @@ -560,8 +560,8 @@ responsekeys: content: |- The status of the content cache's registration with Apple, which is one of the following values: * '-1:' Failed - * ' 0:' Pending - * ' 1:' Succeeded + * '0:' Pending + * '1:' Succeeded - key: RestrictedMedia type: presence: optional @@ -590,8 +590,8 @@ responsekeys: content: |- The status of tethered caching, which is content caching with a shared internet connection, which is one of the following values: * '-1:' Unknown - * ' 0:' Disabled - * ' 1:' Enabled + * '0:' Disabled + * '1:' Enabled - key: TotalBytesAreSince type: presence: optional diff --git a/mdm/commands/settings.yaml b/mdm/commands/settings.yaml index 3b1afdf..0816e5d 100644 --- a/mdm/commands/settings.yaml +++ b/mdm/commands/settings.yaml @@ -625,8 +625,8 @@ payloadkeys: introduced: n/a type: presence: optional - content: A dictionary that contains default application bundle identifiers. Currently - it supports a default web browser app. + content: A dictionary that contains default application bundle identifiers for + each default application type that can be set. subkeys: - key: Item type: diff --git a/mdm/commands/system.update.schedule.yaml b/mdm/commands/system.update.schedule.yaml index c3a3912..db19465 100644 --- a/mdm/commands/system.update.schedule.yaml +++ b/mdm/commands/system.update.schedule.yaml @@ -86,7 +86,6 @@ payloadkeys: * 'InstallLater': Download the software update and install it at a later time. This value is available in macOS 10.11 and later. * 'InstallForceRestart': Perform the 'Default' action, and then force a restart if the update requires it. This value is available in macOS 11 and later. - 'InstallForceRestart' may result in data loss. - key: MaxUserDeferrals supportedOS: diff --git a/mdm/profiles/com.apple.ADCertificate.managed.yaml b/mdm/profiles/com.apple.ADCertificate.managed.yaml index 1a64358..fcfb40f 100644 --- a/mdm/profiles/com.apple.ADCertificate.managed.yaml +++ b/mdm/profiles/com.apple.ADCertificate.managed.yaml @@ -60,9 +60,9 @@ payloadkeys: * CN= * CN='Certification Authorities' * CN='Public Key Services' - * ''CN='Services' - * ''CN='Configuration' - * ''CN= + * CN='Services' + * CN='Configuration' + * CN= - key: CertificateAcquisitionMechanism title: Certificate Acquisition Mechanism supportedOS: diff --git a/mdm/profiles/com.apple.DirectoryService.managed.yaml b/mdm/profiles/com.apple.DirectoryService.managed.yaml index 013187b..4e8c8bb 100644 --- a/mdm/profiles/com.apple.DirectoryService.managed.yaml +++ b/mdm/profiles/com.apple.DirectoryService.managed.yaml @@ -265,7 +265,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', the system enables the 'ADTrustChangePassIntervalDays 'key. + content: If 'true', the system enables the 'ADTrustChangePassIntervalDays' key. - key: ADTrustChangePassIntervalDays title: ADTrustChangePassIntervalDays type: diff --git a/mdm/profiles/com.apple.MCX(EnergySaver).yaml b/mdm/profiles/com.apple.MCX(EnergySaver).yaml index a37bd92..42498f3 100644 --- a/mdm/profiles/com.apple.MCX(EnergySaver).yaml +++ b/mdm/profiles/com.apple.MCX(EnergySaver).yaml @@ -75,21 +75,21 @@ payloadkeys: rangelist: - 0 - 1 - content: If 'true', enables 'Wake for network access.' + content: If 'true', enables “Wake for network access.” - key: Wake On Modem Ring type: presence: optional rangelist: - 0 - 1 - content: If 'true', enables 'Wake for modem ring.' + content: If 'true', enables “Wake for modem ring.” - key: Automatic Restart On Power Loss type: presence: optional rangelist: - 0 - 1 - content: If 'true', enables 'Start up automatically after a power failure.' + content: If 'true', enables “Start up automatically after a power failure.” - key: com.apple.EnergySaver.portable.ACPower type: presence: optional diff --git a/mdm/profiles/com.apple.SoftwareUpdate.yaml b/mdm/profiles/com.apple.SoftwareUpdate.yaml index 89c97f1..dbae4e5 100644 --- a/mdm/profiles/com.apple.SoftwareUpdate.yaml +++ b/mdm/profiles/com.apple.SoftwareUpdate.yaml @@ -60,7 +60,7 @@ payloadkeys: type: presence: optional default: true - content: If 'false', restricts the 'Install macOS Updates' option and prevents the + content: If 'false', restricts the “Install macOS Updates” option and prevents the user from changing the option. - key: AutomaticallyInstallAppUpdates supportedOS: @@ -69,7 +69,7 @@ payloadkeys: type: presence: optional default: true - content: If 'false', deselects the 'Install app updates from the App Store' option + content: If 'false', deselects the “Install app updates from the App Store” option and prevents the user from changing the option. - key: AutomaticCheckEnabled supportedOS: @@ -78,7 +78,7 @@ payloadkeys: type: presence: optional default: true - content: If 'false', deselects the 'Check for updates' option and prevents the user + content: If 'false', deselects the “Check for updates” option and prevents the user from changing the option. - key: AutomaticDownload supportedOS: @@ -87,8 +87,8 @@ payloadkeys: type: presence: optional default: true - content: If 'false', deselects the 'Download new updates when available from the - App Store' option and prevents the user from changing the option. + content: If 'false', deselects the “Download new updates when available from the + App Store” option and prevents the user from changing the option. - key: CriticalUpdateInstall supportedOS: macOS: @@ -97,7 +97,7 @@ payloadkeys: presence: optional default: true content: If 'false', disables the automatic installation of critical updates and - prevents the user from changing the 'Install system data files and security updates' + prevents the user from changing the “Install system data files and security updates” option. - key: ConfigDataInstall supportedOS: diff --git a/mdm/profiles/com.apple.TCC.configuration-profile-policy.yaml b/mdm/profiles/com.apple.TCC.configuration-profile-policy.yaml index 7aea0a1..97ed06f 100644 --- a/mdm/profiles/com.apple.TCC.configuration-profile-policy.yaml +++ b/mdm/profiles/com.apple.TCC.configuration-profile-policy.yaml @@ -55,7 +55,7 @@ payloadkeys: - key: CodeRequirement type: presence: required - content: Obtained via the command ''codesign -display -r -''. + content: Obtained via the command “'codesign -display -r -'”. - key: StaticCode type: presence: optional diff --git a/mdm/profiles/com.apple.applicationaccess.yaml b/mdm/profiles/com.apple.applicationaccess.yaml index d5af8fc..c7588f2 100644 --- a/mdm/profiles/com.apple.applicationaccess.yaml +++ b/mdm/profiles/com.apple.applicationaccess.yaml @@ -1236,6 +1236,40 @@ payloadkeys: default: true content: If 'false', the system disallows dictation input. Available in iOS 10.3 and later, and macOS 10.13 and later. Requires a supervised device in iOS. +- key: allowedExternalIntelligenceWorkspaceIDs + title: Allowed External Intelligence Workspace IDs + supportedOS: + iOS: + introduced: '18.3' + supervised: true + allowmanualinstall: false + sharedipad: + mode: forbidden + userenrollment: + mode: forbidden + macOS: + introduced: '15.3' + allowmanualinstall: false + userenrollment: + mode: forbidden + tvOS: + introduced: n/a + visionOS: + introduced: n/a + watchOS: + introduced: n/a + type: + presence: optional + content: Array of strings, but currently restricted to a single element. If present, + Apple Intelligence will only allow the given external integration workspace ID + to be used, and will require a sign-in in order to make requests; the user will + be required to sign in to integrations that support signing in. Multiple payloads + will combine using an intersect operation. This means the allowed set of workspace + IDs can become the empty set if conflicting values are specified in multiple payloads. + subkeys: + - key: allowedWorkspaceID + title: Allowed Workspace ID + type: - key: allowEnablingRestrictions title: Allow Configuring Restrictions or ScreenTime supportedOS: @@ -1431,7 +1465,7 @@ payloadkeys: macOS: introduced: '15.2' userenrollment: - mode: forbidden + mode: allowed tvOS: introduced: n/a visionOS: @@ -2282,6 +2316,29 @@ payloadkeys: default: true content: If 'false', the system disables NFC. Requires a supervised device. Available in iOS 14.2 and later. +- key: allowNotesTranscriptionSummary + supportedOS: + iOS: + introduced: '18.3' + supervised: true + sharedipad: + mode: forbidden + userenrollment: + mode: forbidden + macOS: + introduced: '15.3' + userenrollment: + mode: forbidden + tvOS: + introduced: n/a + visionOS: + introduced: n/a + watchOS: + introduced: n/a + type: + presence: optional + default: true + content: If false, disables transcription summarization in Notes. - key: allowNotificationsModification title: Allow Modifying Notifications Settings supportedOS: @@ -3199,6 +3256,28 @@ payloadkeys: default: true content: If 'false', the system hides the FaceTime app. Available in iOS 4 and later. Requires a supervised device in iOS 13 and later. +- key: allowVisualIntelligenceSummary + title: Allow Visual Intelligence Summary + supportedOS: + iOS: + introduced: '18.3' + supervised: true + sharedipad: + mode: forbidden + userenrollment: + mode: forbidden + macOS: + introduced: n/a + tvOS: + introduced: n/a + visionOS: + introduced: n/a + watchOS: + introduced: n/a + type: + presence: optional + default: true + content: When false, disables visual intelligence summarization. - key: allowVoiceDialing title: Allow Voice Dialing While Device is Locked supportedOS: diff --git a/mdm/profiles/com.apple.associated-domains.yaml b/mdm/profiles/com.apple.associated-domains.yaml index db15cce..93ca646 100644 --- a/mdm/profiles/com.apple.associated-domains.yaml +++ b/mdm/profiles/com.apple.associated-domains.yaml @@ -46,7 +46,7 @@ payloadkeys: type: presence: required content: The domains to associate with the app. Each string is in the form of - ''service:domain''. Use fully qualified hostnames, such as 'www.example.com'. + “'service:domain'”. Use fully qualified hostnames, such as 'www.example.com'. See Supporting associated domains for more information. subkeys: - key: AssociatedDomain diff --git a/mdm/profiles/com.apple.dock.yaml b/mdm/profiles/com.apple.dock.yaml index 63a41d0..4b68c92 100644 --- a/mdm/profiles/com.apple.dock.yaml +++ b/mdm/profiles/com.apple.dock.yaml @@ -81,7 +81,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', locks 'Minimize windows using.' + content: If 'true', locks “Minimize windows using.” - key: windowtabbing supportedOS: macOS: @@ -92,7 +92,7 @@ payloadkeys: - manual - always - fullscreen - content: Set the 'Prefer tabs when opening documents' to the provided value. + content: Set the “Prefer tabs when opening documents” to the provided value. - key: windowtabbing-immutable supportedOS: macOS: @@ -100,7 +100,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', disables 'Prefer tabs when opening documents' checkbox. + content: If 'true', disables “Prefer tabs when opening documents” checkbox. - key: dblclickbehavior supportedOS: macOS: @@ -119,12 +119,12 @@ payloadkeys: type: presence: optional default: false - content: If 'true', locks 'Double-click a window's title bar.' + content: If 'true', locks “Double-click a window's title bar.” - key: minimize-to-application type: presence: optional default: false - content: If 'true', enables 'Minimize windows into application icon.' + content: If 'true', enables “Minimize windows into application icon.” - key: minintoapp-immutable supportedOS: macOS: @@ -132,27 +132,27 @@ payloadkeys: type: presence: optional default: false - content: If 'true', disables the 'Minimize windows into application icon' checkbox. + content: If 'true', disables the “Minimize windows into application icon” checkbox. - key: launchanim type: presence: optional default: false - content: If 'true', enables 'Animate opening applications.' + content: If 'true', enables “Animate opening applications.” - key: launchanim-immutable type: presence: optional default: false - content: If 'true', locks 'Animate opening applications.' + content: If 'true', locks “Animate opening applications.” - key: autohide type: presence: optional default: false - content: If 'true', enables 'Automatically hide and show the dock.' + content: If 'true', enables “Automatically hide and show the dock.” - key: autohide-immutable type: presence: optional default: false - content: If 'true', locks 'Automatically hide.' + content: If 'true', locks “Automatically hide.” - key: show-process-indicators type: presence: optional @@ -162,7 +162,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', locks 'Show indicators.' + content: If 'true', locks “Show indicators.” - key: show-recents supportedOS: macOS: @@ -170,7 +170,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', enables 'Show recent items.' + content: If 'true', enables “Show recent items.” - key: showrecents-immutable supportedOS: macOS: @@ -178,7 +178,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', disables 'Show recent applications' checkbox. + content: If 'true', disables “Show recent applications” checkbox. - key: contents-immutable type: presence: optional @@ -189,8 +189,7 @@ payloadkeys: presence: optional content: |- One or more special folders that may be created at user login time and placed in the dock. - - The 'My Applications' item is only used for Simple Finder environments. The 'Original Network Home' item is only used for mobile account users. + The “My Applications” item is only used for Simple Finder environments. The “Original Network Home” item is only used for mobile account users. subkeys: - key: MCXDockSpecialFoldersItems type: diff --git a/mdm/profiles/com.apple.extensiblesso(kerberos).yaml b/mdm/profiles/com.apple.extensiblesso(kerberos).yaml index ad0cf54..98309a8 100644 --- a/mdm/profiles/com.apple.extensiblesso(kerberos).yaml +++ b/mdm/profiles/com.apple.extensiblesso(kerberos).yaml @@ -243,7 +243,7 @@ payloadkeys: presence: optional default: false content: If 'true', the system requires passwords to meet Active Directory's definition - of 'complex'. Available in macOS 10.15 and later. + of “complex”. Available in macOS 10.15 and later. - key: pwReqMinAge supportedOS: iOS: diff --git a/mdm/profiles/com.apple.extensiblesso.yaml b/mdm/profiles/com.apple.extensiblesso.yaml index 7e0ef6f..bb2f5a9 100644 --- a/mdm/profiles/com.apple.extensiblesso.yaml +++ b/mdm/profiles/com.apple.extensiblesso.yaml @@ -121,8 +121,8 @@ payloadkeys: content: If set to 'Cancel', the system cancels authentication requests when the screen is locked. If set to 'DoNotHandle', the request continues without SSO instead. This doesn't apply to requests where 'userInterfaceEnabled' is 'false', or for - background NSURLSession requests. Available in iOS 15 and later, and macOS 12 - and later. + background URLSession requests. Available in iOS 15 and later, and macOS 12 and + later. - key: DeniedBundleIdentifiers supportedOS: iOS: diff --git a/mdm/profiles/com.apple.familycontrols.contentfilter.yaml b/mdm/profiles/com.apple.familycontrols.contentfilter.yaml index 02ef68d..bb503dd 100644 --- a/mdm/profiles/com.apple.familycontrols.contentfilter.yaml +++ b/mdm/profiles/com.apple.familycontrols.contentfilter.yaml @@ -43,7 +43,6 @@ payloadkeys: presence: optional content: |- An array of sites that defines an allow list. If specified, this defines additional allowed sites besides those in the automated allow list and deny list, including disallowed adult sites. - This key is required if 'whiteListEnabled' is 'true'. subkeys: - key: siteWhitelistItem diff --git a/mdm/profiles/com.apple.font.yaml b/mdm/profiles/com.apple.font.yaml index 9dbe05d..90b92f2 100644 --- a/mdm/profiles/com.apple.font.yaml +++ b/mdm/profiles/com.apple.font.yaml @@ -48,7 +48,6 @@ payloadkeys: default: '' content: |- The user-visible name for the font. This field is replaced by the actual name of the font after installation. Each payload must contain exactly one font file in trueType (.ttf) or OpenType (.otf) format. Collection formats (.ttc or .otc) are not supported. - Fonts are identified by their embedded PostScript names. Two fonts with the same PostScript name are considered to be the same font even if their contents differ. Installing two different fonts with the same PostScript name isn't supported, and the resulting behavior is undefined. - key: Font title: Font diff --git a/mdm/profiles/com.apple.loginwindow.yaml b/mdm/profiles/com.apple.loginwindow.yaml index 867d93e..86adaf8 100644 --- a/mdm/profiles/com.apple.loginwindow.yaml +++ b/mdm/profiles/com.apple.loginwindow.yaml @@ -50,7 +50,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', the system displays “Other...” when it shows a list of users. + content: If 'true', the system displays “Other…” when it shows a list of users. - key: AdminHostInfo type: presence: optional diff --git a/mdm/profiles/com.apple.networkusagerules.yaml b/mdm/profiles/com.apple.networkusagerules.yaml index 329148c..c7fc0c3 100644 --- a/mdm/profiles/com.apple.networkusagerules.yaml +++ b/mdm/profiles/com.apple.networkusagerules.yaml @@ -39,7 +39,6 @@ payloadkeys: presence: optional content: |- A list of managed app identifiers, as strings, that must follow the associated rules. If this key is missing, the rules apply to all managed apps on the device. - Each string in the 'AppIdentifierMatches' array may either be an exact app identifier match (for example, 'com.mycompany.myapp') or it may specify a prefix match for the bundle ID by using the * wildcard character. If used, this character must appear after a period (.) and may only appear once, at the end of the string; for example, 'com.mycompany.*'. subkeys: - key: AppIdentifierMatchesItem diff --git a/mdm/profiles/com.apple.notificationsettings.yaml b/mdm/profiles/com.apple.notificationsettings.yaml index 49157d3..5674933 100644 --- a/mdm/profiles/com.apple.notificationsettings.yaml +++ b/mdm/profiles/com.apple.notificationsettings.yaml @@ -167,6 +167,4 @@ payloadkeys: * '0' - Always: Previews will be shown when the device is locked and unlocked * '1' - When Unlocked: Previews will only be shown when the device is unlocked * '2' - Never: Previews will never be shown - - Available in iOS 14 and later. diff --git a/mdm/profiles/com.apple.systemuiserver.yaml b/mdm/profiles/com.apple.systemuiserver.yaml index 755a7c6..d43e540 100644 --- a/mdm/profiles/com.apple.systemuiserver.yaml +++ b/mdm/profiles/com.apple.systemuiserver.yaml @@ -108,7 +108,6 @@ payloadkeys: presence: optional content: |- A string or an array of media action strings. Internally installed SD cards and USB flash drives are included in the hard disk-external category. - This key is the default for media types that don't fall into other categories. subkeytype: ActionStringItem subkeys: *id001 diff --git a/mdm/profiles/com.apple.universalaccess.yaml b/mdm/profiles/com.apple.universalaccess.yaml index c8c9ed1..8600bf6 100644 --- a/mdm/profiles/com.apple.universalaccess.yaml +++ b/mdm/profiles/com.apple.universalaccess.yaml @@ -30,7 +30,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', enables 'Use keyboard shortcuts' in the Zoom options. + content: If 'true', enables “Use keyboard shortcuts” in the Zoom options. - key: closeViewNearPoint type: presence: optional @@ -39,7 +39,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', enables 'Use scroll gesture' in the Zoom options. + content: If 'true', enables “Use scroll gesture” in the Zoom options. - key: closeViewShowPreview supportedOS: macOS: @@ -48,13 +48,13 @@ payloadkeys: type: presence: optional default: false - content: If 'true', enables 'Show preview rectangle' in the Zoom options. Only available + content: If 'true', enables “Show preview rectangle” in the Zoom options. Only available in macOS 10.15 and earlier. - key: closeViewSmoothImages type: presence: optional default: false - content: If 'true', enables 'Smooth images' in the Zoom options. + content: If 'true', enables “Smooth images” in the Zoom options. - key: contrast type: presence: optional @@ -66,7 +66,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', enables 'Flash the screen' in the Audio options. + content: If 'true', enables “Flash the screen” in the Audio options. - key: grayscale supportedOS: macOS: @@ -75,7 +75,7 @@ payloadkeys: presence: optional default: false content: |- - If 'true', enables 'Use grayscale' in the Display options. + If 'true', enables “Use grayscale” in the Display options. This option is deprecated in macOS 11. - key: mouseDriver type: @@ -103,12 +103,12 @@ payloadkeys: type: presence: optional default: false - content: If 'true', enables 'Slow Keys' in the Keyboard options. + content: If 'true', enables “Slow Keys” in the Keyboard options. - key: slowKeyBeepOn type: presence: optional default: false - content: If 'true', enables 'click key sounds' for Slow Keys. + content: If 'true', enables “click key sounds” for Slow Keys. - key: slowKeyDelay type: presence: optional @@ -132,7 +132,7 @@ payloadkeys: type: presence: optional default: false - content: If 'true', enables 'Display pressed keys on screen' for Sticky Keys. + content: If 'true', enables “Display pressed keys on screen” for Sticky Keys. - key: voiceOverOnOffKey type: presence: optional diff --git a/mdm/profiles/com.apple.vpn.managed.yaml b/mdm/profiles/com.apple.vpn.managed.yaml index 1f392d2..f099d1b 100644 --- a/mdm/profiles/com.apple.vpn.managed.yaml +++ b/mdm/profiles/com.apple.vpn.managed.yaml @@ -61,7 +61,13 @@ payloadkeys: presence: optional content: |- An identifier for a vendor-specified configuration dictionary when the value for 'VPNType' is 'VPN'. - If 'VPNType' is 'VPN', the system requires this field. If the configuration targets a VPN solution that uses a network extension provider, then this field contains the bundle identifier of the app that contains the provider. Contact the VPN solution vendor for the value of the identifier. + If 'VPNType' is 'VPN', the system requires this field. If the configuration targets a VPN solution that uses a VPN plugin, then this field contains the bundle identifier of the plugin. Here are some examples: + * Cisco AnyConnect: 'com.cisco.anyconnect.applevpn.plugin' + * Juniper SSL: 'net.juniper.sslvpn' + * F5 SSL: 'com.f5.F5-Edge-Client.vpnplugin' + * SonicWALL Mobile Connect: 'com.sonicwall.SonicWALL-SSLVPN.vpnplugin' + * ``Aruba VIA: 'com.arubanetworks.aruba-via.vpnplugin' + If the configuration targets a VPN solution that uses a network extension provider, then this field contains the bundle identifier of the app that contains the provider. Contact the VPN solution vendor for the value of the identifier. If 'VPNType' is 'IKEv2', then the 'VPNSubType' field is optional and reserved for future use. If it's specified, it needs to contain an empty string. Not available in watchOS. - key: UserDefinedName @@ -673,7 +679,7 @@ payloadkeys: type: presence: optional content: |- - The name of the group. For hybrid authentication, the string needs to end with 'hybrid'. + The name of the group. For hybrid authentication, the string needs to end with “hybrid”. Present only for Cisco IPSec if 'AuthenticationMethod' is 'SharedSecret'. - key: LocalIdentifierType title: Local Identifier Type @@ -1744,8 +1750,8 @@ payloadkeys: type: presence: optional content: The array of captive networking apps whose traffic is allowed outside - the VPN tunnel, to perform captive network handling. Used only when 'AllowAllCaptiveNetworkPlugins - 'is 'false'. + the VPN tunnel, to perform captive network handling. Used only when 'AllowAllCaptiveNetworkPlugins' + is 'false'. subkeys: - key: AllowedCaptiveNetworkPluginElement title: An AllowedCaptiveNetworkPlugin Element diff --git a/mdm/profiles/com.apple.wifi.managed.yaml b/mdm/profiles/com.apple.wifi.managed.yaml index 6ff21b6..e1e69c6 100644 --- a/mdm/profiles/com.apple.wifi.managed.yaml +++ b/mdm/profiles/com.apple.wifi.managed.yaml @@ -521,7 +521,6 @@ payloadkeys: default: true content: |- If 'true', disables L3 marking and only uses L2 marking for traffic that goes to the Wi-Fi network. - If 'false', the system behaves as if Wi-Fi doesn't have an association with a Cisco QoS fast lane network. - key: SetupModes supportedOS: diff --git a/mdm/profiles/com.apple.xsan.yaml b/mdm/profiles/com.apple.xsan.yaml index 8e47fee..715ae3f 100644 --- a/mdm/profiles/com.apple.xsan.yaml +++ b/mdm/profiles/com.apple.xsan.yaml @@ -33,7 +33,6 @@ payloadkeys: presence: required content: |- An array of LDAP URLs where Xsan systems can obtain SAN configuration updates. This key is required for all Xsan SANs. There should be one entry for each Xsan MDC. - Example URL: 'ldaps://mdc1.example.com:389'. subkeys: - key: sanConfigURLsItem @@ -45,7 +44,6 @@ payloadkeys: presence: required content: |- An array of storage area network (SAN) File System Name Server coordinators. The list should contain the same addresses in the same order as the metadata controller (MDC) '/Library/Preferences/Xsan/fsnameservers' file. Xsan SAN clients automatically receive updates to the 'fsnameservers' list from the SAN configuration servers whenever this list changes. StorNext administrators should update their profile whenever the 'fsnameservers' list changes. - This key is required for StorNext SANs. subkeys: - key: fsnameserversItem @@ -59,7 +57,6 @@ payloadkeys: - auth_secret content: |- The authentication method for the SAN. This key is required for all Xsan SANs. It's optional for StorNext SANs but should be set if the StorNext SAN uses an 'auth_secret' file. - Only one value is accepted: 'auth_secret' - key: sharedSecret type: