Directory Service (com.apple.DirectoryService.managed)

com.apple.DirectoryService.managed

The payload that configures an Active Directory (AD) domain.

macOS(10.8)
Branch: release

Settings (41)

SettingTypeRequiredDefaultManual InstallSupported OS
HostName
HostName
The Active Directory domain to join.
stringrequired—
✓Yes
macOS (10.8+)
UserName
UserName
The user name of the account for the domain.
stringoptional—
✓Yes
macOS (10.8+)
Password
Password
The password of the account for the domain.
stringoptional—
✓Yes
macOS (10.8+)
Client ID
ClientID
The client's identifier.
stringoptional—
✓Yes
macOS (10.8+)
Description
Description
The directory service description.
stringoptional—
✓Yes
macOS (10.8+)
ADOrganizationalUnit
ADOrganizationalUnit
The organizational unit to add the joining computer object to.
stringoptional—
✓Yes
macOS (10.8+)
ADMountStyle
ADMountStyle
The network home protocol to use: `afp` or `smb`.
stringoptional—
✓Yes
macOS (10.8+)
ADCreateMobileAccountAtLoginFlag
ADCreateMobileAccountAtLoginFlag
If `true`, the system enables the `ADCreateMobileAccountAtLogin` key.
booleanoptionalfalse
✓Yes
macOS (10.9+)
ADCreateMobileAccountAtLogin
ADCreateMobileAccountAtLogin
If `true`, the system creates a mobile account at login.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADWarnUserBeforeCreatingMAFlag
ADWarnUserBeforeCreatingMAFlag
If `true`, the system enables the `ADWarnUserBeforeCreatingMA` key.
booleanoptionalfalse
✓Yes
macOS (10.9+)
ADWarnUserBeforeCreatingMA
ADWarnUserBeforeCreatingMA
If `true`, the system enables the warning before creating the mobile account.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADForceHomeLocalFlag
ADForceHomeLocalFlag
If `true`, the system enables the `ADForceHomeLocal` key.
booleanoptionalfalse
✓Yes
macOS (10.9+)
ADForceHomeLocal
ADForceHomeLocal
If `true`, the system forces a local home directory.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADUseWindowsUNCPathFlag
ADUseWindowsUNCPathFlag
If `true`, the system enables the `ADUseWindowsUNCPath` key.
booleanoptionalfalse
✓Yes
macOS (10.9+)
ADUseWindowsUNCPath
ADUseWindowsUNCPath
If `true`, the system uses the UNC path from Active Directory to derive the network home location.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADAllowMultiDomainAuthFlag
ADAllowMultiDomainAuthFlag
If `true`, the system enables the `ADAllowMultiDomainAuth` key.
booleanoptionalfalse
✓Yes
macOS (10.9+)
ADAllowMultiDomainAuth
ADAllowMultiDomainAuth
If `true`, the system allows authentication from any domain in the namespace.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADDefaultUserShellFlag
ADDefaultUserShellFlag
If `true`, the system enables the `ADDefaultUserShell` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADDefaultUserShell
ADDefaultUserShell
The default user shell.
stringoptional—
✓Yes
macOS (10.8+)
ADMapUIDAttributeFlag
ADMapUIDAttributeFlag
If `true`, the system enables the `ADMapUIDAttribute` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADMapUIDAttribute
ADMapUIDAttribute
The map UID to attribute.
stringoptional—
✓Yes
macOS (10.8+)
ADMapGIDAttributeFlag
ADMapGIDAttributeFlag
If `true`, the system enables the `ADMapGIDAttribute` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADMapGIDAttribute
ADMapGIDAttribute
The map GID to attribute.
stringoptional—
✓Yes
macOS (10.8+)
ADMapGGIDAttributeFlag
ADMapGGIDAttributeFlag
If `true`, the system enables the `ADMapGGIDAttributeFlag` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADMapGGIDAttribute
ADMapGGIDAttribute
The map group GID to attribute.
stringoptional—
✓Yes
macOS (10.8+)
ADPreferredDCServerFlag
ADPreferredDCServerFlag
If `true`, the system enables the `ADPreferredDCServer` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADPreferredDCServer
ADPreferredDCServer
The preferred domain server.
stringoptional—
✓Yes
macOS (10.8+)
ADDomainAdminGroupListFlag
ADDomainAdminGroupListFlag
If `true`, the system enables the `ADDomainAdminGroupList` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADDomainAdminGroupList
ADDomainAdminGroupList
The list of Active Directory groups with admin access.
1 subkey
arrayoptional—
✓Yes
macOS (10.8+)
└─
ADDomainAdminGroupListItem
ADDomainAdminGroupListItem
string—
✓Yes
macOS (10.8+)
ADNamespaceFlag
ADNamespaceFlag
If `true`, the system enables the `ADNamespace` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADNamespace
ADNamespace
The primary user account naming convention; either `forest` or `domain`.
stringoptional—
✓Yes
macOS (10.8+)
ADPacketSignFlag
ADPacketSignFlag
If `true`, the system enables the `ADPacketSign` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADPacketSign
ADPacketSign
The packet signing policy.
stringoptional—
✓Yes
macOS (10.8+)
ADPacketEncryptFlag
ADPacketEncryptFlag
If `true`, the system enables the `ADPacketEncrypt` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADPacketEncrypt
ADPacketEncrypt
The packet encryption policy.
stringoptional—
✓Yes
macOS (10.8+)
ADRestrictDDNSFlag
ADRestrictDDNSFlag
If `true`, the system enables the `ADRestrictDDNS` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADRestrictDDNS
ADRestrictDDNS
An array of strings that represent the interfaces allowed for dynamic DNS updates, such as en0 and en1.
1 subkey
arrayoptional—
✓Yes
macOS (10.8+)
└─
ADRestrictDDNSItem
ADRestrictDDNSItem
string—
✓Yes
macOS (10.8+)
ADTrustChangePassIntervalDaysFlag
ADTrustChangePassIntervalDaysFlag
If `true`, the system enables the `ADTrustChangePassIntervalDays` key.
booleanoptionalfalse
✓Yes
macOS (10.8+)
ADTrustChangePassIntervalDays
ADTrustChangePassIntervalDays
The number of days before requiring a change of the computer trust account password. Set to `0` to disable the feature.
integeroptional—
✓Yes
macOS (10.8+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information