Relay (com.apple.relay.managed)

Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
com.apple.relay.managed

The payload that configures relay settings.

iOS(17.0 - 27.0)macOS(14.0 - 27.0)tvOS(17.0)visionOS(1.0 - 27.0)
Branch: release

Settings (20)

SettingTypeRequiredDefaultManual InstallSupported OS
Relays
Relays
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
An array of dictionaries that describe one or more relay servers that the system can chain together.
1 subkey
arrayrequired—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
└─
Network relay
Relay
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
5 subkeys
dictionary—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
└─ └─
HTTP/3 relay URL
HTTP3RelayURL
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
The URL or URI template, as defined in RFC 9298, of a relay server that's reachable using HTTP/3 and supports proxying TCP and UDP using the CONNECT method. Each relay needs to include either `HTTP2RelayURL` or `HTTP3RelayURL`, or it can include both.
stringoptional—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
└─ └─
HTTP/2 relay URL
HTTP2RelayURL
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
The URL or URI template, as defined in RFC 9298, of a relay server that's reachable using HTTP/2 and supports proxying TCP and UDP using the CONNECT method. Each relay needs to include either `HTTP2RelayURL` or `HTTP3RelayURL`, or it can include both.
stringoptional—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
└─ └─
Additional HTTP header fields
AdditionalHTTPHeaderFields
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
A dictionary that contains custom HTTP header keys and values to add to each request. The dictionary key name represents the HTTP header field name to use, and the dictionary value is the string to use as the HTTP header field value.
1 subkey
dictionaryoptional—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
└─ └─ └─
ANY
ANY
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
The HTTP header field value for the corresponding header field name.
stringrequired—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
└─ └─
Certificate UUID
PayloadCertificateUUID
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
The UUID that points to an identity certificate payload, which the system uses to authenticate the user to the relay server.
stringoptional—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
└─ └─
Raw public keys
RawPublicKeys
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
An array of DER-encoded raw public keys that the system uses to authenticate the server during a TLS handshake. The server needs to use one of the keys in the handshake to authenticate. If this array is empty, the system uses the default TLS trust evaluation.
1 subkey
arrayoptional—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
└─ └─ └─
Raw public key element
RawPublicKeysElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
data—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
Match domains
MatchDomains
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
A list of domain strings that the system uses to determine which connection to route through the servers in `Relays`. Any connection that matches a domain in the list exactly or is a subdomain of the listed domain uses the relay servers, unless it matches a domain in `ExcludedDomains`. If this list and `MatchFQDNs` are empty, the system routes traffic to all domains to the relay servers, except those that match an excluded domain or excluded FQDN.
1 subkey
arrayoptional—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
└─
Match domains element
MatchDomainsElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
string—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
Excluded domains
ExcludedDomains
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
A list of domain strings to exclude from routing through the servers in `Relays`. Any connection that matches a domain in the list exactly or is a subdomain of the listed domain won't use the relay server.
1 subkey
arrayoptional—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
└─
Excluded domains element
ExcludedDomainsElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
string—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
Match FQDNs
MatchFQDNs
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
A list of Fully Qualified Domain Names (FQDNs) to route through the servers contained in `Relays`. Any connection that matches an FQDN in the list exactly uses the relay servers. If this list and `MatchDomains` are empty, the system routes traffic to all domains to the relay servers, except those that match an excluded domain or excluded FQDN.
1 subkey
arrayoptional—
✓Yes
iOS (18.4 - 27.0)macOS (15.4 - 27.0)tvOS (18.4 - deprecated)visionOS (2.4 - 27.0)
└─
Match FQDNs element
MatchFQDNsElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
string—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
Excluded FQDNs
ExcludedFQDNs
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
A list of Fully Qualified Domain Names (FQDNs) to exclude from routing through the servers contained in `Relays`. Any connection that matches an FQDN in the list exactly won't use the relay server. When `MatchDomains` is also present, any FQDN listed in the list should be a subdomain of at least one `MatchDomain` value, otherwise it won't have any effect.
1 subkey
arrayoptional—
✓Yes
iOS (18.4 - 27.0)macOS (15.4 - 27.0)tvOS (18.4 - deprecated)visionOS (2.4 - 27.0)
└─
Excluded FQDNs element
ExcludedFQDNsElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
string—
✓Yes
iOS (17.0 - 27.0)macOS (14.0 - 27.0)tvOS (17.0 - deprecated)visionOS (1.0 - 27.0)
Relay UUID
RelayUUID
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
A globally unique identifier for this relay configuration. The system uses this UUID to route managed apps through the servers in `Relays`. This key is required for user enrollment.
stringoptional—
✗No
UI toggle enabled
UIToggleEnabled
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
If `true`, the device allows the user to disable this network relay configuration.
booleanoptionaltrue
✓Yes
iOS (26.0 - 27.0)macOS (26.0 - 27.0)tvOS (26.0 - deprecated)visionOS (26.0 - 27.0)
Allow DNS failover
AllowDNSFailover
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
If `true`, the device allows the relay to failover to the default system DNS resolver.
booleanoptionalfalse
✓Yes
iOS (26.0 - 27.0)macOS (26.0 - 27.0)tvOS (26.0 - deprecated)visionOS (26.0 - 27.0)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information