Firewall (com.apple.security.firewall)

com.apple.security.firewall

The payload that configures the firewall.

macOS(10.12)
Branch: release

Settings (9)

SettingTypeRequiredDefaultManual InstallSupported OS
EnableFirewall
EnableFirewall
If `true`, the system enables the firewall.
booleanrequired—
✓Yes
macOS (10.12+)
BlockAllIncoming
BlockAllIncoming
If `true`, the system enables blocking all incoming connections.
booleanoptional—
✓Yes
macOS (10.12+)
EnableStealthMode
EnableStealthMode
If `true`, the system enables stealth mode.
booleanoptional—
✓Yes
macOS (10.12+)
Applications
Applications
The list of apps with connections that the firewall controls.
1 subkey
arrayoptional—
✓Yes
macOS (10.12+)
└─
Applications
ApplicationsItem
2 subkeys
dictionary—
✓Yes
macOS (10.12+)
└─ └─
Application identifier
BundleID
The bundle identifier for the app.
stringrequired—
✓Yes
macOS (10.12+)
└─ └─
Allow connections
Allowed
If `true`, the system allows connections for the app.
booleanrequired—
✓Yes
macOS (10.12+)
AllowSigned
AllowSigned
If `true`, the system allows built-in software to receive incoming connections. > Note: > The system ensures that `AllowSigned` always has a value. If missing from the payload, the system sets it to `true`.
booleanoptionaltrue
✓Yes
macOS (12.3+)
AllowSignedApp
AllowSignedApp
If `true`, the system allows downloaded signed software to receive incoming connections. > Note: > The system ensures that `AllowSignedApp` always has a value. If missing from the payload, the system sets it to `true`.
booleanoptionaltrue
✓Yes
macOS (12.3+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information