App-Layer VPN (com.apple.vpn.managed.applayer)

com.apple.vpn.managed.applayer

The payload that configures a per-app VPN.

iOS(7.0)macOS(10.9)visionOS(1.1)watchOS(10.0)
Branch: release

Settings (17)

SettingTypeRequiredDefaultManual InstallSupported OS
VPNUUID
VPNUUID
A globally unique identifier for this VPN configuration.
stringrequired—
✓Yes
iOS (7.0+)macOS (10.9+)visionOS (1.1+)watchOS (10.0+)
Cellular Slice UUID
CellularSliceUUID
A string representing the data network name (DNN) or app category identifying a Cellular Slice. The device forces the VPN tunnel to use the specified Cellular Slice.
stringoptional—
✓Yes
iOS (18.0+)
SafariDomains
SafariDomains
An array with entries that must each specify a domain that triggers the VPN connection in Safari. Each entry is in the format `www.apple.com`.
1 subkey
arrayoptional—
✗No
└─
SafariDomainsItem
SafariDomainsItem
A domain.
stringrequired—
✓Yes
iOS (7.0+)macOS (10.9+)visionOS (1.1+)watchOS (10.0+)
MailDomains
MailDomains
Deprecated (iOS 13.4)
An array with entries that must each specify a domain that triggers this VPN connection in Mail. Each entry is in the format `www.apple.com`. This property is deprecated in iOS 13.4 and later; use the `VPNUUID` property of the `Mail` or `ExchangeActiveSync` payload instead.
1 subkey
arrayoptional—
✓Yes
iOS (13.0 - 13.4)macOS (10.15+)
└─
MailDomainsItem
MailDomainsItem
A domain.
stringrequired—
✓Yes
iOS (7.0+)macOS (10.9+)visionOS (1.1+)watchOS (10.0+)
CalendarDomains
CalendarDomains
Deprecated (iOS 13.4)
An array with entries that must each specify a domain that triggers this VPN connection in Calendar. Each entry is in the format `www.apple.com`. This property is deprecated in iOS 13.4 and later; use the `VPNUUID` property of the `CalDAV` payload instead.
1 subkey
arrayoptional—
✓Yes
iOS (13.0 - 13.4)macOS (10.15+)
└─
CalendarDomainsItem
CalendarDomainsItem
A domain.
stringrequired—
✓Yes
iOS (7.0+)macOS (10.9+)visionOS (1.1+)watchOS (10.0+)
ContactsDomains
ContactsDomains
Deprecated (iOS 13.4)
An array with entries that must each specify a domain that triggers this VPN connection in Contacts. Each entry is in the format `www.apple.com`. This property is deprecated in iOS 13.4 and later; use the `VPNUUID` property of the `CardDAV` payload instead.
1 subkey
arrayoptional—
✓Yes
iOS (13.0 - 13.4)macOS (10.15+)
└─
ContactsDomainsItem
ContactsDomainsItem
A domain.
stringrequired—
✓Yes
iOS (7.0+)macOS (10.9+)visionOS (1.1+)watchOS (10.0+)
AssociatedDomains
AssociatedDomains
An array with entries that must each specify a domain that triggers this VPN. The domains must also be part of the `apple-app-site-association` file, as described in `Supporting associated domains`.
1 subkey
arrayoptional—
✓Yes
iOS (14.0+)macOS (11.0+)
└─
AssociatedDomainsItem
AssociatedDomainsItem
A domain.
stringrequired—
✓Yes
iOS (7.0+)macOS (10.9+)visionOS (1.1+)watchOS (10.0+)
ExcludedDomains
ExcludedDomains
An array with entries that each specify a domain that doesn't trigger this VPN for connections to the domain.
1 subkey
arrayoptional—
✓Yes
iOS (14.0+)macOS (11.0+)
└─
ExcludedDomainsItem
ExcludedDomainsItem
A domain.
stringrequired—
✓Yes
iOS (7.0+)macOS (10.9+)visionOS (1.1+)watchOS (10.0+)
OnDemandMatchAppEnabled
OnDemandMatchAppEnabled
If `true`, automatically connects the VPN when associated apps for this per-app VPN service initiate network communication. Otherwise, the user must initiate the connection manually before those apps can initiate network communication. If this key isn't present, the value of the `OnDemandEnabled` key determines the status of per-app VPN On Demand.
booleanoptional—
✓Yes
iOS (7.0+)macOS (10.9+)visionOS (1.1+)watchOS (10.0+)
SMBDomains
SMBDomains
An array of SMB domains that's accessible through this VPN connection.
1 subkey
arrayoptional—
✓Yes
iOS (13.0+)
└─
SMBDomainsItem
SMBDomainsItem
An SMB domain.
stringrequired—
✓Yes
iOS (7.0+)macOS (10.9+)visionOS (1.1+)watchOS (10.0+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information