Account:Exchange ()

The declaration to configure an Exchange account.

iOS(15.0)macOS(13.0)visionOS(1.1)
Branch: release

Settings (38)

SettingTypeRequiredDefaultManual InstallSupported OS
Account name
VisibleName
The name that apps show to the user for this Exchange account. If not present, the system generates a suitable default.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Enabled protocol types
EnabledProtocolTypes
The set of protocol types to enable on the Exchange server, in order of preference. This is an array of unique strings with possible values: - `EAS:` Exchange ActiveSync - `EWS:` Exchange Web Services If the device supports one or more of the listed protocol types, it sets up an account for the first supported type. If the device doesn't support any of the listed protocol types, it doesn't set up an account and the system reports an error.
1 subkey
arrayrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
EnabledProtocolTypesItem
EnabledProtocolTypesItem
stringrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
User identity asset reference
UserIdentityAssetReference
The identifier of an asset declaration that contains the user identity for this account. The corresponding asset must be of type `UserIdentity`.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Server host name
HostName
The IP address or fully qualified domain name (FQDN) of the Exchange host.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Server port
Port
The port number of the EWS server. The system uses this only when this declaration has a `HostName` value. Applicable for "EWS" only.
integeroptional—
✗No
Server path
Path
The path of the EWS server. The system uses this only when this declaration has a `HostName` value. Applicable for "EWS" only.
stringoptional—
✗No
Server external host name
ExternalHostName
The external hostname of the EWS server (or IP address). Applicable for "EWS" only.
stringoptional—
✗No
Server external port
ExternalPort
The external port number of the EWS server. The system uses this only when this declaration has an `ExternalHostName` value. Applicable for "EWS" only.
integeroptional—
✗No
Server external path
External Path
The external path of the EWS server. The system uses this only when this declaration has an `ExternalHostName` value. Applicable for "EWS" only.
stringoptional—
✗No
Controls use of OAuth
OAuth
The configuration settings for OAuth for this account.
3 subkeys
dictionaryoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Use OAuth
Enabled
If `true`, enables OAuth for this account.
booleanrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Sign in URL
SignInURL
The URL that this account uses for signing in with OAuth. The system ignores this value unless `Enabled` is `true`. The system doesn't use autodiscovery when a declaration contains this URL, so the declaration must also contain a `HostName`.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Token request URL
TokenRequestURL
The URL that this account uses for token requests with OAuth. The system ignores this value unless `Enabled` is `true`. Applicable for "EAS" only.
stringoptional—
✗No
Authentication credentials asset reference
AuthenticationCredentialsAssetReference
The identifier of an asset declaration that contains the credentials for this account to authenticate with an Exchange server. Set the corresponding asset type to `CredentialUserNameAndPassword`.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Authentication identity asset reference
AuthenticationIdentityAssetReference
The identifier of a credential asset declaration that contains the identity that this account requires to authenticate with the Exchange server.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
S/MIME settings
SMIME
Settings for S/MIME. Applicable for "EAS" only.
2 subkeys
dictionaryoptional—
✓Yes
iOS (17.0+)
└─
S/MIME signing settings
Signing
Settings for S/MIME signing. Applicable for "EAS" only.
4 subkeys
dictionaryoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Signing enabled
Enabled
If `true`, the system enables S/MIME signing. Applicable for "EAS" only.
booleanrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
S/MIME signing identity asset reference
IdentityAssetReference
The identifier of an asset declaration containing the identity required for S/MIME signing of messages sent from this account. Applicable for "EAS" only.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Signing user overrideable
UserOverrideable
If `true`, the user can turn S/MIME signing on or off in Settings. Applicable for "EAS" only.
booleanoptionalfalse
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Signing identity user overrideable
IdentityUserOverrideable
If `true`, the user can select an S/MIME signing identity in Settings. Applicable for "EAS" only.
booleanoptionalfalse
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
S/MIME encryption settings
Encryption
Settings for S/MIME encryption. Applicable for "EAS" only.
5 subkeys
dictionaryoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Encryption by default enabled
Enabled
If `true`, the system enables S/MIME encryption by default, which the user can't override if `PerMessageSwitchEnabled` is `false`. Applicable for "EAS" only.
booleanrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
S/MIME encryption identity asset reference
IdentityAssetReference
The identifier of an asset declaration containing the identity required for S/MIME encryption. The system attaches the public certificate to outgoing mail to allow the user to receive encrypted mail. When the user sends encrypted mail, the system uses the public certificate to encrypt the copy of the mail in their Sent mailbox. Applicable for "EAS" only.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Encryption by default user overrideable
UserOverrideable
If `true`, the user can turn S/MIME encryption by default on or off in Settings. Applicable for "EAS" only.
booleanoptionalfalse
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Encryption identity user overrideable
IdentityUserOverrideable
If `true`, the user can select an S/MIME signing identity in Settings. Applicable for "EAS" only.
booleanoptionalfalse
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Per message switch enabled
PerMessageSwitchEnabled
If `true`, the system enables the per-message encryption switch in the compose view. Applicable for "EAS" only.
booleanoptionalfalse
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Mail service active
MailServiceActive
If `true`, the system activates the mail service for this account.
booleanoptionaltrue
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Lock mail service
LockMailService
If `true`, the system prevents the user from changing the status of the mail service for this account. Applicable for "EAS" only.
booleanoptionalfalse
✗No
Contacts service active
ContactsServiceActive
If `true`, activates the address book service for this account.
booleanoptionaltrue
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Lock contacts service
LockContactsService
If `true`, the system prevents the user from changing the status of the address book service for this account. Applicable for "EAS" only.
booleanoptionalfalse
✗No
Calendar service active
CalendarServiceActive
If `true`, activates the calendar service for this account.
booleanoptionaltrue
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Lock calendar service
LockCalendarService
If `true`, the system prevents the user from changing the status of the calendar service for this account. Applicable for "EAS" only.
booleanoptionalfalse
✗No
Reminders service active
RemindersServiceActive
If `true`, the system activates the reminders service for this account.
booleanoptionaltrue
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Lock reminders service
LockRemindersService
If `true`, the system prevents the user from changing the status of the reminders service for this account. Applicable for "EAS" only.
booleanoptionalfalse
✗No
Notes service active
NotesServiceActive
If `true`, the system activates the notes service for this account.
booleanoptionaltrue
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Lock notes service
LockNotesService
If `true`, the system prevents the user from changing the status of the notes service for this account. Applicable for "EAS" only.
booleanoptionalfalse
✗No

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information