The declaration to configure an Exchange account.
| Setting | Type | Required | Default | Manual Install | Supported OS |
|---|---|---|---|---|---|
Account name VisibleName The name that apps show to the user for this Exchange account. If not present, the system generates a suitable default. | string | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
Enabled protocol types EnabledProtocolTypes The set of protocol types to enable on the Exchange server, in order of preference. This is an array of unique strings with possible values:
- `EAS:` Exchange ActiveSync
- `EWS:` Exchange Web Services
If the device supports one or more of the listed protocol types, it sets up an account for the first supported type.
If the device doesn't support any of the listed protocol types, it doesn't set up an account and the system reports an error. 1 subkey | array | required | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ EnabledProtocolTypesItem EnabledProtocolTypesItem | string | required | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
User identity asset reference UserIdentityAssetReference The identifier of an asset declaration that contains the user identity for this account. The corresponding asset must be of type `UserIdentity`. | string | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
Server host name HostName The IP address or fully qualified domain name (FQDN) of the Exchange host. | string | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
Server port Port The port number of the EWS server. The system uses this only when this declaration has a `HostName` value. Applicable for "EWS" only. | integer | optional | — | ✗No | |
Server path Path The path of the EWS server. The system uses this only when this declaration has a `HostName` value. Applicable for "EWS" only. | string | optional | — | ✗No | |
Server external host name ExternalHostName The external hostname of the EWS server (or IP address). Applicable for "EWS" only. | string | optional | — | ✗No | |
Server external port ExternalPort The external port number of the EWS server. The system uses this only when this declaration has an `ExternalHostName` value. Applicable for "EWS" only. | integer | optional | — | ✗No | |
Server external path External Path The external path of the EWS server. The system uses this only when this declaration has an `ExternalHostName` value. Applicable for "EWS" only. | string | optional | — | ✗No | |
Controls use of OAuth OAuth The configuration settings for OAuth for this account. 3 subkeys | dictionary | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ Use OAuth Enabled If `true`, enables OAuth for this account. | boolean | required | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ Sign in URL SignInURL The URL that this account uses for signing in with OAuth. The system ignores this value unless `Enabled` is `true`. The system doesn't use autodiscovery when a declaration contains this URL, so the declaration must also contain a `HostName`. | string | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ Token request URL TokenRequestURL The URL that this account uses for token requests with OAuth. The system ignores this value unless `Enabled` is `true`. Applicable for "EAS" only. | string | optional | — | ✗No | |
Authentication credentials asset reference AuthenticationCredentialsAssetReference The identifier of an asset declaration that contains the credentials for this account to authenticate with an Exchange server. Set the corresponding asset type to `CredentialUserNameAndPassword`. | string | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
Authentication identity asset reference AuthenticationIdentityAssetReference The identifier of a credential asset declaration that contains the identity that this account requires to authenticate with the Exchange server. | string | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
S/MIME settings SMIME Settings for S/MIME. Applicable for "EAS" only. 2 subkeys | dictionary | optional | — | ✓Yes | iOS (17.0+) |
└─ S/MIME signing settings Signing Settings for S/MIME signing. Applicable for "EAS" only. 4 subkeys | dictionary | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ └─ Signing enabled Enabled If `true`, the system enables S/MIME signing. Applicable for "EAS" only. | boolean | required | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ └─ S/MIME signing identity asset reference IdentityAssetReference The identifier of an asset declaration containing the identity required for S/MIME signing of messages sent from this account. Applicable for "EAS" only. | string | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ └─ Signing user overrideable UserOverrideable If `true`, the user can turn S/MIME signing on or off in Settings. Applicable for "EAS" only. | boolean | optional | false | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ └─ Signing identity user overrideable IdentityUserOverrideable If `true`, the user can select an S/MIME signing identity in Settings. Applicable for "EAS" only. | boolean | optional | false | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ S/MIME encryption settings Encryption Settings for S/MIME encryption. Applicable for "EAS" only. 5 subkeys | dictionary | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ └─ Encryption by default enabled Enabled If `true`, the system enables S/MIME encryption by default, which the user can't override if `PerMessageSwitchEnabled` is `false`. Applicable for "EAS" only. | boolean | required | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ └─ S/MIME encryption identity asset reference IdentityAssetReference The identifier of an asset declaration containing the identity required for S/MIME encryption. The system attaches the public certificate to outgoing mail to allow the user to receive encrypted mail. When the user sends encrypted mail, the system uses the public certificate to encrypt the copy of the mail in their Sent mailbox. Applicable for "EAS" only. | string | optional | — | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ └─ Encryption by default user overrideable UserOverrideable If `true`, the user can turn S/MIME encryption by default on or off in Settings. Applicable for "EAS" only. | boolean | optional | false | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ └─ Encryption identity user overrideable IdentityUserOverrideable If `true`, the user can select an S/MIME signing identity in Settings. Applicable for "EAS" only. | boolean | optional | false | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
└─ └─ Per message switch enabled PerMessageSwitchEnabled If `true`, the system enables the per-message encryption switch in the compose view. Applicable for "EAS" only. | boolean | optional | false | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
Mail service active MailServiceActive If `true`, the system activates the mail service for this account. | boolean | optional | true | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
Lock mail service LockMailService If `true`, the system prevents the user from changing the status of the mail service for this account. Applicable for "EAS" only. | boolean | optional | false | ✗No | |
Contacts service active ContactsServiceActive If `true`, activates the address book service for this account. | boolean | optional | true | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
Lock contacts service LockContactsService If `true`, the system prevents the user from changing the status of the address book service for this account. Applicable for "EAS" only. | boolean | optional | false | ✗No | |
Calendar service active CalendarServiceActive If `true`, activates the calendar service for this account. | boolean | optional | true | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
Lock calendar service LockCalendarService If `true`, the system prevents the user from changing the status of the calendar service for this account. Applicable for "EAS" only. | boolean | optional | false | ✗No | |
Reminders service active RemindersServiceActive If `true`, the system activates the reminders service for this account. | boolean | optional | true | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
Lock reminders service LockRemindersService If `true`, the system prevents the user from changing the status of the reminders service for this account. Applicable for "EAS" only. | boolean | optional | false | ✗No | |
Notes service active NotesServiceActive If `true`, the system activates the notes service for this account. | boolean | optional | true | ✓Yes | iOS (15.0+)macOS (13.0+)visionOS (1.1+) |
Lock notes service LockNotesService If `true`, the system prevents the user from changing the status of the notes service for this account. Applicable for "EAS" only. | boolean | optional | false | ✗No |
Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.
com.apple.wifi.managed – Wi-Fi network configurationcom.apple.vpn.managed – VPN configurationcom.apple.applicationaccess – App and feature restrictionscom.apple.security.pkcs1 – Certificate (PKCS#1) payloadcom.apple.security.pkcs12 – Identity certificate (PKCS#12) payloadcom.apple.security.scep – SCEP certificate enrolmentcom.apple.mail.managed – Mail account configurationcom.apple.eas.account – Exchange ActiveSync accountcom.apple.MCX – Managed Client (macOS) preferencescom.apple.MCX.FileVault2 – FileVault 2 disk encryptioncom.apple.dock – macOS Dock configurationcom.apple.screensaver – Screensaver configurationcom.apple.loginwindow – macOS login window configurationcom.apple.systempolicy.managed – Gatekeeper / system policycom.apple.systempreferences – System Preferences pane restrictionscom.apple.SoftwareUpdate – Software update behaviourcom.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)com.apple.notificationsettings – Per-app notification settingscom.apple.webcontent-filter – Web content filtercom.apple.dnsSettings.managed – DNS settings (DoH / DoT)com.apple.relay.managed – Network relay configurationcom.apple.extensiblesso – Extensible Single Sign-Oncom.apple.configuration.passcode.settings – DDM: passcode policycom.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software updatecom.apple.configuration.services.configuration-files – DDM: service configuration filescom.apple.configuration.management.status-subscriptions – DDM: status subscriptionscom.apple.activation.simple – DDM: simple activation predicatecom.apple.management.organization-info – DDM: organization information