Wi-Fi (com.apple.wifi.managed)

com.apple.wifi.managed

The payload that configures Wi-Fi settings.

iOS(4.0)macOS(10.7)tvOS(9.0)visionOS(1.0)watchOS(3.2)
Branch: release

Settings (62)

SettingTypeRequiredDefaultManual InstallSupported OS
Auto join
AutoJoin
If `true`, the device joins the network automatically. If `false`, the user must tap the network name to join it.
booleanoptionaltrue
✓Yes
iOS (5.0+)
SSID
SSID_STR
The SSID of the Wi-Fi network to use. In iOS 7.0 and later, the SSID is optional if a value exists for `DomainName` value.
stringoptional—
✓Yes
iOS (7.0+)
Hidden
HIDDEN_NETWORK
If `true`, defines this network as hidden.
booleanoptionalfalse
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
Proxy type
ProxyType
The proxy type, if any, to use. If you choose the manual proxy type, you need the proxy server address, including its port and optionally a user name and password into the proxy server. If you choose the auto proxy type, you can enter a proxy autoconfiguration (PAC) URL.
stringoptionalNone
✗No
Encryption type
EncryptionType
The encryption type for the network. If set to anything except `None`, the payload may contain the following three keys: `Password`, `PayloadCertificateUUID`, or `EAPClientConfiguration`. As of iOS 16, tvOS 16, watchOS 9, and macOS 13: - `WPA` allows joining WPA or WPA2 networks - `WPA2` allows joining WPA2 or WPA3 networks - `WPA3` allows joining WPA3 networks only - `Any` allows joining WPA, WPA2, WPA3, and WEP networks Prior to iOS 16, tvOS 16, and watchOS 9, specifying `WPA`, `WPA2`, and `WPA3` were equivalent and would allow joining any WPA network. Prior to macOS 13, the encryption type, if specified explicitly, needed to match the encryption type of the network exactly.
stringoptionalAny
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
Password
Password
The password for the access point.
stringoptional—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
Certificate UUID
PayloadCertificateUUID
The UUID of the certificate payload within the same profile to use for the client credential.
stringoptional—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
EAP client configuration
EAPClientConfiguration
The enterprise network configuration.
19 subkeys
dictionaryoptional—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Accept EAP types
AcceptEAPTypes
The EAP types that the system accepts. Allowed values: - `13`: EAP-TLS - `17`: LEAP - `18`: EAP-SIM - `21`: EAP-TTLS - `23`: EAP-AKA - `25`: PEAPv0/v1 - `43`: EAP-FAST For EAP-TLS authentication without a network payload, install the necessary identity certificates and have your users select EAP-TLS mode in the 802.1X credentials dialog that appears when they connect to the network. For other EAP types, a network payload is necessary and must specify the correct settings for the network.
1 subkey
arrayrequired—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─ └─
EAP type
EAPType
integer—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Username
UserName
The user name for the account. If you don't specify a value, the system prompts the user during login.
stringoptional—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Password
UserPassword
The user's password. If you don't specify a value, the system prompts the user during login.
stringoptional—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Certificate anchor UUID
PayloadCertificateAnchorUUID
An array of the UUID of each certificate payload in the same profile to trust for authentication. Use this key to prevent the device from asking the user whether to trust the listed certificates. The device disables dynamic trust (the certificate dialogue) if you specify this property without also enabling 'TLSAllowTrustExceptions'.
1 subkey
arrayoptional—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─ └─
Individual certificate anchor UUID
CertificateAnchorUUID
string—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
TLS trusted certificates
TLSTrustedCertificates
An array of trusted certificates. Each entry in the array must contain certificate data that represents an anchor certificate used for verifying the server certificate.
1 subkey
arrayoptional—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─ └─
TLSTrustedCertificatesItem
TLSTrustedCertificatesItem
A certificate identifier.
stringrequired—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
TLS trusted server names
TLSTrustedServerNames
The list of accepted server certificate common names. If a server presents a certificate that isn't in this list, the system doesn't trust it. If you specify this property, the system disables dynamic trust (the certificate dialog) unless you also specify 'TLSAllowTrustExceptions' with the value 'true'. If necessary, use a single "\*" character to specify a wildcard for an individual component of the name, such as 'wpa.\*.example.com'.
1 subkey
arrayoptional—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─ └─
Individual trusted TLS server name
TLSTrustedServerName
string—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Allow trust exceptions
TLSAllowTrustExceptions
If 'true', allows a dynamic trust decision by the user. The dynamic trust is the certificate dialogue that appears when the system doesn't trust a certificate. If 'false', the authentication fails if the system doesn't already trust the certificate. As of iOS 8, Apple no longer supports this key.
booleanoptionaltrue
✗No
└─
TLSCertificateIsRequired
TLSCertificateIsRequired
If 'true', allows for two-factor authentication for EAP-TTLS, PEAP, or EAP-FAST. If 'false', allows for zero-factor authentication for EAP-TLS. If you don't specify a value, the default is 'true' for EAP-TLS, and 'false' for other EAP types.
booleanoptionalfalse
✓Yes
iOS (7.0+)
└─
TTLS inner authentication
TTLSInnerAuthentication
The inner authentication that the TTLS module uses.
stringoptionalMSCHAPv2
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
TLSMinimumVersion
TLSMinimumVersion
The minimum TLS version for EAP authentication.
stringoptional1.0
✓Yes
iOS (11.0+)macOS (10.13+)tvOS (11.0+)
└─
TLSMaximumVersion
TLSMaximumVersion
The maximum TLS version for EAP authentication.
stringoptional1.2
✓Yes
iOS (11.0+)macOS (10.13+)tvOS (11.0+)
└─
Outer identity
OuterIdentity
A name that hides the user's true name. The user's actual name appears only inside the encrypted tunnel. For example, you might set this to anonymous or anon, or [email protected]. It can increase security because an attacker can't see the authenticating user's name in the clear. This key is only relevant to TTLS, PEAP, and EAP-FAST. This field is required if 'TLSMinimumVersion' is '1.3'.
stringoptional—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Use PAC
EAPFASTUsePAC
If 'true', the device uses an existing PAC if it's present. Otherwise, the server must present its identity using a certificate.
booleanoptionalfalse
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Provision PAC
EAPFASTProvisionPAC
If 'true', allows PAC provisioning. This value is only applicable if 'EAPFASTUsePAC' is 'true'. This value must be 'true' for EAP-FAST PAC usage to succeed because there's no other way to provision a PAC.
booleanoptionalfalse
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Provision PAC anonymously
EAPFASTProvisionPACAnonymously
If 'true', provisions the device anonymously. Note that there are known machine-in-the-middle attacks for anonymous provisioning.
booleanoptionalfalse
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Allow two RANDs
EAPSIMNumberOfRANDs
The minimum number of RAND values to accept from the server. For use with EAP-SIM only.
integeroptional3
✓Yes
iOS (8.0+)
└─
SystemModeCredentialsSource
SystemModeCredentialsSource
Set this string to 'ActiveDirectory' to use the AD computer name and password credentials. If using this property, you can't use 'SystemModeUseOpenDirectoryCredentials'.
stringoptional—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
SystemModeUseOpenDirectoryCredentials
SystemModeUseOpenDirectoryCredentials
If 'true', the system mode connection tries to use the Open Directory credentials. If using this property, you can't use 'SystemModeCredentialsSource'.
booleanoptionalfalse
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Per-connection password
OneTimeUserPassword
If 'true', the user receives a prompt for a password each time they connect to the network.
booleanoptionalfalse
✓Yes
iOS (8.0+)macOS (10.8+)tvOS (9.0+)
Displayed operator name
DisplayedOperatorName
The operator name to display when connected to this network. Used only with Wi-Fi Hotspot 2.0 access points.
stringoptional—
✓Yes
iOS (7.0+)macOS (10.9+)
Domain name
DomainName
The primary domain of the tunnel.
stringoptional—
✓Yes
iOS (7.0+)macOS (10.9+)
Roaming OIs
RoamingConsortiumOIs
An array of Roaming Consortium Organization Identifiers used for Wi-Fi Hotspot 2.0 negotiation.
1 subkey
arrayoptional—
✓Yes
iOS (7.0+)macOS (10.9+)
└─
RoamingConsortiumOI
RoamingConsortiumOI
string—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
Roaming enable
ServiceProviderRoamingEnabled
If `true`, allows connection to roaming service providers.
booleanoptionalfalse
✓Yes
iOS (7.0+)macOS (10.9+)
Is hotspot
IsHotspot
If `true`, the device treats the network as a hotspot.
booleanoptionalfalse
✓Yes
iOS (7.0+)macOS (10.9+)
HESSID
HESSID
The HESSID used for Wi-Fi Hotspot 2.0 negotiation.
stringoptional—
✓Yes
iOS (7.0+)
Realm names
NAIRealmNames
An array of Network Access Identifier Realm names used for Wi-Fi Hotspot 2.0 negotiation.
1 subkey
arrayoptional—
✓Yes
iOS (7.0+)macOS (10.9+)
└─
NAIRealmName
NAIRealmName
string—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
MCC/MNCs
MCCAndMNCs
An array of Mobile Country Code/Mobile Network Code (MCC/MNC) pairs used for Wi-Fi Hotspot 2.0 negotiation. Each string must contain exactly six digits.
1 subkey
arrayoptional—
✓Yes
iOS (7.0+)
└─
MCCAndMNC
MCCAndMNC
string—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
Disable captive network detection
CaptiveBypass
If `true`, the system bypasses Captive Network detection when the device connects to the network.
booleanoptionalfalse
✓Yes
iOS (10.0+)
QoS marking policy
QoSMarkingPolicy
A dictionary that contains the list of apps that the system allows to benefit from L2 and L3 marking. When this dictionary isn't present, the system allows all apps to use L2 and L3 marking when the Wi-Fi network supports Cisco QoS fast lane.
4 subkeys
dictionaryoptional—
✓Yes
iOS (10.0+)macOS (10.13+)
└─
Allowlisted app identifiers
QoSMarkingAllowListAppIdentifiers
An array of app bundle identifiers that defines the allow list for L2 and L3 marking for traffic that goes to the Wi-Fi network. If the array isn't present, but the `QoSMarkingPolicy` key is present — even empty — no apps can use L2 and L3 marking.
1 subkey
arrayoptional—
✓Yes
iOS (14.5+)macOS (14.0+)
└─ └─
Allowlisted app
appBundleID
string—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Whitelisted app identifiers
QoSMarkingWhitelistedAppIdentifiers
Deprecated (iOS 14.5, macOS 14.0)
Use `QoSMarkingAllowListAppIdentifiers` instead.
1 subkey
arrayoptional—
✓Yes
iOS (legacy - 14.5)macOS (legacy - 14.0)
└─ └─
Allowlisted app
appBundleID
string—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
QoS marking for audio or video calls
QoSMarkingAppleAudioVideoCalls
If `true`, adds audio and video traffic of built-in audio or video services, such as FaceTime and Wi-Fi Calling, to the allow list for L2 and L3 marking for traffic that goes to the Wi-Fi network.
booleanoptionaltrue
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
└─
Allow QoS marking
QoSMarkingEnabled
If `true`, disables L3 marking and only uses L2 marking for traffic that goes to the Wi-Fi network. If `false`, the system behaves as if Wi-Fi doesn't have an association with a Cisco QoS fast lane network.
booleanoptionaltrue
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
SetupModes
SetupModes
An array of strings that contain the type of connection mode to attach.
1 subkey
arrayoptional—
✓Yes
macOS (10.7+)
└─
SetupModesItem
SetupModesItem
A type of connection mode.
stringrequired—
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
EnableIPv6
EnableIPv6
If `true`, enables IPv6 on this interface.
booleanoptionaltrue
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
Certificate required
TLSCertificateRequired
If `true`, allows for two-factor authentication for EAP-TTLS, PEAP, or EAP-FAST. If `false`, allows for zero-factor authentication for EAP-TLS.
booleanoptionalfalse
✓Yes
iOS (4.0+)macOS (10.7+)tvOS (9.0+)visionOS (1.0+)watchOS (3.2+)
Proxy server
ProxyServer
The proxy server's network address.
stringoptional—
✗No
Proxy server port
ProxyServerPort
The proxy server's port number.
Range: 0 - 65535
integeroptional—
✗No
Proxy username
ProxyUsername
The user name used to authenticate to the proxy server.
stringoptional—
✗No
Proxy password
ProxyPassword
The password used to authenticate to the proxy server.
stringoptional—
✗No
Proxy PAC URL
ProxyPACURL
The URL of the PAC file that defines the proxy configuration.
stringoptional—
✗No
Proxy PAC fallback allowed
ProxyPACFallbackAllowed
If `true`, allows connecting directly to the destination if the PAC file is unreachable.
booleanoptionalfalse
✗No
Disable MAC address randomization during association
DisableAssociationMACRandomization
If `true,` disables MAC address randomization for a Wi-Fi network while associated with that network. This feature also shows a privacy warning in Settings indicating that the network has reduced privacy protections. If `false`, then the system enables MAC address randomization on iOS, watchOS, and visionOS. This value is only locked when MDM installs the profile. If the profile is manually installed, the system sets the value but the user can change it.
booleanoptionalfalse
✓Yes
iOS (14.0+)macOS (15.0+)watchOS (7.0+)
Allow join before first unlock
AllowJoinBeforeFirstUnlock
If `true`, the device makes this network available for joining before the device is unlocked for the first time following a reboot, on a device configured for return to service. The device places any network credentials into Class D storage within the keychain and stores information about the network on disk in Class D. There are several restrictions on the use of this flag: - This property is only available in the return to service mode. - You can designate only one network as available before first unlock. - `EAPClientConfiguration` must not be present. - If `IsHotspot` is present, it must be set to `false`. - `QoSMarkingPolicy` must not be present. - If `ProxyType` is present, it must be set to `None`. The device fails to install the profile payload if any of these conditions aren't met.
booleanoptionalfalse
✓Yes
visionOS (26.0+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information