Single Sign-On (com.apple.sso)

Deprecated (iOS 26.0)
com.apple.sso

The payload that configures single sign-on (SSO).

iOS(7.0 - 26.0)
Branch: release

Settings (9)

SettingTypeRequiredDefaultManual InstallSupported OS
Name
Name
Deprecated (iOS 26.0)
The human-readable name for the account.
stringrequired—
✓Yes
iOS (7.0 - 26.0)
Kerberos
Kerberos
Deprecated (iOS 26.0)
The Kerberos dictionary.
5 subkeys
dictionaryoptional—
✓Yes
iOS (7.0 - 26.0)
└─
PrincipalName
PrincipalName
Deprecated (iOS 26.0)
The principal name. If not provided, the system prompts the user for one during profile installation. Required for MDM installation.
stringoptional—
✓Yes
iOS (7.0 - 26.0)
└─
PayloadCertificateUUID
PayloadCertificateUUID
Deprecated (iOS 26.0)
The `PayloadUUID` of an identity certificate payload that the system can use to renew the Kerberos credential without user interaction. Set the payload type to either `com.apple.security.pkcs12` or `com.apple.security.scep` in the certificate payload. The configuration file needs to contain both the SSO payload and the identity certificate payload.
stringoptional—
✓Yes
iOS (8.0 - 26.0)
└─
Realm
Realm
Deprecated (iOS 26.0)
The properly capitalized realm name.
stringrequired—
✓Yes
iOS (7.0 - 26.0)
└─
URLPrefixMatches
URLPrefixMatches
Deprecated (iOS 26.0)
The list of URL prefixes to match in order to use this account for Kerberos authentication over HTTP. If this key is missing, the system makes the account eligible to match all `http://` and `https://` URLs. Begin the URL matching patterns with either `http://` or `https://`. The system performs a simple string match, so the URL prefix `http://www.apple.com/` doesn't match `http://www.apple.com:80/`. However, if a matching pattern doesn't end in `/`, the system automatically append a `/` to it.
1 subkey
arrayoptional—
✓Yes
iOS (7.0 - 26.0)
└─ └─
URLPrefixMatchesItem
URLPrefixMatchesItem
Deprecated (iOS 26.0)
A URL prefix.
stringrequired—
✓Yes
iOS (7.0 - 26.0)
└─
AppIdentifierMatches
AppIdentifierMatches
Deprecated (iOS 26.0)
The list of app identifiers that the system allows to use this login. If this field missing, the system matches all app identifiers with this login. Don't set an empty array. The array needs to contain strings that match App Bundle IDs. These strings can be exact matches such as `com.mycompany.myapp`, or they may specify a prefix match on the Bundle ID by using the `\*` wildcard character. The wildcard character needs to appear after a period (`.`), and may only appear once, at the end of the string, for example, `com.mycompany.\*`. When you provide a wildcard, the system grants access to the account to any app with a Bundle ID that begins with the prefix.
1 subkey
arrayoptional—
✓Yes
iOS (7.0 - 26.0)
└─ └─
AppIdentifierMatchesItem
AppIdentifierMatchesItem
Deprecated (iOS 26.0)
An app identifier.
stringrequired—
✓Yes
iOS (7.0 - 26.0)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information