The declaration to configure Extensible Single Sign-On.
| Setting | Type | Required | Default | Manual Install | Supported OS |
|---|---|---|---|---|---|
Extension composed identifier ExtensionComposedIdentifier The identifier of the provider to use for this configuration. Useful for apps that contain more than one DNS proxy extension.
In iOS and visionOS, the identifier is a bundle ID, for example, "com.example.app.sso-extension".
In macOS, the identifier is a composed identifier. The format of the composed identifier is "Bundle-ID (Team-ID)". "Bundle-ID" is the bundle identifier string of the app extension. "Team-ID" is the team identifier from the app extension's code signature. For example, "com.example.app.sso-extension (ABCD1234)". | string | required | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
Type Type The type of SSO. | string | required | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
Realm Realm The realm name for `Credential` payloads. Use proper capitalization for this value. Ignored for `Redirect` payloads. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
Extension data ExtensionData A dictionary of arbitrary data passed through to the app extension. 1 subkey | dictionary | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ ANY ANY Keys and values to pass to the app extension. | any | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
URLs URLs An array of URL prefixes of identity providers where the app extension performs SSO.
Required for `Redirect` payloads. Ignored for `Credential` payloads.
The URLs need to begin with `http://` or `https://`.
The system:
- Matches scheme and host name case-insensitively
- Doesn't allow query parameters and URL fragments
- Requires that the URLs of all installed Extensible SSO payloads are unique 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ URL URL An http or https URL prefix. | string | required | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
Hosts Hosts An array of host or domain names that apps can authenticate through the app extension.
Required for `Credential` payloads. Ignored for `Redirect` payloads.
The system:
- Matches host or domain names case-insensitively
- Requires that all the host and domain names of all installed Extensible SSO payloads are unique
> Note:
> Host names that begin with a "." are wildcard suffixes that match all subdomains; otherwise the host name needs be an exact match. 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ hostname hostname A host or domain name, with or without a leading dot. | string | required | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
Denied bundle identifiers DeniedBundleIdentifiers An array of bundle identifiers of apps that don't use SSO provided by this extension. 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ bundleIdentifier bundleIdentifier The bundle identifier of the app. | string | required | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
Screen locked behavior ScreenLockedBehavior If set to `Cancel`, the system cancels authentication requests when the screen is locked. If set to `DoNotHandle`, the request continues without SSO instead. This doesn't apply to requests where `userInterfaceEnabled` is `false`, or for background `URLSession` requests. | string | optional | Cancel | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
Platform SSO PlatformSSO The dictionary to configure Platform SSO. 11 subkeys | dictionary | optional | — | ✗No | |
└─ Authentication method AuthenticationMethod The Platform SSO authentication method to use with the extension. Requires that the SSO Extension also support the method. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ Registration token RegistrationToken The token this device uses for registration with Platform SSO. Use it for silent registration with the Identity Provider. Requires that `AuthenticationMethod` in `PlatformSSO` isn't empty. | string | optional | — | ✗No | |
└─ Use shared device keys UseSharedDeviceKeys If `true`, the system uses the same signing and encryption keys for all users. | boolean | optional | false | ✗No | |
└─ Login frequency LoginFrequency The duration, in seconds, until the system requires a full login instead of a refresh. The default value is 64,800 (18 hours). The minimum value is 3600 (1 hour). Range: 3600 - | integer | optional | 64800 | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ Allow device identifiers in attestation AllowDeviceIdentifiersInAttestation If `true`, the system includes the device UDID and serial number in Platform SSO attestations. | boolean | optional | false | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ Account Account Account display and profile settings. 2 subkeys | dictionary | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Display name DisplayName The display name for the account in notifications and authentication requests. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Synchronize profile picture SynchronizeProfilePicture If `true`, the system requests the user's profile picture from the SSO extension. | boolean | optional | false | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ User creation UserCreation Settings for creating new users via Platform SSO. 7 subkeys | dictionary | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Enable at login EnableAtLogin Enables creating users at the Login Window with an `AuthenticationMethod` of either `Password` or `SmartCard`. Requires that `UseSharedDeviceKeys` is `true`. | boolean | optional | false | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Enable first user during setup EnableFirstUserDuringSetup If `true`, the device uses Platform SSO to create the first user account on the Mac during `Setup Assistant`. | boolean | optional | true | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Enable registration during setup EnableRegistrationDuringSetup If `true`, the system enables the PlatformSSO registration process during Setup Assistant on devices running macOS 26 and later. Set this key to `true` when configuring PlatformSSO before enrollment using the `com.apple.psso.required` error response. | boolean | optional | false | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ New user authentication methods NewUserAuthenticationMethods The set of authentication methods to use for newly created accounts at login or during `Setup Assistant`. The system uses `Password` and `SmartCard` if this key isn't present. 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ NewUserAuthenticationMethod NewUserAuthenticationMethod An authentication method to use for newly created accounts at login or during `Setup Assistant`. Allowed values:
* `Password`: The account uses a password for authentication.
* `SmartCard`: The account uses a smart card for authentication.
* `AccessKey`: The account uses an access key for authentication.
* `OpenID`: The account uses OpenID for authentication. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ New user authorization mode NewUserAuthorizationMode The permission to apply to newly created accounts at login. Allowed values:
* `Standard`: The account is a standard user.
* `Admin`: The system adds the account to the local administrators group.
* `Groups`: The system assigns groups to the account using `Authorization.AdministratorGroups`, `Authorization.AdditionalGroups`, or `Authorization.AuthorizationGroups`.
* `Temporary`: The system uses a temporary session configuration for newly created accounts at login. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Token to user mapping TokenToUserMapping The attribute mapping to use when creating users, or for authorization. 2 subkeys | dictionary | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ Account name AccountName The claim name to use for the user's account name. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ Full name FullName The claim name to use for the user's full name. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Temporary session quick login TemporarySessionQuickLogin If `true`, the system uses a quicker Authenticated Guest Mode login to Mac behavior. The system erases user data from only select locations in the user home directory after each session completes. Once every eight hours the system erases the full user home directory after a session completes. Turn this on for shared environments that have a high frequency of short sessions. | boolean | optional | false | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ Authorization Authorization Settings for authorization prompts and group management. 5 subkeys | dictionary | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Enable identity provider accounts EnableIdentityProviderAccounts Enables using identity provider accounts at authorization prompts. Requires that `UseSharedDeviceKeys` is `true`. The system assigns groups using `AdministratorGroups`, `AdditionalGroups`, or `AuthorizationGroups`. | boolean | optional | false | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ User authorization mode UserAuthorizationMode The permission to apply to an account each time the user authenticates. Allowed values:
* `Standard`: The account is a standard user.
* `Admin`: The system adds the account to the local administrators group.
* `Groups`: The system assigns group to the account using `AdministratorGroups`, `AdditionalGroups`, or `AuthorizationGroups`. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Administrator groups AdministratorGroups The list of groups to use for administrator access. The system requests membership during authentication. 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ Group Group The group name. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Additional groups AdditionalGroups The list of created groups that don't have administrator access. 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ Group Group The group name. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Authorization groups AuthorizationGroups The pairing of Authorization Rights to group names. When using this, the system updates the Authorization Right to use the group. 1 subkey | dictionary | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ ANY ANY The key is an access right value, the value is the group to be associated with that access right. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ Access key AccessKey Settings for Access Key authentication. 4 subkeys | dictionary | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Reader group identifier ReaderGroupIdentifier The reader group identifier for use with the `AccessKey`. The value needs to match the configured access key. Required if `UserCreation.AuthenticationMethods` contains `AccessKey`. | data | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Terminal identity asset reference TerminalIdentityAssetReference The identifier of an asset declaration that contains the identity to use as the Terminal identity of the Access Key. The Access Key needs to trust the identity. Required if `UserCreation.AuthenticationMethods` includes `AccessKey`. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Reader issuer certificate asset reference ReaderIssuerCertificateAssetReference The identifier of an asset declaration that contains the certificate for the issuer certificate of the `Terminal` identity of the access key. Other specifications refer to the key as the "Reader CA Public Key". The key must be an elliptic curve key. Required if `UserCreation.AuthenticationMethods` includes `AccessKey`. The issuer of the Terminal identity of the access key needs to match this certificate, otherwise the device fails the authentication. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Allow express mode AllowExpressMode If `true`, the system uses the access key in express mode, and doesn't require authentication before use. | boolean | optional | false | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ Policies Policies Policies for login, unlock, and FileVault behavior. 6 subkeys | dictionary | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ FileVault FileVault The policy to apply when using Platform SSO at FileVault unlock on a Mac with Apple silicon. Applies when `AuthenticationMethod` is `Password`.
* `AttemptAuthentication`: The device attempts Platform SSO authentication before proceeding. If offline, unlock continues if the local account password matches. If online and the credential is incorrect, then the device requires a successful Platform SSO authentication is required, even if taken offline.
* `RequireAuthentication`: The device requires Platform SSO authentication before proceeding. If the device is offline and `AllowOfflineGracePeriod` is enabled, then the device uses the offline `OfflineGracePeriod` to determine if the user can proceed or not. If online and the credential is incorrect, then the device requires a valid Platform SSO authentication to proceed, regardless of the `OfflineGracePeriod`. If the account isn't registered for Platform SSO and `AllowAuthenticationGracePeriod` is enabled, then the device uses `AuthenticationGracePeriod` to determine if the user can proceed or not.
* `AllowOfflineGracePeriod`: The device allows the use of the `OfflineGracePeriod` when `RequireAuthentication` is enabled. If `AllowOfflineGracePeriod` isn't set, then the device denies offline access.
* `AllowAuthenticationGracePeriod`: The device allows the use of the `AuthenticationGracePeriod` for other local accounts when `RequireAuthentication` is enabled. The `AuthenticationGracePeriod` starts when any of the policies are updated. If `AllowAuthenticationGracePeriod` isn't set, then the device denies unregistered account access.
* `RequireTouchID`: The device requires the use of Touch ID (and not Apple Watch) for File Vault unlock.
* `RequireTouchIDOrWatch`: The device requires the use of Touch ID or Apple Watch for File Vault unlock.
* `AllowOpenIDForTouchIDFallback`: The device allows web login as a fallback if touchID fails or isn't available. 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ policy policy The policy to apply. | string | required | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Login Login The policy to apply when using Platform SSO at the Login Window. Applies when `AuthenticationMethod` is `Password`.
* `AttemptAuthentication`: The device attempts Platform SSO authentication before proceeding. If offline, login continues if the local account password matches. If online and the credential is incorrect, then the device requires a successful Platform SSO authentication to proceed, even if taken offline.
* `RequireAuthentication`: The device requires Platform SSO authentication before proceeding. If the device is offline and `AllowOfflineGracePeriod` is enabled, then the device uses the offline `OfflineGracePeriod` to determine if the user can proceed or not. If online and the credential is incorrect, then the device requires a valid Platform SSO authentication to proceed, regardless of the `OfflineGracePeriod`. If the account isn't registered for Platform SSO and `AllowAuthenticationGracePeriod` is enabled, then the device uses the `AuthenticationGracePeriod` to determine if the user can proceed or not.
* `AllowOfflineGracePeriod`: The device allows the use of the `OfflineGracePeriod` when `RequireAuthentication` is enabled. If `AllowOfflineGracePeriod` isn't set, then the device denies offline access. Applies to web login and all offline passwords.
* `AllowAuthenticationGracePeriod`: The device allows the use of the `AuthenticationGracePeriod` for other local accounts when `RequireAuthentication` is enabled. The `AuthenticationGracePeriod` starts when any of the policies have been updated. If `AllowAuthenticationGracePeriod` isn't set, then the device denies unregistered account access.
* `RequireTouchID`: The device requires the use of Touch ID (and not Apple Watch) for login.
* `RequireTouchIDOrWatch`: The device requires the use of Touch ID or Apple Watch for login.
* `AllowOpenIDForTouchIDFallback`: The device allows web login as fallback if touchID fails or isn't available. 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ policy policy The policy to apply. | string | required | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Unlock Unlock The policy to apply when using Platform SSO at screensaver unlock. Applies when `AuthenticationMethod` is `Password`. later.
* `AttemptAuthentication`: The device attempts Platform SSO authentication before proceeding. If offline, unlock will continue if the local account password matches. If online and the credential is incorrect, then the device requires a successful Platform SSO authentication to proceed, even if taken offline.
* `RequireAuthentication`: The device requires Platform SSO authentication before proceeding. If the device is offline and `AllowOfflineGracePeriod` is enabled, then the offline `OfflineGracePeriod` is used to determine if the user can proceed or not. If online and the credential is incorrect, then the device requires a valid Platform SSO authentication to proceed regardless of the `OfflineGracePeriod`. If the account isn't registered for Platform SSO and `AllowAuthenticationGracePeriod` is enabled, then the device uses `AuthenticationGracePeriod` to determine if the user can proceed or not.
* `AllowOfflineGracePeriod`: The device allows the use of the `OfflineGracePeriod` when `RequireAuthentication` is enabled. If `AllowOfflineGracePeriod` isn't set, then the device denies offline access.
* `AllowAuthenticationGracePeriod`: The device allows the use of the `AuthenticationGracePeriod` for other local accounts when `RequireAuthentication` is enabled. The `AuthenticationGracePeriod` starts when any of the policies have been updated. If `AllowAuthenticationGracePeriod` isn't set, then the device denies the unregistered account access.
* `AllowTouchIDOrWatchForUnlock`: The device allows TouchID or Watch to unlock the screensaver instead of Platform SSO authentication when `RequireAuthentication` is enabled.
* `RequireTouchID`: The device requires the use of Touch ID (and not Apple Watch) for unlock.
* `RequireTouchIDOrWatch`: RThe device requires the use of Touch ID or Apple Watch for unlock.
* `AllowOpenIDForTouchIDFallback`: The device allows web login as fallback if touchID fails or isn't available. 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ policy policy The policy to apply. | string | required | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Offline grace period OfflineGracePeriod The amount of time after the last successful Platform SSO login for using a local account password offline. Required when setting `AllowOfflineGracePeriod`. | integer | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Authentication grace period AuthenticationGracePeriod The amount of time after receiving or updating a `Policies.FileVault`, `Policies.Login`, or `Policies.Unlock` that the system can use unregistered local accounts. Required when `AllowAuthenticationGracePeriod` is set. | integer | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Non-platform SSO accounts NonPlatformSSOAccounts The list of local accounts that aren't subject to the `Policies.FileVault`, `Policies.Login`, or `Policies.Unlock` policies. The accounts don't receive a prompt to register for Platform SSO. 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ username username A local account username. | string | required | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ Web authentication WebAuthentication New in macOS 27.0 Settings for web authentication behavior. 2 subkeys | dictionary | optional | — | ✓Yes | macOS (27.0+) |
└─ └─ URL allow list URLAllowList The set of allowed hosts that the system can load in the PSSO web view. Required if `AuthenticationMethod` is set to `OpenID`, or `UserCreation.AuthenticationMethods` contains `OpenID`. 1 subkey | array | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ └─ Hosts Hosts A host or host prefix. | string | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
└─ └─ Allow password sync AllowPasswordSync If `true`, the system detects the password during web authentication and synchronizes it to the local account password for the user. | boolean | optional | false | ✓Yes | iOS (27.0+)macOS (27.0+)visionOS (27.0+) |
Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.
com.apple.wifi.managed – Wi-Fi network configurationcom.apple.vpn.managed – VPN configurationcom.apple.applicationaccess – App and feature restrictionscom.apple.security.pkcs1 – Certificate (PKCS#1) payloadcom.apple.security.pkcs12 – Identity certificate (PKCS#12) payloadcom.apple.security.scep – SCEP certificate enrolmentcom.apple.mail.managed – Mail account configurationcom.apple.eas.account – Exchange ActiveSync accountcom.apple.MCX – Managed Client (macOS) preferencescom.apple.MCX.FileVault2 – FileVault 2 disk encryptioncom.apple.dock – macOS Dock configurationcom.apple.screensaver – Screensaver configurationcom.apple.loginwindow – macOS login window configurationcom.apple.systempolicy.managed – Gatekeeper / system policycom.apple.systempreferences – System Preferences pane restrictionscom.apple.SoftwareUpdate – Software update behaviourcom.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)com.apple.notificationsettings – Per-app notification settingscom.apple.webcontent-filter – Web content filtercom.apple.dnsSettings.managed – DNS settings (DoH / DoT)com.apple.relay.managed – Network relay configurationcom.apple.extensiblesso – Extensible Single Sign-Oncom.apple.configuration.passcode.settings – DDM: passcode policycom.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software updatecom.apple.configuration.services.configuration-files – DDM: service configuration filescom.apple.configuration.management.status-subscriptions – DDM: status subscriptionscom.apple.activation.simple – DDM: simple activation predicatecom.apple.management.organization-info – DDM: organization information