Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Use the interactive explorer to search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Lights Out Management (LOM) (com.apple.lom)

com.apple.lom

The payload that configures lights-out management (LOM) settings.

macOS(11.0)
Branch: release

Settings (6)

SettingTypeRequiredDefaultManual InstallSupported OS
Device Certificate payload UUID
DeviceCertificateUUID
The UUID certificate for the device. This key indicates the device can receive `PowerON`, `PowerOFF`, and `Reset` requests from a LOM controller. This certificate must contain the Key Usage attributes of Digital Signature, Key Encipherment and Data Encipherment. As well as the Extended Key Usage attributes of Server Authentication and Client Authentication.
stringoptional
No
macOS (11.0+)
Controller Certificate payload UUID
ControllerCertificateUUID
The UUID certificate for the LOM controller. This key configures the device to accept the `LOMDeviceRequestCommand` from MDM and then send it to the target device.
stringoptional
No
macOS (11.0+)
CA certificate payload UUIDs
DeviceCACertificateUUIDs
An array of payload UUIDs containing CA certificates that controllers use to evaluate trust of device certificates.
1 subkey
arrayoptional
No
macOS (11.0+)
└─
DeviceCACertificateUUIDsItem
DeviceCACertificateUUIDsItem
string
No
macOS (11.0+)
CA certificate payload UUIDs
ControllerCACertificateUUIDs
An array of payload UUIDs containing CA certificates that devices use to evaluate trust of controller certificates. This key configures the device to accept the `LOMDeviceRequestCommand` from MDM and then send it to the target device. This certificate must contain the Key Usage attributes of Digital Signature, Key Encipherment and Data Encipherment. As well as the Extended Key Usage attributes of Server Authentication and Client Authentication.
1 subkey
arrayoptional
No
macOS (11.0+)
└─
ControllerCACertificateUUIDsItem
ControllerCACertificateUUIDsItem
string
No
macOS (11.0+)