This commit is contained in:
Cyrus Daboo
2026-08-12 10:12:50 -04:00
parent 97a11a861f
commit 61449b07e2
50 changed files with 992 additions and 239 deletions
+2
View File
@@ -31,6 +31,8 @@ The following schema items are available:
* Other device management data formats
* OpenAPI specifications for select services - `openapi`
* Examples for schema items - `examples`
* This directory contains `declarative`, `mdm`, and `other` directories.
* Each sub-directory contains directories and files that mirror the structure of the corresponding schema directories.
@@ -0,0 +1,50 @@
title: Accessibility Settings
description: The declaration to configure accessibility settings.
payload:
declarationtype: com.apple.configuration.accessibility.settings
supportedOS:
iOS:
introduced: '27.0'
allowed-enrollments:
- supervised
allowed-scopes:
- system
sharedipad:
allowed-scopes: []
macOS:
introduced: '27.0'
allowed-enrollments:
- supervised
allowed-scopes:
- system
- user
tvOS:
introduced: n/a
visionOS:
introduced: '27.0'
allowed-enrollments:
- supervised
allowed-scopes:
- system
watchOS:
introduced: n/a
apply: combined
payloadkeys:
- key: Vision
title: Vision
type: <dictionary>
presence: optional
content: If present, configures vision accessibility settings.
subkeys:
- key: AllowLiveRecognition
title: Allow live recognition
type: <boolean>
presence: optional
default: true
combinetype: boolean-and
content: If `false`, disables the Live Recognition accessibility feature.
examples:
- title: Configuration example
files:
- description: This configuration prevents the use of Live Recognition.
file: examples/declarative/declarations/configurations/accessibility.settings/example1.json
@@ -87,7 +87,7 @@ payloadkeys:
type: <integer>
presence: optional
content: The port number of the EWS server. The system uses this only when this
declaration has a `HostName` value.
declaration has a `HostName` value. Applicable for "EWS" only.
- key: Path
title: Server path
supportedOS:
@@ -98,7 +98,7 @@ payloadkeys:
type: <string>
presence: optional
content: The path of the EWS server. The system uses this only when this declaration
has a `HostName` value.
has a `HostName` value. Applicable for "EWS" only.
- key: ExternalHostName
title: Server external host name
supportedOS:
@@ -108,7 +108,8 @@ payloadkeys:
introduced: n/a
type: <string>
presence: optional
content: The external hostname of the EWS server (or IP address).
content: The external hostname of the EWS server (or IP address). Applicable for
"EWS" only.
- key: ExternalPort
title: Server external port
supportedOS:
@@ -119,7 +120,7 @@ payloadkeys:
type: <integer>
presence: optional
content: The external port number of the EWS server. The system uses this only when
this declaration has a `ExternalHostName` value.
this declaration has an `ExternalHostName` value. Applicable for "EWS" only.
- key: External Path
title: Server external path
supportedOS:
@@ -130,7 +131,7 @@ payloadkeys:
type: <string>
presence: optional
content: The external path of the EWS server. The system uses this only when this
declaration has a `ExternalHostName` value.
declaration has an `ExternalHostName` value. Applicable for "EWS" only.
- key: OAuth
title: Controls use of OAuth
type: <dictionary>
@@ -158,7 +159,7 @@ payloadkeys:
type: <string>
presence: optional
content: The URL that this account uses for token requests with OAuth. The system
ignores this value unless `Enabled` is `true`.
ignores this value unless `Enabled` is `true`. Applicable for "EAS" only.
- key: AuthenticationCredentialsAssetReference
title: Authentication credentials asset reference
type: <string>
@@ -187,19 +188,20 @@ payloadkeys:
introduced: n/a
type: <dictionary>
presence: optional
content: Settings for S/MIME.
content: Settings for S/MIME. Applicable for "EAS" only.
subkeys:
- key: Signing
title: S/MIME signing settings
type: <dictionary>
presence: optional
content: Settings for S/MIME signing.
content: Settings for S/MIME signing. Applicable for "EAS" only.
subkeys:
- key: Enabled
title: Signing enabled
type: <boolean>
presence: required
content: If `true`, the system enables S/MIME signing.
content: If `true`, the system enables S/MIME signing. Applicable for "EAS"
only.
- key: IdentityAssetReference
title: S/MIME signing identity asset reference
type: <string>
@@ -208,32 +210,36 @@ payloadkeys:
- com.apple.asset.credential.identity
- com.apple.asset.credential.scep
presence: optional
content: Specifies the identifier of an asset declaration containing the identity
required for S/MIME signing of messages sent from this account.
content: The identifier of an asset declaration containing the identity required
for S/MIME signing of messages sent from this account. Applicable for "EAS"
only.
- key: UserOverrideable
title: Signing user overrideable
type: <boolean>
presence: optional
default: false
content: If `true`, the user can turn S/MIME signing on or off in Settings.
Applicable for "EAS" only.
- key: IdentityUserOverrideable
title: Signing identity user overrideable
type: <boolean>
presence: optional
default: false
content: If `true`, the user can select an S/MIME signing identity in Settings.
Applicable for "EAS" only.
- key: Encryption
title: S/MIME encryption settings
type: <dictionary>
presence: optional
content: Settings for S/MIME encryption.
content: Settings for S/MIME encryption. Applicable for "EAS" only.
subkeys:
- key: Enabled
title: Encryption by default enabled
type: <boolean>
presence: required
content: If `true`, the system enables S/MIME encryption by default, which the
user can't override if `PerMessageSwitchEnabled` is `false`.
user can't override if `PerMessageSwitchEnabled` is `false`. Applicable for
"EAS" only.
- key: IdentityAssetReference
title: S/MIME encryption identity asset reference
type: <string>
@@ -242,31 +248,32 @@ payloadkeys:
- com.apple.asset.credential.identity
- com.apple.asset.credential.scep
presence: optional
content: Specifies the identifier of an asset declaration containing the identity
required for S/MIME encryption. The system attaches the public certificate
to outgoing mail to allow the user to receive encrypted mail. When the user
sends encrypted mail, the system uses the public certificate to encrypt the
copy of the mail in their Sent mailbox.
content: The identifier of an asset declaration containing the identity required
for S/MIME encryption. The system attaches the public certificate to outgoing
mail to allow the user to receive encrypted mail. When the user sends encrypted
mail, the system uses the public certificate to encrypt the copy of the mail
in their Sent mailbox. Applicable for "EAS" only.
- key: UserOverrideable
title: Encryption by default user overrideable
type: <boolean>
presence: optional
default: false
content: If `true`, the user can turn S/MIME encryption by default on or off
in Settings.
in Settings. Applicable for "EAS" only.
- key: IdentityUserOverrideable
title: Encryption identity user overrideable
type: <boolean>
presence: optional
default: false
content: If `true`, the user can select an S/MIME signing identity in Settings.
Applicable for "EAS" only.
- key: PerMessageSwitchEnabled
title: Per message switch enabled
type: <boolean>
presence: optional
default: false
content: If `true`, the system enables the per-message encryption switch in
the compose view.
the compose view. Applicable for "EAS" only.
- key: MailServiceActive
title: Mail service active
type: <boolean>
@@ -282,7 +289,7 @@ payloadkeys:
presence: optional
default: false
content: If `true`, the system prevents the user from changing the status of the
mail service for this account.
mail service for this account. Applicable for "EAS" only.
- key: ContactsServiceActive
title: Contacts service active
type: <boolean>
@@ -298,7 +305,7 @@ payloadkeys:
presence: optional
default: false
content: If `true`, the system prevents the user from changing the status of the
address book service for this account.
address book service for this account. Applicable for "EAS" only.
- key: CalendarServiceActive
title: Calendar service active
type: <boolean>
@@ -314,7 +321,7 @@ payloadkeys:
presence: optional
default: false
content: If `true`, the system prevents the user from changing the status of the
calendar service for this account.
calendar service for this account. Applicable for "EAS" only.
- key: RemindersServiceActive
title: Reminders service active
type: <boolean>
@@ -330,7 +337,7 @@ payloadkeys:
presence: optional
default: false
content: If `true`, the system prevents the user from changing the status of the
reminders service for this account.
reminders service for this account. Applicable for "EAS" only.
- key: NotesServiceActive
title: Notes service active
type: <boolean>
@@ -346,7 +353,7 @@ payloadkeys:
presence: optional
default: false
content: If `true`, the system prevents the user from changing the status of the
notes service for this account.
notes service for this account. Applicable for "EAS" only.
related-status-items:
- status-items:
- account.list.exchange
@@ -140,27 +140,6 @@ payloadkeys:
- `User`: The app has a user license.
This key needs to be present for App Store apps, when either `AppStoreID` or `BundleID` are present in the configuration.
- key: VPPType
title: VPP type
supportedOS:
iOS:
removed: '18.0'
macOS:
introduced: n/a
visionOS:
introduced: n/a
type: <string>
presence: optional
rangelist:
- Device
- User
content: |-
The type of VPP license that the app uses for installation through the App Store, which is one of the following values:
- `Device`: The app has a VPP device license.
- `User`: The app has a VPP user license.
This key needs to be present to install an app through the App Store.
- key: Version
title: Version
supportedOS:
@@ -108,7 +108,7 @@ payloadkeys:
title: Code directory hash
type: <string>
presence: optional
content: The code signature code directory hash of the binary.
content: The 40 character code signature code directory hash of the binary.
- key: SigningID
title: Signing ID
type: <string>
@@ -118,7 +118,7 @@ payloadkeys:
title: Team ID
type: <string>
presence: optional
content: The code signature team identifier of the binary. Use the value "*APPLE*"
content: The code signature team identifier of the binary. Use the value "\*APPLE\*"
instead of an empty string for Apple binaries with an empty team identifier.
- key: PathPrefix
title: Path prefix
@@ -202,7 +202,7 @@ payloadkeys:
In iOS, the app identifier is a bundle ID, for example, "com.example.app".
In macOS, the app identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID", "Bundle-ID (Team-ID)", or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the app. "Team-ID" is the team identifier from the app's code signature. "Designated-Requirement" is the designated requirement string from the code signature of the app. For example, "com.example.app" for the bundle ID format, "com.example.app (ABCD1234)" for the team ID format, or "com.example.app {anchor apple generic}" for the designated requirement format. The device only applies defaults for an app if its code signature matches the composed identifier.
In macOS, the app identifier is a composed identifier. The format of the composed identifier is "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the app. "Designated-Requirement" is the designated requirement string the device uses to match the code signature of the app. For example, "com.example.app {anchor apple generic}". The device only applies defaults for an app if its code signature matches the composed identifier.
subkeys:
- key: ANY
type: <dictionary>
@@ -359,3 +359,55 @@ examples:
description: This configuration sets various privacy permission defaults for several
apps.
file: examples/declarative/declarations/configurations/app.settings/example2.json
- title: App settings allowlist examples
files:
- tab: Allow apps by code directory hash
description: This configuration allows an app with a specific code directory hash
to run on macOS.
file: examples/declarative/declarations/configurations/app.settings/alr-single-rule-cdhash-base-allowlist-only.json
- tab: Allow apps by team ID
description: This configuration allows any app with a specific team ID to run
on macOS.
file: examples/declarative/declarations/configurations/app.settings/alr-single-rule-team-id-base-allowlist-only.json
- tab: Complex rules in an allowlist
description: This configuration allows any app that matches a set of complex rules
to run on macOS.
file: examples/declarative/declarations/configurations/app.settings/alr-single-rule-complex-allowlist-only.json
- title: App settings denylist examples
files:
- tab: Deny apps by code directory hash
description: This configuration prevents an app with a specific code directory
hash from running on macOS.
file: examples/declarative/declarations/configurations/app.settings/alr-single-rule-cdhash-base-denylist-only.json
- tab: Deny apps by team ID
description: This configuration prevents any app with a specific team ID from
running on macOS.
file: examples/declarative/declarations/configurations/app.settings/alr-single-rule-team-id-base-denylist-only.json
- tab: Deny apps by signing ID
description: This configuration prevents any app with a specific signing ID from
running on macOS.
file: examples/declarative/declarations/configurations/app.settings/alr-single-rule-signing-id-base-denylist-only.json
- tab: Complex rules in a denylist
description: This configuration prevents any app that matches a set of complex
rules from running on macOS.
file: examples/declarative/declarations/configurations/app.settings/alr-single-rule-complex-denylist-only.json
- title: App settings allowlist and denylist examples
files:
- tab: Combine allowlist and denylist rules
description: This configuration allows one set of apps to run, and prevents ome
other apps that would otherwise be allowed from running.
file: examples/declarative/declarations/configurations/app.settings/alr-denylist-and-allowlist-rules.json
- title: App settings managed apps examples
files:
- tab: Always allow managed apps
description: This configuration always allows all managed apps and one other app
to run on macOS.
file: examples/declarative/declarations/configurations/app.settings/alr-single-rule-always-allow-managed-apps.json
- title: App settings WebClips examples
files:
- tab: Allow WebClips on macOS
description: This configuration allows only WebClips to be run on macOS.
file: examples/declarative/declarations/configurations/app.settings/alr-allow-webclips.json
- tab: Deny WebClips on macOS
description: This configuration prevents all WebClips from running on macOS.
file: examples/declarative/declarations/configurations/app.settings/alr-deny-webclips.json
@@ -73,9 +73,26 @@ payloadkeys:
default: true
combinetype: boolean-and
content: If `false`, disables Personalized Handwriting Results.
- key: AllowVisualIntelligence
title: Allow Visual Intelligence
supportedOS:
iOS:
introduced: '27.0'
macOS:
introduced: '27.0'
visionOS:
introduced: n/a
type: <boolean>
presence: optional
default: true
combinetype: boolean-and
content: If `false`, disables Visual Intelligence.
- key: AllowVisualIntelligenceSummary
title: Allow Visual Intelligence Summary
supportedOS:
iOS:
introduced: '26.4'
deprecated: '27.0'
macOS:
introduced: n/a
visionOS:
@@ -84,7 +101,10 @@ payloadkeys:
presence: optional
default: true
combinetype: boolean-and
content: If `false`, disables Visual Intelligence Summary.
content: |-
If `false`, disables Visual Intelligence Summary.
Deprecated: use the `AllowVisualIntelligence` key.
- key: AllowWritingTools
title: Allow Writing Tools
type: <boolean>
@@ -43,6 +43,7 @@ payloadkeys:
title: Add square root
type: <boolean>
presence: required
default: false
combinetype: boolean-or
content: Add the square root button to the basic calculator by replacing the
+/- button. Normally, the square root button is available in scientific mode,
@@ -58,6 +59,7 @@ payloadkeys:
title: Enabled
type: <boolean>
presence: required
default: true
combinetype: boolean-and
content: Controls whether the mode is enabled.
- key: ProgrammerMode
@@ -74,6 +76,7 @@ payloadkeys:
title: Enabled
type: <boolean>
presence: required
default: true
combinetype: boolean-and
content: Controls whether the mode is enabled.
- key: MathNotesMode
@@ -87,6 +90,7 @@ payloadkeys:
title: Enabled
type: <boolean>
presence: required
default: true
combinetype: boolean-and
content: Controls whether the mode is enabled.
- key: InputModes
@@ -100,6 +104,7 @@ payloadkeys:
title: Unit conversion
type: <boolean>
presence: required
default: true
combinetype: boolean-and
content: Configures whether unit conversions are enabled.
- key: RPN
@@ -109,6 +114,7 @@ payloadkeys:
introduced: n/a
type: <boolean>
presence: required
default: true
combinetype: boolean-and
content: Configures whether RPN input is enabled.
- key: SystemBehavior
@@ -121,6 +127,7 @@ payloadkeys:
title: Keyboard suggestions
type: <boolean>
presence: required
default: true
combinetype: boolean-and
content: Controls whether keyboard suggestions include math solutions. This key
is also supported by the keyboard.settings configuration.
@@ -128,6 +135,7 @@ payloadkeys:
title: Math notes
type: <boolean>
presence: required
default: true
combinetype: boolean-and
content: Controls whether Math Notes is allowed in other apps such as Notes.
examples:
@@ -55,7 +55,7 @@ payloadkeys:
In iOS and visionOS, the identifier is a bundle ID, for example, "com.example.app".
In macOS, the identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID" or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string from the code signature of the provider. For example, "com.example.app" for the bundle ID format, or "com.example.app {anchor apple generic}" for the designated requirement format.
In macOS, the identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID" or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string the device uses to match the code signature of the provider. For example, "com.example.app" for the bundle ID format, or "com.example.app {anchor apple generic}" for the designated requirement format.
- key: ProviderConfiguration
title: Provider configuration
type: <dictionary>
@@ -104,7 +104,7 @@ payloadkeys:
content: |-
A list of domain strings used to determine which DNS queries use the DNS server. If not set, all domains use the DNS server.
The system supports a single wildcard (`*`) prefix, but it's not required. For example, both `*.example.com` and `example.com` match against `mydomain.example.com` and `your.domain.example.com`, but don't match against `mydomain-example.com`.
The system supports a single wildcard (`\*`) prefix, but it's not required. For example, both `\*.example.com` and `example.com` match against `mydomain.example.com` and `your.domain.example.com`, but don't match against `mydomain-example.com`.
subkeys:
- key: SupplementalMatchDomainsElement
title: Supplemental match domains element
@@ -179,7 +179,7 @@ payloadkeys:
content: |-
An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device's search domains list.
The system supports a single wildcard (`*`) prefix, but it's not required. For example, both `*.example.com` and `example.com` match against `mydomain.example.com` and `your.domain.example.com`, but don't match against `mydomain-example.com`.
The system supports a single wildcard (`\*`) prefix, but it's not required. For example, both `\*.example.com` and `example.com` match against `mydomain.example.com` and `your.domain.example.com`, but don't match against `mydomain-example.com`.
subkeys:
- key: DNSDomainMatchElement
title: DNS domain match element
@@ -191,7 +191,7 @@ payloadkeys:
content: |-
An array of IP addresses. This rule matches if any of the network's specified DNS servers match any entry in the array.
The system supports matching with a single wildcard. For example, `17.*` matches any DNS server in the 17.0.0.0/8 subnet.
The system supports matching with a single wildcard. For example, `17.\*` matches any DNS server in the 17.0.0.0/8 subnet.
subkeys:
- key: DNSServerAddressMatchElement
title: DNS server address match element
@@ -9,18 +9,20 @@ payload:
- supervised
- device
- user
- local
allowed-scopes:
- system
sharedipad:
allowed-scopes:
- user
- system
macOS:
introduced: '27.0'
allowed-enrollments:
- supervised
- user
- local
allowed-scopes:
- system
- user
tvOS:
introduced: n/a
visionOS:
@@ -29,6 +31,7 @@ payload:
- supervised
- device
- user
- local
allowed-scopes:
- system
watchOS:
@@ -80,8 +83,8 @@ payloadkeys:
type: <string>
presence: required
content: The HTTP header field value for the corresponding header field name.
- key: CredentialAssetReference
title: Credential asset reference
- key: IdentityAssetReference
title: Identity asset reference
type: <string>
assettypes:
- com.apple.asset.credential.identity
@@ -229,7 +229,7 @@ payloadkeys:
content: |-
In iOS, tvOS, and visionOS, the identifier is a bundle ID, for example, "com.example.app".
In macOS, the identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID", "Bundle-ID (Team-ID)", or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Team-ID" is the team identifier from the provider's code signature. "Designated-Requirement" is the designated requirement string from the code signature of the provider. For example, "com.example.app" for the bundle ID format, "com.example.app (ABCD1234)" for the team ID format, or "com.example.app {anchor apple generic}" for the designated requirement format.
In macOS, the identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID", "Bundle-ID (Team-ID)", or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Team-ID" is the team identifier from the provider's code signature. "Designated-Requirement" is the designated requirement string the device uses to match the code signature of the provider. For example, "com.example.app" for the bundle ID format, "com.example.app (ABCD1234)" for the team ID format, or "com.example.app {anchor apple generic}" for the designated requirement format.
- key: Idle
title: Disconnect on idle settings.
type: <dictionary>
@@ -378,7 +378,7 @@ payloadkeys:
presence: optional
content: |-
An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device's search domains list.
The system supports a wildcard (`*`) prefix. For example, `*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`.
The system supports a wildcard (`\*`) prefix. For example, `\*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`.
subkeys:
- key: DNSDomainMatchElement
title: DNS domain match element
@@ -389,7 +389,7 @@ payloadkeys:
presence: optional
content: |-
An array of IP addresses. This rule matches if any of the network's specified DNS servers match any entry in the array.
The system supports matching with a single wildcard. For example, `17.*` matches any DNS server in the `17.0.0.0/8` subnet.
The system supports matching with a single wildcard. For example, `17.\*` matches any DNS server in the `17.0.0.0/8` subnet.
subkeys:
- key: DNSServerAddressMatchElement
title: DNS server address match element
@@ -200,7 +200,7 @@ payloadkeys:
content: |-
In iOS, tvOS, and visionOS, the identifier is a bundle ID, for example, "com.example.app".
In macOS, the identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID" or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string from the code signature of the provider. For example, "com.example.app" for the bundle ID format, or "com.example.app {anchor apple generic}" for the designated requirement format.
In macOS, the identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID" or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string the device uses to match the code signature of the provider. For example, "com.example.app" for the bundle ID format, or "com.example.app {anchor apple generic}" for the designated requirement format.
- key: NetworkRouting
title: Network routing details
supportedOS:
@@ -409,7 +409,7 @@ payloadkeys:
presence: optional
content: |-
An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device's search domains list.
The system supports a wildcard (`*`) prefix. For example, `*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`.
The system supports a wildcard (`\*`) prefix. For example, `\*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`.
subkeys:
- key: DNSDomainMatchElement
title: DNS domain match element
@@ -420,7 +420,7 @@ payloadkeys:
presence: optional
content: |-
An array of IP addresses. This rule matches if any of the network's specified DNS servers match any entry in the array.
The system supports matching with a single wildcard. For example, `17.*` matches any DNS server in the `17.0.0.0/8` subnet.
The system supports matching with a single wildcard. For example, `17.\*` matches any DNS server in the `17.0.0.0/8` subnet.
subkeys:
- key: DNSServerAddressMatchElement
title: DNS server address match element
@@ -259,7 +259,7 @@ payloadkeys:
presence: optional
content: |-
An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device's search domains list.
The system supports a wildcard (`*`) prefix. For example, `*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`.
The system supports a wildcard (`\*`) prefix. For example, `\*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`.
subkeys:
- key: DNSDomainMatchElement
title: DNS domain match element
@@ -270,7 +270,7 @@ payloadkeys:
presence: optional
content: |-
An array of IP addresses. This rule matches if any of the network's specified DNS servers match any entry in the array.
The system supports matching with a single wildcard. For example, `17.*` matches any DNS server in the `17.0.0.0/8` subnet.
The system supports matching with a single wildcard. For example, `17.\*` matches any DNS server in the `17.0.0.0/8` subnet.
subkeys:
- key: DNSServerAddressMatchElement
title: DNS server address match element
@@ -158,7 +158,7 @@ payloadkeys:
In iOS, tvOS, and visionOS, the identifier is a bundle ID, for example, "com.example.app".
In macOS, the identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID" or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string from the code signature of the provider. For example, "com.example.app" for the bundle ID format, or "com.example.app {anchor apple generic}" for the designated requirement format.
In macOS, the identifier is a composed identifier. The format of the composed identifier is either "Bundle-ID" or "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string the device uses to match the code signature of the provider. For example, "com.example.app" for the bundle ID format, or "com.example.app {anchor apple generic}" for the designated requirement format.
- key: NetworkRouting
title: Network routing details
supportedOS:
@@ -350,7 +350,7 @@ payloadkeys:
presence: optional
content: |-
An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device's search domains list.
The system supports a wildcard (`*`) prefix. For example, `*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`.
The system supports a wildcard (`\*`) prefix. For example, `\*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`.
subkeys:
- key: DNSDomainMatchElement
title: DNS domain match element
@@ -361,7 +361,7 @@ payloadkeys:
presence: optional
content: |-
An array of IP addresses. This rule matches if any of the network's specified DNS servers match any entry in the array.
The system supports matching with a single wildcard. For example, `17.*` matches any DNS server in the `17.0.0.0/8` subnet.
The system supports matching with a single wildcard. For example, `17.\*` matches any DNS server in the `17.0.0.0/8` subnet.
subkeys:
- key: DNSServerAddressMatchElement
title: DNS server address match element
@@ -35,7 +35,7 @@ payloadkeys:
type: <dictionary>
presence: optional
content: |-
The dictionary of managed extensions settings. Each key in the dictionary represents a composed identifier for a specific managed extension, or you can specify a single "*" character to match any extension. The dictionary values represent the settings that Safari applies to each extension that matches the key. In order for the extension to be managed, its host app needs to be present on the device.
The dictionary of managed extensions settings. Each key in the dictionary represents a composed identifier for a specific managed extension, or you can specify a single "\*" character to match any extension. The dictionary values represent the settings that Safari applies to each extension that matches the key. In order for the extension to be managed, its host app needs to be present on the device.
The composed identifier of a managed extension uses the format "Identifier (TeamIdentifier)", for example "com.example.app (ABCD1234)". Use `codesign -dv <path_to_appex>` to show the information you need to generate this string on macOS, using the path to the extension bundle located in the "PlugIns" folder inside the app bundle. For other platforms, request this information from the app developer.
subkeys:
@@ -57,7 +57,7 @@ payloadkeys:
- AlwaysOff
combinetype: enum-last
content: |-
Controls whether an extension is allowed. The device uses this key when the extension identifier is a composed identifier or a single "*" character.
Controls whether an extension is allowed. The device uses this key when the extension identifier is a composed identifier or a single "\*" character.
* `Allowed` - The user is allowed to turn the extension on or off.
* `AlwaysOn` - The extension will always be on.
* `AlwaysOff` - The extension will always be off.
@@ -71,7 +71,7 @@ payloadkeys:
- AlwaysOff
combinetype: enum-last
content: |-
Controls whether an extension is allowed in Private Browsing. The device uses this key when the extension identifier is a composed identifier or a single "*" character.
Controls whether an extension is allowed in Private Browsing. The device uses this key when the extension identifier is a composed identifier or a single "\*" character.
* `Allowed` - The user is allowed to turn the extension on or off in Private Browsing.
* `AlwaysOn` - The extension will always be on in Private Browsing if the extension is on outside of Private Browsing.
* `AlwaysOff` - The extension will never be on in Private Browsing.
@@ -214,7 +214,7 @@ payloadkeys:
- A specific domain such as "example.com" or "www.example.com". The permission defaults apply to that website only.
- A wildcard domain that uses a single "\*" character as a prefix for the domain, such as "\*example.com". The permission defaults apply to both the exact domain "example.com", and any sub-domains such as "www.example.com". It won't match other domains with a similar string suffix such as "myexample.com".
When multiple patterns match a website, Safari uses the most precise pattern. For example, for the website "www.example.com", if rules "www.example.com" and "*example.com" match, Safari uses the former.
When multiple patterns match a website, Safari uses the most precise pattern. For example, for the website "www.example.com", if rules "www.example.com" and "\*example.com" match, Safari uses the former.
subkeys:
- key: ANY
type: <dictionary>
@@ -162,7 +162,7 @@ payloadkeys:
In iOS and visionOS, the identifier is a bundle ID, for example, "com.example.app".
In macOS, the identifier is a composed identifier. The format of the composed identifier is "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string from the code signature of the provider. For example, "com.example.app {anchor apple generic}".
In macOS, the identifier is a composed identifier. The format of the composed identifier is "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string the device uses to match the code signature of the provider. For example, "com.example.app {anchor apple generic}".
- key: Packets
title: Packet filter details
supportedOS:
@@ -187,7 +187,7 @@ payloadkeys:
content: |-
The packet provider identifier. This string identifies the filter data provider when the filter starts running. Required when Enabled is true.
The identifier is a composed identifier. The format of the composed identifier is "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string from the code signature of the provider. For example, "com.example.app {anchor apple generic}".
The identifier is a composed identifier. The format of the composed identifier is "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string the device uses to match the code signature of the provider. For example, "com.example.app {anchor apple generic}".
- key: URLs
title: URL filter details
supportedOS:
@@ -219,7 +219,7 @@ payloadkeys:
In iOS, the identifier is a bundle ID, for example, "com.example.app".
In macOS, the identifier is a composed identifier. The format of the composed identifier is "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string from the code signature of the provider. For example, "com.example.app {anchor apple generic}".
In macOS, the identifier is a composed identifier. The format of the composed identifier is "Bundle-ID {Designated-Requirement}". "Bundle-ID" is the bundle identifier string of the provider. "Designated-Requirement" is the designated requirement string the device uses to match the code signature of the provider. For example, "com.example.app {anchor apple generic}".
- key: PIR
title: Private information retrieval server settings.
type: <dictionary>
@@ -0,0 +1,10 @@
{
"Type": "com.apple.configuration.accessibility.settings",
"Identifier": "119D31F8-E3A2-454A-A019-FD3F05A008D3",
"ServerToken": "DC31F056-0ADE-4D01-8E63-A7CA093EC7CD",
"Payload": {
"Vision": {
"AllowLiveRecognition": false
}
}
}
@@ -0,0 +1,15 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4B1",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC193B",
"Payload": {
"Allowed": {
"AllowedBinaries": [
{
"TeamID": "*APPLE*",
"SigningID": "com.apple.Safari.WebApp"
}
]
}
}
}
@@ -0,0 +1,14 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4B2",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC193C",
"Payload": {
"Allowed": {
"DeniedBinaries": [
{
"SigningID": "com.apple.Safari.WebApp"
}
]
}
}
}
@@ -0,0 +1,30 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4B3",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC193D",
"Payload": {
"Allowed": {
"AllowedBinaries": [
{
"TeamID": "XXXXXXXXXX",
"CDHash": "90bc96cd95be55c12e7d9b1611cbc677610bb70c",
"SigningID": "com.example.app",
"PathPrefix": "/Applications/Example.app",
"SigningState": "All"
},
{
"TeamID": "*APPLE*",
"SigningID": "com.apple.iCal"
}
],
"DeniedBinaries": [
{
"SigningID": "com.apple.iCal"
},
{
"CDHash": "03552d8140254d0c190af06f1e470dbc5ded53ba"
}
]
}
}
}
@@ -0,0 +1,16 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4B4",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC193E",
"Payload": {
"Allowed": {
"AlwaysAllowManagedApps": true,
"AllowedBinaries": [
{
"TeamID": "XXXXXXXXXX",
"SigningID": "com.example.app"
}
]
}
}
}
@@ -0,0 +1,14 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4B5",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC193F",
"Payload": {
"Allowed": {
"AllowedBinaries": [
{
"CDHash": "90bc96cd95be55c12e7d9b1611cbc677610bb70c"
}
]
}
}
}
@@ -0,0 +1,14 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4B6",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC1940",
"Payload": {
"Allowed": {
"DeniedBinaries": [
{
"CDHash": "90bc96cd95be55c12e7d9b1611cbc677610bb70c"
}
]
}
}
}
@@ -0,0 +1,18 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4B7",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC1941",
"Payload": {
"Allowed": {
"AllowedBinaries": [
{
"TeamID": "XXXXXXXXXX",
"CDHash": "90bc96cd95be55c12e7d9b1611cbc677610bb70c",
"SigningID": "com.example.app",
"PathPrefix": "/Applications/Example.app",
"SigningState": "All"
}
]
}
}
}
@@ -0,0 +1,18 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4B8",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC1942",
"Payload": {
"Allowed": {
"DeniedBinaries": [
{
"TeamID": "XXXXXXXXXX",
"CDHash": "90bc96cd95be55c12e7d9b1611cbc677610bb70c",
"SigningID": "com.example.app",
"PathPrefix": "/Applications/Example.app",
"SigningState": "All"
}
]
}
}
}
@@ -0,0 +1,14 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4B9",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC1943",
"Payload": {
"Allowed": {
"DeniedBinaries": [
{
"SigningID": "com.example.app"
}
]
}
}
}
@@ -0,0 +1,14 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4BA",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC1944",
"Payload": {
"Allowed": {
"AllowedBinaries": [
{
"TeamID": "XXXXXXXXXX"
}
]
}
}
}
@@ -0,0 +1,14 @@
{
"Type": "com.apple.configuration.app.settings",
"Identifier": "AF389B6F-5784-4DB6-BEFF-EA6D689BD4BB",
"ServerToken": "A5CA3371-559E-44B4-B9ED-A0A7DFEC1945",
"Payload": {
"Allowed": {
"DeniedBinaries": [
{
"TeamID": "XXXXXXXXXX"
}
]
}
}
}
@@ -3,8 +3,7 @@
"Identifier": "EB13EE2B-5D63-4EBA-810F-5B81D07F5017",
"ServerToken": "E180CA9A-F089-4FA3-BBDF-94CC159C4AE8",
"Payload": {
"ExtensionIdentifier": "com.example.sso.extension",
"TeamIdentifier": "ABCDE12345",
"ExtensionComposedIdentifier": "com.example.sso.extension (ABCDE12345)",
"Type": "Credential",
"Realm": "EXAMPLE.COM",
"Hosts": [
@@ -3,8 +3,7 @@
"Identifier": "2A3B4C5D-6E7F-8A9B-0C1D-2E3F4A5B6C7D",
"ServerToken": "F1E2D3C4-B5A6-7890-ABCD-EF1234567890",
"Payload": {
"ExtensionIdentifier": "com.example.sso.extension",
"TeamIdentifier": "ABCDE12345",
"ExtensionComposedIdentifier": "com.example.sso.extension",
"Type": "Redirect",
"URLs": [
"https://login.example.com/auth",
+2 -2
View File
@@ -220,11 +220,11 @@ notes:
In addition to sending the initial `TokenUpdate` message, the device may send additional `TokenUpdate` messages to the check-in server at any time while it has a valid MDM enrollment.
The use of `PushMagic` constrains the device to a unique MDM relationship. When a user removes the MDM profile, the device no longer listens to the former relationship, even if the user reestablishes a management relationship with the same server topic. Note that only the push topic is the same in this case; the server's address might change. This also helps when a user restores a device from backup that contains an older relationship. The use of `PushMagic` also ensures that the same organization owns both the server that receives the `CheckIn` message and the computer sending the push notifications. This is important because there's no way of knowing if the push topic belongs to the owner of the check-in server. It's conceivable that Apple might revoke a push token for one party, only to have that party reenroll people from some other topic that's actively pushing. The fact that all MDM push topics reside in the namespace `com.apple.mgmt.*` helps prevent this.
The use of `PushMagic` constrains the device to a unique MDM relationship. When a user removes the MDM profile, the device no longer listens to the former relationship, even if the user reestablishes a management relationship with the same server topic. Note that only the push topic is the same in this case; the server's address might change. This also helps when a user restores a device from backup that contains an older relationship. The use of `PushMagic` also ensures that the same organization owns both the server that receives the `CheckIn` message and the computer sending the push notifications. This is important because there's no way of knowing if the push topic belongs to the owner of the check-in server. It's conceivable that Apple might revoke a push token for one party, only to have that party reenroll people from some other topic that's actively pushing. The fact that all MDM push topics reside in the namespace `com.apple.mgmt.\*` helps prevent this.
The `PushMagic` or `UnlockToken` fields of subsequent `TokenUpdate` messages may be identical to those in previous messages, or may be different (and may differ in size from previous values). If different, the server needs to update its record for the device to the new values in the message. Failure to do so results in the server being unable to send push notifications or perform passcode resets.
Although a device can send the `TokenUpdate` message multiple times, it might send it only once if the values in the message never change. Ensure your implementation doesn't rely on repeated messages to update lost server-side data or to recover from a failure to process a previous `TokenUpdate` message. Also note that `UnlockToken` is optional. Don't treat the absence of an `UnlockToken` in a `TokenUpdate` message as an invalidation of a previously received `UnlockToken`.
> Note:
> The topic string for the MDM check-in protocol needs to start with `com.apple.mgmt.*` where `*` is a unique suffix.
> The topic string for the MDM check-in protocol needs to start with `com.apple.mgmt.\*` where `\*` is a unique suffix.
@@ -163,9 +163,9 @@ payloadkeys:
type: <array>
presence: optional
content: |-
Specifies the policies for the app via the Accessibility subsystem. This profile deprecated its ability to grant access as of macOS 26.2, and removes that ability in macOS 27.0.
Specifies the policies for the app via the Accessibility subsystem. In macOS 27.0, the device shows a non-blocking notification for each application when this setting is applied, and it allows the user to make changes to the setting in the System Settings app.
Deprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.
Deprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app.settings` configuration.
subkeytype: Identity
subkeys: *id001
- key: PostEvent
@@ -246,7 +246,7 @@ payloadkeys:
content: |-
Allows the application to use the system Speech Recognition facility and to send speech data to Apple.
Deprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.
Deprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app.settings` configuration.
subkeytype: Identity
subkeys: *id001
- key: SystemPolicyDesktopFolder
@@ -322,7 +322,7 @@ payloadkeys:
content: |-
Specifies the policies for the app to access Bluetooth devices.
Deprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.
Deprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app.settings` configuration.
subkeytype: Identity
subkeys: *id001
examples:
+23 -44
View File
@@ -3299,6 +3299,29 @@ payloadkeys:
default: true
content: If `false`, the system disables Shared Photo Stream. Support for this restriction
on unsupervised devices is deprecated.
- key: allowSiriAI
title: Allow Siri Apple Intelligence integration
supportedOS:
iOS:
introduced: '27.0'
deprecated: '27.0'
sharedipad:
mode: forbidden
macOS:
introduced: n/a
tvOS:
introduced: n/a
visionOS:
introduced: n/a
watchOS:
introduced: n/a
type: <boolean>
presence: optional
default: true
content: |-
If `false`, the system disables Apple Intelligence integration in Siri.
Deprecated: use the declarative management `com.apple.configuration.siri.settings` configuration.
- key: allowSpellCheck
title: Allow spell check
supportedOS:
@@ -4195,28 +4218,6 @@ payloadkeys:
default: false
content: If `true`, then the system bypasses the presentation of a screen capture
alert.
- key: ForceCaptivePortalConnectionFromLockScreen
title: Enable captive WiFi portal for login and unlock
supportedOS:
iOS:
introduced: n/a
macOS:
introduced: '27.0'
supervised: true
allowmanualinstall: false
userenrollment:
mode: forbidden
tvOS:
introduced: n/a
visionOS:
introduced: n/a
watchOS:
introduced: n/a
type: <boolean>
presence: optional
default: false
content: If `true`, the system allows use of the captive WiFi portal at login or
unlock.
- key: forceClassroomAutomaticallyJoinClasses
supportedOS:
iOS:
@@ -4529,28 +4530,6 @@ payloadkeys:
presence: optional
default: false
content: If `true`, the system forces a paired Apple Watch to use Wrist Detection.
- key: ForceWifiConfigurationOnLockScreen
title: Enable WiFi network selection for login and unlock
supportedOS:
iOS:
introduced: n/a
macOS:
introduced: '27.0'
supervised: true
allowmanualinstall: false
userenrollment:
mode: forbidden
tvOS:
introduced: n/a
visionOS:
introduced: n/a
watchOS:
introduced: n/a
type: <boolean>
presence: optional
default: false
content: If `true`, the system allows the user to select WiFi networks at login
or unlock.
- key: forceWiFiPowerOn
title: Disallow Wi-Fi from being turned off
supportedOS:
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '11.0'
deprecated: '27.0'
multiple: false
supervised: false
allowmanualinstall: false
@@ -16,6 +17,7 @@ payload:
mode: allowed
macOS:
introduced: '10.15'
deprecated: '27.0'
multiple: false
devicechannel: true
userchannel: false
@@ -28,6 +30,7 @@ payload:
introduced: n/a
visionOS:
introduced: '1.1'
deprecated: '27.0'
multiple: false
supervised: false
allowmanualinstall: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '14.0'
deprecated: '27.0'
multiple: true
supervised: false
allowmanualinstall: true
@@ -16,6 +17,7 @@ payload:
mode: forbidden
macOS:
introduced: '11.0'
deprecated: '27.0'
multiple: true
devicechannel: true
userchannel: false
@@ -28,6 +30,7 @@ payload:
introduced: n/a
visionOS:
introduced: '1.0'
deprecated: '27.0'
multiple: true
supervised: false
allowmanualinstall: true
@@ -109,7 +112,7 @@ payloadkeys:
content: |-
A list of domain strings used to determine which DNS queries use the DNS server. If not set, all domains use the DNS server.
The system supports a single wildcard (`*`) prefix, but it's not required. For example, both `*.example.com` and `example.com` match against `mydomain.example.com` and `your.domain.example.com`, but don't match against `mydomain-example.com`.
The system supports a single wildcard (`\*`) prefix, but it's not required. For example, both `\*.example.com` and `example.com` match against `mydomain.example.com` and `your.domain.example.com`, but don't match against `mydomain-example.com`.
subkeys:
- key: SupplementalMatchDomainsElement
title: Supplemental match domains element
@@ -184,7 +187,7 @@ payloadkeys:
content: |-
An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device's search domains list.
The system supports a single wildcard (`*`) prefix, but it's not required. For example, both `*.example.com` and `example.com` match against `mydomain.example.com` and `your.domain.example.com`, but don't match against `mydomain-example.com`.
The system supports a single wildcard (`\*`) prefix, but it's not required. For example, both `\*.example.com` and `example.com` match against `mydomain.example.com` and `your.domain.example.com`, but don't match against `mydomain-example.com`.
subkeys:
- key: DNSDomainMatchElement
title: DNS domain match element
@@ -196,7 +199,7 @@ payloadkeys:
content: |-
An array of IP addresses. This rule matches if any of the network's specified DNS servers match any entry in the array.
The system supports matching with a single wildcard. For example, `17.*` matches any DNS server in the 17.0.0.0/8 subnet.
The system supports matching with a single wildcard. For example, `17.\*` matches any DNS server in the 17.0.0.0/8 subnet.
subkeys:
- key: DNSServerAddressMatchElement
title: DNS server address match element
+1 -1
View File
@@ -139,7 +139,7 @@ notes:
Trailing slashes are ignored.
If a domain string contains a port number, the system considers only addresses that specify that port number managed. Otherwise, the system matches the domain without regard to the port number specified. For example, the pattern `*.example.com:8080` matches `http://site.example.com:8080/page.html` but not `http://site.example.com/page.html`, while the pattern `*.example.com` matches both URLs.
If a domain string contains a port number, the system considers only addresses that specify that port number managed. Otherwise, the system matches the domain without regard to the port number specified. For example, the pattern `\*.example.com:8080` matches `http://site.example.com:8080/page.html` but not `http://site.example.com/page.html`, while the pattern `\*.example.com` matches both URLs.
examples:
- title: Profile example
files:
-10
View File
@@ -28,16 +28,6 @@ payloadkeys:
presence: optional
default: false
content: If `true`, the system disables the Finder's burn support.
- key: InterfaceLevel
supportedOS:
macOS:
removed: '10.15'
type: <string>
presence: optional
rangelist:
- Simple
- Full
content: Specifies whether Finder should operate in Simple or Full mode.
- key: ProhibitConnectTo
type: <boolean>
presence: optional
+22
View File
@@ -198,6 +198,28 @@ payloadkeys:
presence: optional
content: An optional user password to set up auto login. This must match the `AutologinUsername`
user's current password.
- key: ForceWifiConfigurationOnLockScreen
title: Enable WiFi network selection for login and unlock
supportedOS:
macOS:
introduced: '27.0'
allowmanualinstall: false
type: <boolean>
presence: optional
default: false
content: If `true`, the system allows the user to select WiFi networks at login
or unlock.
- key: ForceCaptivePortalConnectionFromLockScreen
title: Enable captive WiFi portal for login and unlock
supportedOS:
macOS:
introduced: '27.0'
allowmanualinstall: false
type: <boolean>
presence: optional
default: false
content: If `true`, the system allows use of the captive WiFi portal at login or
unlock.
examples:
- title: Profile example
files:
@@ -43,7 +43,7 @@ payloadkeys:
Each string in the `AppIdentifierMatches` array may either be an exact app identifier match (for example, `com.mycompany.myapp`) or it may specify a prefix match for the bundle ID by using the \* wildcard character. If used, this character must appear after a period (.) and may only appear once, at the end of the string; for example, `com.mycompany.*`.
Each string in the `AppIdentifierMatches` array may either be an exact app identifier match (for example, `com.mycompany.myapp`) or it may specify a prefix match for the bundle ID by using the \* wildcard character. If used, this character must appear after a period (.) and may only appear once, at the end of the string; for example, `com.mycompany.\*`.
subkeys:
- key: AppIdentifierMatchesItem
type: <string>
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '17.0'
deprecated: '27.0'
multiple: true
supervised: false
allowmanualinstall: true
@@ -16,6 +17,7 @@ payload:
mode: allowed
macOS:
introduced: '14.0'
deprecated: '27.0'
multiple: true
devicechannel: true
userchannel: true
@@ -32,6 +34,7 @@ payload:
allowmanualinstall: true
visionOS:
introduced: '1.0'
deprecated: '27.0'
multiple: true
supervised: false
allowmanualinstall: true
+1 -1
View File
@@ -22,7 +22,7 @@ payload:
introduced: n/a
watchOS:
introduced: n/a
content: Specifies *user* screen saver settings. (Settings for Login Window screen
content: Specifies user screen saver settings. (Settings for Login Window screen
saver use a different payload)
payloadkeys:
- key: moduleName
@@ -23,7 +23,7 @@ payload:
watchOS:
introduced: n/a
content: |-
*** This payload will be ignored on macOS 10.13 and later. See "com.apple.security.FDERecoveryKeyEscrow" payload. ***
This payload will be ignored on macOS 10.13 and later. See "com.apple.security.FDERecoveryKeyEscrow" payload.
Old notes:
Once installed, this payload will cause any FDE (Full Disk Encryption) recovery keys to be redirected to the specified URL instead of being sent to Apple. This will require sites to implement their own HTTPS server that will receive the recovery keys via a POST request. Details of the data sent to the server will be provided in a different document.
Notes:
@@ -58,28 +58,6 @@ payloadkeys:
type: <boolean>
presence: required
content: If `true`, the system allows connections for the app.
- key: EnableLogging
supportedOS:
macOS:
introduced: '12.0'
deprecated: '15.0'
removed: '15.0'
type: <boolean>
presence: optional
content: If `true`, the system enables logging.
- key: LoggingOption
supportedOS:
macOS:
introduced: '12.0'
deprecated: '15.0'
removed: '15.0'
type: <string>
presence: optional
rangelist:
- throttled
- brief
- detail
content: The type of logging.
- key: AllowSigned
supportedOS:
macOS:
+1 -1
View File
@@ -69,7 +69,7 @@ payloadkeys:
content: |-
The list of app identifiers that the system allows to use this login. If this field missing, the system matches all app identifiers with this login.
Don't set an empty array. The array needs to contain strings that match App Bundle IDs. These strings can be exact matches such as `com.mycompany.myapp`, or they may specify a prefix match on the Bundle ID by using the `*` wildcard character. The wildcard character needs to appear after a period (`.`), and may only appear once, at the end of the string, for example, `com.mycompany.*`. When you provide a wildcard, the system grants access to the account to any app with a Bundle ID that begins with the prefix.
Don't set an empty array. The array needs to contain strings that match App Bundle IDs. These strings can be exact matches such as `com.mycompany.myapp`, or they may specify a prefix match on the Bundle ID by using the `\*` wildcard character. The wildcard character needs to appear after a period (`.`), and may only appear once, at the end of the string, for example, `com.mycompany.\*`. When you provide a wildcard, the system grants access to the account to any app with a Bundle ID that begins with the prefix.
subkeys:
- key: AppIdentifierMatchesItem
type: <string>
+2 -2
View File
@@ -483,7 +483,7 @@ payloadkeys:
presence: optional
content: |-
An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device's search domains list.
The system supports a wildcard (`*`) prefix. For example, `*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`.
The system supports a wildcard (`\*`) prefix. For example, `\*.example.com` matches against either `mydomain.example.com` or `yourdomain.example.com`.
subkeys:
- key: DNSDomainMatchElement
title: DNS domain match element
@@ -494,7 +494,7 @@ payloadkeys:
presence: optional
content: |-
An array of IP addresses. This rule matches if any of the network's specified DNS servers match any entry in the array.
The system supports matching with a single wildcard. For example, `17.*` matches any DNS server in the `17.0.0.0/8` subnet.
The system supports matching with a single wildcard. For example, `17.\*` matches any DNS server in the `17.0.0.0/8` subnet.
subkeys:
- key: DNSServerAddressMatchElement
title: DNS server address match element
+1 -1
View File
@@ -207,7 +207,7 @@ payloadkeys:
content: |-
The list of accepted server certificate common names. If a server presents a certificate that isn't in this list, the system doesn't trust it.
If you specify this property, the system disables dynamic trust (the certificate dialog) unless you also specify 'TLSAllowTrustExceptions' with the value 'true'.
If necessary, use a single "*" character to specify a wildcard for an individual component of the name, such as 'wpa.*.example.com'.
If necessary, use a single "\*" character to specify a wildcard for an individual component of the name, such as 'wpa.\*.example.com'.
subkeys:
- key: TLSTrustedServerName
title: Individual trusted TLS server name
+513
View File
@@ -0,0 +1,513 @@
{
"openapi": "3.0.1",
"info": {
"title": "Apple Cache Server Metrics Report",
"description": "Metrics data collected from Apple Content Cache servers.",
"version": "1"
},
"servers": [
{
"url": "{scheme}://{host}",
"description": "Metrics ingest endpoint (host configured per deployment)",
"variables": {
"scheme": {
"default": "https",
"enum": [
"https",
"http"
]
},
"host": {
"default": "metrics.example.invalid",
"description": "Hostname or IP of the metrics ingest service"
}
}
}
],
"paths": {
"/metrics": {
"post": {
"operationId": "postCacheServerMetricsReport",
"summary": "Submit a cache server metrics report",
"description": "Upload a single CacheServerMetricsReport document describing the state of an Apple Content Cache server and its byte/replies/requests counters since the last report.",
"requestBody": {
"required": true,
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/CacheServerMetricsReport"
}
}
}
},
"responses": {
"202": {
"description": "Report accepted for asynchronous ingest."
},
"400": {
"description": "Malformed report (failed schema validation)."
},
"401": {
"description": "Authentication or client-certificate validation failed."
},
"415": {
"description": "Unsupported media type (expects application/json)."
}
}
}
}
},
"components": {
"schemas": {
"CacheServerMetricsReport": {
"type": "object",
"required": [
"version",
"reportDate",
"hostname",
"hardware",
"serverGUID"
],
"properties": {
"version": {
"type": "integer",
"description": "Schema version for tracking migrations and evolution"
},
"reportDate": {
"type": "string",
"format": "date-time",
"description": "Collection timestamp in ISO 8601 format - PRIMARY TIME INDEX"
},
"creationDate": {
"type": "string",
"format": "date-time",
"description": "Collection timestamp in ISO 8601 format for byte count metrics (60-second cadence, only emitted when values change)"
},
"hostname": {
"type": "string",
"description": "Hostname of the cache"
},
"hardware": {
"type": "string",
"description": "Machine model identifier (e.g. MacBookPro7,1)"
},
"memorySize": {
"type": "integer",
"description": "Total RAM in bytes on the cache machine"
},
"hardwareUUID": {
"type": "string",
"description": "Hardware UUID"
},
"serialNumber": {
"type": "string",
"description": "Hardware serial number"
},
"buildVersion": {
"type": "string",
"description": "The software version of the cache"
},
"connectedClients": {
"type": "integer",
"description": "Number of currently connected clients"
},
"uniqueClients": {
"type": "integer",
"description": "Count of unique clients in the collection period"
},
"peakClients": {
"type": "integer",
"description": "Maximum number of simultaneously connected clients during the period"
},
"numberOfCacheEntries": {
"type": "integer",
"description": "Total number of cached files/objects"
},
"transactions": {
"type": "integer",
"description": "Total transaction count since last metric collection"
},
"recentErrors": {
"type": "string",
"description": "Array of recent errors as 'errorCode : reasonCode : count' comma separated triples"
},
"cpuLoad": {
"type": "number",
"description": "Number of threads ready to run (corresponds to the load average reported via top/uptime)"
},
"reportPeriod": {
"type": "integer",
"description": "Period of the overall report in seconds"
},
"assetsLessThan10M": {
"type": "integer",
"description": "Assets in the cache that are less than 10 MB in size"
},
"assetsFrom10to100M": {
"type": "integer",
"description": "Assets in the cache that are between 10 MB and 100 MB in size"
},
"assetsFrom100Mto1G": {
"type": "integer",
"description": "Assets in the cache that are between 100 MB and 1 GB in size"
},
"assetsMoreThan1G": {
"type": "integer",
"description": "Assets in the cache that are greater than 1 GB in size"
},
"averageAssetSizeInM": {
"type": "integer",
"description": "Average size of asset files in the cache in megabytes"
},
"serverGUID": {
"type": "string",
"format": "uuid",
"description": "Server unique identifier - UUID string (e.g. 13D4D110-B2B7-4F26-8E25-CD22E58C00EE)"
},
"registrationState": {
"type": "integer",
"enum": [
-1,
0,
1
],
"description": "Cache registration status with Apple: Registration Failed (-1), Registration Pending (0), Registration Succeeded (1)"
},
"registrationStarted": {
"type": "string",
"format": "date-time",
"description": "[Optional] Last time registration was attempted (only present when not registered)"
},
"registrationError": {
"type": "integer",
"description": "[Optional] Error code from last registration attempt with Apple servers (0 = success)"
},
"actualCacheUsed": {
"type": "integer",
"description": "Actual bytes stored (real content) for bandwidth calculations (macOS 10.15+) - distinct from cacheUsed"
},
"startupStatus": {
"type": "boolean",
"description": "Cache startup completion status (true = finished startup OK)"
},
"restrictedMedia": {
"type": "boolean",
"description": "Media restrictions enabled for content filtering"
},
"tetheratorStatus": {
"type": "integer",
"enum": [
-1,
0,
1
],
"description": "Tethered caching status: Unknown (-1), Disabled (0), Enabled (1)"
},
"active": {
"type": "boolean",
"description": "Cache service running status (true = running)"
},
"activated": {
"type": "boolean",
"description": "Cache service activation status (true = ordered to start up)"
},
"cacheDetails": {
"type": "string",
"description": "Human-readable cache breakdown by content type (e.g. \"iCloud: 1.83GB Other: 487KB\") - keys configured by Apple config bag"
},
"cacheFree": {
"type": "integer",
"description": "Available cache space in bytes (derived from cacheLimit - cacheUsed when limit > 0, or DiskFree when unlimited)"
},
"cacheLimit": {
"type": "integer",
"description": "Maximum cache size in bytes (0 = unlimited) - administrative limit"
},
"cacheUsed": {
"type": "integer",
"description": "Allocated cache space with overhead for capacity management - distinct from actualCacheUsed"
},
"publicAddress": {
"type": "string",
"description": "Internet-facing IP address (e.g. 17.192.77.246)"
},
"port": {
"type": "integer",
"description": "Service port number (e.g. 56636)"
},
"privateAddresses": {
"type": "string",
"description": "Internal network IP addresses as a space-separated list (e.g. \"10.10.1.67 10.23.1.83\")"
},
"parents": {
"type": "array",
"description": "Array of parent cache server info",
"items": {
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "Parent cache IP address"
},
"port": {
"type": "integer",
"description": "Parent cache port"
},
"guid": {
"type": "string",
"format": "uuid",
"description": "Parent cache server UUID"
},
"healthy": {
"type": "boolean",
"description": "Parent cache health status"
},
"version": {
"type": "string",
"description": "Parent cache software version"
},
"details": {
"type": "string",
"description": "Additional details"
}
}
}
},
"peers": {
"type": "array",
"description": "Array of peer cache server info",
"items": {
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "Peer cache IP address"
},
"port": {
"type": "integer",
"description": "Peer cache port"
},
"guid": {
"type": "string",
"format": "uuid",
"description": "Peer cache server UUID"
},
"healthy": {
"type": "boolean",
"description": "Peer cache health status"
},
"friendly": {
"type": "boolean",
"description": "Peer allows peering"
},
"version": {
"type": "string",
"description": "Peer cache software version"
},
"details": {
"type": "string",
"description": "Additional details"
}
}
}
},
"personalCacheFree": {
"type": "integer",
"description": "Free space in personal (iCloud) cache in bytes"
},
"personalCacheUsed": {
"type": "integer",
"description": "Used space in personal (iCloud) cache in bytes"
},
"personalCacheLimit": {
"type": "integer",
"description": "Personal (iCloud) cache size limit in bytes (0 = unlimited)"
},
"allowPersonalCaching": {
"type": "boolean",
"description": "Personal (iCloud read/write) caching enabled setting"
},
"allowSharedCaching": {
"type": "boolean",
"description": "Generic read-only caching enabled setting"
},
"allowTetheredCaching": {
"type": "boolean",
"description": "Tethered caching enabled setting (requires macOS 10.13+)"
},
"listenRangesOnly": {
"type": "boolean",
"description": "Restrict serving to specific IP ranges only"
},
"localSubnetsOnly": {
"type": "boolean",
"description": "Serve local subnets only (client filtering)"
},
"peerLocalSubnetsOnly": {
"type": "boolean",
"description": "Peer with local subnets only (peer filtering)"
},
"listenRanges": {
"type": "string",
"description": "Network IP ranges for client filtering - array of dicts with first/last IP addresses"
},
"parentSelectionPolicy": {
"type": "string",
"enum": [
"first-available",
"random",
"round-robin",
"sticky-available",
"url-path-hash"
],
"description": "Parent selection algorithm: first-available | random | round-robin | sticky-available | url-path-hash"
},
"period": {
"type": "integer",
"description": "Metric collection period duration in seconds"
},
"bytesDropped": {
"type": "integer",
"description": "Bytes dropped due to errors or capacity issues"
},
"bytesFromCacheToChild": {
"type": "integer",
"description": "Bytes served from local cache to downstream child caches"
},
"bytesFromCacheToClient": {
"type": "integer",
"description": "Bytes served from local cache to end-user clients"
},
"bytesFromCacheToPeer": {
"type": "integer",
"description": "Bytes served from local cache to peer caches"
},
"bytesFromOriginToChild": {
"type": "integer",
"description": "Bytes proxied from origin server to downstream child caches"
},
"bytesFromOriginToClient": {
"type": "integer",
"description": "Bytes proxied from origin server to end-user clients"
},
"bytesFromOriginToPeer": {
"type": "integer",
"description": "Bytes proxied from origin server to peer caches"
},
"bytesFromParentToChild": {
"type": "integer",
"description": "Bytes proxied from parent cache to downstream child caches"
},
"bytesFromParentToClient": {
"type": "integer",
"description": "Bytes proxied from parent cache to end-user clients"
},
"bytesFromParentToPeer": {
"type": "integer",
"description": "Bytes proxied from parent cache to peer caches"
},
"bytesFromPeerToChild": {
"type": "integer",
"description": "Bytes proxied from peer cache to downstream child caches"
},
"bytesFromPeerToClient": {
"type": "integer",
"description": "Bytes proxied from peer cache to end-user clients"
},
"bytesImportedByHTTP": {
"type": "integer",
"description": "Bytes imported into cache via HTTP protocol"
},
"bytesImportedByXPC": {
"type": "integer",
"description": "Bytes imported into cache via XPC (inter-process communication)"
},
"bytesPurgedTotal": {
"type": "integer",
"description": "Total bytes purged/evicted from cache"
},
"bytesPurgedYoungerThan1Day": {
"type": "integer",
"description": "Bytes purged that were cached for less than 1 day"
},
"bytesPurgedYoungerThan7Days": {
"type": "integer",
"description": "Bytes purged that were cached for less than 7 days"
},
"bytesPurgedYoungerThan30Days": {
"type": "integer",
"description": "Bytes purged that were cached for less than 30 days"
},
"importsByHTTP": {
"type": "integer",
"description": "Number of content imports via HTTP protocol"
},
"importsByXPC": {
"type": "integer",
"description": "Number of content imports via XPC (inter-process communication)"
},
"repliesFromCacheToChild": {
"type": "integer",
"description": "Number of replies from local cache to downstream child caches"
},
"repliesFromCacheToClient": {
"type": "integer",
"description": "Number of replies from local cache to end-user clients"
},
"repliesFromCacheToPeer": {
"type": "integer",
"description": "Number of replies from local cache to peer caches"
},
"repliesFromOriginToChild": {
"type": "integer",
"description": "Number of replies proxied from origin to downstream child caches"
},
"repliesFromOriginToClient": {
"type": "integer",
"description": "Number of replies proxied from origin to end-user clients"
},
"repliesFromOriginToPeer": {
"type": "integer",
"description": "Number of replies proxied from origin to peer caches"
},
"repliesFromParentToChild": {
"type": "integer",
"description": "Number of replies proxied from parent to downstream child caches"
},
"repliesFromParentToClient": {
"type": "integer",
"description": "Number of replies proxied from parent to end-user clients"
},
"repliesFromParentToPeer": {
"type": "integer",
"description": "Number of replies proxied from parent to peer caches"
},
"repliesFromPeerToChild": {
"type": "integer",
"description": "Number of replies proxied from peer to downstream child caches"
},
"repliesFromPeerToClient": {
"type": "integer",
"description": "Number of replies proxied from peer to end-user clients"
},
"requestsFromChild": {
"type": "integer",
"description": "Number of requests received from downstream child caches"
},
"requestsFromClient": {
"type": "integer",
"description": "Number of requests received from end-user clients"
},
"requestsFromPeer": {
"type": "integer",
"description": "Number of requests received from peer caches"
},
"requestsRejectedForNoSpace": {
"type": "integer",
"description": "Number of requests rejected due to insufficient disk space"
}
}
}
}
}
}
+2 -66
View File
@@ -62,7 +62,7 @@ payloadkeys:
title: MD5 chunk size
type: <integer>
presence: optional
content: The data *chunk* size the device uses when verifying the hash of
content: The data chunk size the device uses when verifying the hash of
the manifest item data. The device requires this key when the `md5s` key
is present.
- key: md5s
@@ -89,7 +89,7 @@ payloadkeys:
title: SHA256 chunk size
type: <integer>
presence: optional
content: The data *chunk* size the device uses when verifying the hash of
content: The data chunk size the device uses when verifying the hash of
the manifest item data. The device requires this key when the `sha256s`
key is present.
- key: sha256s
@@ -112,23 +112,6 @@ payloadkeys:
presence: required
content: The URL that hosts the manifest item data. The URL needs to start
with `https://`.
- key: needs-shine
title: Icon treatment
supportedOS:
iOS:
removed: '0'
macOS:
removed: '0'
tvOS:
removed: '0'
visionOS:
removed: '0'
watchOS:
introduced: n/a
type: <boolean>
presence: optional
default: false
content: Removed
- key: metadata
title: Application metadata
type: <dictionary>
@@ -153,22 +136,6 @@ payloadkeys:
- software
content: The type of manifest item. For an app or package, this needs to be
`software`.
- key: sizeInBytes
title: Size in bytes
supportedOS:
iOS:
removed: '0'
macOS:
removed: '0'
tvOS:
removed: '0'
visionOS:
removed: '0'
watchOS:
introduced: n/a
type: <integer>
presence: optional
content: Removed
- key: subtitle
title: The application subtitle
type: <string>
@@ -179,37 +146,6 @@ payloadkeys:
type: <string>
presence: required
content: The title of the app or package being installed.
- key: items
title: The items
supportedOS:
iOS:
removed: '0'
macOS:
removed: '0'
tvOS:
removed: '0'
visionOS:
removed: '0'
watchOS:
introduced: n/a
type: <array>
presence: optional
content: Removed
subkeys:
- key: metadata-items-item
type: <dictionary>
presence: optional
subkeys:
- key: bundle-identifier
title: Removed
type: <string>
presence: optional
content: Removed
- key: bundle-version
title: Removed
type: <string>
presence: optional
content: Removed
notes:
- title: ''
content: Use SHA-256 hashes instead of MD5 because SHA-256 has stronger security.
+16
View File
@@ -139,6 +139,20 @@ payloadkeys:
type: <string>
presence: optional
content: The key to skip the Camera Button pane.
- key: DeviceFeaturesTour
title: Skip Device Features tour pane
supportedOS:
iOS:
introduced: '27.0'
macOS:
introduced: n/a
tvOS:
introduced: n/a
visionOS:
introduced: n/a
type: <string>
presence: optional
content: The key to skip the Device Features Tour pane.
- key: DeviceToDeviceMigration
title: Skip Device To Device Migration pane
supportedOS:
@@ -359,8 +373,10 @@ payloadkeys:
supportedOS:
iOS:
introduced: '26.0'
removed: '27.0'
macOS:
introduced: '26.1'
removed: '27.0'
tvOS:
introduced: n/a
visionOS: