The declaration to configure Safari settings.
| Setting | Type | Required | Default | Manual Install | Supported OS |
|---|---|---|---|---|---|
Accept cookies AcceptCookies The policy Safari uses for managing cookies:
- `Never`: Safari always blocks cookies.
- `CurrentWebsite`: Safari allows cookies only from the current website.
- `VisitedWebsites`: Safari allows cookies only from visited websites.
- `Always`: Safari always allows cookies. | string | optional | Always | ✗No | |
Allow disabling fraud warning AllowDisablingFraudWarning If `false`, the system forces fraud warnings on in Safari. | boolean | optional | true | ✗No | |
Allow history clearing AllowHistoryClearing If `false`, the system disables clearing history in Safari. | boolean | optional | true | ✗No | |
Allow JavaScript AllowJavaScript If `false`, the system disables JavaScript in Safari. | boolean | optional | true | ✗No | |
Allow private browsing AllowPrivateBrowsing If `false`, the system disables private browsing in Safari. | boolean | optional | true | ✗No | |
Allow popups AllowPopups If `false`, the system disables popups in Safari. | boolean | optional | true | ✗No | |
Allow summary AllowSummary If `false`, the system disables summarization of content in Safari. | boolean | optional | true | ✗No | |
New tab start page NewTabStartPage Sets the start page for new tabs in Safari. 3 subkeys | dictionary | optional | — | ✓Yes | iOS (26.0+)macOS (26.0+)visionOS (26.0+) |
└─ Page type PageType Sets the start page type in Safari:
- `Start` - Safari uses the default start page. Safari disables the Homepage.
- `Home` - Safari uses the page specified by `HomepageURL`, and Safari also sets that as the Homepage.
- `Extension` - Safari uses the page specified by the Safari extension whose identifier is `ExtensionIdentifier`. Safari disables the Homepage. | string | required | — | ✓Yes | iOS (26.0+)macOS (26.0+)visionOS (26.0+) |
└─ The homepage URL. HomepageURL The URL of the homepage which needs to start with `https://` or `http://`. Required when setting `PageType` to `Home`. | string | optional | — | ✓Yes | iOS (26.0+)macOS (26.0+)visionOS (26.0+) |
└─ The extension identifier. ExtensionIdentifier The composed identifier of the extension that provides the start page. The required format is "Identifier (TeamIdentifier)", for example "com.example.app (ABCD1234)". Required when setting `PageType` to `Extension`. | string | optional | — | ✓Yes | iOS (26.0+)macOS (26.0+)visionOS (26.0+) |
Website privacy Privacy New in iOS 27.0, macOS 27.0 The dictionary of website privacy settings. 1 subkey | dictionary | optional | — | ✓Yes | iOS (27.0+)macOS (27.0+) |
└─ Website privacy permission defaults PermissionDefaults The dictionary of website permission defaults. Each key in the dictionary represents a single website, or a website and its sub-domains. The dictionary values represent the permission defaults that Safari applies for each website that matches the key.
Safari supports the following patterns for the website key:
- A specific domain such as "example.com" or "www.example.com". The permission defaults apply to that website only.
- A wildcard domain that uses a single "\*" character as a prefix for the domain, such as "\*example.com". The permission defaults apply to both the exact domain "example.com", and any sub-domains such as "www.example.com". It won't match other domains with a similar string suffix such as "myexample.com".
When multiple patterns match a website, Safari uses the most precise pattern. For example, for the website "www.example.com", if rules "www.example.com" and "*example.com" match, Safari uses the former. 1 subkey | dictionary | optional | — | ✓Yes | iOS (26.0+)macOS (26.0+)visionOS (26.0+) |
└─ └─ ANY ANY The dictionary that defines the website privacy permission defaults. Each key represents a website. 3 subkeys | dictionary | optional | — | ✓Yes | iOS (26.0+)macOS (26.0+)visionOS (26.0+) |
└─ └─ └─ Organization justification OrganizationJustification Text that clearly explains to the Safari user the reason why the organization requires these website privacy permission defaults. Safari includes this text in the permission consent prompt it displays when it first displays the website. | string | required | — | ✓Yes | iOS (26.0+)macOS (26.0+)visionOS (26.0+) |
└─ └─ └─ Camera permission Camera Controls whether a website privacy permission default is set.
* `None`: Safari sets no website privacy permission default for use of the camera.
* `Allow`: Safari sets the website privacy permission default to allow use of the camera. | string | optional | — | ✓Yes | iOS (26.0+)macOS (26.0+)visionOS (26.0+) |
└─ └─ └─ Microphone permission Microphone Controls whether a website privacy permission default is set.
* `None`: Safari sets no website privacy permission default for use of the microphone.
* `Allow`: Safari sets the website privacy permission default to allow use of the microphone. | string | optional | — | ✓Yes | iOS (26.0+)macOS (26.0+)visionOS (26.0+) |
Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.
com.apple.wifi.managed – Wi-Fi network configurationcom.apple.vpn.managed – VPN configurationcom.apple.applicationaccess – App and feature restrictionscom.apple.security.pkcs1 – Certificate (PKCS#1) payloadcom.apple.security.pkcs12 – Identity certificate (PKCS#12) payloadcom.apple.security.scep – SCEP certificate enrolmentcom.apple.mail.managed – Mail account configurationcom.apple.eas.account – Exchange ActiveSync accountcom.apple.MCX – Managed Client (macOS) preferencescom.apple.MCX.FileVault2 – FileVault 2 disk encryptioncom.apple.dock – macOS Dock configurationcom.apple.screensaver – Screensaver configurationcom.apple.loginwindow – macOS login window configurationcom.apple.systempolicy.managed – Gatekeeper / system policycom.apple.systempreferences – System Preferences pane restrictionscom.apple.SoftwareUpdate – Software update behaviourcom.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)com.apple.notificationsettings – Per-app notification settingscom.apple.webcontent-filter – Web content filtercom.apple.dnsSettings.managed – DNS settings (DoH / DoT)com.apple.relay.managed – Network relay configurationcom.apple.extensiblesso – Extensible Single Sign-Oncom.apple.configuration.passcode.settings – DDM: passcode policycom.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software updatecom.apple.configuration.services.configuration-files – DDM: service configuration filescom.apple.configuration.management.status-subscriptions – DDM: status subscriptionscom.apple.activation.simple – DDM: simple activation predicatecom.apple.management.organization-info – DDM: organization information