Safari:Extension Settings ()

The declaration to configure Safari Extensions.

iOS(18.0)macOS(15.0)visionOS(26.0)
Branch: release

Settings (8)

SettingTypeRequiredDefaultManual InstallSupported OS
Managed extensions
ManagedExtensions
The dictionary of managed extensions settings. Each key in the dictionary represents a composed identifier for a specific managed extension, or you can specify a single "\*" character to match any extension. The dictionary values represent the settings that Safari applies to each extension that matches the key. In order for the extension to be managed, its host app needs to be present on the device. The composed identifier of a managed extension uses the format "Identifier (TeamIdentifier)", for example "com.example.app (ABCD1234)". Use `codesign -dv <path_to_appex>` to show the information you need to generate this string on macOS, using the path to the extension bundle located in the "PlugIns" folder inside the app bundle. For other platforms, request this information from the app developer.
1 subkey
dictionaryoptional—
✓Yes
iOS (18.0+)macOS (15.0+)visionOS (26.0+)
└─
ANY
ANY
The dictionary that defines the settings for a managed extension. Each key represents a specific managed extension, or you can specify a single "*" character to match any extension.
4 subkeys
dictionaryoptional—
✓Yes
iOS (18.0+)macOS (15.0+)visionOS (26.0+)
└─ └─
Extension state
State
Controls whether an extension is allowed. The device uses this key when the extension identifier is a composed identifier or a single "\*" character. * `Allowed` - The user is allowed to turn the extension on or off. * `AlwaysOn` - The extension will always be on. * `AlwaysOff` - The extension will always be off.
stringoptional—
✓Yes
iOS (18.0+)macOS (15.0+)visionOS (26.0+)
└─ └─
Private browsing state
PrivateBrowsing
Controls whether an extension is allowed in Private Browsing. The device uses this key when the extension identifier is a composed identifier or a single "\*" character. * `Allowed` - The user is allowed to turn the extension on or off in Private Browsing. * `AlwaysOn` - The extension will always be on in Private Browsing if the extension is on outside of Private Browsing. * `AlwaysOff` - The extension will never be on in Private Browsing.
stringoptional—
✓Yes
iOS (18.0+)macOS (15.0+)visionOS (26.0+)
└─ └─
Allowed domains
AllowedDomains
Controls the domains and sub-domains the extension can access. The device ignores this key when the extension identifier is a single "*" character.
1 subkey
arrayoptional—
✓Yes
iOS (18.0+)macOS (15.0+)visionOS (26.0+)
└─ └─ └─
Domain
Domain
A domain or set of sub-domains where the extension is allowed
string—
✓Yes
iOS (18.0+)macOS (15.0+)visionOS (26.0+)
└─ └─
Denied domains
DeniedDomains
Controls the domains and sub-domains the extension isn't allowed to access. The device uses this key when the extension identifier is a composed identifier or a single "*" character.
1 subkey
arrayoptional—
✓Yes
iOS (18.0+)macOS (15.0+)visionOS (26.0+)
└─ └─ └─
Domain
Domain
A domain or set of sub-domains where the extension is not allowed
string—
✓Yes
iOS (18.0+)macOS (15.0+)visionOS (26.0+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information