Media Management: Allowed Media (com.apple.systemuiserver)

Deprecated (macOS 11.0)
com.apple.systemuiserver

The payload that configures media management.

macOS(10.7 - 11.0)
Branch: release

Settings (72)

SettingTypeRequiredDefaultManual InstallSupported OS
logout-eject
logout-eject
Deprecated (macOS 11.0)
The media type dictionary that defines volumes to eject when the user logs out.
12 subkeys
dictionaryoptional—
✓Yes
macOS (10.7 - 11.0)
└─
all-media
all-media
Deprecated (macOS 11.0)
Unused; set to an empty string.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
cd
cd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
dvd
dvd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
bd
bd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
blankcd
blankcd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
blankdvd
blankdvd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
blankbd
blankbd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
dvdram
dvdram
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
disk-image
disk-image
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
harddisk-internal
harddisk-internal
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
harddisk-external
harddisk-external
Deprecated (macOS 11.0)
A string or an array of media action strings. The hard disk-external category includes internally installed SD cards and USB flash drives. This key is the default for media types that don't fall into other categories.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
networkdisk
networkdisk
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
mount-controls
mount-controls
Deprecated (macOS 11.0)
The media type dictionary that controls volume mounting.
12 subkeys
dictionaryoptional—
✓Yes
macOS (10.7 - 11.0)
└─
all-media
all-media
Deprecated (macOS 11.0)
Unused; set to an empty string.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
cd
cd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
dvd
dvd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
bd
bd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
blankcd
blankcd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
blankdvd
blankdvd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
blankbd
blankbd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
dvdram
dvdram
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
disk-image
disk-image
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
harddisk-internal
harddisk-internal
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
harddisk-external
harddisk-external
Deprecated (macOS 11.0)
A string or an array of media action strings. The hard disk-external category includes internally installed SD cards and USB flash drives. This key is the default for media types that don't fall into other categories.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
networkdisk
networkdisk
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
unmount-controls
unmount-controls
Deprecated (macOS 11.0)
The media type dictionary that controls volume unmounting.
12 subkeys
dictionaryoptional—
✓Yes
macOS (10.7 - 11.0)
└─
all-media
all-media
Deprecated (macOS 11.0)
Unused; set to an empty string.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
cd
cd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
dvd
dvd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
bd
bd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
blankcd
blankcd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
blankdvd
blankdvd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
blankbd
blankbd
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
dvdram
dvdram
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
disk-image
disk-image
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
harddisk-internal
harddisk-internal
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
harddisk-external
harddisk-external
Deprecated (macOS 11.0)
A string or an array of media action strings. The hard disk-external category includes internally installed SD cards and USB flash drives. This key is the default for media types that don't fall into other categories.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)
└─
networkdisk
networkdisk
Deprecated (macOS 11.0)
A media action string or an array of media action strings.
1 subkey
arrayoptional—
✓Yes
macOS (10.7 - 11.0)
└─ └─
ActionStringItem
ActionStringItem
Deprecated (macOS 11.0)
One of the following values: * authenticate - User will be authenticated before media is mounted * read-only - The media will be mounted read-only. Not valid for unmount-controls. * deny - The media will not be mounted. * eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.
stringoptional—
✓Yes
macOS (10.7 - 11.0)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information