Parental Controls: Application Restrictions (com.apple.applicationaccess.new)

Deprecated (macOS 27.0)
com.apple.applicationaccess.new

The payload that configures parental controls for apps.

macOS(10.7 - 27.0)
Branch: release

Settings (29)

SettingTypeRequiredDefaultManual InstallSupported OS
familyControlsEnabled
familyControlsEnabled
Deprecated (macOS 27.0)
If `true`, enables app access restrictions.
booleanrequired—
✓Yes
macOS (10.7 - 27.0)
allowList
allowList
Deprecated (macOS 27.0)
The allow list of app item dictionaries.
1 subkey
arrayoptional—
✓Yes
macOS (10.15 - 27.0)
└─
allowListItem
allowListItem
Deprecated (macOS 27.0)
A dictionary defining an app for parental control.
6 subkeys
dictionary—
✓Yes
macOS (10.7 - 27.0)
└─ └─
bundleID
bundleID
Deprecated (macOS 27.0)
The bundle ID of the app.
stringrequired—
✓Yes
macOS (10.7 - 27.0)
└─ └─
appID
appID
Deprecated (macOS 27.0)
The identifier of the app. Obtain this value from the Security framework using `SecCodeCopyDesignatedRequirement`.
datarequired—
✓Yes
macOS (10.7 - 27.0)
└─ └─
detachedSignature
detachedSignature
Deprecated (macOS 27.0)
The signature for an unsigned binary.
dataoptional—
✓Yes
macOS (10.7 - 27.0)
└─ └─
disabled
disabled
Deprecated (macOS 27.0)
If `true`, this app isn't added to the allow list.
booleanoptionalfalse
✓Yes
macOS (10.7 - 27.0)
└─ └─
subApps
subApps
Deprecated (macOS 27.0)
An array of nested helper applications.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 27.0)
└─ └─ └─
allowListItem
allowListItem
Deprecated (macOS 27.0)
A dictionary defining an app for parental control.
6 subkeys
dictionary—
✓Yes
macOS (10.7 - 27.0)
└─ └─ └─ └─
[Structure continues recursively]
↻
Deprecated (macOS 27.0)
This structure continues with 6 subkeys (recursive structure - refers back to allowListItem). See Apple's documentation for the complete structure.
—
✓Yes
macOS (10.7 - 27.0)
└─ └─
displayName
displayName
Deprecated (macOS 27.0)
The name used for display purposes.
stringoptional—
✓Yes
macOS (10.7 - 27.0)
whiteList
whiteList
Deprecated (macOS 10.15)
The allow list of app item dictionaries. This property is deprecated in macOS 10.15 and later - use `allowList` instead.
1 subkey
arrayoptional—
✓Yes
macOS (legacy - 10.15)
└─
allowListItem
allowListItem
Deprecated (macOS 27.0)
A dictionary defining an app for parental control.
6 subkeys
dictionary—
✓Yes
macOS (10.7 - 27.0)
└─ └─
bundleID
bundleID
Deprecated (macOS 27.0)
The bundle ID of the app.
stringrequired—
✓Yes
macOS (10.7 - 27.0)
└─ └─
appID
appID
Deprecated (macOS 27.0)
The identifier of the app. Obtain this value from the Security framework using `SecCodeCopyDesignatedRequirement`.
datarequired—
✓Yes
macOS (10.7 - 27.0)
└─ └─
detachedSignature
detachedSignature
Deprecated (macOS 27.0)
The signature for an unsigned binary.
dataoptional—
✓Yes
macOS (10.7 - 27.0)
└─ └─
disabled
disabled
Deprecated (macOS 27.0)
If `true`, this app isn't added to the allow list.
booleanoptionalfalse
✓Yes
macOS (10.7 - 27.0)
└─ └─
subApps
subApps
Deprecated (macOS 27.0)
An array of nested helper applications.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 27.0)
└─ └─ └─
allowListItem
allowListItem
Deprecated (macOS 27.0)
A dictionary defining an app for parental control.
6 subkeys
dictionary—
✓Yes
macOS (10.7 - 27.0)
└─ └─ └─ └─
[Structure continues recursively]
↻
Deprecated (macOS 27.0)
This structure continues with 6 subkeys (recursive structure - refers back to allowListItem). See Apple's documentation for the complete structure.
—
✓Yes
macOS (10.7 - 27.0)
└─ └─
displayName
displayName
Deprecated (macOS 27.0)
The name used for display purposes.
stringoptional—
✓Yes
macOS (10.7 - 27.0)
pathDenyList
pathDenyList
Deprecated (macOS 27.0)
The paths to apps in the deny list.
1 subkey
arrayoptional—
✓Yes
macOS (10.15 - 27.0)
└─
pathDenyListItem
pathDenyListItem
Deprecated (macOS 27.0)
A path.
stringrequired—
✓Yes
macOS (10.7 - 27.0)
pathBlackList
pathBlackList
Deprecated (macOS 10.15)
The paths to apps in the deny list. This property is deprecated in macOS 10.15 and later - use `pathDenyList` instead.
1 subkey
arrayoptional—
✓Yes
macOS (legacy - 10.15)
└─
pathBlackListItem
pathBlackListItem
Deprecated (macOS 27.0)
A path.
stringrequired—
✓Yes
macOS (10.7 - 27.0)
pathAllowList
pathAllowList
Deprecated (macOS 27.0)
The paths to apps in the allow list.
1 subkey
arrayoptional—
✓Yes
macOS (10.15 - 27.0)
└─
pathAllowListItem
pathAllowListItem
Deprecated (macOS 27.0)
A path.
stringrequired—
✓Yes
macOS (10.7 - 27.0)
pathWhiteList
pathWhiteList
Deprecated (macOS 10.15)
The paths to apps in the allow list. This property is deprecated in macOS 10.15 and later - use `pathAllowList` instead.
1 subkey
arrayoptional—
✓Yes
macOS (legacy - 10.15)
└─
pathWhiteListItem
pathWhiteListItem
Deprecated (macOS 27.0)
A path.
stringrequired—
✓Yes
macOS (10.7 - 27.0)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information