Login Window (com.apple.loginwindow)

com.apple.loginwindow

The payload that configures Login Window behavior.

macOS(10.7)
Branch: release

Settings (29)

SettingTypeRequiredDefaultManual InstallSupported OS
SHOWFULLNAME
SHOWFULLNAME
If `true`, the system shows the name and password dialog. If `false`, the system displays a list of users.
booleanoptionalfalse
✓Yes
macOS (10.7+)
HideLocalUsers
HideLocalUsers
If `true`, the system shows only network and system users when showing a user list.
booleanoptionalfalse
✓Yes
macOS (10.7+)
IncludeNetworkUser
IncludeNetworkUser
If `true`, the system shows network users when showing a user list.
booleanoptionalfalse
✓Yes
macOS (10.7+)
HideAdminUsers
HideAdminUsers
If `true`, the system hides administrator users when showing a user list.
booleanoptionalfalse
✓Yes
macOS (10.7+)
SHOWOTHERUSERS_MANAGED
SHOWOTHERUSERS_MANAGED
If `true`, the system displays "Other..." when it shows a list of users.
booleanoptionalfalse
✓Yes
macOS (10.7+)
AdminHostInfo
AdminHostInfo
The admin host info. If present in the payload, the system displays its value in the Login Window as additional computer information. Before macOS 10.10, this string could only contain host name, system version, or IP address. After macOS 10.10, setting this key to any value allows the user to click the time area of the menu bar to toggle through various computer information values.
stringoptional—
✓Yes
macOS (10.7+)
AdminMayDisableMCX
AdminMayDisableMCX
If `true`, a local administrator user can bypass or disable managed preferences (MCX settings) for their login session. The device presents the user with this option at login only when the user is a local administrator, and other users are not logged in.
booleanoptionalfalse
✓Yes
macOS (10.7+)
AllowList
AllowList
The list of user GUIDs or group GUIDs of users that the system allows to log in. An asterisk (`*`) string specifies all users or groups. This only applies to network accounts and mobile accounts.
1 subkey
arrayoptional—
✓Yes
macOS (10.7+)
└─
AllowListItem
AllowListItem
A user or group GUID.
stringrequired—
✓Yes
macOS (10.7+)
DenyList
DenyList
The list of user GUIDs or group GUIDs of users that the system disallows to log in. This list takes priority over the list in the `AllowList` key. This only applies to network accounts and mobile accounts.
1 subkey
arrayoptional—
✓Yes
macOS (10.7+)
└─
DenyListItem
DenyListItem
A user or group GUID.
stringrequired—
✓Yes
macOS (10.7+)
HideMobileAccounts
HideMobileAccounts
If `true`, the system hides mobile account users in a user list. In some cases, mobile users show up as network users.
booleanoptionalfalse
✓Yes
macOS (10.7+)
ShutDownDisabled
ShutDownDisabled
If `true`, the system disables the Shut Down button.
booleanoptionalfalse
✓Yes
macOS (10.7+)
RestartDisabled
RestartDisabled
If `true`, the system disables the Restart item.
booleanoptionalfalse
✓Yes
macOS (10.7+)
RetriesUntilHint
RetriesUntilHint
If specified, allows a certain number of retries until the device shows a password hint. The device shows no hints if set to a value of 0.
integeroptional0
✓Yes
macOS (10.7+)
SleepDisabled
SleepDisabled
If `true`, the system disables the Sleep button.
booleanoptionalfalse
✓Yes
macOS (10.7+)
DisableConsoleAccess
DisableConsoleAccess
If `true`, the system disregards the `>console` special user name, which provides a command line UI.
booleanoptionalfalse
✓Yes
macOS (10.7+)
LoginwindowText
LoginwindowText
The text to display in the Login Window.
stringoptional—
✓Yes
macOS (10.7+)
ShutDownDisabledWhileLoggedIn
ShutDownDisabledWhileLoggedIn
If `true`, the system disables the Shut Down menu item when the user is logged in.
booleanoptionalfalse
✓Yes
macOS (10.7+)
RestartDisabledWhileLoggedIn
RestartDisabledWhileLoggedIn
If `true`, the system disables the Restart menu item when the user is logged in.
booleanoptionalfalse
✓Yes
macOS (10.7+)
PowerOffDisabledWhileLoggedIn
PowerOffDisabledWhileLoggedIn
If `true`, the system disables the Power Off menu item when the user is logged in.
booleanoptionalfalse
✓Yes
macOS (10.7+)
LogOutDisabledWhileLoggedIn
LogOutDisabledWhileLoggedIn
If `true`, the system disables the Log Out menu item when the user is logged in.
booleanoptionalfalse
✓Yes
macOS (10.13+)
DisableScreenLockImmediate
DisableScreenLockImmediate
If `true`, the system disables the immediate Screen Lock functions.
booleanoptionalfalse
✓Yes
macOS (10.13+)
showInputMenu
showInputMenu
If `true`, the system shows the Input Menu in the Login Window.
booleanoptionalfalse
✓Yes
macOS (10.8+)
DisableFDEAutoLogin
DisableFDEAutoLogin
If `true`, the system disables the automatic login option when using FileVault.
booleanoptionalfalse
✓Yes
macOS (10.9+)
AutologinUsername
AutologinUsername
The user short name for an existing user to set up auto login.
stringoptional—
✗No
macOS (14.0+)
AutologinPassword
AutologinPassword
An optional user password to set up auto login. This must match the `AutologinUsername` user's current password.
stringoptional—
✗No
macOS (14.0+)
Enable WiFi network selection for login and unlock
ForceWifiConfigurationOnLockScreen
New in macOS 27.0
If `true`, the system allows the user to select WiFi networks at login or unlock.
booleanoptionalfalse
✗No
macOS (27.0+)
Enable captive WiFi portal for login and unlock
ForceCaptivePortalConnectionFromLockScreen
New in macOS 27.0
If `true`, the system allows use of the captive WiFi portal at login or unlock.
booleanoptionalfalse
✗No
macOS (27.0+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information