System Policy - Kernel Extensions (com.apple.syspolicy.kernel-extension-policy)

com.apple.syspolicy.kernel-extension-policy

The payload that configures the kernel extension policies.

macOS(10.13.2)
Branch: release

Settings (7)

SettingTypeRequiredDefaultManual InstallSupported OS
AllowNonAdminUserApprovals
AllowNonAdminUserApprovals
If `true`, nonadministrative users can approve additional kernel extensions in the Security & Privacy preferences. Available in macOS 11 and later.
booleanoptionalfalse
Yes
macOS (11.0+)
AllowUserOverrides
AllowUserOverrides
If `true`, users can approve additional kernel extensions that configuration profiles don't explicitly allow.
booleanoptionalfalse
No
macOS (10.13.2+)
AllowedTeamIdentifiers
AllowedTeamIdentifiers
The array of team identifiers that define which validly signed kernel extensions can load.
1 subkey
arrayoptional
No
macOS (10.13.2+)
└─
Identifier
AllowedTeamIdentifiersItem
string
No
macOS (10.13.2+)
AllowedKernelExtensions
AllowedKernelExtensions
The dictionary that represents a set of kernel extensions that the system always allows to load on the computer. The dictionary maps team identifiers (keys) to arrays of bundle identifiers.
1 subkey
dictionaryoptional
No
macOS (10.13.2+)
└─
ANY
ANY
The kernel extension data.
1 subkey
arrayoptional
No
macOS (10.13.2+)
└─ └─
AllowedKernelExtensionsItems
AllowedKernelExtensionsItems
Kernel extension data.
stringrequired
No
macOS (10.13.2+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managedWi-Fi network configuration
  • com.apple.vpn.managedVPN configuration
  • com.apple.applicationaccessApp and feature restrictions
  • com.apple.security.pkcs1Certificate (PKCS#1) payload
  • com.apple.security.pkcs12Identity certificate (PKCS#12) payload
  • com.apple.security.scepSCEP certificate enrolment
  • com.apple.mail.managedMail account configuration
  • com.apple.eas.accountExchange ActiveSync account
  • com.apple.MCXManaged Client (macOS) preferences
  • com.apple.MCX.FileVault2FileVault 2 disk encryption
  • com.apple.dockmacOS Dock configuration
  • com.apple.screensaverScreensaver configuration
  • com.apple.loginwindowmacOS login window configuration
  • com.apple.systempolicy.managedGatekeeper / system policy
  • com.apple.systempreferencesSystem Preferences pane restrictions
  • com.apple.SoftwareUpdateSoftware update behaviour
  • com.apple.TCC.configuration-profile-policyPrivacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettingsPer-app notification settings
  • com.apple.webcontent-filterWeb content filter
  • com.apple.dnsSettings.managedDNS settings (DoH / DoT)
  • com.apple.relay.managedNetwork relay configuration
  • com.apple.extensiblessoExtensible Single Sign-On
  • com.apple.configuration.passcode.settingsDDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specificDDM: enforced software update
  • com.apple.configuration.services.configuration-filesDDM: service configuration files
  • com.apple.configuration.management.status-subscriptionsDDM: status subscriptions
  • com.apple.activation.simpleDDM: simple activation predicate
  • com.apple.management.organization-infoDDM: organization information