Account:Mail ()

The declaration to configure a Mail account.

iOS(15.0)macOS(13.0)visionOS(1.1)
Branch: release

Settings (26)

SettingTypeRequiredDefaultManual InstallSupported OS
Account name
VisibleName
The name that apps show to the user for this mail account. If not present, the system generates a suitable default.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
User identity asset reference
UserIdentityAssetReference
The identifier of an asset declaration that contains the user identity for this account. Set the corresponding asset type to `UserIdentity`.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Incoming server settings
IncomingServer
The settings for the incoming mail server for this account.
6 subkeys
dictionaryrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Server type
ServerType
The mail protocol this account uses.
stringrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Server host name
HostName
The host name for the incoming mail server.
stringrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Server port
Port
The port number for the incoming mail server.
integeroptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Server authentication method
AuthenticationMethod
The authentication method for the incoming mail server.
stringrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Authentication credentials asset reference
AuthenticationCredentialsAssetReference
The identifier of an asset declaration that contains the credentials for this account to authenticate with an incoming mail server. The corresponding asset must be of type `CredentialUserNameAndPassword`. If the `AuthenticationMethod` is `None`, this field must be blank. Otherwise, the declaration must contain this field.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
IMAP path prefix
IMAPPathPrefix
The path prefix for the IMAP server. The system uses this only when `ServerType` is `IMAP`.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
Outgoing server settings
OutgoingServer
The settings for the outgoing mail server for this account.
4 subkeys
dictionaryrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Server host name
HostName
The host name for the outgoing mail server.
stringrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Server port
Port
The port number for the outgoing mail server.
integeroptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Server authentication method
AuthenticationMethod
The authentication method for the outgoing mail server.
stringrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
Authentication credentials asset reference
AuthenticationCredentialsAssetReference
The identifier of an asset declaration that contains the credentials for this account to authenticate with an outgoing mail server. The corresponding asset must be of type `CredentialUserNameAndPassword`. If the `AuthenticationMethod` is `None`, this field must be blank. Otherwise, the declaration must contain this field.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
S/MIME settings
SMIME
Settings for S/MIME.
2 subkeys
dictionaryoptional—
✓Yes
iOS (17.0+)
└─
S/MIME signing settings
Signing
Settings for S/MIME signing.
4 subkeys
dictionaryoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Signing enabled
Enabled
If `true`, the system enables S/MIME signing.
booleanrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
S/MIME signing identity asset reference
IdentityAssetReference
Specifies the identifier of an asset declaration containing the identity required for S/MIME signing of messages sent from this account.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Signing user overrideable
UserOverrideable
If `true`, the user can turn S/MIME signing on or off in Settings.
booleanoptionalfalse
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Signing identity user overrideable
IdentityUserOverrideable
If `true`, the user can select an S/MIME signing identity in Settings.
booleanoptionalfalse
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─
S/MIME encryption settings
Encryption
Settings for S/MIME encryption.
5 subkeys
dictionaryoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Encryption by default enabled
Enabled
If `true`, the system enables S/MIME encryption by default, which the user can't override if `PerMessageSwitchEnabled` is `false`.
booleanrequired—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
S/MIME encryption identity asset reference
IdentityAssetReference
Specifies the identifier of an asset declaration containing the identity required for S/MIME encryption. The system attaches the public certificate to outgoing mail to allow the user to receive encrypted mail. When the user sends encrypted mail, the system uses the public certificate to encrypt the copy of the mail in their Sent mailbox.
stringoptional—
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Encryption by default user overrideable
UserOverrideable
If `true`, the user can set the default value for S/MIME encryption to on or off in Settings.
booleanoptionalfalse
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Encryption identity user overrideable
IdentityUserOverrideable
If `true`, the user can select an S/MIME signing identity in Settings.
booleanoptionalfalse
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)
└─ └─
Per message switch enabled
PerMessageSwitchEnabled
If `true`, the system enables the per-message encryption switch in the compose view.
booleanoptionalfalse
✓Yes
iOS (15.0+)macOS (13.0+)visionOS (1.1+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information