Active Directory Certificate (com.apple.ADCertificate.managed)

com.apple.ADCertificate.managed

The payload that configures Active Directory Certificate settings.

macOS(10.7)
Branch: release

Settings (11)

SettingTypeRequiredDefaultManual InstallSupported OS
Certificate server
CertServer
The fully qualified host name of the CA.
stringrequired—
✓Yes
macOS (10.7+)
Certificate template
CertTemplate
The certificate template for your environment. The default user certificate value is `User`. The default computer certificate value is `Machine`.
stringrequired—
✓Yes
macOS (10.7+)
Description
Description
A user-friendly description of the certification identity.
stringoptional—
✓Yes
macOS (10.7+)
Certificate renewal time interval
CertificateRenewalTimeInterval
The number of days in advance of certificate expiration that the notification center notifies the user.
integeroptional—
✓Yes
macOS (10.7+)
Certificate authority
CertificateAuthority
The name of the certificate authority (CA), which the device determines from the common name (CN) of the Active Directory entry. Valid values: - CN=<your CA Name> - CN=`Certification Authorities` - CN=`Public Key Services` - CN=`Services` - CN=`Configuration` - CN=<your base Domain Name>
stringoptional—
✓Yes
macOS (10.8+)
Certificate acquisition mechanism
CertificateAcquisitionMechanism
This value is most commonly `RPC`; if using web enrollment, use `HTTP`.
stringoptional—
✓Yes
macOS (10.8+)
Allow all apps access
AllowAllAppsAccess
If `true`, gives apps access to the private key.
booleanoptionalfalse
✓Yes
macOS (10.10+)
Prompt for credentials
PromptForCredentials
If `true`, the system prompts the user for credentials when is installs the profile. This key applies only to user certificates with the Manual Download profile delivery method. Omit this key for computer certificates.
booleanoptionalfalse
✓Yes
macOS (10.8+)
Key is extractable
KeyIsExtractable
If `true`, the system allows exporting the private key.
booleanoptionalfalse
✓Yes
macOS (10.10+)
Key size
Keysize
The RSA key size for the certificate signing request (CSR).
integeroptional2048
✓Yes
macOS (10.11+)
Enable auto renewal
EnableAutoRenewal
If `true`, the certificate obtained with this payload attempts auto-renewal. Auto-renewal can only be used with device Active Directory certificate payloads.
booleanoptionalfalse
✓Yes
macOS (10.13.4+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information