diff --git a/CHANGES.md b/CHANGES.md index d700a32..47576cb 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -42,6 +42,10 @@ Significant changes in this release. - Changed: declarative/declarations/configurations/app.managed.yaml/ExtensionConfigs [macOS 27.0] - Changed: declarative/declarations/configurations/app.managed.yaml/LegacyAppConfigAssetReference [macOS 27.0] +### Deprecated Payload Keys + +- Deprecated: declarative/declarations/configurations/intelligence.settings.yaml/AllowVisualIntelligenceSummary [iOS 27.0] + ### Removed Payload Keys - Removed: declarative/declarations/configurations/app.managed.yaml/VPPType @@ -128,6 +132,26 @@ Significant changes in this release. - Changed: mdm/profiles/com.apple.applicationaccess.yaml/allowListedAppBundleIDs [visionOS 27.0] - Changed: mdm/profiles/com.apple.applicationaccess.yaml/blockedAppBundleIDs [visionOS 27.0] +### Deprecated Objects + +- Deprecated: mdm/profiles/com.apple.AssetCache.managed.yaml [macOS 27.0] +- Deprecated: mdm/profiles/com.apple.applicationaccess.new.yaml [macOS 27.0] +- Deprecated: mdm/profiles/com.apple.dnsProxy.managed.yaml [iOS 27.0, macOS 27.0, visionOS 27.0] +- Deprecated: mdm/profiles/com.apple.dnsSettings.managed.yaml [iOS 27.0, macOS 27.0, visionOS 27.0] +- Deprecated: mdm/profiles/com.apple.mobiledevice.passwordpolicy.yaml [iOS 27.0, macOS 27.0, visionOS 27.0, watchOS 27.0] +- Deprecated: mdm/profiles/com.apple.relay.managed.yaml [iOS 27.0, macOS 27.0, visionOS 27.0] + +### Deprecated Payload Keys + +- Deprecated: mdm/profiles/com.apple.TCC.configuration-profile-policy.yaml/Services/Accessibility [macOS 27.0] +- Deprecated: mdm/profiles/com.apple.TCC.configuration-profile-policy.yaml/Services/BluetoothAlways [macOS 27.0] +- Deprecated: mdm/profiles/com.apple.TCC.configuration-profile-policy.yaml/Services/Camera [macOS 27.0] +- Deprecated: mdm/profiles/com.apple.TCC.configuration-profile-policy.yaml/Services/Microphone [macOS 27.0] +- Deprecated: mdm/profiles/com.apple.TCC.configuration-profile-policy.yaml/Services/SpeechRecognition [macOS 27.0] +- Deprecated: mdm/profiles/com.apple.applicationaccess.yaml/allowListedAppBundleIDs [iOS 27.0, tvOS 27.0, visionOS 27.0] +- Deprecated: mdm/profiles/com.apple.applicationaccess.yaml/allowSiriAI [iOS 27.0] +- Deprecated: mdm/profiles/com.apple.applicationaccess.yaml/blockedAppBundleIDs [iOS 27.0, tvOS 27.0, visionOS 27.0] + ### Removed Objects - Removed: mdm/profiles/com.apple.SoftwareUpdate.yaml diff --git a/declarative/declarations/configurations/accessibility.settings.yaml b/declarative/declarations/configurations/accessibility.settings.yaml index 03a133f..6eca562 100644 --- a/declarative/declarations/configurations/accessibility.settings.yaml +++ b/declarative/declarations/configurations/accessibility.settings.yaml @@ -42,7 +42,8 @@ payloadkeys: presence: optional default: true combinetype: boolean-and - content: If `false`, disables the Live Recognition accessibility feature. + content: If `false`, disables the Accessibility Live Recognition Ask about Images + and Surroundings features. examples: - title: Configuration example files: diff --git a/declarative/declarations/configurations/app.settings.yaml b/declarative/declarations/configurations/app.settings.yaml index 7bf1eea..0f6991f 100644 --- a/declarative/declarations/configurations/app.settings.yaml +++ b/declarative/declarations/configurations/app.settings.yaml @@ -176,7 +176,7 @@ payloadkeys: default: false combinetype: boolean-or content: If `true`, the device implicitly includes managed apps in the effective - allow list when `AllowedApps` or `AllowedBinaries` is present. + allow list when `AllowedBinaries` is present. - key: Privacy title: App privacy supportedOS: diff --git a/declarative/declarations/configurations/network.vpn.always-on.yaml b/declarative/declarations/configurations/network.vpn.always-on.yaml index 424bf6d..502e86e 100644 --- a/declarative/declarations/configurations/network.vpn.always-on.yaml +++ b/declarative/declarations/configurations/network.vpn.always-on.yaml @@ -205,49 +205,12 @@ payloadkeys: - '1.3' default: '1.2' content: The maximum TLS version to use with EAP-TLS authentication. - - key: Provider - title: Provider details - type: - presence: optional - content: Specifies details about the provider. - subkeys: - - key: Type - title: Type - type: - presence: optional - rangelist: - - packet-tunnel - - app-proxy - default: packet-tunnel - content: The type of VPN service. If the value is `app-proxy`, the service - tunnels traffic at the app level. If the value is `packet-tunnel`, the - service tunnels traffic at the IP layer. - - key: ComposedIdentifier - title: Composed identifier - type: - presence: optional - content: |- - In iOS, tvOS, and visionOS, the identifier is a bundle ID, for example, "com.example.app". - - In macOS, the identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID", "Bundle-ID (Team-ID)", or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Team-ID" is the team identifier from the provider's code signature. "Designated-Requirement" is the designated requirement string the device uses to match the code signature of the provider. For example, "com.example.app" for the bundle ID format, "com.example.app (ABCD1234)" for the team ID format, or "com.example.app {anchor apple generic}" for the designated requirement format. - key: Idle title: Disconnect on idle settings. type: presence: optional content: Specifies details about how the system handles idle VPN connections. subkeys: - - key: Disconnect - title: Enable disconnect on idle - type: - presence: optional - default: false - content: If `true`, disconnects after an on-demand connection idles. - - key: Timer - title: Disconnect on idle time - type: - presence: optional - content: The length of time to wait, in seconds, before disconnecting an - on-demand connection. - key: DeadPeerDetectionRate title: Dead peer detection rate type: @@ -265,162 +228,6 @@ payloadkeys: - `Low`: Send keepalive every 30 minutes. - `Medium`: Send keepalive every 10 minutes. - `High`: Send keepalive every 1 minute. - - key: OnDemand - title: On demand details - type: - presence: optional - content: Specifies details about how the system controls on-demand VPN. - subkeys: - - key: Enabled - title: Enable VPN on demand - type: - presence: optional - default: false - content: If `true`, enables VPN On Demand. - - key: DisableUserOverride - title: Prevent users from toggling VPN on demand - supportedOS: - macOS: - introduced: n/a - type: - presence: optional - default: false - content: If `true`, the Connect On Demand toggle in Settings is disabled - for this configuration. - - key: Rules - title: On demand rules - type: - presence: optional - content: An array of dictionaries defining On Demand Rules. - subkeytype: RulesElement - subkeys: - - key: RulesElement - title: Rules element - type: - subkeys: - - key: Action - title: On demand action - type: - presence: required - rangelist: - - Allow - - Connect - - Disconnect - - EvaluateConnection - - Ignore - content: |- - The action to take if this dictionary matches the current network. Possible values are: - - `Allow`: Deprecated. Allow VPN On Demand to connect if triggered. - - `Connect`: Unconditionally initiate a VPN connection on the next network attempt. - - `Disconnect`: Tear down the VPN connection and don't reconnect on demand as long as this dictionary matches. - - `EvaluateConnection`: Evaluate the ActionParameters array for each connection attempt. - - `Ignore`: Leave any existing VPN connection up, but don't reconnect on demand as long as this dictionary matches. - - key: ActionParameters - title: Action parameters - type: - presence: optional - content: An array of dictionaries that provides rules similar to the - `OnDemandRules` dictionary, but evaluated on each connection instead - of when the network changes. This value is only for use with dictionaries - in which the `Action` value is `EvaluateConnection`. The system evaluates - these dictionaries in order and the first dictionary that matches - determines the behavior. - subkeys: - - key: ActionParameter - title: Action parameter - type: - presence: optional - content: |- - A dictionary that provides rules similar to the OnDemandRules dictionary, but evaluated on each connection instead of when the network changes. These dictionaries are evaluated in order, and the behavior is determined by the first dictionary that matches. - The keys allowed in each dictionary are described below. Note: This array is used only for dictionaries in which EvaluateConnection is the Action value. - subkeys: - - key: Domains - title: Domains - type: - presence: required - content: The domains to apply this evaluation. - subkeys: - - key: DomainsElement - title: Domains element - type: - - key: DomainAction - title: Domain action - type: - presence: required - rangelist: - - ConnectIfNeeded - - NeverConnect - content: |- - Defines the VPN behavior for the specified domains. Allowed values are: - * 'ConnectIfNeeded': The specified domains should trigger a VPN connection attempt if domain name resolution fails, such as when the DNS server indicates that it can't resolve the domain, responds with a redirection to a different server, or fails to respond (timeout). - * 'NeverConnect': The specified domains should never trigger a VPN connection attempt. - - key: RequiredDNSServers - title: Required DNS servers - type: - presence: optional - content: |- - An array of IP addresses of DNS servers to use for resolving the specified domains. These servers don't need to be part of the device's current network configuration. If these DNS servers aren't reachable, the system establishes a VPN connection. These DNS servers need to be either internal DNS servers or trusted external DNS servers. - This key is valid only if the value of 'DomainAction' is 'ConnectIfNeeded'. - subkeys: - - key: RequiredDNSServersElement - title: Required DNS servers element - type: - - key: RequiredURLStringProbe - title: Required URL string probe - type: - presence: optional - content: |- - An HTTP or HTTPS (preferred) URL to probe, using a GET request. If the URL's hostname can't be resolved, if the server is unreachable, or if the server doesn't respond with a 200 HTTP status code, a VPN connection is established in response. - This key is valid only if the value of 'DomainAction' is 'ConnectIfNeeded'. - - key: DNSDomainMatch - title: DNS domain match - type: - presence: optional - content: |- - An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device's search domains list. - The system supports a wildcard (`\*`) prefix. For example, `\*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`. - subkeys: - - key: DNSDomainMatchElement - title: DNS domain match element - type: - - key: DNSServerAddressMatch - title: DNS server address match - type: - presence: optional - content: |- - An array of IP addresses. This rule matches if any of the network's specified DNS servers match any entry in the array. - The system supports matching with a single wildcard. For example, `17.\*` matches any DNS server in the `17.0.0.0/8` subnet. - subkeys: - - key: DNSServerAddressMatchElement - title: DNS server address match element - type: - - key: InterfaceTypeMatch - title: Interface type match - type: - presence: optional - rangelist: - - Ethernet - - WiFi - - Cellular - content: An interface type. If specified, this rule matches only if - the primary network interface hardware matches the specified type. - - key: SSIDMatch - title: SSID match - type: - presence: optional - content: |- - An array of SSIDs to match against the current network. If the network isn't a Wi-Fi network or if the SSID doesn't appear in this array, the match fails. - Omit this key and the corresponding array to match against any SSID. - subkeys: - - key: SSIDMatchElement - title: SSID match element - type: - - key: URLStringProbe - title: URL string probe - type: - presence: optional - content: A URL to probe. This rule matches when this URL is successfully - fetched (returns a `200` HTTP status code) without redirection. - key: UseConfigurationAttributeInternalIPSubnet title: Use IPv4 / IPv6 internal subnet attributes type: @@ -474,18 +281,6 @@ payloadkeys: content: If `true`, the system performs a certificate revocation check for IKEv2 connections. This is a best-effort revocation check and server response timeouts won't cause it to fail. - - key: EnableFallback - title: Enable fallback - supportedOS: - macOS: - introduced: n/a - type: - presence: optional - default: false - content: |- - If `true`, the system enables a tunnel over cellular data to carry traffic that's eligible for Wi-Fi Assist and also requires VPN. - - Enabling fallback requires that the server support multiple tunnels for a single user. - key: MTU title: Maximum transmission unit type: @@ -719,190 +514,6 @@ payloadkeys: type: presence: required content: The bundle identifier for the app that's allowed on the captive network. -- key: DNS - title: DNS - type: - presence: optional - content: A dictionary to use for all VPN types. - subkeys: - - key: Protocol - title: DNS protocol - type: - presence: required - rangelist: - - Cleartext - - HTTPS - - TLS - content: The transport protocol to communicate with the DNS server. - - key: ServerURL - title: Server URL - type: - presence: optional - content: The URI template of a DNS-over-HTTPS server, as defined in RFC 8484, - which needs to use the `https://` scheme. The system uses the hostname or address - in the URL to validate the server certificate. If `ServerAddresses` isn't specified, - the system uses the hostname or address in the URL to determine the server addresses. - This key is required if the `DNSProtocol` is `HTTPS`. - - key: ServerName - title: Server name - type: - presence: optional - content: The hostname of a DNS-over-TLS server to validate the server certificate, - as defined in RFC 7858. If `ServerAddresses` isn't specified, the system uses - the hostname to determine the server addresses. This key is required if the - `DNSProtocol` is `TLS`. - - key: ServerAddresses - title: DNS server addresses - type: - presence: required - content: The array of DNS server IP address strings. These IP addresses can be - a mixture of IPv4 and IPv6 addresses. - subkeys: - - key: ServerAddressesElement - title: Server address element - type: - - key: SearchDomains - title: DNS search domains - type: - presence: optional - content: The list of domain strings used to fully qualify single-label host names. - subkeys: - - key: SearchDomainsElement - title: Search domains element - type: - - key: DomainName - title: Domain name - type: - presence: optional - content: The primary domain of the tunnel. - - key: SupplementalMatchDomains - title: Supplemental match domains - type: - presence: optional - content: |- - The list of domain strings used to determine which DNS queries use the DNS resolver settings in `ServerAddresses`. The system uses this key to create a split DNS configuration where it resolves only hosts in certain domains using the tunnel's DNS resolver. The system uses the default resolver for hosts that aren't in one of the domains in this list. - - If `SupplementalMatchDomains` contains the empty string it becomes the default domain. - - Split-tunnel configurations can direct all DNS queries to the VPN DNS servers before the primary DNS servers. If the VPN tunnel becomes the network's default route, the servers listed in `ServerAddresses` become the default resolver and the system ignores the `SupplementalMatchDomains` list. - subkeys: &id002 - - key: SupplementalMatchDomainsElement - title: Supplemental match domains element - type: - - key: SupplementalMatchDomainsNoSearch - title: Supplemental match domains no search - type: - presence: optional - default: false - content: If `true`, don't append the domains in the `SupplementalMatchDomains` - list to the resolver's list of search domains. - - key: IdentityAssetReference - title: Identity asset reference - type: - assettypes: - - com.apple.asset.credential.acme - - com.apple.asset.credential.identity - - com.apple.asset.credential.scep - presence: optional - content: The identifier of a credential asset declaration that contains the identity - that the system uses to authenticate the user to the DNS resolver. -- key: Proxies - title: Proxies - type: - presence: optional - content: The dictionary to use to configure `Proxies` for use with `VPN`. - subkeys: - - key: AutoConfigEnable - title: Proxy auto config enable - type: - presence: optional - default: false - content: If `true`, enables automatic proxy configuration. - - key: AutoDiscoveryEnable - title: Proxy auto discovery enable - type: - presence: optional - default: true - content: If `true`, enables proxy auto discovery. - - key: AutoConfigURLString - title: Proxy server URL - type: - presence: optional - content: The URL to the location of the proxy auto-configuration file. Used only - when `ProxyAutoConfigEnable` is `true`. - - key: SupplementalMatchDomains - title: Supplemental match domains - type: - presence: optional - content: An array of domains that defines which hosts use proxy settings for hosts. - subkeys: *id002 - - key: Protocol - title: Protocol - type: - presence: optional - content: The dictionary to use to configure HTTP servers for `Proxies` for use - with `VPN`. - subkeys: - - key: HTTP - title: HTTP protocol - type: - presence: optional - content: The dictionary to use to configure the HTTP (non-TLS) server. - subkeys: - - key: Enable - title: Enable HTTP - type: - presence: optional - default: false - content: If `true`, enables proxy for HTTP traffic. - - key: HostName - title: HTTP host name - type: - presence: optional - content: The host name of the HTTP proxy. - - key: Port - title: HTTP port - type: - presence: optional - range: - min: 0 - max: 65535 - content: The port number of the HTTP proxy. This field is required if `HostName` - is specified. - - key: HTTPS - title: HTTPS protocol - type: - presence: optional - content: The dictionary to use to configure the HTTPS (TLS) server. - subkeys: - - key: Enable - title: Enable HTTPS - type: - presence: optional - default: false - content: If `true`, enables proxy for HTTPS traffic. - - key: HostName - title: HTTPS host name - type: - presence: optional - content: The host name of the HTTPS proxy. - - key: Port - title: HTTPS port - type: - presence: optional - range: - min: 0 - max: 65535 - content: The port number of the HTTPS proxy. This field is required if `HostName` - is specified. - - key: CredentialsAssetReference - title: Credentials asset reference - type: - assettypes: - - com.apple.asset.credential.userpassword - presence: optional - content: The identifier of an asset declaration that contains the credentials - (user name and password) to authenticate with the proxy server. examples: - title: Configuration example files: diff --git a/declarative/declarations/configurations/network.vpn.ikev2.yaml b/declarative/declarations/configurations/network.vpn.ikev2.yaml index 12a8712..766b495 100644 --- a/declarative/declarations/configurations/network.vpn.ikev2.yaml +++ b/declarative/declarations/configurations/network.vpn.ikev2.yaml @@ -176,31 +176,6 @@ payloadkeys: - '1.3' default: '1.2' content: The maximum TLS version to use with EAP-TLS authentication. -- key: Provider - title: Provider details - type: - presence: optional - content: Specifies details about the provider. - subkeys: - - key: Type - title: Type - type: - presence: optional - rangelist: - - packet-tunnel - - app-proxy - default: packet-tunnel - content: The type of VPN service. If the value is `app-proxy`, the service tunnels - traffic at the app level. If the value is `packet-tunnel`, the service tunnels - traffic at the IP layer. - - key: ComposedIdentifier - title: Composed identifier - type: - presence: optional - content: |- - In iOS, tvOS, and visionOS, the identifier is a bundle ID, for example, "com.example.app". - - In macOS, the identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID" or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string the device uses to match the code signature of the provider. For example, "com.example.app" for the bundle ID format, or "com.example.app {anchor apple generic}" for the designated requirement format. - key: NetworkRouting title: Network routing details supportedOS: @@ -472,24 +447,6 @@ payloadkeys: default: false content: If `true`, the system disables IKEv2 redirect. If not set, the system redirects an IKEv2 connection when it receives a redirect request from the server. -- key: EnableNATKeepAliveOffload - title: Enable NAT keep alive offload - type: - presence: optional - default: true - content: |- - If `true`, enables NAT keepalive offload for Always On VPN IKEv2 connections. The device sends keepalive packets to maintain NAT mappings for IKEv2 connections that have a NAT on the path. It sends keepalive packets at regular intervals when the device is awake. If `NATKeepAliveOffloadEnable` is `true`, the system offloads keepalive packets to hardware while the device is asleep. - - NAT keepalive offload has an impact on the battery life due to the extra workload during sleep. The default interval for the keepalive offload packets is 20 seconds over Wi-Fi and 110 seconds over Cellular interface. The default NAT keepalive works well on networks with small NAT mapping timeouts but imposes a potential battery impact. If a network has larger NAT mapping timeouts, larger keepalive intervals may be safely used to minimize battery impact. Modify the keepalive interval through the `NATKeepAliveInterval` key. -- key: NATKeepAliveInterval - title: NAT keepalive interval - type: - presence: optional - default: 20 - content: The NAT Keepalive interval for Always On VPN IKEv2 connections. This value - controls the interval that the device sends keepalive offload packets. The minimum - value is 20 seconds. If no key is specified, the default is 20 seconds over Wi-Fi - and 110 seconds over a cellular interface. - key: EnablePFS title: Enable perfect forward secrecy type: @@ -663,32 +620,6 @@ payloadkeys: presence: optional content: A dictionary to use for all VPN types. subkeys: - - key: Protocol - title: DNS protocol - type: - presence: required - rangelist: - - Cleartext - - HTTPS - - TLS - content: The transport protocol to communicate with the DNS server. - - key: ServerURL - title: Server URL - type: - presence: optional - content: The URI template of a DNS-over-HTTPS server, as defined in RFC 8484, - which needs to use the `https://` scheme. The system uses the hostname or address - in the URL to validate the server certificate. If `ServerAddresses` isn't specified, - the system uses the hostname or address in the URL to determine the server addresses. - This key is required if the `DNSProtocol` is `HTTPS`. - - key: ServerName - title: Server name - type: - presence: optional - content: The hostname of a DNS-over-TLS server to validate the server certificate, - as defined in RFC 7858. If `ServerAddresses` isn't specified, the system uses - the hostname to determine the server addresses. This key is required if the - `DNSProtocol` is `TLS`. - key: ServerAddresses title: DNS server addresses type: diff --git a/declarative/declarations/configurations/network.vpn.ipsec.yaml b/declarative/declarations/configurations/network.vpn.ipsec.yaml index 1f1528c..8872d8d 100644 --- a/declarative/declarations/configurations/network.vpn.ipsec.yaml +++ b/declarative/declarations/configurations/network.vpn.ipsec.yaml @@ -45,12 +45,6 @@ payloadkeys: type: presence: required content: The IP address or hostname of the VPN server. -- key: OverridePrimary - title: Override primary connection - type: - presence: optional - default: false - content: If `true`, the system sends all network traffic over VPN. - key: Authentication title: Authentication details type: @@ -308,32 +302,6 @@ payloadkeys: presence: optional content: A dictionary to use for all VPN types. subkeys: - - key: Protocol - title: DNS protocol - type: - presence: required - rangelist: - - Cleartext - - HTTPS - - TLS - content: The transport protocol to communicate with the DNS server. - - key: ServerURL - title: Server URL - type: - presence: optional - content: The URI template of a DNS-over-HTTPS server, as defined in RFC 8484, - which needs to use the `https://` scheme. The system uses the hostname or address - in the URL to validate the server certificate. If `ServerAddresses` isn't specified, - the system uses the hostname or address in the URL to determine the server addresses. - This key is required if the `DNSProtocol` is `HTTPS`. - - key: ServerName - title: Server name - type: - presence: optional - content: The hostname of a DNS-over-TLS server to validate the server certificate, - as defined in RFC 7858. If `ServerAddresses` isn't specified, the system uses - the hostname to determine the server addresses. This key is required if the - `DNSProtocol` is `TLS`. - key: ServerAddresses title: DNS server addresses type: diff --git a/declarative/declarations/configurations/network.vpn.vpn-plugin.yaml b/declarative/declarations/configurations/network.vpn.vpn-plugin.yaml index a2b5af9..a3f0371 100644 --- a/declarative/declarations/configurations/network.vpn.vpn-plugin.yaml +++ b/declarative/declarations/configurations/network.vpn.vpn-plugin.yaml @@ -399,32 +399,6 @@ payloadkeys: presence: optional content: A dictionary to use for all VPN types. subkeys: - - key: Protocol - title: DNS protocol - type: - presence: required - rangelist: - - Cleartext - - HTTPS - - TLS - content: The transport protocol to communicate with the DNS server. - - key: ServerURL - title: Server URL - type: - presence: optional - content: The URI template of a DNS-over-HTTPS server, as defined in RFC 8484, - which needs to use the `https://` scheme. The system uses the hostname or address - in the URL to validate the server certificate. If `ServerAddresses` isn't specified, - the system uses the hostname or address in the URL to determine the server addresses. - This key is required if the `DNSProtocol` is `HTTPS`. - - key: ServerName - title: Server name - type: - presence: optional - content: The hostname of a DNS-over-TLS server to validate the server certificate, - as defined in RFC 7858. If `ServerAddresses` isn't specified, the system uses - the hostname to determine the server addresses. This key is required if the - `DNSProtocol` is `TLS`. - key: ServerAddresses title: DNS server addresses type: diff --git a/mdm/profiles/com.apple.ADCertificate.managed.yaml b/mdm/profiles/com.apple.ADCertificate.managed.yaml index 9d3cf72..afd198c 100644 --- a/mdm/profiles/com.apple.ADCertificate.managed.yaml +++ b/mdm/profiles/com.apple.ADCertificate.managed.yaml @@ -36,7 +36,7 @@ payloadkeys: type: presence: required content: The certificate template for your environment. The default user certificate - value is \`User\`. The default computer certificate value is \`Machine\`. + value is `User`. The default computer certificate value is `Machine`. - key: Description title: Description type: diff --git a/mdm/profiles/com.apple.apn.managed.yaml b/mdm/profiles/com.apple.apn.managed.yaml index fb931af..4d742ac 100644 --- a/mdm/profiles/com.apple.apn.managed.yaml +++ b/mdm/profiles/com.apple.apn.managed.yaml @@ -37,7 +37,7 @@ payloadkeys: - key: apns type: presence: required - content: An array of APN dictionaries (\`APN.DefaultsData.Apns\`). + content: An array of APN dictionaries. subkeys: - key: apnsItem type: diff --git a/mdm/profiles/com.apple.mobiledevice.passwordpolicy.yaml b/mdm/profiles/com.apple.mobiledevice.passwordpolicy.yaml index 2e7040f..4881321 100644 --- a/mdm/profiles/com.apple.mobiledevice.passwordpolicy.yaml +++ b/mdm/profiles/com.apple.mobiledevice.passwordpolicy.yaml @@ -5,6 +5,7 @@ payload: supportedOS: iOS: introduced: '4.0' + deprecated: '27.0' multiple: true supervised: false allowmanualinstall: true @@ -14,6 +15,7 @@ payload: mode: allowed macOS: introduced: '10.7' + deprecated: '27.0' multiple: true devicechannel: true userchannel: true @@ -27,6 +29,7 @@ payload: introduced: n/a visionOS: introduced: '2.0' + deprecated: '27.0' multiple: true supervised: false allowmanualinstall: true @@ -34,6 +37,7 @@ payload: mode: allowed watchOS: introduced: '10.0' + deprecated: '27.0' multiple: true supervised: false allowmanualinstall: true diff --git a/mdm/profiles/com.apple.security.FDERecoveryRedirect.yaml b/mdm/profiles/com.apple.security.FDERecoveryRedirect.yaml index 3c2bf62..c6bf9d0 100644 --- a/mdm/profiles/com.apple.security.FDERecoveryRedirect.yaml +++ b/mdm/profiles/com.apple.security.FDERecoveryRedirect.yaml @@ -40,7 +40,7 @@ payloadkeys: presence: required content: The UUID of a payload within the same profile that contains a certificate used to encrypt the recovery key when the device sends it to the redirected URL. - The referenced payload must be of type \`com.apple.security.pkcs1\`. + The referenced payload must be of type `com.apple.security.pkcs1`. notes: - title: '' content: |-