The payload that configures the kernel extension policies.
| Setting | Type | Required | Default | Manual Install | Supported OS |
|---|---|---|---|---|---|
AllowNonAdminUserApprovals AllowNonAdminUserApprovals If `true`, nonadministrative users can approve additional kernel extensions in the Security & Privacy preferences.
Available in macOS 11 and later. | boolean | optional | false | ✓Yes | macOS (11.0+) |
AllowUserOverrides AllowUserOverrides If `true`, users can approve additional kernel extensions that configuration profiles don't explicitly allow. | boolean | optional | false | ✗No | macOS (10.13.2+) |
AllowedTeamIdentifiers AllowedTeamIdentifiers The array of team identifiers that define which validly signed kernel extensions can load. 1 subkey | array | optional | — | ✗No | macOS (10.13.2+) |
└─ Identifier AllowedTeamIdentifiersItem | string | — | ✗No | macOS (10.13.2+) | |
AllowedKernelExtensions AllowedKernelExtensions The dictionary that represents a set of kernel extensions that the system always allows to load on the computer. The dictionary maps team identifiers (keys) to arrays of bundle identifiers. 1 subkey | dictionary | optional | — | ✗No | macOS (10.13.2+) |
└─ ANY ANY The kernel extension data. 1 subkey | array | optional | — | ✗No | macOS (10.13.2+) |
└─ └─ AllowedKernelExtensionsItems AllowedKernelExtensionsItems Kernel extension data. | string | required | — | ✗No | macOS (10.13.2+) |
Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.
com.apple.wifi.managed – Wi-Fi network configurationcom.apple.vpn.managed – VPN configurationcom.apple.applicationaccess – App and feature restrictionscom.apple.security.pkcs1 – Certificate (PKCS#1) payloadcom.apple.security.pkcs12 – Identity certificate (PKCS#12) payloadcom.apple.security.scep – SCEP certificate enrolmentcom.apple.mail.managed – Mail account configurationcom.apple.eas.account – Exchange ActiveSync accountcom.apple.MCX – Managed Client (macOS) preferencescom.apple.MCX.FileVault2 – FileVault 2 disk encryptioncom.apple.dock – macOS Dock configurationcom.apple.screensaver – Screensaver configurationcom.apple.loginwindow – macOS login window configurationcom.apple.systempolicy.managed – Gatekeeper / system policycom.apple.systempreferences – System Preferences pane restrictionscom.apple.SoftwareUpdate – Software update behaviourcom.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)com.apple.notificationsettings – Per-app notification settingscom.apple.webcontent-filter – Web content filtercom.apple.dnsSettings.managed – DNS settings (DoH / DoT)com.apple.relay.managed – Network relay configurationcom.apple.extensiblesso – Extensible Single Sign-Oncom.apple.configuration.passcode.settings – DDM: passcode policycom.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software updatecom.apple.configuration.services.configuration-files – DDM: service configuration filescom.apple.configuration.management.status-subscriptions – DDM: status subscriptionscom.apple.activation.simple – DDM: simple activation predicatecom.apple.management.organization-info – DDM: organization information