profiles

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 7, 2026 License: MIT Imports: 4 Imported by: 0

Documentation

Overview

Package profiles holds the configuration profile payloads generated from Apple's device management schema: 127 schema files and 230 types.

Design

Apple publishes the wire format of the configuration profile payloads as YAML in https://github.com/apple/device-management, pinned here as a git submodule. Generating this package from that pinned commit derives the wire types, validation, and support metadata from Apple's schema (decision record 0003). Every type carries plist and json struct tags with Apple's wire keys, a Validate method driven by the schema's constraints, and support metadata queryable through Support(path) or the schema/support package.

Edit the generator to change this package. admgen verify fails when regeneration would change it or drop an exported name (schema/EXPORTED_IDENTIFIERS.lock). Protocol semantics that Apple documents only in prose live in the hand-written packages that import this one.

References

Index

Constants

View Source
const (
	// PayloadTypeCommonPayloadKeys: Common Payload Keys
	PayloadTypeCommonPayloadKeys = "CommonPayloadKeys"
	// PayloadTypeGlobalPreferences: Global Preferences
	PayloadTypeGlobalPreferences = ".GlobalPreferences"
	// PayloadTypeTopLevel: Top Level
	PayloadTypeTopLevel = "TopLevel"
	// PayloadTypeActiveDirectoryCertificate: Active Directory Certificate
	PayloadTypeActiveDirectoryCertificate = "com.apple.ADCertificate.managed"
	// PayloadTypeAIMAccount: AIM Account
	PayloadTypeAIMAccount = "com.apple.AIM.account"
	// PayloadTypeContentCaching: Content Caching
	PayloadTypeContentCaching = "com.apple.AssetCache.managed"
	// PayloadTypeParentalControlsDictionary: Parental Controls: Dictionary
	PayloadTypeParentalControlsDictionary = "com.apple.Dictionary"
	// PayloadTypeDirectoryService: Directory Service
	PayloadTypeDirectoryService = "com.apple.DirectoryService.managed"
	// PayloadTypeMediaManagementDiscBurning: Media Management: Disc Burning
	PayloadTypeMediaManagementDiscBurning = "com.apple.DiscRecording"
	// PayloadTypeAccounts: Accounts
	PayloadTypeAccounts = "com.apple.MCX"
	// PayloadTypeEnergySaver: Energy Saver
	PayloadTypeEnergySaver = "com.apple.MCX"
	// PayloadTypeFDEFileVaultOptions: FDE FileVault Options
	PayloadTypeFDEFileVaultOptions = "com.apple.MCX"
	// PayloadTypeMobileAccounts: Mobile Accounts
	PayloadTypeMobileAccounts = "com.apple.MCX"
	// PayloadTypeTimeServer: Time Server
	PayloadTypeTimeServer = "com.apple.MCX"
	// PayloadTypeWiFiManagedSettings: Wi-Fi Managed Settings
	PayloadTypeWiFiManagedSettings = "com.apple.MCX"
	// PayloadTypeFDEFileVault: FDE FileVault
	PayloadTypeFDEFileVault = "com.apple.MCX.FileVault2"
	// PayloadTypeTimeMachine: Time Machine
	PayloadTypeTimeMachine = "com.apple.MCX.TimeMachine"
	// PayloadTypeManagedPreferences: Managed Preferences
	PayloadTypeManagedPreferences = "com.apple.ManagedClient.preferences"
	// PayloadTypeNSExtensionManagement: NSExtension Management
	PayloadTypeNSExtensionManagement = "com.apple.NSExtension"
	// PayloadTypeSetupAssistant: Setup Assistant
	PayloadTypeSetupAssistant = "com.apple.SetupAssistant.managed" // #nosec G101 -- Apple wire identifier, not a credential
	// PayloadTypeShareKit: ShareKit
	PayloadTypeShareKit = "com.apple.ShareKitHelper"
	// PayloadTypeSoftwareUpdate: Software Update
	PayloadTypeSoftwareUpdate = "com.apple.SoftwareUpdate"
	// PayloadTypeNetworkProxyConfiguration: Network Proxy Configuration
	PayloadTypeNetworkProxyConfiguration = "com.apple.SystemConfiguration"
	// PayloadTypePrivacyPreferencesPolicyControl: Privacy Preferences Policy Control
	PayloadTypePrivacyPreferencesPolicyControl = "com.apple.TCC.configuration-profile-policy"
	// PayloadTypeAirPlaySecurity: AirPlay Security
	PayloadTypeAirPlaySecurity = "com.apple.airplay.security"
	// PayloadTypeAirPlay: AirPlay
	PayloadTypeAirPlay = "com.apple.airplay"
	// PayloadTypeAirPrint: AirPrint
	PayloadTypeAirPrint = "com.apple.airprint"
	// PayloadTypeAPN: APN
	PayloadTypeAPN = "com.apple.apn.managed"
	// PayloadTypeAppLock: App Lock
	PayloadTypeAppLock = "com.apple.app.lock"
	// PayloadTypeParentalControlsApplicationRestrictions: Parental Controls: Application Restrictions
	PayloadTypeParentalControlsApplicationRestrictions = "com.apple.applicationaccess.new"
	// PayloadTypeRestrictions: Restrictions
	PayloadTypeRestrictions = "com.apple.applicationaccess"
	// PayloadTypeAppStore: App Store
	PayloadTypeAppStore = "com.apple.appstore"
	// PayloadTypeAutonomousSingleAppMode: Autonomous Single App Mode
	PayloadTypeAutonomousSingleAppMode = "com.apple.asam"
	// PayloadTypeAssociatedDomains: Associated Domains
	PayloadTypeAssociatedDomains = "com.apple.associated-domains"
	// PayloadTypeCalDAV: CalDAV
	PayloadTypeCalDAV = "com.apple.caldav.account"
	// PayloadTypeCardDAV: CardDAV
	PayloadTypeCardDAV = "com.apple.carddav.account"
	// PayloadTypeCellular: Cellular
	PayloadTypeCellular = "com.apple.cellular"
	// PayloadTypeCellularPrivateNetwork: Cellular Private Network
	PayloadTypeCellularPrivateNetwork = "com.apple.cellularprivatenetwork.managed" // #nosec G101 -- Apple wire identifier, not a credential
	// PayloadTypeConferenceRoomDisplay: Conference Room Display
	PayloadTypeConferenceRoomDisplay = "com.apple.conferenceroomdisplay"
	// PayloadTypeIdentification: Identification
	PayloadTypeIdentification = "com.apple.configurationprofile.identification"
	// PayloadTypeParentalControlsDashboardWidgetRestrictions: Parental Controls: Dashboard Widget Restrictions
	PayloadTypeParentalControlsDashboardWidgetRestrictions = "com.apple.dashboard"
	// PayloadTypeDeclarations: Declarations
	PayloadTypeDeclarations = "com.apple.declarations"
	// PayloadTypeDesktop: Desktop
	PayloadTypeDesktop = "com.apple.desktop"
	// PayloadTypeDNSProxy: DNS Proxy
	PayloadTypeDNSProxy = "com.apple.dnsProxy.managed"
	// PayloadTypeDNSSettings: DNS Settings
	PayloadTypeDNSSettings = "com.apple.dnsSettings.managed"
	// PayloadTypeDock: Dock
	PayloadTypeDock = "com.apple.dock"
	// PayloadTypeDomains: Domains
	PayloadTypeDomains = "com.apple.domains"
	// PayloadTypeExchangeActiveSync: Exchange ActiveSync
	PayloadTypeExchangeActiveSync = "com.apple.eas.account"
	// PayloadTypeEducationConfiguration: Education Configuration
	PayloadTypeEducationConfiguration = "com.apple.education"
	// PayloadTypeExchangeWebServices: Exchange Web Services
	PayloadTypeExchangeWebServices = "com.apple.ews.account"
	// PayloadTypeExtensibleSingleSignOnKerberos: Extensible Single Sign-On (Kerberos)
	PayloadTypeExtensibleSingleSignOnKerberos = "com.apple.extensiblesso"
	// PayloadTypeExtensibleSingleSignOn: Extensible Single Sign-On
	PayloadTypeExtensibleSingleSignOn = "com.apple.extensiblesso"
	// PayloadTypeParentalControlsContentFilter: Parental Controls: Content Filter
	PayloadTypeParentalControlsContentFilter = "com.apple.familycontrols.contentfilter"
	// PayloadTypeParentalControlsTimeLimits: Parental Controls: Time Limits
	PayloadTypeParentalControlsTimeLimits = "com.apple.familycontrols.timelimits.v2"
	// PayloadTypeFileProvider: File Provider
	PayloadTypeFileProvider = "com.apple.fileproviderd"
	// PayloadTypeFinder: Finder
	PayloadTypeFinder = "com.apple.finder"
	// PayloadTypeX8021XFirstActiveEthernet: 802.1X: First Active Ethernet
	PayloadTypeX8021XFirstActiveEthernet = "com.apple.firstactiveethernet.managed"
	// PayloadTypeX8021XFirstEthernet: 802.1X: First Ethernet
	PayloadTypeX8021XFirstEthernet = "com.apple.firstethernet.managed"
	// PayloadTypeFont: Font
	PayloadTypeFont = "com.apple.font"
	// PayloadTypeParentalControlsGameCenter: Parental Controls: Game Center
	PayloadTypeParentalControlsGameCenter = "com.apple.gamed"
	// PayloadTypeX8021XGlobalEthernet: 802.1X: Global Ethernet
	PayloadTypeX8021XGlobalEthernet = "com.apple.globalethernet.managed"
	// PayloadTypeGoogleAccount: Google Account
	PayloadTypeGoogleAccount = "com.apple.google-oauth"
	// PayloadTypeHomeScreenLayout: Home Screen Layout
	PayloadTypeHomeScreenLayout = "com.apple.homescreenlayout"
	// PayloadTypeParentalControlDictationAndProfanity: Parental Control: Dictation and Profanity
	PayloadTypeParentalControlDictationAndProfanity = "com.apple.ironwood.support"
	// PayloadTypeJabberAccount: Jabber Account
	PayloadTypeJabberAccount = "com.apple.jabber.account"
	// PayloadTypeLDAP: LDAP
	PayloadTypeLDAP = "com.apple.ldap.account"
	// PayloadTypeLoginItemsManagedItems: Login Items: Managed Items
	PayloadTypeLoginItemsManagedItems = "com.apple.loginitems.managed"
	// PayloadTypeLoginWindow: Login Window
	PayloadTypeLoginWindow = "com.apple.loginwindow"
	// PayloadTypeLightsOutManagementLOM: Lights Out Management (LOM)
	PayloadTypeLightsOutManagementLOM = "com.apple.lom"
	// PayloadTypeMail: Mail
	PayloadTypeMail = "com.apple.mail.managed"
	// PayloadTypeManagedMenuExtras: Managed Menu Extras
	PayloadTypeManagedMenuExtras = "com.apple.mcxMenuExtras"
	// PayloadTypeLoginWindowScripts: Login Window: Scripts
	PayloadTypeLoginWindowScripts = "com.apple.mcxloginscripts"
	// PayloadTypePrinting: Printing
	PayloadTypePrinting = "com.apple.mcxprinting"
	// PayloadTypeMDM: MDM
	PayloadTypeMDM = "com.apple.mdm"
	// PayloadTypePasscode: Passcode
	PayloadTypePasscode = "com.apple.mobiledevice.passwordpolicy" // #nosec G101 -- Apple wire identifier, not a credential
	// PayloadTypeNetworkUsageRules: Network Usage Rules
	PayloadTypeNetworkUsageRules = "com.apple.networkusagerules"
	// PayloadTypeNotifications: Notifications
	PayloadTypeNotifications = "com.apple.notificationsettings"
	// PayloadTypeMacOSServerAccount: macOS Server Account
	PayloadTypeMacOSServerAccount = "com.apple.osxserver.account"
	// PayloadTypeSecurityPreferences: Security Preferences
	PayloadTypeSecurityPreferences = "com.apple.preference.security"
	// PayloadTypeUserPreferences: User Preferences
	PayloadTypeUserPreferences = "com.apple.preference.users"
	// PayloadTypeProfileRemovalPassword: Profile Removal Password
	PayloadTypeProfileRemovalPassword = "com.apple.profileRemovalPassword" // #nosec G101 -- Apple wire identifier, not a credential
	// PayloadTypeGlobalHTTPProxy: Global HTTP Proxy
	PayloadTypeGlobalHTTPProxy = "com.apple.proxy.http.global"
	// PayloadTypeRelay: Relay
	PayloadTypeRelay = "com.apple.relay.managed"
	// PayloadTypeScreensaverUser: Screensaver User
	PayloadTypeScreensaverUser = "com.apple.screensaver.user"
	// PayloadTypeScreensaver: Screensaver
	PayloadTypeScreensaver = "com.apple.screensaver"
	// PayloadTypeX8021XSecondActiveEthernet: 802.1X: Second Active Ethernet
	PayloadTypeX8021XSecondActiveEthernet = "com.apple.secondactiveethernet.managed"
	// PayloadTypeX8021XSecondEthernet: 802.1X: Second Ethernet
	PayloadTypeX8021XSecondEthernet = "com.apple.secondethernet.managed"
	// PayloadTypeFDERecoveryKeyEscrow: FDE Recovery Key Escrow
	PayloadTypeFDERecoveryKeyEscrow = "com.apple.security.FDERecoveryKeyEscrow"
	// PayloadTypeFDERecoveryKeyRedirection: FDE Recovery Key Redirection
	PayloadTypeFDERecoveryKeyRedirection = "com.apple.security.FDERecoveryRedirect"
	// PayloadTypeACMECertificate: ACME Certificate
	PayloadTypeACMECertificate = "com.apple.security.acme"
	// PayloadTypeCertificatePreference: Certificate Preference
	PayloadTypeCertificatePreference = "com.apple.security.certificatepreference"
	// PayloadTypeCertificateRevocation: Certificate Revocation
	PayloadTypeCertificateRevocation = "com.apple.security.certificaterevocation"
	// PayloadTypeCertificateTransparency: Certificate Transparency
	PayloadTypeCertificateTransparency = "com.apple.security.certificatetransparency"
	// PayloadTypeFirewall: Firewall
	PayloadTypeFirewall = "com.apple.security.firewall"
	// PayloadTypeIdentityPreference: Identity Preference
	PayloadTypeIdentityPreference = "com.apple.security.identitypreference"
	// PayloadTypeCertificatePEM: Certificate (PEM)
	PayloadTypeCertificatePEM = "com.apple.security.pem"
	// PayloadTypeCertificatePKCS1: Certificate (PKCS #1)
	PayloadTypeCertificatePKCS1 = "com.apple.security.pkcs1"
	// PayloadTypeCertificatePKCS12: Certificate (PKCS #12)
	PayloadTypeCertificatePKCS12 = "com.apple.security.pkcs12"
	// PayloadTypeCertificateRoot: Certificate (Root)
	PayloadTypeCertificateRoot = "com.apple.security.root"
	// PayloadTypeSCEP: SCEP
	PayloadTypeSCEP = "com.apple.security.scep"
	// PayloadTypeSmartCard: SmartCard
	PayloadTypeSmartCard = "com.apple.security.smartcard"
	// PayloadTypeServiceManagementManagedLoginItems: Service Management - Managed Login Items
	PayloadTypeServiceManagementManagedLoginItems = "com.apple.servicemanagement"
	// PayloadTypeLockScreenMessage: Lock Screen Message
	PayloadTypeLockScreenMessage = "com.apple.shareddeviceconfiguration"
	// PayloadTypeSingleSignOn: Single Sign-On
	PayloadTypeSingleSignOn = "com.apple.sso"
	// PayloadTypeSubscribedCalendars: Subscribed Calendars
	PayloadTypeSubscribedCalendars = "com.apple.subscribedcalendar.account"
	// PayloadTypeSystemPolicyKernelExtensions: System Policy - Kernel Extensions
	PayloadTypeSystemPolicyKernelExtensions = "com.apple.syspolicy.kernel-extension-policy"
	// PayloadTypeSystemExtensions: System Extensions
	PayloadTypeSystemExtensions = "com.apple.system-extension-policy"
	// PayloadTypeSystemLogging: System Logging
	PayloadTypeSystemLogging = "com.apple.system.logging"
	// PayloadTypeSystemMigration: System Migration
	PayloadTypeSystemMigration = "com.apple.systemmigration"
	// PayloadTypeSystemPolicyControl: System Policy Control
	PayloadTypeSystemPolicyControl = "com.apple.systempolicy.control"
	// PayloadTypeSystemPolicyManaged: System Policy Managed
	PayloadTypeSystemPolicyManaged = "com.apple.systempolicy.managed"
	// PayloadTypeSystemPolicyRule: System Policy Rule
	PayloadTypeSystemPolicyRule = "com.apple.systempolicy.rule"
	// PayloadTypeSystemPreferences: System Preferences
	PayloadTypeSystemPreferences = "com.apple.systempreferences"
	// PayloadTypeMediaManagementAllowedMedia: Media Management: Allowed Media
	PayloadTypeMediaManagementAllowedMedia = "com.apple.systemuiserver"
	// PayloadTypeX8021XThirdActiveEthernet: 802.1X: Third Active Ethernet
	PayloadTypeX8021XThirdActiveEthernet = "com.apple.thirdactiveethernet.managed"
	// PayloadTypeX8021XThirdEthernet: 802.1X: Third Ethernet
	PayloadTypeX8021XThirdEthernet = "com.apple.thirdethernet.managed"
	// PayloadTypeTVRemote: TV Remote
	PayloadTypeTVRemote = "com.apple.tvremote"
	// PayloadTypeAccessibility: Accessibility
	PayloadTypeAccessibility = "com.apple.universalaccess"
	// PayloadTypeAppLayerVPN: App-Layer VPN
	PayloadTypeAppLayerVPN = "com.apple.vpn.managed.applayer"
	// PayloadTypeAppToAppLayerVPNMapping: App-to-App-Layer VPN Mapping
	PayloadTypeAppToAppLayerVPNMapping = "com.apple.vpn.managed.appmapping"
	// PayloadTypeVPN: VPN
	PayloadTypeVPN = "com.apple.vpn.managed"
	// PayloadTypeWebClip: Web Clip
	PayloadTypeWebClip = "com.apple.webClip.managed"
	// PayloadTypeWebContentFilter: Web Content Filter
	PayloadTypeWebContentFilter = "com.apple.webcontent-filter"
	// PayloadTypeWiFi: Wi-Fi
	PayloadTypeWiFi = "com.apple.wifi.managed"
	// PayloadTypeXsanPreferences: Xsan Preferences
	PayloadTypeXsanPreferences = "com.apple.xsan.preferences"
	// PayloadTypeXsan: Xsan
	PayloadTypeXsan = "com.apple.xsan"
	// PayloadTypeLoginWindowLoginItems: Login Window: Login Items
	PayloadTypeLoginWindowLoginItems = "loginwindow"
)

Wire identifiers.

Variables

View Source
var Registry = map[string]Entry{}/* 127 elements not displayed */

Registry maps Go type names to constructors, one entry per schema file. Several schemas may share a wire identifier (for example six profile payloads use com.apple.MCX), so look up by identifier with ByID.

Functions

func IDs

func IDs() []string

IDs returns the distinct wire identifiers in sorted order.

func Support

func Support(path string) *support.Entry

Support returns the support entry for a key path such as "DeviceLock.Message" or "DeviceLock.response.MessageResult", or nil when unknown.

Types

type ACMECertificate

type ACMECertificate struct {
	// The directory URL of the ACME server. The URL must use the https scheme.
	DirectoryURL string `plist:"DirectoryURL" json:"DirectoryURL"`
	// A unique string identifying a specific device. The server may use this as an anti-replay
	// code to prevent issuing multiple certificates. This identifier also indicates to the
	// ACME server that the device has access to a valid client identifier issued by the
	// enterprise infrastructure. This can help the ACME server determine whether to trust the
	// device. Though this is a relatively weak indication because of the risk that an attacker
	// can intercept the client identifier.
	ClientIdentifier string `plist:"ClientIdentifier" json:"ClientIdentifier"`
	// The valid values for `KeySize` depend on the values of `KeyType` and `HardwareBound`.
	// See those keys for specific requirements.
	KeySize int64 `plist:"KeySize" json:"KeySize"`
	// The type of key pair to generate. Allowed values:
	KeyType string `plist:"KeyType" json:"KeyType"`
	// If `false`, the private key isn't bound to the device.
	HardwareBound bool `plist:"HardwareBound" json:"HardwareBound"`
	// The device requests this subject for the certificate that the ACME server issues. The
	// ACME server may override or ignore this field in the certificate it issues.
	Subject [][][]string `plist:"Subject,omitempty" json:"Subject,omitempty"`
	// The Subject Alt Name that the device requests for the certificate that the ACME server
	// issues. The ACME server may override or ignore this field in the certificate it issues.
	SubjectAltName *ACMECertificateSubjectAltName `plist:"SubjectAltName,omitempty" json:"SubjectAltName,omitempty"`
	// This value is a bit field.
	UsageFlags *int64 `plist:"UsageFlags,omitempty" json:"UsageFlags,omitempty"`
	// The value is an array of strings. Each string is an OID in dotted notation. For
	// instance, `["1.3.6.1.5.5.7.3.2", "1.3.6.1.5.5.7.3.4"]` indicates client authentication
	// and email protection.
	ExtendedKeyUsage []string `plist:"ExtendedKeyUsage,omitempty" json:"ExtendedKeyUsage,omitempty"`
	// If `true`, the device provides attestations that describe the device and the generated
	// key to the ACME server. The server can use the attestations as strong evidence that the
	// key is bound to the device, and that the device has properties listed in the
	// attestation. The server can use that as part of a trust score to decide whether to issue
	// the requested certificate.
	Attest *bool `plist:"Attest,omitempty" json:"Attest,omitempty"`
	// If `true`, the private key of the identity obtained through Automated Certificate
	// Management Environment (ACME) needs to be tagged as "non-extractable" in the keychain.
	KeyIsExtractable *bool `plist:"KeyIsExtractable,omitempty" json:"KeyIsExtractable,omitempty"`
	// If `true`, all apps have access to the private key.
	AllowAllAppsAccess *bool `plist:"AllowAllAppsAccess,omitempty" json:"AllowAllAppsAccess,omitempty"`
}

ACMECertificate: The payload that configures Automated Certificate Management Environment (ACME) settings.

ACMECertificate corresponds to mdm/profiles/com.apple.security.acme.yaml (ACME Certificate).

func (*ACMECertificate) PayloadTypeName

func (*ACMECertificate) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.acme".

func (*ACMECertificate) SchemaPath

func (*ACMECertificate) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ACMECertificate) Validate

func (x *ACMECertificate) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ACMECertificateSubjectAltName

type ACMECertificateSubjectAltName struct {
	// The RFC 822 (email address) string.
	Rfc822Name *string `plist:"rfc822Name,omitempty" json:"rfc822Name,omitempty"`
	// The DNS name.
	DNSName *string `plist:"dNSName,omitempty" json:"dNSName,omitempty"`
	// The Uniform Resource Identifier.
	UniformResourceIdentifier *string `plist:"uniformResourceIdentifier,omitempty" json:"uniformResourceIdentifier,omitempty"`
	// The NT principal name. Use an other name OID set to `1.3.6.1.4.1.311.20.2.3`.
	NtPrincipalName *string `plist:"ntPrincipalName,omitempty" json:"ntPrincipalName,omitempty"`
}

ACMECertificateSubjectAltName: The Subject Alt Name that the device requests for the certificate that the ACME server issues. The ACME server may override or ignore this field in the certificate it issues.

type AIMAccount

type AIMAccount struct {
	// The description of the account.
	AIMAccountDescription *string `plist:"AIMAccountDescription,omitempty" json:"AIMAccountDescription,omitempty"`
	// The server address.
	AIMHostName string `plist:"AIMHostName" json:"AIMHostName"`
	// The user's login name.
	AIMUserName *string `plist:"AIMUserName,omitempty" json:"AIMUserName,omitempty"`
	// The user's password.
	AIMPassword *string `plist:"AIMPassword,omitempty" json:"AIMPassword,omitempty"`
	// If `true`, enables SSL.
	AIMUseSSL *bool `plist:"AIMUseSSL,omitempty" json:"AIMUseSSL,omitempty"`
	// The connection port for the server.
	AIMPort *int64 `plist:"AIMPort,omitempty" json:"AIMPort,omitempty"`
	// The authentication method for the account.
	AIMAuthentication string `plist:"AIMAuthentication" json:"AIMAuthentication"`
}

AIMAccount: The payload that configures an AIM account on the device.

AIMAccount corresponds to mdm/profiles/com.apple.AIM.account.yaml (AIM Account).

func (*AIMAccount) PayloadTypeName

func (*AIMAccount) PayloadTypeName() string

PayloadTypeName returns "com.apple.AIM.account".

func (*AIMAccount) SchemaPath

func (*AIMAccount) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*AIMAccount) Validate

func (x *AIMAccount) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type APN

type APN struct {
	// The list of access point names (APNs).
	DefaultsData APNDefaultsData `plist:"DefaultsData,omitempty" json:"DefaultsData,omitempty"`
	// The domain name.
	DefaultsDomainName string `plist:"DefaultsDomainName" json:"DefaultsDomainName"`
}

APN: The payload that configures access point names.

APN corresponds to mdm/profiles/com.apple.apn.managed.yaml (APN).

func (*APN) PayloadTypeName

func (*APN) PayloadTypeName() string

PayloadTypeName returns "com.apple.apn.managed".

func (*APN) SchemaPath

func (*APN) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*APN) Validate

func (x *APN) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type APNDefaultsData

type APNDefaultsData struct {
	// An array of APN dictionaries (\`APN.DefaultsData.Apns\`).
	Apns []APNDefaultsDataApns `plist:"apns,omitempty" json:"apns,omitempty"`
}

APNDefaultsData: The list of access point names (APNs).

type APNDefaultsDataApns

type APNDefaultsDataApns struct {
	// The access point name.
	Apn string `plist:"apn" json:"apn"`
	// The user name. If missing, the device prompts for it during profile installation.
	Username *string `plist:"username,omitempty" json:"username,omitempty"`
	// The password for the user. For obfuscation purposes, the system encodes the password. If
	// missing, the device prompts for the password during profile installation.
	Password []byte `plist:"password,omitempty" json:"password,omitempty"`
	// The IP address or URL of the APN proxy.
	Proxy *string `plist:"proxy,omitempty" json:"proxy,omitempty"`
	// The port number of the APN proxy.
	ProxyPort *int64 `plist:"proxyPort,omitempty" json:"proxyPort,omitempty"`
}

APNDefaultsDataApns: A dictionary that describes an APN configuration.

type Accessibility

type Accessibility struct {
	// The minimum zoom level in the Zoom options.
	CloseViewFarPoint *int64 `plist:"closeViewFarPoint,omitempty" json:"closeViewFarPoint,omitempty"`
	// If `true`, enables "Use keyboard shortcuts" in the Zoom options.
	CloseViewHotkeysEnabled *bool `plist:"closeViewHotkeysEnabled,omitempty" json:"closeViewHotkeysEnabled,omitempty"`
	// The maximum zoom level in the Zoom options.
	CloseViewNearPoint *int64 `plist:"closeViewNearPoint,omitempty" json:"closeViewNearPoint,omitempty"`
	// If `true`, enables "Use scroll gesture" in the Zoom options.
	CloseViewScrollWheelToggle *bool `plist:"closeViewScrollWheelToggle,omitempty" json:"closeViewScrollWheelToggle,omitempty"`
	// If `true`, enables "Show preview rectangle" in the Zoom options. Only available in macOS
	// 10.15 and earlier.
	CloseViewShowPreview *bool `plist:"closeViewShowPreview,omitempty" json:"closeViewShowPreview,omitempty"`
	// If `true`, enables "Smooth images" in the Zoom options.
	CloseViewSmoothImages *bool `plist:"closeViewSmoothImages,omitempty" json:"closeViewSmoothImages,omitempty"`
	// The contrast value in the Display options.
	Contrast *float64 `plist:"contrast,omitempty" json:"contrast,omitempty"`
	// If `true`, enables "Flash the screen" in the Audio options.
	FlashScreen *bool `plist:"flashScreen,omitempty" json:"flashScreen,omitempty"`
	// If `true`, enables "Use grayscale" in the Display options.
	Grayscale *bool `plist:"grayscale,omitempty" json:"grayscale,omitempty"`
	// If `true`, enables Mouse Keys in the Mouse & Trackpad options.
	MouseDriver *bool `plist:"mouseDriver,omitempty" json:"mouseDriver,omitempty"`
	// The size of the cursor.
	MouseDriverCursorSize *int64 `plist:"mouseDriverCursorSize,omitempty" json:"mouseDriverCursorSize,omitempty"`
	// If `true`, ignores the built-in trackpad.
	MouseDriverIgnoreTrackpad *bool `plist:"mouseDriverIgnoreTrackpad,omitempty" json:"mouseDriverIgnoreTrackpad,omitempty"`
	// The initial delay before moving the mouse with Mouse Keys.
	MouseDriverInitialDelay *int64 `plist:"mouseDriverInitialDelay,omitempty" json:"mouseDriverInitialDelay,omitempty"`
	// The maximum speed for the cursor when using Mouse Keys.
	MouseDriverMaxSpeed *int64 `plist:"mouseDriverMaxSpeed,omitempty" json:"mouseDriverMaxSpeed,omitempty"`
	// If `true`, enables "Slow Keys" in the Keyboard options.
	SlowKey *bool `plist:"slowKey,omitempty" json:"slowKey,omitempty"`
	// If `true`, enables "click key sounds" for Slow Keys.
	SlowKeyBeepOn *bool `plist:"slowKeyBeepOn,omitempty" json:"slowKeyBeepOn,omitempty"`
	// The acceptance delay, in milliseconds, for Slow Keys.
	SlowKeyDelay *int64 `plist:"slowKeyDelay,omitempty" json:"slowKeyDelay,omitempty"`
	// If `true`, plays stereo audio as mono.
	StereoAsMono *bool `plist:"stereoAsMono,omitempty" json:"stereoAsMono,omitempty"`
	// If `true`, enables Sticky Keys in the Keyboard options.
	StickyKey *bool `plist:"stickyKey,omitempty" json:"stickyKey,omitempty"`
	// If `true`, enables the beep when a modifier key is set for Sticky Keys.
	StickyKeyBeepOnModifier *bool `plist:"stickyKeyBeepOnModifier,omitempty" json:"stickyKeyBeepOnModifier,omitempty"`
	// If `true`, enables "Display pressed keys on screen" for Sticky Keys.
	StickyKeyShowWindow *bool `plist:"stickyKeyShowWindow,omitempty" json:"stickyKeyShowWindow,omitempty"`
	// If `true`, enables Voice Over.
	VoiceOverOnOffKey *bool `plist:"voiceOverOnOffKey,omitempty" json:"voiceOverOnOffKey,omitempty"`
	// If `true`, enables Invert Colors in Display Accommodations.
	WhiteOnBlack *bool `plist:"whiteOnBlack,omitempty" json:"whiteOnBlack,omitempty"`
}

Accessibility: The payload that configures the accessibility features of the device.

Accessibility corresponds to mdm/profiles/com.apple.universalaccess.yaml (Accessibility).

func (*Accessibility) PayloadTypeName

func (*Accessibility) PayloadTypeName() string

PayloadTypeName returns "com.apple.universalaccess".

func (*Accessibility) SchemaPath

func (*Accessibility) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Accessibility) Validate

func (x *Accessibility) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type Accounts

type Accounts struct {
	// If `true`, the system enables the guest account.
	EnableGuestAccount *bool `plist:"EnableGuestAccount,omitempty" json:"EnableGuestAccount,omitempty"`
	// If `true`, the system disables the guest account. This property has no effect if
	// `EnableGuestAccount` is `true`.
	DisableGuestAccount *bool `plist:"DisableGuestAccount,omitempty" json:"DisableGuestAccount,omitempty"`
}

Accounts: The payload that configures guest accounts.

Accounts corresponds to mdm/profiles/com.apple.MCX(Accounts).yaml (Accounts).

func (*Accounts) PayloadTypeName

func (*Accounts) PayloadTypeName() string

PayloadTypeName returns "com.apple.MCX".

func (*Accounts) SchemaPath

func (*Accounts) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Accounts) Validate

func (x *Accounts) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ActiveDirectoryCertificate

type ActiveDirectoryCertificate struct {
	// The fully qualified host name of the CA.
	CertServer string `plist:"CertServer" json:"CertServer"`
	// The certificate template for your environment. The default user certificate value is
	// \`User\`. The default computer certificate value is \`Machine\`.
	CertTemplate string `plist:"CertTemplate" json:"CertTemplate"`
	// A user-friendly description of the certification identity.
	Description *string `plist:"Description,omitempty" json:"Description,omitempty"`
	// The number of days in advance of certificate expiration that the notification center
	// notifies the user.
	CertificateRenewalTimeInterval *int64 `plist:"CertificateRenewalTimeInterval,omitempty" json:"CertificateRenewalTimeInterval,omitempty"`
	// The name of the certificate authority (CA), which is determined from the common name
	// (CN) of the Active Directory entry. Available in macOS 10.8 and later. Valid values:
	CertificateAuthority *string `plist:"CertificateAuthority,omitempty" json:"CertificateAuthority,omitempty"`
	// This value is most commonly `RPC`; if using web enrollment, use `HTTP`. Available in
	// macOS 10.8 and later.
	CertificateAcquisitionMechanism *string `plist:"CertificateAcquisitionMechanism,omitempty" json:"CertificateAcquisitionMechanism,omitempty"`
	// If `true`, gives apps access to the private key. Available in macOS 10.10 and later.
	AllowAllAppsAccess *bool `plist:"AllowAllAppsAccess,omitempty" json:"AllowAllAppsAccess,omitempty"`
	// If `true`, the system prompts the user for credentials when is installs the profile.
	// This key applies only to user certificates with the Manual Download profile delivery
	// method. Omit this key for computer certificates. Available in macOS 10.8 and later.
	PromptForCredentials *bool `plist:"PromptForCredentials,omitempty" json:"PromptForCredentials,omitempty"`
	// If `true`, the system allows exporting the private key. Available in macOS 10.10 and
	// later.
	KeyIsExtractable *bool `plist:"KeyIsExtractable,omitempty" json:"KeyIsExtractable,omitempty"`
	// The RSA key size for the certificate signing request (CSR). Available in macOS 10.11 and
	// later.
	Keysize *int64 `plist:"Keysize,omitempty" json:"Keysize,omitempty"`
	// If `true`, the certificate obtained with this payload attempts auto-renewal.
	// Auto-renewal can only be used with device Active Directory certificate payloads.
	// Available in macOS 10.13.4 and later.
	EnableAutoRenewal *bool `plist:"EnableAutoRenewal,omitempty" json:"EnableAutoRenewal,omitempty"`
}

ActiveDirectoryCertificate: The payload that configures Active Directory Certificate settings.

ActiveDirectoryCertificate corresponds to mdm/profiles/com.apple.ADCertificate.managed.yaml (Active Directory Certificate).

func (*ActiveDirectoryCertificate) PayloadTypeName

func (*ActiveDirectoryCertificate) PayloadTypeName() string

PayloadTypeName returns "com.apple.ADCertificate.managed".

func (*ActiveDirectoryCertificate) SchemaPath

func (*ActiveDirectoryCertificate) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ActiveDirectoryCertificate) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type AirPlay

type AirPlay struct {
	// If present, only AirPlay destinations in this list are available to the device. This
	// allow list applies to supervised devices.
	AllowList []AirPlayAllowList `plist:"AllowList,omitempty" json:"AllowList,omitempty"`
	// If present, sets passwords for known AirPlay destinations. Using multiple entries for
	// the same destination, whether within the same payload or across multiple installed
	// payloads, is an error and results in undefined behavior.
	Passwords []AirPlayPasswords `plist:"Passwords,omitempty" json:"Passwords,omitempty"`
	// Use `AllowList` instead. This key is deprecated in iOS 14.5 and macOS 11.3.
	Whitelist []AirPlayWhitelist `plist:"Whitelist,omitempty" json:"Whitelist,omitempty"`
}

AirPlay: The payload that configures AirPlay settings.

AirPlay corresponds to mdm/profiles/com.apple.airplay.yaml (AirPlay).

func (*AirPlay) PayloadTypeName

func (*AirPlay) PayloadTypeName() string

PayloadTypeName returns "com.apple.airplay".

func (*AirPlay) SchemaPath

func (*AirPlay) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*AirPlay) Validate

func (x *AirPlay) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type AirPlayAllowList

type AirPlayAllowList struct {
	// The device ID of the AirPlay destination in the format `xx:xx:xx:xx:xx:xx`. This field
	// isn't case-sensitive.
	DeviceID *string `plist:"DeviceID,omitempty" json:"DeviceID,omitempty"`
	// The name of the AirPlay device.
	DeviceName *string `plist:"DeviceName,omitempty" json:"DeviceName,omitempty"`
}

AirPlayAllowList: is generated from mdm/profiles/com.apple.airplay.yaml.

type AirPlayPasswords

type AirPlayPasswords struct {
	// The name of the AirPlay destination; used in iOS, and available in macOS 15 and later.
	DeviceName *string `plist:"DeviceName,omitempty" json:"DeviceName,omitempty"`
	// The password for the AirPlay destination.
	Password string `plist:"Password" json:"Password"`
	// The device ID of the AirPlay destination; used in macOS.
	DeviceID *string `plist:"DeviceID,omitempty" json:"DeviceID,omitempty"`
}

AirPlayPasswords: is generated from mdm/profiles/com.apple.airplay.yaml.

type AirPlaySecurity

type AirPlaySecurity struct {
	// The security policy for AirPlay. Allowed values:
	SecurityType string `plist:"SecurityType" json:"SecurityType"`
	// The access policy for AirPlay.
	AccessType string `plist:"AccessType" json:"AccessType"`
	// The AirPlay password; required if `SecurityType` is `PASSWORD`.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
}

AirPlaySecurity: The payload that configures Apple TV for a particular style of AirPlay security.

AirPlaySecurity corresponds to mdm/profiles/com.apple.airplay.security.yaml (AirPlay Security).

func (*AirPlaySecurity) PayloadTypeName

func (*AirPlaySecurity) PayloadTypeName() string

PayloadTypeName returns "com.apple.airplay.security".

func (*AirPlaySecurity) SchemaPath

func (*AirPlaySecurity) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*AirPlaySecurity) Validate

func (x *AirPlaySecurity) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type AirPlayWhitelist

type AirPlayWhitelist struct {
	// The device ID of the AirPlay destination in the format `xx:xx:xx:xx:xx:xx`. This field
	// isn't case-sensitive.
	DeviceID *string `plist:"DeviceID,omitempty" json:"DeviceID,omitempty"`
	// The name of the AirPlay device.
	DeviceName *string `plist:"DeviceName,omitempty" json:"DeviceName,omitempty"`
}

AirPlayWhitelist: is generated from mdm/profiles/com.apple.airplay.yaml.

type AirPrint

type AirPrint struct {
	// An array of AirPrint printers that are presented to the user.
	AirPrint []AirPrintAirPrint `plist:"AirPrint,omitempty" json:"AirPrint,omitempty"`
}

AirPrint: The payload that configures AirPrint printer discoverability in the user's printer list.

AirPrint corresponds to mdm/profiles/com.apple.airprint.yaml (AirPrint).

func (*AirPrint) PayloadTypeName

func (*AirPrint) PayloadTypeName() string

PayloadTypeName returns "com.apple.airprint".

func (*AirPrint) SchemaPath

func (*AirPrint) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*AirPrint) Validate

func (x *AirPrint) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type AirPrintAirPrint

type AirPrintAirPrint struct {
	// The IP address or hostname of the AirPrint destination.
	IPAddress string `plist:"IPAddress" json:"IPAddress"`
	// The resource path associated with the printer. This path corresponds to the `rp`
	// parameter of the `_ipps.tcp` Bonjour record. For example:
	ResourcePath string `plist:"ResourcePath" json:"ResourcePath"`
	// The listening port of the AirPrint destination. Available only in iOS 11 and later.
	Port *int64 `plist:"Port,omitempty" json:"Port,omitempty"`
	// If `true`, AirPrint connections are secured by Transport Layer Security (TLS). Available
	// only in iOS 11 and later.
	ForceTLS *bool `plist:"ForceTLS,omitempty" json:"ForceTLS,omitempty"`
}

AirPrintAirPrint: is generated from mdm/profiles/com.apple.airprint.yaml.

type AppLayerVPN

type AppLayerVPN struct {
	// A globally unique identifier for this VPN configuration.
	VPNUUID string `plist:"VPNUUID" json:"VPNUUID"`
	// A string representing the data network name (DNN) or app category identifying a Cellular
	// Slice. The device forces the VPN tunnel to use the specified Cellular Slice.
	CellularSliceUUID *string `plist:"CellularSliceUUID,omitempty" json:"CellularSliceUUID,omitempty"`
	// An array with entries that must each specify a domain that triggers the VPN connection
	// in Safari. Each entry is in the format `www.apple.com`.
	SafariDomains []string `plist:"SafariDomains,omitempty" json:"SafariDomains,omitempty"`
	// An array with entries that must each specify a domain that triggers this VPN connection
	// in Mail. Each entry is in the format `www.apple.com`.
	MailDomains []string `plist:"MailDomains,omitempty" json:"MailDomains,omitempty"`
	// An array with entries that must each specify a domain that triggers this VPN connection
	// in Calendar. Each entry is in the format `www.apple.com`.
	CalendarDomains []string `plist:"CalendarDomains,omitempty" json:"CalendarDomains,omitempty"`
	// An array with entries that must each specify a domain that triggers this VPN connection
	// in Contacts. Each entry is in the format `www.apple.com`.
	ContactsDomains []string `plist:"ContactsDomains,omitempty" json:"ContactsDomains,omitempty"`
	// An array with entries that must each specify a domain that triggers this VPN. The
	// domains must also be part of the `apple-app-site-association` file, as described in
	// `Supporting associated domains`.
	AssociatedDomains []string `plist:"AssociatedDomains,omitempty" json:"AssociatedDomains,omitempty"`
	// An array with entries that each specify a domain that doesn't trigger this VPN for
	// connections to the domain.
	ExcludedDomains []string `plist:"ExcludedDomains,omitempty" json:"ExcludedDomains,omitempty"`
	// If `true`, automatically connects the VPN when associated apps for this per-app VPN
	// service initiate network communication. Otherwise, the user must initiate the connection
	// manually before those apps can initiate network communication. If this key isn't
	// present, the value of the `OnDemandEnabled` key determines the status of per-app VPN On
	// Demand.
	OnDemandMatchAppEnabled *bool `plist:"OnDemandMatchAppEnabled,omitempty" json:"OnDemandMatchAppEnabled,omitempty"`
	// An array of SMB domains that's accessible through this VPN connection.
	SMBDomains []string `plist:"SMBDomains,omitempty" json:"SMBDomains,omitempty"`
}

AppLayerVPN: The payload that configures a per-app VPN.

AppLayerVPN corresponds to mdm/profiles/com.apple.vpn.managed.applayer.yaml (App-Layer VPN).

func (*AppLayerVPN) PayloadTypeName

func (*AppLayerVPN) PayloadTypeName() string

PayloadTypeName returns "com.apple.vpn.managed.applayer".

func (*AppLayerVPN) SchemaPath

func (*AppLayerVPN) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*AppLayerVPN) Validate

func (x *AppLayerVPN) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type AppLock

type AppLock struct {
	// A dictionary that contains information about the app.
	App AppLockApp `plist:"App,omitempty" json:"App,omitempty"`
}

AppLock: The payload that configures a device to run a single app.

AppLock corresponds to mdm/profiles/com.apple.app.lock.yaml (App Lock).

func (*AppLock) PayloadTypeName

func (*AppLock) PayloadTypeName() string

PayloadTypeName returns "com.apple.app.lock".

func (*AppLock) SchemaPath

func (*AppLock) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*AppLock) Validate

func (x *AppLock) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type AppLockApp

type AppLockApp struct {
	// The app's bundle identifier.
	Identifier string `plist:"Identifier" json:"Identifier"`
	// A dictionary of options that the user can't change.
	Options *AppLockAppOptions `plist:"Options,omitempty" json:"Options,omitempty"`
	// A dictionary of user-editable options.
	UserEnabledOptions *AppLockAppUserEnabledOptions `plist:"UserEnabledOptions,omitempty" json:"UserEnabledOptions,omitempty"`
}

AppLockApp: A dictionary that contains information about the app.

type AppLockAppOptions

type AppLockAppOptions struct {
	// If `true`, the system disables the touch screen. In tvOS, it disables the touch surface
	// on the Apple TV Remote.
	DisableTouch *bool `plist:"DisableTouch,omitempty" json:"DisableTouch,omitempty"`
	// If `true`, the system disables device rotation sensing.
	DisableDeviceRotation *bool `plist:"DisableDeviceRotation,omitempty" json:"DisableDeviceRotation,omitempty"`
	// If `true`, the system disables the volume buttons.
	DisableVolumeButtons *bool `plist:"DisableVolumeButtons,omitempty" json:"DisableVolumeButtons,omitempty"`
	// If `true`, the system disables the ringer switch. When disabled, the ringer behavior
	// depends on what position the switch was in when it was first disabled.
	DisableRingerSwitch *bool `plist:"DisableRingerSwitch,omitempty" json:"DisableRingerSwitch,omitempty"`
	// If `true`, the system disables the sleep/wake button.
	DisableSleepWakeButton *bool `plist:"DisableSleepWakeButton,omitempty" json:"DisableSleepWakeButton,omitempty"`
	// If `true`, the device doesn't automatically go to sleep after an idle period.
	DisableAutoLock *bool `plist:"DisableAutoLock,omitempty" json:"DisableAutoLock,omitempty"`
	// If `true`, the system enables VoiceOver.
	EnableVoiceOver *bool `plist:"EnableVoiceOver,omitempty" json:"EnableVoiceOver,omitempty"`
	// If `true`, the system enables Zoom.
	EnableZoom *bool `plist:"EnableZoom,omitempty" json:"EnableZoom,omitempty"`
	// If `true`, the system enables Invert Colors.
	EnableInvertColors *bool `plist:"EnableInvertColors,omitempty" json:"EnableInvertColors,omitempty"`
	// If `true`, the system enables AssistiveTouch.
	EnableAssistiveTouch *bool `plist:"EnableAssistiveTouch,omitempty" json:"EnableAssistiveTouch,omitempty"`
	// If `true`, the system enables Speak Selection.
	EnableSpeakSelection *bool `plist:"EnableSpeakSelection,omitempty" json:"EnableSpeakSelection,omitempty"`
	// If `true`, the system enables Mono Audio.
	EnableMonoAudio *bool `plist:"EnableMonoAudio,omitempty" json:"EnableMonoAudio,omitempty"`
	// If `true`, the system enables Voice Control.
	EnableVoiceControl *bool `plist:"EnableVoiceControl,omitempty" json:"EnableVoiceControl,omitempty"`
}

AppLockAppOptions: A dictionary of options that the user can't change.

type AppLockAppUserEnabledOptions

type AppLockAppUserEnabledOptions struct {
	// If `true`, the system allows the user to toggle Voice Control.
	VoiceControl *bool `plist:"VoiceControl,omitempty" json:"VoiceControl,omitempty"`
	// If `true`, the system allows the user to toggle VoiceOver.
	VoiceOver *bool `plist:"VoiceOver,omitempty" json:"VoiceOver,omitempty"`
	// If `true`, the system allows the user to toggle Zoom.
	Zoom *bool `plist:"Zoom,omitempty" json:"Zoom,omitempty"`
	// If `true`, the system allows the user to toggle Invert Colors.
	InvertColors *bool `plist:"InvertColors,omitempty" json:"InvertColors,omitempty"`
	// If `true`, the system allows the user to toggle AssistiveTouch.
	AssistiveTouch *bool `plist:"AssistiveTouch,omitempty" json:"AssistiveTouch,omitempty"`
}

AppLockAppUserEnabledOptions: A dictionary of user-editable options.

type AppStore

type AppStore struct {
	// If `true`, the system restricts app installations to admin users only. Deprecated in
	// macOS 10.14. Use the `com.apple.SoftwareUpdate` payload key
	// `restrict-software-update-require-admin-to-install` instead.
	RestrictStoreRequireAdminToInstall *bool `plist:"restrict-store-require-admin-to-install,omitempty" json:"restrict-store-require-admin-to-install,omitempty"`
	// If `true`, the system prevents App Store from launching. Available in macOS 10.14 and
	// later. Restricts installations to software updates only in macOS 10.10 through 10.13.
	RestrictStoreSoftwareupdateOnly *bool `plist:"restrict-store-softwareupdate-only,omitempty" json:"restrict-store-softwareupdate-only,omitempty"`
	// If `true`, the system disables app adoption by users. Available in macOS 10.10 and
	// later.
	RestrictStoreDisableAppAdoption *bool `plist:"restrict-store-disable-app-adoption,omitempty" json:"restrict-store-disable-app-adoption,omitempty"`
	// If `true`, the system disables software update notifications. Available in macOS 10.10
	// and later.
	DisableSoftwareUpdateNotifications *bool `plist:"DisableSoftwareUpdateNotifications,omitempty" json:"DisableSoftwareUpdateNotifications,omitempty"`
}

AppStore: The payload that configures macOS App Store restrictions.

AppStore corresponds to mdm/profiles/com.apple.appstore.yaml (App Store).

func (*AppStore) PayloadTypeName

func (*AppStore) PayloadTypeName() string

PayloadTypeName returns "com.apple.appstore".

func (*AppStore) SchemaPath

func (*AppStore) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*AppStore) Validate

func (x *AppStore) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type AppToAppLayerVPNMapping

type AppToAppLayerVPNMapping struct {
	// The array of VPN mapping dictionaries.
	AppLayerVPNMapping []AppToAppLayerVPNMappingAppLayerVPNMapping `plist:"AppLayerVPNMapping,omitempty" json:"AppLayerVPNMapping,omitempty"`
}

AppToAppLayerVPNMapping: The payload that configures per-app VPN settings.

AppToAppLayerVPNMapping corresponds to mdm/profiles/com.apple.vpn.managed.appmapping.yaml (App-to-App-Layer VPN Mapping).

func (*AppToAppLayerVPNMapping) PayloadTypeName

func (*AppToAppLayerVPNMapping) PayloadTypeName() string

PayloadTypeName returns "com.apple.vpn.managed.appmapping".

func (*AppToAppLayerVPNMapping) SchemaPath

func (*AppToAppLayerVPNMapping) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*AppToAppLayerVPNMapping) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type AppToAppLayerVPNMappingAppLayerVPNMapping

type AppToAppLayerVPNMappingAppLayerVPNMapping struct {
	// The bundle identifier of the app using the per-app VPN.
	Identifier string `plist:"Identifier" json:"Identifier"`
	// The identifier of the per-app VPN payload, which defines the per-app VPN that the app
	// uses. See the `VPNUUID` key of the `AppLayerVPN` payload.
	VPNUUID string `plist:"VPNUUID" json:"VPNUUID"`
	// The code signature designated requirement of the app using the per-app VPN.
	DesignatedRequirement string `plist:"DesignatedRequirement" json:"DesignatedRequirement"`
	// The code signature signing identifier of the app using the per-app VPN.
	SigningIdentifier string `plist:"SigningIdentifier" json:"SigningIdentifier"`
	// The file-system path of the executable using the per-app VPN.
	Path *string `plist:"Path,omitempty" json:"Path,omitempty"`
	// An array of dictionaries. Each dictionary specifies a per-app VPN rule. Use this
	// property to restrict this per-app VPN rule to only match the app's spawned _helper tool_
	// network traffic.
	MatchTools []AppToAppLayerVPNMappingAppLayerVPNMappingMatchTools `plist:"MatchTools,omitempty" json:"MatchTools,omitempty"`
}

AppToAppLayerVPNMappingAppLayerVPNMapping: A dictionary defining a per-app VPN relationship.

type AppToAppLayerVPNMappingAppLayerVPNMappingMatchTools

type AppToAppLayerVPNMappingAppLayerVPNMappingMatchTools struct {
	// The code signature designated requirement of the command-line tool using the per-app
	// VPN.
	DesignatedRequirement string `plist:"DesignatedRequirement" json:"DesignatedRequirement"`
	// The code signature signing identifier of the command-line tool using the per-app VPN.
	SigningIdentifier string `plist:"SigningIdentifier" json:"SigningIdentifier"`
	// The file-system path of the command-line tool using the per-app VPN.
	Path *string `plist:"Path,omitempty" json:"Path,omitempty"`
}

AppToAppLayerVPNMappingAppLayerVPNMappingMatchTools: Specifies a per-app VPN rule to match network traffic that the app's spawned command-line tool generates.

type AssociatedDomains

type AssociatedDomains struct {
	// A dictionary that maps apps to their associated domains.
	Configuration []AssociatedDomainsConfiguration `plist:"Configuration,omitempty" json:"Configuration,omitempty"`
}

AssociatedDomains: The payload that configures associated domains.

AssociatedDomains corresponds to mdm/profiles/com.apple.associated-domains.yaml (Associated Domains).

func (*AssociatedDomains) PayloadTypeName

func (*AssociatedDomains) PayloadTypeName() string

PayloadTypeName returns "com.apple.associated-domains".

func (*AssociatedDomains) SchemaPath

func (*AssociatedDomains) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*AssociatedDomains) Validate

func (x *AssociatedDomains) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type AssociatedDomainsConfiguration

type AssociatedDomainsConfiguration struct {
	// The app identifier to associate the domains with.
	ApplicationIdentifier string `plist:"ApplicationIdentifier" json:"ApplicationIdentifier"`
	// The domains to associate with the app. Each string is in the form of `service:domain`.
	// Use fully qualified hostnames, such as `www.example.com`. See `Supporting associated
	// domains` for more information.
	AssociatedDomains []string `plist:"AssociatedDomains,omitempty" json:"AssociatedDomains,omitempty"`
	// If `true`, the system enables direct download of data for this domain instead of through
	// a CDN. Set the entitlement value for this domain to `service:domain?mode=managed`;
	// otherwise, the system ignores this value. Available in macOS 11 and later.
	EnableDirectDownloads *bool `plist:"EnableDirectDownloads,omitempty" json:"EnableDirectDownloads,omitempty"`
}

AssociatedDomainsConfiguration: A dictionary that maps apps to their associated domains.

type AutonomousSingleAppMode

type AutonomousSingleAppMode struct {
	// An array of dictionaries that specifies the apps that the system grants access to the
	// Accessibility APIs.
	AllowedApplications []AutonomousSingleAppModeAllowedApplications `plist:"AllowedApplications,omitempty" json:"AllowedApplications,omitempty"`
}

AutonomousSingleAppMode: The payload that configures Autonomous Single App mode.

AutonomousSingleAppMode corresponds to mdm/profiles/com.apple.asam.yaml (Autonomous Single App Mode).

func (*AutonomousSingleAppMode) PayloadTypeName

func (*AutonomousSingleAppMode) PayloadTypeName() string

PayloadTypeName returns "com.apple.asam".

func (*AutonomousSingleAppMode) SchemaPath

func (*AutonomousSingleAppMode) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*AutonomousSingleAppMode) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type AutonomousSingleAppModeAllowedApplications

type AutonomousSingleAppModeAllowedApplications struct {
	// The unique bundle identifier. If two dictionaries contain the same `BundleIdentifier`
	// value but a different `TeamIdentifier` value, an error occurs and the profile won't be
	// installed.
	BundleIdentifier string `plist:"BundleIdentifier" json:"BundleIdentifier"`
	// The developer's team identifier that the system used when it signed the app.
	TeamIdentifier string `plist:"TeamIdentifier" json:"TeamIdentifier"`
}

AutonomousSingleAppModeAllowedApplications: A dictionary that specifies an app that can be granted access to the Accessibilty APIs.

type CalDAV

type CalDAV struct {
	// The description of the account.
	CalDAVAccountDescription *string `plist:"CalDAVAccountDescription,omitempty" json:"CalDAVAccountDescription,omitempty"`
	// The server's address.
	CalDAVHostName string `plist:"CalDAVHostName" json:"CalDAVHostName"`
	// The user name for logins. If this profile is part of a non-interactive install, the
	// system requires this field.
	CalDAVUsername *string `plist:"CalDAVUsername,omitempty" json:"CalDAVUsername,omitempty"`
	// The user's password. Only use this in encrypted profiles.
	CalDAVPassword *string `plist:"CalDAVPassword,omitempty" json:"CalDAVPassword,omitempty"`
	// The base URL to the user's calendar.
	CalDAVPrincipalURL *string `plist:"CalDAVPrincipalURL,omitempty" json:"CalDAVPrincipalURL,omitempty"`
	// If `true`, the system enables SSL.
	CalDAVUseSSL *bool `plist:"CalDAVUseSSL,omitempty" json:"CalDAVUseSSL,omitempty"`
	// The server's port.
	CalDAVPort *int64 `plist:"CalDAVPort,omitempty" json:"CalDAVPort,omitempty"`
	// The VPNUUID of the per-app VPN the account uses for network communication. Available in
	// iOS 14 and later.
	VPNUUID *string `plist:"VPNUUID,omitempty" json:"VPNUUID,omitempty"`
}

CalDAV: The payload that configures a Calendar account.

CalDAV corresponds to mdm/profiles/com.apple.caldav.account.yaml (CalDAV).

func (*CalDAV) PayloadTypeName

func (*CalDAV) PayloadTypeName() string

PayloadTypeName returns "com.apple.caldav.account".

func (*CalDAV) SchemaPath

func (*CalDAV) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CalDAV) Validate

func (x *CalDAV) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CardDAV

type CardDAV struct {
	// The description of the account.
	CardDAVAccountDescription *string `plist:"CardDAVAccountDescription,omitempty" json:"CardDAVAccountDescription,omitempty"`
	// The server's address.
	CardDAVHostName string `plist:"CardDAVHostName" json:"CardDAVHostName"`
	// The user name for logins.
	CardDAVUsername *string `plist:"CardDAVUsername,omitempty" json:"CardDAVUsername,omitempty"`
	// The user's password. Only use this in encrypted profiles.
	CardDAVPassword *string `plist:"CardDAVPassword,omitempty" json:"CardDAVPassword,omitempty"`
	// The base URL to the user's address book.
	CardDAVPrincipalURL *string `plist:"CardDAVPrincipalURL,omitempty" json:"CardDAVPrincipalURL,omitempty"`
	// If `true`, the system enables SSL.
	CardDAVUseSSL *bool `plist:"CardDAVUseSSL,omitempty" json:"CardDAVUseSSL,omitempty"`
	// The server's port.
	CardDAVPort *int64 `plist:"CardDAVPort,omitempty" json:"CardDAVPort,omitempty"`
	// An array of communication service rules for this account.
	CommunicationServiceRules *CardDAVCommunicationServiceRules `plist:"CommunicationServiceRules,omitempty" json:"CommunicationServiceRules,omitempty"`
	// The VPNUUID of the per-app VPN the account uses for network communication. Available in
	// iOS 14 and later.
	VPNUUID *string `plist:"VPNUUID,omitempty" json:"VPNUUID,omitempty"`
}

CardDAV: The payload that configures a Contacts account.

CardDAV corresponds to mdm/profiles/com.apple.carddav.account.yaml (CardDAV).

func (*CardDAV) PayloadTypeName

func (*CardDAV) PayloadTypeName() string

PayloadTypeName returns "com.apple.carddav.account".

func (*CardDAV) SchemaPath

func (*CardDAV) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CardDAV) Validate

func (x *CardDAV) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CardDAVCommunicationServiceRules

type CardDAVCommunicationServiceRules struct {
	// A dictionary of service handlers for contacts from this account.
	DefaultServiceHandlers *CardDAVCommunicationServiceRulesDefaultServiceHandlers `plist:"DefaultServiceHandlers,omitempty" json:"DefaultServiceHandlers,omitempty"`
}

CardDAVCommunicationServiceRules: An array of communication service rules for this account.

type CardDAVCommunicationServiceRulesDefaultServiceHandlers

type CardDAVCommunicationServiceRulesDefaultServiceHandlers struct {
	// The bundle identifier for the default application that handles audio calls to contacts
	// from this account.
	AudioCall *string `plist:"AudioCall,omitempty" json:"AudioCall,omitempty"`
}

CardDAVCommunicationServiceRulesDefaultServiceHandlers: A dictionary of service handlers for contacts from this account.

type Cellular

type Cellular struct {
	// A configuration dictionary.
	AttachAPN *CellularAttachAPN `plist:"AttachAPN,omitempty" json:"AttachAPN,omitempty"`
	// An array of access point name (APN) dictionaries.
	APNs []CellularAPNs `plist:"APNs,omitempty" json:"APNs,omitempty"`
}

Cellular: The payload that configures cellular settings.

Cellular corresponds to mdm/profiles/com.apple.cellular.yaml (Cellular).

func (*Cellular) PayloadTypeName

func (*Cellular) PayloadTypeName() string

PayloadTypeName returns "com.apple.cellular".

func (*Cellular) SchemaPath

func (*Cellular) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Cellular) Validate

func (x *Cellular) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CellularAPNs

type CellularAPNs struct {
	// The name for this configuration.
	Name string `plist:"Name" json:"Name"`
	// The authentication type for logging in.
	AuthenticationType *string `plist:"AuthenticationType,omitempty" json:"AuthenticationType,omitempty"`
	// The user name for the APN.
	Username *string `plist:"Username,omitempty" json:"Username,omitempty"`
	// The user's password for the APN.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// The proxy server's address.
	ProxyServer *string `plist:"ProxyServer,omitempty" json:"ProxyServer,omitempty"`
	// The proxy server's port number.
	ProxyPort *int64 `plist:"ProxyPort,omitempty" json:"ProxyPort,omitempty"`
	// The default Internet Protocol versions. Available in iOS 10.3 but no longer used in iOS
	// 11 and later. Allowed values:
	DefaultProtocolMask *int64 `plist:"DefaultProtocolMask,omitempty" json:"DefaultProtocolMask,omitempty"`
	// The Internet Protocol versions that the system supports. Available in iOS 10.3 and
	// later. Allowed values:
	AllowedProtocolMask *int64 `plist:"AllowedProtocolMask,omitempty" json:"AllowedProtocolMask,omitempty"`
	// The Internet Protocol versions that the system supports while roaming. Available in iOS
	// 10.3 and later. Allowed values:
	AllowedProtocolMaskInRoaming *int64 `plist:"AllowedProtocolMaskInRoaming,omitempty" json:"AllowedProtocolMaskInRoaming,omitempty"`
	// The Internet Protocol versions that the system supports while roaming. Available in iOS
	// 10.3 and later. Allowed values:
	AllowedProtocolMaskInDomesticRoaming *int64 `plist:"AllowedProtocolMaskInDomesticRoaming,omitempty" json:"AllowedProtocolMaskInDomesticRoaming,omitempty"`
	// If `true`, the system enables XLAT464. Available in iOS 16 and later and watchOS 9 and
	// later.
	EnableXLAT464 *bool `plist:"EnableXLAT464,omitempty" json:"EnableXLAT464,omitempty"`
}

CellularAPNs: A dictionary that contains details about an access point name (APN) configuration.

type CellularAttachAPN

type CellularAttachAPN struct {
	// The name for this configuration.
	Name string `plist:"Name" json:"Name"`
	// The authentication type.
	AuthenticationType *string `plist:"AuthenticationType,omitempty" json:"AuthenticationType,omitempty"`
	// The user name.
	Username *string `plist:"Username,omitempty" json:"Username,omitempty"`
	// The password for the user.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// The Internet Protocol versions that the system supports. Allowed values:
	AllowedProtocolMask *int64 `plist:"AllowedProtocolMask,omitempty" json:"AllowedProtocolMask,omitempty"`
}

CellularAttachAPN: A configuration dictionary.

type CellularPrivateNetwork

type CellularPrivateNetwork struct {
	// A list of up to 1000 geofences for private networks. Geofencing is only used on iPhone.
	Geofences []CellularPrivateNetworkGeofences `plist:"Geofences,omitempty" json:"Geofences,omitempty"`
	// The name of the private network configuration data set.
	DataSetName string `plist:"DataSetName" json:"DataSetName"`
	// The version number of this dataset that the system uses to track updates.
	VersionNumber string `plist:"VersionNumber" json:"VersionNumber"`
	// Set to `true` to prefer this private network over Wi-Fi.
	CellularDataPreferred *bool `plist:"CellularDataPreferred,omitempty" json:"CellularDataPreferred,omitempty"`
	// Set to `true` if this private network is NR Standalone.
	EnableNRStandalone *bool `plist:"EnableNRStandalone,omitempty" json:"EnableNRStandalone,omitempty"`
	// A string using the 3GPP "Coordinated NID" (option 1 or option 2) format (defined in 3GPP
	// 31.102, Section 12.7.1). The device uses this value to match a SIM present on the
	// device.
	NetworkIdentifier *string `plist:"NetworkIdentifier,omitempty" json:"NetworkIdentifier,omitempty"`
	// A string using the 3GPP "CSG_ID" format (defined in 3GPP 23.003, Section 4.7). The
	// device uses this value to match a SIM present on the device.
	CsgNetworkIdentifier *string `plist:"CsgNetworkIdentifier,omitempty" json:"CsgNetworkIdentifier,omitempty"`
}

CellularPrivateNetwork: The payload that provides device info on private network deployments, including geographical location, preference over Wi-Fi, and network deployment type.

CellularPrivateNetwork corresponds to mdm/profiles/com.apple.cellularprivatenetwork.managed.yaml (Cellular Private Network).

func (*CellularPrivateNetwork) PayloadTypeName

func (*CellularPrivateNetwork) PayloadTypeName() string

PayloadTypeName returns "com.apple.cellularprivatenetwork.managed".

func (*CellularPrivateNetwork) SchemaPath

func (*CellularPrivateNetwork) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CellularPrivateNetwork) Validate

func (x *CellularPrivateNetwork) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CellularPrivateNetworkGeofences

type CellularPrivateNetworkGeofences struct {
	// The longitude of the geofence.
	Longitude float64 `plist:"Longitude" json:"Longitude"`
	// The latitude of the geofence.
	Latitude float64 `plist:"Latitude" json:"Latitude"`
	// Specifies the radius of the geofence in meters. Set this value slightly greater than the
	// private cellular network coverage area.
	Radius float64 `plist:"Radius" json:"Radius"`
	// A geofence identifier that's unique within a list of geofences.
	GeofenceId string `plist:"GeofenceId" json:"GeofenceId"`
}

CellularPrivateNetworkGeofences: A geofence for a private network.

type CertificatePEM

type CertificatePEM struct {
	// The file name of the enclosed certificate.
	PayloadCertificateFileName *string `plist:"PayloadCertificateFileName,omitempty" json:"PayloadCertificateFileName,omitempty"`
	// The binary representation of the payload, encoded in Base64.
	PayloadContent []byte `plist:"PayloadContent,omitempty" json:"PayloadContent,omitempty"`
}

CertificatePEM: The payload that configures a PEM-formatted certificate.

CertificatePEM corresponds to mdm/profiles/com.apple.security.pem.yaml (Certificate (PEM)).

func (*CertificatePEM) PayloadTypeName

func (*CertificatePEM) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.pem".

func (*CertificatePEM) SchemaPath

func (*CertificatePEM) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CertificatePEM) Validate

func (x *CertificatePEM) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CertificatePKCS1

type CertificatePKCS1 struct {
	// The file name of the enclosed certificate.
	PayloadCertificateFileName *string `plist:"PayloadCertificateFileName,omitempty" json:"PayloadCertificateFileName,omitempty"`
	// The binary representation of the payload, encoded in Base64.
	PayloadContent []byte `plist:"PayloadContent,omitempty" json:"PayloadContent,omitempty"`
}

CertificatePKCS1: The payload that configures a PKCS #1-formatted certificate.

CertificatePKCS1 corresponds to mdm/profiles/com.apple.security.pkcs1.yaml (Certificate (PKCS #1)).

func (*CertificatePKCS1) PayloadTypeName

func (*CertificatePKCS1) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.pkcs1".

func (*CertificatePKCS1) SchemaPath

func (*CertificatePKCS1) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CertificatePKCS1) Validate

func (x *CertificatePKCS1) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CertificatePKCS12

type CertificatePKCS12 struct {
	// The file name of the enclosed certificate.
	PayloadCertificateFileName *string `plist:"PayloadCertificateFileName,omitempty" json:"PayloadCertificateFileName,omitempty"`
	// The binary representation of the payload, encoded in Base64.
	PayloadContent []byte `plist:"PayloadContent,omitempty" json:"PayloadContent,omitempty"`
	// The password to the identity.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// If `true`, the system allows apps access to the private key. Available in macOS 10.10
	// and later.
	AllowAllAppsAccess *bool `plist:"AllowAllAppsAccess,omitempty" json:"AllowAllAppsAccess,omitempty"`
	// If `false`, the system doesn't tag the private key data as extractable in the keychain.
	KeyIsExtractable *bool `plist:"KeyIsExtractable,omitempty" json:"KeyIsExtractable,omitempty"`
}

CertificatePKCS12: The payload that configures a PKCS #12-formatted certificate.

CertificatePKCS12 corresponds to mdm/profiles/com.apple.security.pkcs12.yaml (Certificate (PKCS #12)).

func (*CertificatePKCS12) PayloadTypeName

func (*CertificatePKCS12) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.pkcs12".

func (*CertificatePKCS12) SchemaPath

func (*CertificatePKCS12) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CertificatePKCS12) Validate

func (x *CertificatePKCS12) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CertificatePreference

type CertificatePreference struct {
	// An email address (in RFC 822 format) or other name for which a preferred certificate is
	// requested.
	Name string `plist:"Name" json:"Name"`
	// The UUID of the certificate payload within the same profile to use for the identity
	// credential.
	PayloadCertificateUUID string `plist:"PayloadCertificateUUID" json:"PayloadCertificateUUID"`
}

CertificatePreference: The payload that configures a certificate preference.

CertificatePreference corresponds to mdm/profiles/com.apple.security.certificatepreference.yaml (Certificate Preference).

func (*CertificatePreference) PayloadTypeName

func (*CertificatePreference) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.certificatepreference".

func (*CertificatePreference) SchemaPath

func (*CertificatePreference) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CertificatePreference) Validate

func (x *CertificatePreference) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CertificateRevocation

type CertificateRevocation struct {
	// An array of certificates that the system checks for revocation.
	EnabledForCerts []CertificateRevocationEnabledForCerts `plist:"EnabledForCerts,omitempty" json:"EnabledForCerts,omitempty"`
}

CertificateRevocation: The payload that configures certificate revocation checking.

CertificateRevocation corresponds to mdm/profiles/com.apple.security.certificaterevocation.yaml (Certificate Revocation).

func (*CertificateRevocation) PayloadTypeName

func (*CertificateRevocation) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.certificaterevocation".

func (*CertificateRevocation) SchemaPath

func (*CertificateRevocation) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CertificateRevocation) Validate

func (x *CertificateRevocation) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CertificateRevocationEnabledForCerts

type CertificateRevocationEnabledForCerts struct {
	// The algorithm must be `sha256`.
	Algorithm string `plist:"Algorithm" json:"Algorithm"`
	// The hash of the DER-encoding of the certificate's `subjectPublicKeyInfo`.
	Hash []byte `plist:"Hash,omitempty" json:"Hash,omitempty"`
}

CertificateRevocationEnabledForCerts: A dictionary of hashed public keys.

type CertificateRoot

type CertificateRoot struct {
	// The file name of the enclosed certificate.
	PayloadCertificateFileName *string `plist:"PayloadCertificateFileName,omitempty" json:"PayloadCertificateFileName,omitempty"`
	// The binary representation of the payload encoded in base64.
	PayloadContent []byte `plist:"PayloadContent,omitempty" json:"PayloadContent,omitempty"`
}

CertificateRoot: The payload that configures a root certificate.

CertificateRoot corresponds to mdm/profiles/com.apple.security.root.yaml (Certificate (Root)).

func (*CertificateRoot) PayloadTypeName

func (*CertificateRoot) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.root".

func (*CertificateRoot) SchemaPath

func (*CertificateRoot) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CertificateRoot) Validate

func (x *CertificateRoot) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CertificateTransparency

type CertificateTransparency struct {
	// An array of certificates for which certificate transparency is disabled. One of the
	// following conditions needs to be met to disable certificate transparency enforcement
	// when this policy is set:
	DisabledForCerts []CertificateTransparencyDisabledForCerts `plist:"DisabledForCerts,omitempty" json:"DisabledForCerts,omitempty"`
	// An array of strings that represent the domains to exclude from certificate transparency
	// enforcement. The system supports using a leading period (`.`) to signify subdomains.
	// However, the system doesn't support wildcards. If you include a leading period, the
	// domain can't be a top-level domain, such as `.com` and `.co.uk`.
	DisabledForDomains []string `plist:"DisabledForDomains,omitempty" json:"DisabledForDomains,omitempty"`
}

CertificateTransparency: The payload that configures certificate transparency enforcement.

CertificateTransparency corresponds to mdm/profiles/com.apple.security.certificatetransparency.yaml (Certificate Transparency).

func (*CertificateTransparency) PayloadTypeName

func (*CertificateTransparency) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.certificatetransparency".

func (*CertificateTransparency) SchemaPath

func (*CertificateTransparency) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CertificateTransparency) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type CertificateTransparencyDisabledForCerts

type CertificateTransparencyDisabledForCerts struct {
	// The algorithm must be `sha256`.
	Algorithm string `plist:"Algorithm" json:"Algorithm"`
	// The hash of the DER-encoding of the certificate's `subjectPublicKeyInfo`.
	Hash []byte `plist:"Hash,omitempty" json:"Hash,omitempty"`
}

CertificateTransparencyDisabledForCerts: A dictionary of hashed public keys.

type CommonPayloadKeys

type CommonPayloadKeys struct {
	// The reverse-DNS-style identifier for the payload. This identifier is usually the same as
	// the `TopLevel` value, with an additional appended component. This string must be unique
	// within the profile.
	PayloadIdentifier string `plist:"PayloadIdentifier" json:"PayloadIdentifier"`
	// The globally unique identifier for the payload. The actual content is unimportant, but
	// must be globally unique. In macOS, use `uuidgen` to generate UUIDs.
	PayloadUUID string `plist:"PayloadUUID" json:"PayloadUUID"`
	// The payload type, which each payload domain's reference page specifies.
	PayloadType string `plist:"PayloadType" json:"PayloadType"`
	// The version of this specific payload.
	PayloadVersion int64 `plist:"PayloadVersion" json:"PayloadVersion"`
	// The human-readable description of this payload. This description appears on the Detail
	// screen.
	PayloadDescription *string `plist:"PayloadDescription,omitempty" json:"PayloadDescription,omitempty"`
	// The human-readable name for the profile payload. The name appears on the Detail screen
	// and doesn't need to be unique.
	PayloadDisplayName *string `plist:"PayloadDisplayName,omitempty" json:"PayloadDisplayName,omitempty"`
	// The human-readable string containing the name of the organization that provides the
	// profile. This value doesn't need to match the organization payload value in the
	// enclosing dictionary.
	PayloadOrganization *string `plist:"PayloadOrganization,omitempty" json:"PayloadOrganization,omitempty"`
}

CommonPayloadKeys: The properties common to all payloads.

CommonPayloadKeys corresponds to mdm/profiles/CommonPayloadKeys.yaml (Common Payload Keys).

func (*CommonPayloadKeys) PayloadTypeName

func (*CommonPayloadKeys) PayloadTypeName() string

PayloadTypeName returns "CommonPayloadKeys".

func (*CommonPayloadKeys) SchemaPath

func (*CommonPayloadKeys) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*CommonPayloadKeys) Validate

func (x *CommonPayloadKeys) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ConferenceRoomDisplay

type ConferenceRoomDisplay struct {
	// The custom message displayed on the screen in Conference Room Display mode.
	Message *string `plist:"Message,omitempty" json:"Message,omitempty"`
}

ConferenceRoomDisplay: The payload that configures Conference Room Display mode for Apple TV.

ConferenceRoomDisplay corresponds to mdm/profiles/com.apple.conferenceroomdisplay.yaml (Conference Room Display).

func (*ConferenceRoomDisplay) PayloadTypeName

func (*ConferenceRoomDisplay) PayloadTypeName() string

PayloadTypeName returns "com.apple.conferenceroomdisplay".

func (*ConferenceRoomDisplay) SchemaPath

func (*ConferenceRoomDisplay) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ConferenceRoomDisplay) Validate

func (x *ConferenceRoomDisplay) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ContentCaching

type ContentCaching struct {
	// If true, the system purges content from the cache automatically when it needs disk space
	// for other apps when free disk space runs low on the computer. Set to `false` to maximize
	// effectiveness of Content Caching. Available in macOS 10.15 and later.
	AllowCacheDelete *bool `plist:"AllowCacheDelete,omitempty" json:"AllowCacheDelete,omitempty"`
	// If `true`, the system caches the user's iCloud data. Changes to this value don't have an
	// immediate effect. Clients may take some time, such as hours or days, to react to
	// changes.
	AllowPersonalCaching *bool `plist:"AllowPersonalCaching,omitempty" json:"AllowPersonalCaching,omitempty"`
	// If `true`, the system caches non-iCloud content, such as apps and software updates.
	// Changes to this value don't have an immediate effect. Clients may take some time, such
	// as hours or days, to react to changes.
	AllowSharedCaching *bool `plist:"AllowSharedCaching,omitempty" json:"AllowSharedCaching,omitempty"`
	// If `true`, the system automatically activates the content cache when possible and
	// prevents disabling it. If `allowContentCaching` is `false`, `AutoActivation` is also
	// `false`.
	AutoActivation *bool `plist:"AutoActivation,omitempty" json:"AutoActivation,omitempty"`
	// If `true`, the system automatically enables Internet connection sharing when possible
	// and prevent disabling Internet connection sharing. `DenyTetheredCaching` overrides
	// `AutoEnableTetheredCaching`. Tethered caching requires Content Caching.
	AutoEnableTetheredCaching *bool `plist:"AutoEnableTetheredCaching,omitempty" json:"AutoEnableTetheredCaching,omitempty"`
	// The maximum number of bytes of disk space to use for the content cache. Set to `0` for
	// unlimited disk space.
	CacheLimit *int64 `plist:"CacheLimit,omitempty" json:"CacheLimit,omitempty"`
	// The path to the directory used to store cached content. Changing this setting manually
	// doesn't automatically move cached content from the old location to the new one. To move
	// content automatically, use the Sharing preference's Content Caching pane. The value must
	// be (or end with) `/Library/Application Support/Apple/AssetCache/Data`.
	DataPath *string `plist:"DataPath,omitempty" json:"DataPath,omitempty"`
	// If `true`, the system disables tethered caching.
	DenyTetheredCaching *bool `plist:"DenyTetheredCaching,omitempty" json:"DenyTetheredCaching,omitempty"`
	// If `true`, Content Caching displays exceptional conditions (alerts) as system
	// notifications in the upper corner of the screen. Alerts were automatically displayed
	// starting in macOS 10.13. In macOS 10.15 the alerts are off by default, but still
	// available through this setting. Available in macOS 10.15 and later.
	DisplayAlerts *bool `plist:"DisplayAlerts,omitempty" json:"DisplayAlerts,omitempty"`
	// If `true`, the system prevents the computer from sleeping as long as Content Caching is
	// on (System Preferences > Sharing > Content Caching is on). Customers who want Content
	// Caching to be as available as much as possible should turn this setting on. Available in
	// macOS 10.15 and later.
	KeepAwake *bool `plist:"KeepAwake,omitempty" json:"KeepAwake,omitempty"`
	// An array of dictionaries that describe a range of client IP addresses to serve.
	ListenRanges []ContentCachingRanges `plist:"ListenRanges,omitempty" json:"ListenRanges,omitempty"`
	// If `true`, the content cache provides content to the clients in the `ListenRanges`.
	ListenRangesOnly *bool `plist:"ListenRangesOnly,omitempty" json:"ListenRangesOnly,omitempty"`
	// If `true`, the content cache provides content to the clients in the union of the
	// `ListenRanges`, `PeerListenRanges` and `Parents`.
	ListenWithPeersAndParents *bool `plist:"ListenWithPeersAndParents,omitempty" json:"ListenWithPeersAndParents,omitempty"`
	// If `true`, the content cache offers content to clients only on the same immediate local
	// network only. No content is offered to clients on other networks reachable by the
	// content cache. If `LocalSubnetsOnly` is `true`, the system ignores `ListenRanges`.
	LocalSubnetsOnly *bool `plist:"LocalSubnetsOnly,omitempty" json:"LocalSubnetsOnly,omitempty"`
	// If `true`, the Content Cache logs the IP address and port number of the clients that
	// request content.
	LogClientIdentity *bool `plist:"LogClientIdentity,omitempty" json:"LogClientIdentity,omitempty"`
	// An array of the local IP addresses of other content caches that this cache should
	// download from or upload to, instead of downloading from or uploading to Apple directly.
	// The system ignores invalid addresses and addresses of computers that aren't content
	// caches. The system skips Parent caches that become unavailable. If all parent content
	// caches become unavailable, the content cache downloads from or uploads to Apple
	// directly, until a parent content cache becomes available again.
	Parents []string `plist:"Parents,omitempty" json:"Parents,omitempty"`
	// The policy to implement when choosing among more than one configured parent content
	// cache. With every policy, the system skips parent caches that are temporarily
	// unavailable. Allowed values:
	ParentSelectionPolicy *string `plist:"ParentSelectionPolicy,omitempty" json:"ParentSelectionPolicy,omitempty"`
	// An array of dictionaries describing a range of peer IP addresses that the content cache
	// uses to filter its list of peers to query for content. The content cache only queries
	// peers in `PeerFilterRanges`. When `PeerFilterRanges` is an empty array, the content
	// cache doesn't query any peers.
	PeerFilterRanges []ContentCachingRanges `plist:"PeerFilterRanges,omitempty" json:"PeerFilterRanges,omitempty"`
	// An array of dictionaries describing a range of peer IP addresses the content cache
	// responds to. When `PeerListenRanges` is an empty array, the content cache responds with
	// an error to all cache queries.
	PeerListenRanges []ContentCachingRanges `plist:"PeerListenRanges,omitempty" json:"PeerListenRanges,omitempty"`
	// If `true`, the content cache only peers with other content caches on the same immediate
	// local network, rather than with content caches that use the same public IP address as
	// the device. When `PeerLocalSubnetsOnly` is `true`, it overrides the configuration of
	// `PeerFilterRanges` and `PeerListenRanges`. If the network changes, the local network
	// peering restrictions update appropriately. If `false`, the content cache defers to
	// `PeerFilterRanges` and `PeerListenRanges` for configuring the peering restrictions.
	PeerLocalSubnetsOnly *bool `plist:"PeerLocalSubnetsOnly,omitempty" json:"PeerLocalSubnetsOnly,omitempty"`
	// The TCP port number on which the content cache accepts requests for uploads or
	// downloads. Set to `0` to pick a random, available port.
	Port *int64 `plist:"Port,omitempty" json:"Port,omitempty"`
	// An array of dictionaries describing a range of public IP addresses that the cloud
	// servers should use for matching clients to content caches.
	PublicRanges []ContentCachingRanges `plist:"PublicRanges,omitempty" json:"PublicRanges,omitempty"`
}

ContentCaching: The payload that configures the Content Caching service.

ContentCaching corresponds to mdm/profiles/com.apple.AssetCache.managed.yaml (Content Caching).

func (*ContentCaching) PayloadTypeName

func (*ContentCaching) PayloadTypeName() string

PayloadTypeName returns "com.apple.AssetCache.managed".

func (*ContentCaching) SchemaPath

func (*ContentCaching) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ContentCaching) Validate

func (x *ContentCaching) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ContentCachingRanges

type ContentCachingRanges struct {
	// The IP address type.
	Type *string `plist:"type,omitempty" json:"type,omitempty"`
	// The first IP address in the range.
	First string `plist:"first" json:"first"`
	// The last IP address in the range.
	Last string `plist:"last" json:"last"`
}

ContentCachingRanges: A range of IP addresses to cache.

type DNSProxy

type DNSProxy struct {
	// The bundle identifier of the app containing the DNS proxy network extension.
	AppBundleIdentifier string `plist:"AppBundleIdentifier" json:"AppBundleIdentifier"`
	// The bundle identifier of the DNS proxy network extension to use. Declaring the bundle
	// identifier is useful for apps that contain more than one DNS proxy extension.
	ProviderBundleIdentifier *string `plist:"ProviderBundleIdentifier,omitempty" json:"ProviderBundleIdentifier,omitempty"`
	// The dictionary of vendor-specific configuration items.
	ProviderConfiguration map[string]any `plist:"ProviderConfiguration,omitempty" json:"ProviderConfiguration,omitempty"`
	// A globally unique identifier for this DNS proxy configuration. The proxy processes DNS
	// lookups traffic for managed apps with the same `DNSProxyUUID` in their app attributes.
	// This key is required for user enrollment.
	DNSProxyUUID *string `plist:"DNSProxyUUID,omitempty" json:"DNSProxyUUID,omitempty"`
}

DNSProxy: The payload that configures DNS proxies.

DNSProxy corresponds to mdm/profiles/com.apple.dnsProxy.managed.yaml (DNS Proxy).

func (*DNSProxy) PayloadTypeName

func (*DNSProxy) PayloadTypeName() string

PayloadTypeName returns "com.apple.dnsProxy.managed".

func (*DNSProxy) SchemaPath

func (*DNSProxy) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*DNSProxy) Validate

func (x *DNSProxy) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type DNSSettings

type DNSSettings struct {
	// A dictionary that defines a configuration for an encrypted DNS server.
	DNSSettings DNSSettingsDNSSettings `plist:"DNSSettings,omitempty" json:"DNSSettings,omitempty"`
	// An array of rules that define the DNS settings. If not set, the system always applies
	// the DNS settings. These rules are identical to the `OnDemandRules` array in VPN
	// payloads.
	OnDemandRules []DNSSettingsOnDemandRulesElement `plist:"OnDemandRules,omitempty" json:"OnDemandRules,omitempty"`
	// If `true`, the system prohibits users from disabling DNS settings. This key is only
	// available on supervised devices.
	ProhibitDisablement *bool `plist:"ProhibitDisablement,omitempty" json:"ProhibitDisablement,omitempty"`
}

DNSSettings: The payload that configures encrypted DNS settings.

DNSSettings corresponds to mdm/profiles/com.apple.dnsSettings.managed.yaml (DNS Settings).

func (*DNSSettings) PayloadTypeName

func (*DNSSettings) PayloadTypeName() string

PayloadTypeName returns "com.apple.dnsSettings.managed".

func (*DNSSettings) SchemaPath

func (*DNSSettings) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*DNSSettings) Validate

func (x *DNSSettings) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type DNSSettingsDNSSettings

type DNSSettingsDNSSettings struct {
	// The encrypted transport protocol used to communicate with the DNS server.
	DNSProtocol string `plist:"DNSProtocol" json:"DNSProtocol"`
	// The URI template of a DNS-over-HTTPS server, as defined in RFC 8484. This URL needs to
	// use the `https://` scheme, and the system uses the hostname or address in the URL to
	// validate the server certificate. If no `ServerAddresses` are provided, the system uses
	// the hostname or address in the URL to determine the server addresses. Required if
	// `DNSProtocol` is `HTTPS`.
	ServerURL *string `plist:"ServerURL,omitempty" json:"ServerURL,omitempty"`
	// The hostname of a DNS-over-TLS server used to validate the server certificate, as
	// defined in RFC 7858. If no `ServerAddresses` are provided, the system uses the hostname
	// to determine the server addresses. This key must be present only if the DNSProtocol is
	// `TLS`.
	ServerName *string `plist:"ServerName,omitempty" json:"ServerName,omitempty"`
	// An unordered list of DNS server IP address strings. These IP addresses can be a mixture
	// of IPv4 and IPv6 addresses.
	ServerAddresses []string `plist:"ServerAddresses,omitempty" json:"ServerAddresses,omitempty"`
	// If `true`, the device allows failover to the default system DNS resolver.
	AllowFailover *bool `plist:"AllowFailover,omitempty" json:"AllowFailover,omitempty"`
	// The UUID that points to an identity certificate payload. The system uses this identity
	// to authenticate the user to the DNS resolver.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// A list of domain strings used to determine which DNS queries use the DNS server. If not
	// set, all domains use the DNS server.
	SupplementalMatchDomains []string `plist:"SupplementalMatchDomains,omitempty" json:"SupplementalMatchDomains,omitempty"`
}

DNSSettingsDNSSettings: A dictionary that defines a configuration for an encrypted DNS server.

type DNSSettingsOnDemandRulesElement

type DNSSettingsOnDemandRulesElement struct {
	// The action to take if this dictionary matches the current network. Allowed values:
	Action string `plist:"Action" json:"Action"`
	// An array of dictionaries that provide per-connection rules. The system uses this array
	// only for settings where the `Action` value is `EvaluateConnection`.
	ActionParameters []DNSSettingsOnDemandRulesElementActionParameters `plist:"ActionParameters,omitempty" json:"ActionParameters,omitempty"`
	// An array of domain names. This rule matches if any of the domain names in the specified
	// list matches any domain in the device's search domains list.
	DNSDomainMatch []string `plist:"DNSDomainMatch,omitempty" json:"DNSDomainMatch,omitempty"`
	// An array of IP addresses. This rule matches if any of the network's specified DNS
	// servers match any entry in the array.
	DNSServerAddressMatch []string `plist:"DNSServerAddressMatch,omitempty" json:"DNSServerAddressMatch,omitempty"`
	// An interface type. If specified, this rule matches only if the primary network interface
	// hardware matches the specified type.
	InterfaceTypeMatch *string `plist:"InterfaceTypeMatch,omitempty" json:"InterfaceTypeMatch,omitempty"`
	// An array of SSIDs to match against the current network. If the network isn't a Wi-Fi
	// network or if the SSID doesn't appear in this array, the match fails. Omit this key and
	// the corresponding array to match against any SSID.
	SSIDMatch []string `plist:"SSIDMatch,omitempty" json:"SSIDMatch,omitempty"`
	// A URL to probe. This rule matches if this URL is successfully fetched and returns a 200
	// HTTP status code without redirection.
	URLStringProbe *string `plist:"URLStringProbe,omitempty" json:"URLStringProbe,omitempty"`
}

DNSSettingsOnDemandRulesElement: is generated from mdm/profiles/com.apple.dnsSettings.managed.yaml.

type DNSSettingsOnDemandRulesElementActionParameters

type DNSSettingsOnDemandRulesElementActionParameters struct {
	// The domains for which this evaluation applies.
	Domains []string `plist:"Domains,omitempty" json:"Domains,omitempty"`
	// The DNS settings behavior for the specified domains. Allowed values:
	DomainAction string `plist:"DomainAction" json:"DomainAction"`
}

DNSSettingsOnDemandRulesElementActionParameters: A dictionary that provides per-connection rules. The keys allowed in each dictionary are described below. Note: This array is only for dictionaries in which `EvaluateConnection` is the `Action` value.

type Declarations

type Declarations struct {
	// The set of declarations to apply. The array items are Base64-encoded data
	// representations of the declaration JSON data.
	Declarations [][]byte `plist:"Declarations,omitempty" json:"Declarations,omitempty"`
}

Declarations: The payload that applies a set of declarations to the device through the Settings app.

Declarations corresponds to mdm/profiles/com.apple.declarations.yaml (Declarations).

func (*Declarations) PayloadTypeName

func (*Declarations) PayloadTypeName() string

PayloadTypeName returns "com.apple.declarations".

func (*Declarations) SchemaPath

func (*Declarations) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Declarations) Validate

func (x *Declarations) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type Desktop

type Desktop struct {
	// If `true`, locks the desktop picture. Replaced with allowWallpaperModification in macOS
	// 10.13.
	Locked *bool `plist:"locked,omitempty" json:"locked,omitempty"`
	// The path to the desktop picture. If set, this picture is always locked.
	OverridePicturePath *string `plist:"override-picture-path,omitempty" json:"override-picture-path,omitempty"`
}

Desktop: The payload that configures the desktop wallpaper.

Desktop corresponds to mdm/profiles/com.apple.desktop.yaml (Desktop).

func (*Desktop) PayloadTypeName

func (*Desktop) PayloadTypeName() string

PayloadTypeName returns "com.apple.desktop".

func (*Desktop) SchemaPath

func (*Desktop) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Desktop) Validate

func (x *Desktop) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type DirectoryService

type DirectoryService struct {
	// The Active Directory domain to join.
	HostName string `plist:"HostName" json:"HostName"`
	// The user name of the account for the domain.
	UserName *string `plist:"UserName,omitempty" json:"UserName,omitempty"`
	// The password of the account for the domain.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// The client's identifier.
	ClientID *string `plist:"ClientID,omitempty" json:"ClientID,omitempty"`
	// The directory service description.
	Description *string `plist:"Description,omitempty" json:"Description,omitempty"`
	// The organizational unit to add the joining computer object to.
	ADOrganizationalUnit *string `plist:"ADOrganizationalUnit,omitempty" json:"ADOrganizationalUnit,omitempty"`
	// The network home protocol to use: `afp` or `smb`.
	ADMountStyle *string `plist:"ADMountStyle,omitempty" json:"ADMountStyle,omitempty"`
	// If `true`, the system enables the `ADCreateMobileAccountAtLogin` key.
	ADCreateMobileAccountAtLoginFlag *bool `plist:"ADCreateMobileAccountAtLoginFlag,omitempty" json:"ADCreateMobileAccountAtLoginFlag,omitempty"`
	// If `true`, the system creates a mobile account at login.
	ADCreateMobileAccountAtLogin *bool `plist:"ADCreateMobileAccountAtLogin,omitempty" json:"ADCreateMobileAccountAtLogin,omitempty"`
	// If `true`, the system enables the `ADWarnUserBeforeCreatingMA` key.
	ADWarnUserBeforeCreatingMAFlag *bool `plist:"ADWarnUserBeforeCreatingMAFlag,omitempty" json:"ADWarnUserBeforeCreatingMAFlag,omitempty"`
	// If `true`, the system enables the warning before creating the mobile account.
	ADWarnUserBeforeCreatingMA *bool `plist:"ADWarnUserBeforeCreatingMA,omitempty" json:"ADWarnUserBeforeCreatingMA,omitempty"`
	// If `true`, the system enables the `ADForceHomeLocal` key.
	ADForceHomeLocalFlag *bool `plist:"ADForceHomeLocalFlag,omitempty" json:"ADForceHomeLocalFlag,omitempty"`
	// If `true`, the system forces a local home directory.
	ADForceHomeLocal *bool `plist:"ADForceHomeLocal,omitempty" json:"ADForceHomeLocal,omitempty"`
	// If `true`, the system enables the `ADUseWindowsUNCPath` key.
	ADUseWindowsUNCPathFlag *bool `plist:"ADUseWindowsUNCPathFlag,omitempty" json:"ADUseWindowsUNCPathFlag,omitempty"`
	// If `true`, the system uses the UNC path from Active Directory to derive the network home
	// location.
	ADUseWindowsUNCPath *bool `plist:"ADUseWindowsUNCPath,omitempty" json:"ADUseWindowsUNCPath,omitempty"`
	// If `true`, the system enables the `ADAllowMultiDomainAuth` key.
	ADAllowMultiDomainAuthFlag *bool `plist:"ADAllowMultiDomainAuthFlag,omitempty" json:"ADAllowMultiDomainAuthFlag,omitempty"`
	// If `true`, the system allows authentication from any domain in the namespace.
	ADAllowMultiDomainAuth *bool `plist:"ADAllowMultiDomainAuth,omitempty" json:"ADAllowMultiDomainAuth,omitempty"`
	// If `true`, the system enables the `ADDefaultUserShell` key.
	ADDefaultUserShellFlag *bool `plist:"ADDefaultUserShellFlag,omitempty" json:"ADDefaultUserShellFlag,omitempty"`
	// The default user shell.
	ADDefaultUserShell *string `plist:"ADDefaultUserShell,omitempty" json:"ADDefaultUserShell,omitempty"`
	// If `true`, the system enables the `ADMapUIDAttribute` key.
	ADMapUIDAttributeFlag *bool `plist:"ADMapUIDAttributeFlag,omitempty" json:"ADMapUIDAttributeFlag,omitempty"`
	// The map UID to attribute.
	ADMapUIDAttribute *string `plist:"ADMapUIDAttribute,omitempty" json:"ADMapUIDAttribute,omitempty"`
	// If `true`, the system enables the `ADMapGIDAttribute` key.
	ADMapGIDAttributeFlag *bool `plist:"ADMapGIDAttributeFlag,omitempty" json:"ADMapGIDAttributeFlag,omitempty"`
	// The map GID to attribute.
	ADMapGIDAttribute *string `plist:"ADMapGIDAttribute,omitempty" json:"ADMapGIDAttribute,omitempty"`
	// If `true`, the system enables the `ADMapGGIDAttributeFlag` key.
	ADMapGGIDAttributeFlag *bool `plist:"ADMapGGIDAttributeFlag,omitempty" json:"ADMapGGIDAttributeFlag,omitempty"`
	// The map group GID to attribute.
	ADMapGGIDAttribute *string `plist:"ADMapGGIDAttribute,omitempty" json:"ADMapGGIDAttribute,omitempty"`
	// If `true`, the system enables the `ADPreferredDCServer` key.
	ADPreferredDCServerFlag *bool `plist:"ADPreferredDCServerFlag,omitempty" json:"ADPreferredDCServerFlag,omitempty"`
	// The preferred domain server.
	ADPreferredDCServer *string `plist:"ADPreferredDCServer,omitempty" json:"ADPreferredDCServer,omitempty"`
	// If `true`, the system enables the `ADDomainAdminGroupList` key.
	ADDomainAdminGroupListFlag *bool `plist:"ADDomainAdminGroupListFlag,omitempty" json:"ADDomainAdminGroupListFlag,omitempty"`
	// The list of Active Directory groups with admin access.
	ADDomainAdminGroupList []string `plist:"ADDomainAdminGroupList,omitempty" json:"ADDomainAdminGroupList,omitempty"`
	// If `true`, the system enables the `ADNamespace` key.
	ADNamespaceFlag *bool `plist:"ADNamespaceFlag,omitempty" json:"ADNamespaceFlag,omitempty"`
	// The primary user account naming convention; either `forest` or `domain`.
	ADNamespace *string `plist:"ADNamespace,omitempty" json:"ADNamespace,omitempty"`
	// If `true`, the system enables the `ADPacketSign` key.
	ADPacketSignFlag *bool `plist:"ADPacketSignFlag,omitempty" json:"ADPacketSignFlag,omitempty"`
	// The packet signing policy.
	ADPacketSign *string `plist:"ADPacketSign,omitempty" json:"ADPacketSign,omitempty"`
	// If `true`, the system enables the `ADPacketEncrypt` key.
	ADPacketEncryptFlag *bool `plist:"ADPacketEncryptFlag,omitempty" json:"ADPacketEncryptFlag,omitempty"`
	// The packet encryption policy.
	ADPacketEncrypt *string `plist:"ADPacketEncrypt,omitempty" json:"ADPacketEncrypt,omitempty"`
	// If `true`, the system enables the `ADRestrictDDNS` key.
	ADRestrictDDNSFlag *bool `plist:"ADRestrictDDNSFlag,omitempty" json:"ADRestrictDDNSFlag,omitempty"`
	// An array of strings that represent the interfaces allowed for dynamic DNS updates, such
	// as en0 and en1.
	ADRestrictDDNS []string `plist:"ADRestrictDDNS,omitempty" json:"ADRestrictDDNS,omitempty"`
	// If `true`, the system enables the `ADTrustChangePassIntervalDays` key.
	ADTrustChangePassIntervalDaysFlag *bool `plist:"ADTrustChangePassIntervalDaysFlag,omitempty" json:"ADTrustChangePassIntervalDaysFlag,omitempty"`
	// The number of days before requiring a change of the computer trust account password. Set
	// to `0` to disable the feature.
	ADTrustChangePassIntervalDays *int64 `plist:"ADTrustChangePassIntervalDays,omitempty" json:"ADTrustChangePassIntervalDays,omitempty"`
}

DirectoryService: The payload that configures an Active Directory (AD) domain.

DirectoryService corresponds to mdm/profiles/com.apple.DirectoryService.managed.yaml (Directory Service).

func (*DirectoryService) PayloadTypeName

func (*DirectoryService) PayloadTypeName() string

PayloadTypeName returns "com.apple.DirectoryService.managed".

func (*DirectoryService) SchemaPath

func (*DirectoryService) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*DirectoryService) Validate

func (x *DirectoryService) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type Dock

type Dock struct {
	// The tile size. Values must be in the range from 16 to 128.
	Tilesize *int64 `plist:"tilesize,omitempty" json:"tilesize,omitempty"`
	// If `true`, locks the size slider.
	SizeImmutable *bool `plist:"size-immutable,omitempty" json:"size-immutable,omitempty"`
	// If `true`, enables magnification.
	Magnification *bool `plist:"magnification,omitempty" json:"magnification,omitempty"`
	// If `true`, locks magnification.
	MagnifyImmutable *bool `plist:"magnify-immutable,omitempty" json:"magnify-immutable,omitempty"`
	// The size of the largest magnification.
	Largesize *int64 `plist:"largesize,omitempty" json:"largesize,omitempty"`
	// If `true`, locks the magnification slider.
	MagsizeImmutable *bool `plist:"magsize-immutable,omitempty" json:"magsize-immutable,omitempty"`
	// The orientation of the Dock.
	Orientation *string `plist:"orientation,omitempty" json:"orientation,omitempty"`
	// If `true`, locks the position.
	PositionImmutable *bool `plist:"position-immutable,omitempty" json:"position-immutable,omitempty"`
	// The minimize effect.
	Mineffect *string `plist:"mineffect,omitempty" json:"mineffect,omitempty"`
	// If `true`, locks "Minimize windows using."
	MineffectImmutable *bool `plist:"mineffect-immutable,omitempty" json:"mineffect-immutable,omitempty"`
	// Set the "Prefer tabs when opening documents" to the provided value.
	Windowtabbing *string `plist:"windowtabbing,omitempty" json:"windowtabbing,omitempty"`
	// If `true`, disables "Prefer tabs when opening documents" checkbox.
	WindowtabbingImmutable *bool `plist:"windowtabbing-immutable,omitempty" json:"windowtabbing-immutable,omitempty"`
	// The behavior when the window's title bar is double-clicked.
	Dblclickbehavior *string `plist:"dblclickbehavior,omitempty" json:"dblclickbehavior,omitempty"`
	// If `true`, locks "Double-click a window's title bar."
	DblclickbehaviorImmutable *bool `plist:"dblclickbehavior-immutable,omitempty" json:"dblclickbehavior-immutable,omitempty"`
	// If `true`, enables "Minimize windows into application icon."
	MinimizeToApplication *bool `plist:"minimize-to-application,omitempty" json:"minimize-to-application,omitempty"`
	// If `true`, disables the "Minimize windows into application icon" checkbox.
	MinintoappImmutable *bool `plist:"minintoapp-immutable,omitempty" json:"minintoapp-immutable,omitempty"`
	// If `true`, enables "Animate opening applications."
	Launchanim *bool `plist:"launchanim,omitempty" json:"launchanim,omitempty"`
	// If `true`, locks "Animate opening applications."
	LaunchanimImmutable *bool `plist:"launchanim-immutable,omitempty" json:"launchanim-immutable,omitempty"`
	// If `true`, enables "Automatically hide and show the Dock."
	Autohide *bool `plist:"autohide,omitempty" json:"autohide,omitempty"`
	// If `true`, locks "Automatically hide."
	AutohideImmutable *bool `plist:"autohide-immutable,omitempty" json:"autohide-immutable,omitempty"`
	// If true, shows the process indicator.
	ShowProcessIndicators *bool `plist:"show-process-indicators,omitempty" json:"show-process-indicators,omitempty"`
	// If `true`, locks "Show indicators."
	ShowindicatorsImmutable *bool `plist:"showindicators-immutable,omitempty" json:"showindicators-immutable,omitempty"`
	// If `true`, enables "Show recent items."
	ShowRecents *bool `plist:"show-recents,omitempty" json:"show-recents,omitempty"`
	// If `true`, disables "Show recent applications" checkbox.
	ShowrecentsImmutable *bool `plist:"showrecents-immutable,omitempty" json:"showrecents-immutable,omitempty"`
	// If `true`, disables changes to the Dock.
	ContentsImmutable *bool `plist:"contents-immutable,omitempty" json:"contents-immutable,omitempty"`
	// One or more special folders that may be created at user login time and placed in the
	// Dock.
	MCXDockSpecialFolders []string `plist:"MCXDockSpecialFolders,omitempty" json:"MCXDockSpecialFolders,omitempty"`
	// If `true`, use the file in `/Library/Preferences/com.apple.dockfixup.plist` when a new
	// user or migrated user logs in. This option has no effect for existing users. Available
	// in macOS 10.12 and later. Only available on the device channel.
	AllowDockFixupOverride *bool `plist:"AllowDockFixupOverride,omitempty" json:"AllowDockFixupOverride,omitempty"`
	// If `true`, uses the `static-apps` and `static-others` dictionaries for the Dock and
	// ignores any items in the `persistent-apps` and `persistent-others` dictionaries. If
	// `false`, the contents are merged with the static items listed first.
	StaticOnly *bool `plist:"static-only,omitempty" json:"static-only,omitempty"`
	// An array of items located on the Documents side of the Dock and cannot be removed from
	// that location.
	StaticOthers []DockStaticItem `plist:"static-others,omitempty" json:"static-others,omitempty"`
	// An array of items located on the Applications side of the Dock and cannot be removed
	// from that location.
	StaticApps []DockStaticItem `plist:"static-apps,omitempty" json:"static-apps,omitempty"`
	// An array of items located on the Applications side of the Dock that can be removed from
	// the Dock.
	PersistentApps []DockStaticItem `plist:"persistent-apps,omitempty" json:"persistent-apps,omitempty"`
	// An array of items located on the Documents side of the Dock that can be removed from the
	// Dock.
	PersistentOthers []DockStaticItem `plist:"persistent-others,omitempty" json:"persistent-others,omitempty"`
}

Dock: The payload that configures the Dock.

Dock corresponds to mdm/profiles/com.apple.dock.yaml (Dock).

func (*Dock) PayloadTypeName

func (*Dock) PayloadTypeName() string

PayloadTypeName returns "com.apple.dock".

func (*Dock) SchemaPath

func (*Dock) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Dock) Validate

func (x *Dock) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type DockStaticItem

type DockStaticItem struct {
	// The information about the Dock item.
	TileData DockStaticItemTileData `plist:"tile-data,omitempty" json:"tile-data,omitempty"`
	// The type of tile.
	TileType string `plist:"tile-type" json:"tile-type"`
}

DockStaticItem: Items that are located on the Documents side of the Dock and cannot be removed from that location.

type DockStaticItemTileData

type DockStaticItemTileData struct {
	// The label of the Dock item.
	Label string `plist:"label" json:"label"`
	// The URL string.
	Url *string `plist:"url,omitempty" json:"url,omitempty"`
	// The type of tile:
	FileType int64 `plist:"file-type" json:"file-type"`
	// The data in a file. For Apple use only.
	FileData map[string]any `plist:"file-data,omitempty" json:"file-data,omitempty"`
}

DockStaticItemTileData: The information about the Dock item.

type Domains

type Domains struct {
	// An array of domains. Mail marks in red all email addresses that lack a suffix matching
	// any of these strings.
	EmailDomains []string `plist:"EmailDomains,omitempty" json:"EmailDomains,omitempty"`
	// An array of domains. The system considers URLs matching the patterns listed in this
	// property managed.
	WebDomains []string `plist:"WebDomains,omitempty" json:"WebDomains,omitempty"`
	// An array of domains. Users can only save passwords in Safari from URLs matching the
	// patterns listed here. This property doesn't disable the autofill feature itself.
	SafariPasswordAutoFillDomains []string `plist:"SafariPasswordAutoFillDomains,omitempty" json:"SafariPasswordAutoFillDomains,omitempty"`
	// An array of up to 10 strings. URLs matching the patterns listed here have relaxed
	// enforcement of cross-site tracking prevention.
	CrossSiteTrackingPreventionRelaxedDomains []string `plist:"CrossSiteTrackingPreventionRelaxedDomains,omitempty" json:"CrossSiteTrackingPreventionRelaxedDomains,omitempty"`
	// An array of up to 10 strings representing app bundle-ids. Apps matching the bundle-ids
	// listed here have relaxed enforcement of cross-site tracking prevention for the domains
	// listed in `CrossSiteTrackingPreventionRelaxedDomains`.
	CrossSiteTrackingPreventionRelaxedApps []string `plist:"CrossSiteTrackingPreventionRelaxedApps,omitempty" json:"CrossSiteTrackingPreventionRelaxedApps,omitempty"`
}

Domains: The payload that configures the domains under an organization's management.

Domains corresponds to mdm/profiles/com.apple.domains.yaml (Domains).

func (*Domains) PayloadTypeName

func (*Domains) PayloadTypeName() string

PayloadTypeName returns "com.apple.domains".

func (*Domains) SchemaPath

func (*Domains) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Domains) Validate

func (x *Domains) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type EducationConfiguration

type EducationConfiguration struct {
	// The organization's UUID identifier. This identifier can be any valid UUID. All teacher
	// and student devices that need to communicate with one another must have the same
	// organization UUID, particularly if they originated from different Device Enrollment
	// Programs.
	OrganizationUUID string `plist:"OrganizationUUID" json:"OrganizationUUID"`
	// The organization's display name. The system displays this name in the iOS login screen.
	OrganizationName string `plist:"OrganizationName" json:"OrganizationName"`
	// The UUID of an identity certificate payload within the same profile to use for
	// performing client authentication with other devices. This property supports PKCS12
	// certificates.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// The array of UUIDs referring to certificate payloads within the same profile that the
	// system uses to authorize leader peer certificate identities. This array needs to contain
	// all necessary certificates to validate the entire chain of trust. Leader certificates
	// needs to have the common name prefix leader, which is case insensitive.
	LeaderPayloadCertificateAnchorUUID []string `plist:"LeaderPayloadCertificateAnchorUUID,omitempty" json:"LeaderPayloadCertificateAnchorUUID,omitempty"`
	// The array of UUIDs referring to certificate payloads within the same profile that the
	// system uses to authorize group member peer certificate identities. This array must
	// contain all certificates needed to validate the entire chain of trust. Member
	// certificates must have the common name prefix member (case insensitive).
	MemberPayloadCertificateAnchorUUID []string `plist:"MemberPayloadCertificateAnchorUUID,omitempty" json:"MemberPayloadCertificateAnchorUUID,omitempty"`
	// The UUID of an identity certificate payload within the same profile that the system uses
	// to perform client authentication when fetching additional resources, such as student
	// images.
	ResourcePayloadCertificateUUID *string `plist:"ResourcePayloadCertificateUUID,omitempty" json:"ResourcePayloadCertificateUUID,omitempty"`
	// The unique string that identifies the user of this device within the organization.
	UserIdentifier string `plist:"UserIdentifier" json:"UserIdentifier"`
	// _For Shared iPad profiles:_ The array of dictionaries that defines which departments the
	// system displays in the Shared iPad login screen. If set, the system uses this key to
	// configure both Classroom and the Shared iPad login screen.
	Departments []EducationConfigurationDepartments `plist:"Departments,omitempty" json:"Departments,omitempty"`
	// _For Shared iPad profiles:_ The array of dictionaries that defines which groups the user
	// can select in the Login Window.
	Groups []EducationConfigurationGroups `plist:"Groups,omitempty" json:"Groups,omitempty"`
	// For Shared iPad profiles: The array of dictionaries that define the users that the
	// system displays in the iOS Login Window.
	Users []EducationConfigurationUsers `plist:"Users,omitempty" json:"Users,omitempty"`
	// _For leader/teacher profiles:_ The array of dictionaries that defines which device
	// groups the leader can assign devices to. Not included in member payloads.
	DeviceGroups []EducationConfigurationDeviceGroups `plist:"DeviceGroups,omitempty" json:"DeviceGroups,omitempty"`
	// If `true`, the system allows students enrolled in managed classes to modify their
	// teacher's permissions for screen observation on their device.
	ScreenObservationPermissionModificationAllowed *bool `` /* 128-byte string literal not displayed */
}

EducationConfiguration: The payload that configures the users, groups, and departments within an educational organization.

EducationConfiguration corresponds to mdm/profiles/com.apple.education.yaml (Education Configuration).

func (*EducationConfiguration) PayloadTypeName

func (*EducationConfiguration) PayloadTypeName() string

PayloadTypeName returns "com.apple.education".

func (*EducationConfiguration) SchemaPath

func (*EducationConfiguration) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*EducationConfiguration) Validate

func (x *EducationConfiguration) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type EducationConfigurationDepartments

type EducationConfigurationDepartments struct {
	// The display name of the department.
	Name string `plist:"Name" json:"Name"`
	// The group beacon identifiers that are members of this department.
	GroupBeaconIDs []int64 `plist:"GroupBeaconIDs,omitempty" json:"GroupBeaconIDs,omitempty"`
}

EducationConfigurationDepartments: A department in the organization.

type EducationConfigurationDeviceGroups

type EducationConfigurationDeviceGroups struct {
	// The unique identifier for the device group in the organization.
	Identifier string `plist:"Identifier" json:"Identifier"`
	// The name of the device group, which must be unique in the organization.
	Name string `plist:"Name" json:"Name"`
	// The serial numbers of the devices in the group.
	SerialNumbers []string `plist:"SerialNumbers,omitempty" json:"SerialNumbers,omitempty"`
}

EducationConfigurationDeviceGroups: A device group in the organization.

type EducationConfigurationGroups

type EducationConfigurationGroups struct {
	// An unsigned 16 bit integer specifying this group's unique beacon ID.
	BeaconID int64 `plist:"BeaconID" json:"BeaconID"`
	// The display name of the group.
	Name string `plist:"Name" json:"Name"`
	// The description of the group.
	Description *string `plist:"Description,omitempty" json:"Description,omitempty"`
	// Deprecated in iOS 9.3.1 and later. The URL of an image for the group.
	ImageURL *string `plist:"ImageURL,omitempty" json:"ImageURL,omitempty"`
	// The source that provided this group, such as SIS, or MDM.
	ConfigurationSource *string `plist:"ConfigurationSource,omitempty" json:"ConfigurationSource,omitempty"`
	// The user identifiers that are leaders of this group.
	LeaderIdentifiers []string `plist:"LeaderIdentifiers,omitempty" json:"LeaderIdentifiers,omitempty"`
	// The entries in the Users array that are members of the group.
	MemberIdentifiers []string `plist:"MemberIdentifiers,omitempty" json:"MemberIdentifiers,omitempty"`
	// The identifiers that refer to entries in the `DeviceGroups` array to which the
	// instructor can assign users from this class.
	DeviceGroupIdentifiers []string `plist:"DeviceGroupIdentifiers,omitempty" json:"DeviceGroupIdentifiers,omitempty"`
}

EducationConfigurationGroups: An array of dictionaries defining groups.

type EducationConfigurationUsers

type EducationConfigurationUsers struct {
	// The unique identifier for a user in the organization.
	Identifier string `plist:"Identifier" json:"Identifier"`
	// The name of the user.
	Name string `plist:"Name" json:"Name"`
	// The given name of the user.
	GivenName *string `plist:"GivenName,omitempty" json:"GivenName,omitempty"`
	// The family name of the user.
	FamilyName *string `plist:"FamilyName,omitempty" json:"FamilyName,omitempty"`
	// The user's phonetic given name. The system uses this name to sort users in the Classroom
	// app and the Shared iPad Login Screen.
	PhoneticGivenName *string `plist:"PhoneticGivenName,omitempty" json:"PhoneticGivenName,omitempty"`
	// The user's phonetic family name. The system uses this name to sort users in the
	// Classroom app and the Shared iPad login screen.
	PhoneticFamilyName *string `plist:"PhoneticFamilyName,omitempty" json:"PhoneticFamilyName,omitempty"`
	// A string that contains a URL pointing to an image of the user. The system displays this
	// image in the iOS login screen and in the Classroom app. The recommended resolution is
	// 256 x 256 pixels (512 x 512 pixels on a 2x device). The recommended formats are JPEG,
	// PNG, and TIFF. The system uses the `ResourcePayloadCertificateUUID` identity certificate
	// or the MDM client identity to perform authentication when fetching the image.
	ImageURL *string `plist:"ImageURL,omitempty" json:"ImageURL,omitempty"`
	// Deprecated in iOS 9.3.1 and later. The URL pointing to an image of the user. The system
	// uses the `ResourcePayloadCertificateUUID` identity certificate or the MDM client
	// identity to perform authentication when fetching the specified resource.
	FullScreenImageURL *string `plist:"FullScreenImageURL,omitempty" json:"FullScreenImageURL,omitempty"`
	// The Managed Apple Account for this user.
	AppleID *string `plist:"AppleID,omitempty" json:"AppleID,omitempty"`
	// The type of passcode UI to show when the user is at the Login Window.
	PasscodeType *string `plist:"PasscodeType,omitempty" json:"PasscodeType,omitempty"`
}

EducationConfigurationUsers: A user in the organization.

type EnergySaver

type EnergySaver struct {
	// The settings for a desktop computer.
	ComAppleEnergySaverDesktopACPower *EnergySaverPowerSettings `plist:"com.apple.EnergySaver.desktop.ACPower,omitempty" json:"com.apple.EnergySaver.desktop.ACPower,omitempty"`
	// The settings for a laptop computer using AC power.
	ComAppleEnergySaverPortableACPower *EnergySaverPowerSettings `plist:"com.apple.EnergySaver.portable.ACPower,omitempty" json:"com.apple.EnergySaver.portable.ACPower,omitempty"`
	// The settings for a laptop computer using battery power.
	ComAppleEnergySaverPortableBatteryPower *EnergySaverPowerSettings `plist:"com.apple.EnergySaver.portable.BatteryPower,omitempty" json:"com.apple.EnergySaver.portable.BatteryPower,omitempty"`
	// The schedule for turning a computer on and off.
	ComAppleEnergySaverDesktopSchedule *EnergySaverEnergySaverSchedule `plist:"com.apple.EnergySaver.desktop.Schedule,omitempty" json:"com.apple.EnergySaver.desktop.Schedule,omitempty"`
	// If `true`, disables sleep.
	SleepDisabled *bool `plist:"SleepDisabled,omitempty" json:"SleepDisabled,omitempty"`
}

EnergySaver: The payload that configures Energy Saver settings.

EnergySaver corresponds to mdm/profiles/com.apple.MCX(EnergySaver).yaml (Energy Saver).

func (*EnergySaver) PayloadTypeName

func (*EnergySaver) PayloadTypeName() string

PayloadTypeName returns "com.apple.MCX".

func (*EnergySaver) SchemaPath

func (*EnergySaver) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*EnergySaver) Validate

func (x *EnergySaver) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type EnergySaverEnergySaverSchedule

type EnergySaverEnergySaverSchedule struct {
	// The schedule for turning the device on.
	RepeatingPowerOn *EnergySaverRepeatingPowerItem `plist:"RepeatingPowerOn,omitempty" json:"RepeatingPowerOn,omitempty"`
	// The schedule for turning the device off.
	RepeatingPowerOff *EnergySaverRepeatingPowerItem `plist:"RepeatingPowerOff,omitempty" json:"RepeatingPowerOff,omitempty"`
}

EnergySaverEnergySaverSchedule: The schedule for turning a computer on and off.

type EnergySaverPowerSettings

type EnergySaverPowerSettings struct {
	// The display sleep time, in minutes. A value of 0 means never.
	DisplaySleepTimer *int64 `plist:"Display Sleep Timer,omitempty" json:"Display Sleep Timer,omitempty"`
	// The disk sleep time, in minutes. A value of 0 means never.
	DiskSleepTimer *int64 `plist:"Disk Sleep Timer,omitempty" json:"Disk Sleep Timer,omitempty"`
	// System sleep time, in minutes. A value of 0 means never.
	SystemSleepTimer *int64 `plist:"System Sleep Timer,omitempty" json:"System Sleep Timer,omitempty"`
	// May not be available on all systems.
	ReduceProcessorSpeed *int64 `plist:"Reduce Processor Speed,omitempty" json:"Reduce Processor Speed,omitempty"`
	// May not be available on all systems.
	DynamicPowerStep *int64 `plist:"Dynamic Power Step,omitempty" json:"Dynamic Power Step,omitempty"`
	// If `true`, enables "Wake for network access."
	WakeOnLAN *int64 `plist:"Wake on LAN,omitempty" json:"Wake on LAN,omitempty"`
	// If `true`, enables "Wake for modem ring."
	WakeOnModemRing *int64 `plist:"Wake On Modem Ring,omitempty" json:"Wake On Modem Ring,omitempty"`
	// If `true`, enables "Start up automatically after a power failure."
	AutomaticRestartOnPowerLoss *int64 `plist:"Automatic Restart On Power Loss,omitempty" json:"Automatic Restart On Power Loss,omitempty"`
}

EnergySaverPowerSettings: The settings for a desktop computer.

type EnergySaverRepeatingPowerItem

type EnergySaverRepeatingPowerItem struct {
	// The type of action defined by this schedule.
	Eventtype string `plist:"eventtype" json:"eventtype"`
	// One or more days of the week in an unsigned integer bitmap:
	Weekdays *int64 `plist:"weekdays,omitempty" json:"weekdays,omitempty"`
	// The time, in minutes, since midnight.
	Time *int64 `plist:"time,omitempty" json:"time,omitempty"`
}

EnergySaverRepeatingPowerItem: The schedule for turning the device on.

type Entry

type Entry struct {
	// ID is the wire identifier: RequestType, MessageType, PayloadType,
	// DeclarationType, StatusItemType, error code, or type name.
	ID string
	// Schema is the YAML path in apple/device-management.
	Schema string
	Title  string
	// New returns a zero value of the type as Payload.
	New func() Payload
	// NewResponse returns a zero response value, or nil when the schema
	// defines no response keys.
	NewResponse func() any
}

Entry describes one schema in the Registry.

func ByID

func ByID(id string) []Entry

ByID returns every entry with the given wire identifier, sorted by type name.

type ExchangeActiveSync

type ExchangeActiveSync struct {
	// The full email address for the account. If not present in the payload, the device
	// prompts for this string during profile installation.
	EmailAddress *string `plist:"EmailAddress,omitempty" json:"EmailAddress,omitempty"`
	// The Exchange server host name or IP address.
	Host *string `plist:"Host,omitempty" json:"Host,omitempty"`
	// If `true`, the system enables SSL for authentication.
	SSL *bool `plist:"SSL,omitempty" json:"SSL,omitempty"`
	// If `true`, enables OAuth for authentication. If enabled, don't specify a password.
	OAuth *bool `plist:"OAuth,omitempty" json:"OAuth,omitempty"`
	// This user name for this Exchange account. Required for noninteractive installations like
	// MDM in iOS.
	UserName *string `plist:"UserName,omitempty" json:"UserName,omitempty"`
	// The password of the account. Use only with encrypted profiles.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// The `.p12` identity certificate in NSData blob format, for accounts that allow
	// authentication via certificate.
	Certificate []byte `plist:"Certificate,omitempty" json:"Certificate,omitempty"`
	// The name or description of the certificate.
	CertificateName *string `plist:"CertificateName,omitempty" json:"CertificateName,omitempty"`
	// The password necessary for the `.p12` identity certificate. Used with mandatory
	// encryption of profiles.
	CertificatePassword *string `plist:"CertificatePassword,omitempty" json:"CertificatePassword,omitempty"`
	// If `true`, the system prevents moving messages from out of this email account into
	// another account. This setting also prevents forwarding or replying from an account other
	// than the recipient of the message.
	PreventMove *bool `plist:"PreventMove,omitempty" json:"PreventMove,omitempty"`
	// If `true`, prevents this account from sending mail in any app other than the Apple Mail
	// app.
	PreventAppSheet *bool `plist:"PreventAppSheet,omitempty" json:"PreventAppSheet,omitempty"`
	// The UUID of the certificate payload within the same profile to use for the identity
	// credential. If this field is present, the Certificate field isn't used.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// If `true`, the system enables S/MIME encryption. In iOS 10.0 and later, this key is
	// ignored. Use `SMIMESigningEnabled` instead.
	SMIMEEnabled *bool `plist:"SMIMEEnabled,omitempty" json:"SMIMEEnabled,omitempty"`
	// If `true`, the system enables S/MIME signing for this account. Available in iOS 10.0 and
	// later.
	SMIMESigningEnabled *bool `plist:"SMIMESigningEnabled,omitempty" json:"SMIMESigningEnabled,omitempty"`
	// The UUID of the identity certificate used to sign messages sent from this account.
	SMIMESigningCertificateUUID *string `plist:"SMIMESigningCertificateUUID,omitempty" json:"SMIMESigningCertificateUUID,omitempty"`
	// If `true`, the system enables S/MIME encryption for this account. Available in iOS 10.0
	// and later. As of iOS 12.0, this key is deprecated. Use `SMIMEEncryptByDefault` instead.
	SMIMEEncryptionEnabled *bool `plist:"SMIMEEncryptionEnabled,omitempty" json:"SMIMEEncryptionEnabled,omitempty"`
	// The payload UUID of the identity certificate used to decrypt messages sent to this
	// account. The system attaches the public certificate to outgoing mail to allow the user
	// to receive encrypted mail. When the user sends encrypted mail, the system uses the
	// public certificate to encrypt the copy of the mail in the user's Sent mailbox.
	SMIMEEncryptionCertificateUUID *string `plist:"SMIMEEncryptionCertificateUUID,omitempty" json:"SMIMEEncryptionCertificateUUID,omitempty"`
	// If `true`, the system displays the per-message encryption switch in the Mail Compose UI.
	SMIMEEnablePerMessageSwitch *bool `plist:"SMIMEEnablePerMessageSwitch,omitempty" json:"SMIMEEnablePerMessageSwitch,omitempty"`
	// If `true`, the system excludes this account from Recent Addresses syncing.
	DisableMailRecentsSyncing *bool `plist:"disableMailRecentsSyncing,omitempty" json:"disableMailRecentsSyncing,omitempty"`
	// The number of days in the past to sync mail on the device.
	MailNumberOfPastDaysToSync *int64 `plist:"MailNumberOfPastDaysToSync,omitempty" json:"MailNumberOfPastDaysToSync,omitempty"`
	// The value of the `X-Apple-Config-Magic` header in each EAS HTTP request.
	HeaderMagic *string `plist:"HeaderMagic,omitempty" json:"HeaderMagic,omitempty"`
	// The communication service handler rules for this account.
	CommunicationServiceRules *ExchangeActiveSyncCommunicationServiceRules `plist:"CommunicationServiceRules,omitempty" json:"CommunicationServiceRules,omitempty"`
	// If `true`, the system enables this account to use Mail Drop.
	AllowMailDrop *bool `plist:"allowMailDrop,omitempty" json:"allowMailDrop,omitempty"`
	// If `true`, the user can turn S/MIME signing on or off in Settings. Available in iOS 12.0
	// and later.
	SMIMESigningUserOverrideable *bool `plist:"SMIMESigningUserOverrideable,omitempty" json:"SMIMESigningUserOverrideable,omitempty"`
	// If `true`, the user can select the signing identity. Available in iOS 12.0 and later.
	SMIMESigningCertificateUUIDUserOverrideable *bool `plist:"SMIMESigningCertificateUUIDUserOverrideable,omitempty" json:"SMIMESigningCertificateUUIDUserOverrideable,omitempty"`
	// If `true`, the system enables S/MIME encryption by default. If
	// `SMIMEEnableEncryptionPerMessageSwitch` is `false`, the user can't change this default.
	// Available in iOS 12.0 and later.
	SMIMEEncryptByDefault *bool `plist:"SMIMEEncryptByDefault,omitempty" json:"SMIMEEncryptByDefault,omitempty"`
	// If `true`, the system enables encryption by default and the user can't change it.
	// Available in iOS 12.0 and later.
	SMIMEEncryptByDefaultUserOverrideable *bool `plist:"SMIMEEncryptByDefaultUserOverrideable,omitempty" json:"SMIMEEncryptByDefaultUserOverrideable,omitempty"`
	// If `true`, the user can select the S/MIME encryption identity, and encryption is
	// on.Available in iOS 12.0 and later.
	SMIMEEncryptionCertificateUUIDUserOverrideable *bool `` /* 128-byte string literal not displayed */
	// If `true`, the system displays the per-message encryption switch in the Mail Compose UI.
	// Available in iOS 12.0 and later.
	SMIMEEnableEncryptionPerMessageSwitch *bool `plist:"SMIMEEnableEncryptionPerMessageSwitch,omitempty" json:"SMIMEEnableEncryptionPerMessageSwitch,omitempty"`
	// If `false`, the system disables the Mail service for this account. The user can reenable
	// Mail service in Settings unless `EnableMailUserOverridable` is `false`.
	EnableMail *bool `plist:"EnableMail,omitempty" json:"EnableMail,omitempty"`
	// If `false`, the system disables the Contacts service for this account. The user can
	// reenable Contacts service in Settings unless `EnableContactsUserOverridable` is `false`.
	EnableContacts *bool `plist:"EnableContacts,omitempty" json:"EnableContacts,omitempty"`
	// If `false`, the system disables the Calendars service for this account. The user can
	// reenable Calendars service in Settings unless `EnableCalendarsUserOverridable` is
	// `false`.
	EnableCalendars *bool `plist:"EnableCalendars,omitempty" json:"EnableCalendars,omitempty"`
	// If `false`, the system disables the Reminders service for this account. The user can
	// reenable Reminders service in Settings unless `EnableRemindersUserOverridable` is
	// `false`.
	EnableReminders *bool `plist:"EnableReminders,omitempty" json:"EnableReminders,omitempty"`
	// If `false`, the system disables the Notes service for this account. The user can
	// reenable Notes service in Settings unless `EnableNotesUserOverridable` is `false`.
	EnableNotes *bool `plist:"EnableNotes,omitempty" json:"EnableNotes,omitempty"`
	// If `false`, the system prevents the user from changing the state of the Mail service for
	// this account in Settings.
	EnableMailUserOverridable *bool `plist:"EnableMailUserOverridable,omitempty" json:"EnableMailUserOverridable,omitempty"`
	// If `false`, the system prevents the user from changing the state of the Contacts service
	// for this account in Settings.
	EnableContactsUserOverridable *bool `plist:"EnableContactsUserOverridable,omitempty" json:"EnableContactsUserOverridable,omitempty"`
	// If `false`, the system prevents the user from changing the state of the Calendars
	// service for this account in Settings.
	EnableCalendarsUserOverridable *bool `plist:"EnableCalendarsUserOverridable,omitempty" json:"EnableCalendarsUserOverridable,omitempty"`
	// If `false`, the system prevents the user from changing the state of the Reminders
	// service for this account in Settings.
	EnableRemindersUserOverridable *bool `plist:"EnableRemindersUserOverridable,omitempty" json:"EnableRemindersUserOverridable,omitempty"`
	// If `false`, prevents the user from changing the state of the Notes service for this
	// account in Settings.
	EnableNotesUserOverridable *bool `plist:"EnableNotesUserOverridable,omitempty" json:"EnableNotesUserOverridable,omitempty"`
	// The URL that this account should use for signing in through OAuth. Ignored unless
	// `OAuth` is `true`. If you specify this URL, auto-discovery isn't used for this account,
	// so you need to also specify a host.
	OAuthSignInURL *string `plist:"OAuthSignInURL,omitempty" json:"OAuthSignInURL,omitempty"`
	// The URL that this account should use for token requests through OAuth. Ignored unless
	// `OAuth` is `true`.
	OAuthTokenRequestURL *string `plist:"OAuthTokenRequestURL,omitempty" json:"OAuthTokenRequestURL,omitempty"`
	// If `true`, the system overrides the previous user/EAS password with the new EAS password
	// in the payload. Available in iOS 14 and later.
	OverridePreviousPassword *bool `plist:"OverridePreviousPassword,omitempty" json:"OverridePreviousPassword,omitempty"`
	// The VPNUUID of the per-app VPN the account uses for network communication. Available in
	// iOS 14 and later.
	VPNUUID *string `plist:"VPNUUID,omitempty" json:"VPNUUID,omitempty"`
}

ExchangeActiveSync: The payload that configures Exchange ActiveSync accounts.

ExchangeActiveSync corresponds to mdm/profiles/com.apple.eas.account.yaml (Exchange ActiveSync).

func (*ExchangeActiveSync) PayloadTypeName

func (*ExchangeActiveSync) PayloadTypeName() string

PayloadTypeName returns "com.apple.eas.account".

func (*ExchangeActiveSync) SchemaPath

func (*ExchangeActiveSync) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ExchangeActiveSync) Validate

func (x *ExchangeActiveSync) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ExchangeActiveSyncCommunicationServiceRules

type ExchangeActiveSyncCommunicationServiceRules struct {
	// The default handlers to use for contacts from this account.
	DefaultServiceHandlers *ExchangeActiveSyncCommunicationServiceRulesDefaultServiceHandlers `plist:"DefaultServiceHandlers,omitempty" json:"DefaultServiceHandlers,omitempty"`
}

ExchangeActiveSyncCommunicationServiceRules: The communication service handler rules for this account.

type ExchangeActiveSyncCommunicationServiceRulesDefaultServiceHandlers

type ExchangeActiveSyncCommunicationServiceRulesDefaultServiceHandlers struct {
	// The bundle identifier of the default application to use for audio calls made to contacts
	// from this account.
	AudioCall *string `plist:"AudioCall,omitempty" json:"AudioCall,omitempty"`
}

ExchangeActiveSyncCommunicationServiceRulesDefaultServiceHandlers: The default handlers to use for contacts from this account.

type ExchangeWebServices

type ExchangeWebServices struct {
	// The full email address for the account. If the email address string isn't present in the
	// payload, the device prompts for it during profile installation.
	EmailAddress *string `plist:"EmailAddress,omitempty" json:"EmailAddress,omitempty"`
	// The Exchange server host name or IP address. Ignored if using OAuth.
	Host *string `plist:"Host,omitempty" json:"Host,omitempty"`
	// If `true`, the system enables SSL.
	SSL *bool `plist:"SSL,omitempty" json:"SSL,omitempty"`
	// If `true`, the system enables OAuth for authentication. Don't specify a password if
	// `OAuth` is `true`. Available in macOS 10.14 and later
	OAuth *bool `plist:"OAuth,omitempty" json:"OAuth,omitempty"`
	// The URL to load into a web view for authentication through OAuth when autodiscovery
	// isn't used. This setting requires a `Host` value.
	OAuthSignInURL *string `plist:"OAuthSignInURL,omitempty" json:"OAuthSignInURL,omitempty"`
	// The user name for this Exchange account. Required for noninteractive installation, such
	// as through MDM. If missing, the system prompts the user for it during interactive
	// profile installation.
	UserName *string `plist:"UserName,omitempty" json:"UserName,omitempty"`
	// The password of the account. Use only with encrypted profiles.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// The UUID of the certificate payload within the same profile to use for the identity
	// credential. Supported on macOS 10.12 or later.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// The UUID of the certificate payload within the same profile to use for the identity
	// credential. Supported on macOS 10.11 or later. On macOS 10.12 or later use the
	// PayloadCertificateUUID.
	AuthenticationCertificateUUID *string `plist:"AuthenticationCertificateUUID,omitempty" json:"AuthenticationCertificateUUID,omitempty"`
	// If `true`, the system enables Mail Drop.
	AllowMailDrop *bool `plist:"allowMailDrop,omitempty" json:"allowMailDrop,omitempty"`
	// The server path.
	Path *string `plist:"Path,omitempty" json:"Path,omitempty"`
	// The server port number.
	Port *int64 `plist:"Port,omitempty" json:"Port,omitempty"`
	// The external server address.
	ExternalHost *string `plist:"ExternalHost,omitempty" json:"ExternalHost,omitempty"`
	// If `true`, the system enables SSL for connections to the external server.
	ExternalSSL *bool `plist:"ExternalSSL,omitempty" json:"ExternalSSL,omitempty"`
	// The external server path.
	ExternalPath *string `plist:"ExternalPath,omitempty" json:"ExternalPath,omitempty"`
	// The external server port number.
	ExternalPort *int64 `plist:"ExternalPort,omitempty" json:"ExternalPort,omitempty"`
}

ExchangeWebServices: The payload that configures an Exchange Web Services accounts.

ExchangeWebServices corresponds to mdm/profiles/com.apple.ews.account.yaml (Exchange Web Services).

func (*ExchangeWebServices) PayloadTypeName

func (*ExchangeWebServices) PayloadTypeName() string

PayloadTypeName returns "com.apple.ews.account".

func (*ExchangeWebServices) SchemaPath

func (*ExchangeWebServices) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ExchangeWebServices) Validate

func (x *ExchangeWebServices) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ExtensibleSingleSignOn

type ExtensibleSingleSignOn struct {
	// The bundle identifier of the app extension that performs SSO for the specified URLs.
	ExtensionIdentifier string `plist:"ExtensionIdentifier" json:"ExtensionIdentifier"`
	// The team identifier of the app extension. This key is required on macOS and ignored
	// elsewhere.
	TeamIdentifier *string `plist:"TeamIdentifier,omitempty" json:"TeamIdentifier,omitempty"`
	// The type of SSO.
	Type string `plist:"Type" json:"Type"`
	// The realm name for `Credential` payloads. Use proper capitalization for this value.
	// Ignored for `Redirect` payloads.
	Realm *string `plist:"Realm,omitempty" json:"Realm,omitempty"`
	// A dictionary of arbitrary data passed through to the app extension.
	ExtensionData map[string]any `plist:"ExtensionData,omitempty" json:"ExtensionData,omitempty"`
	// An array of URL prefixes of identity providers where the app extension performs SSO.
	URLs []string `plist:"URLs,omitempty" json:"URLs,omitempty"`
	// An array of host or domain names that apps can authenticate through the app extension.
	Hosts []string `plist:"Hosts,omitempty" json:"Hosts,omitempty"`
	// If set to `Cancel`, the system cancels authentication requests when the screen is
	// locked. If set to `DoNotHandle`, the request continues without SSO instead. This doesn't
	// apply to requests where `userInterfaceEnabled` is `false`, or for background
	// `URLSession` requests. Available in iOS 15 and later, and macOS 12 and later.
	ScreenLockedBehavior *string `plist:"ScreenLockedBehavior,omitempty" json:"ScreenLockedBehavior,omitempty"`
	// An array of bundle identifiers of apps that don't use SSO provided by this extension.
	// Available in iOS 15 and later, and macOS 12 and later.
	DeniedBundleIdentifiers []string `plist:"DeniedBundleIdentifiers,omitempty" json:"DeniedBundleIdentifiers,omitempty"`
	// The Platform SSO authentication method the extension uses. Requires that the SSO
	// Extension also supports the method. Available in macOS 13 and later, and deprecated in
	// macOS 14.
	AuthenticationMethod *string `plist:"AuthenticationMethod,omitempty" json:"AuthenticationMethod,omitempty"`
	// The token this device uses for registration with Platform SSO. Use it for silent
	// registration with the Identity Provider. Requires that `AuthenticationMethod` in
	// `PlatformSSO` isn't empty. Available in macOS 13 and later.
	RegistrationToken *string `plist:"RegistrationToken,omitempty" json:"RegistrationToken,omitempty"`
	// The dictionary to configure Platform SSO. Requires `Type` to be set to `Redirect`.
	PlatformSSO *ExtensibleSingleSignOnPlatformSSO `plist:"PlatformSSO,omitempty" json:"PlatformSSO,omitempty"`
}

ExtensibleSingleSignOn: The payload that configures an app extension that performs single sign-on (SSO).

ExtensibleSingleSignOn corresponds to mdm/profiles/com.apple.extensiblesso.yaml (Extensible Single Sign-On).

func (*ExtensibleSingleSignOn) PayloadTypeName

func (*ExtensibleSingleSignOn) PayloadTypeName() string

PayloadTypeName returns "com.apple.extensiblesso".

func (*ExtensibleSingleSignOn) SchemaPath

func (*ExtensibleSingleSignOn) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ExtensibleSingleSignOn) Validate

func (x *ExtensibleSingleSignOn) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ExtensibleSingleSignOnKerberos

type ExtensibleSingleSignOnKerberos struct {
	// Set this to `com.apple.AppSSOKerberos.KerberosExtension` for this extension.
	ExtensionIdentifier string `plist:"ExtensionIdentifier" json:"ExtensionIdentifier"`
	// Set this to `apple` for this extension.
	TeamIdentifier string `plist:"TeamIdentifier" json:"TeamIdentifier"`
	// Set this to `Credential` for this extension.
	Type string `plist:"Type" json:"Type"`
	// The Kerberos realm. Use proper capitalization for this value. If in an Active Directory
	// forest, this is the realm where the user logs in.
	Realm string `plist:"Realm" json:"Realm"`
	// This is the dictionary used by the Apple built-in Kerberos extension.
	ExtensionData *ExtensibleSingleSignOnKerberosExtensionData `plist:"ExtensionData,omitempty" json:"ExtensionData,omitempty"`
	// One or more host or domain names for which the app extension performs SSO.
	Hosts []string `plist:"Hosts,omitempty" json:"Hosts,omitempty"`
}

ExtensibleSingleSignOnKerberos: The payload that configures an app extension that performs single sign-on with the Kerberos extension.

ExtensibleSingleSignOnKerberos corresponds to mdm/profiles/com.apple.extensiblesso(kerberos).yaml (Extensible Single Sign-On (Kerberos)).

func (*ExtensibleSingleSignOnKerberos) PayloadTypeName

func (*ExtensibleSingleSignOnKerberos) PayloadTypeName() string

PayloadTypeName returns "com.apple.extensiblesso".

func (*ExtensibleSingleSignOnKerberos) SchemaPath

func (*ExtensibleSingleSignOnKerberos) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ExtensibleSingleSignOnKerberos) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ExtensibleSingleSignOnKerberosExtensionData

type ExtensibleSingleSignOnKerberosExtensionData struct {
	// The GSS name of the Kerberos cache to use. Rarely set by an administrator.
	CacheName *string `plist:"cacheName,omitempty" json:"cacheName,omitempty"`
	// The principal (username) to use. You don't need to include the realm.
	PrincipalName *string `plist:"principalName,omitempty" json:"principalName,omitempty"`
	// The name of the Active Directory site the Kerberos extension should use. Most
	// administrators don't need to modify this value, as the Kerberos extension can normally
	// find the site automatically.
	SiteCode *string `plist:"siteCode,omitempty" json:"siteCode,omitempty"`
	// The PayloadUUID of a PKINIT certificate.
	CertificateUUID *string `plist:"certificateUUID,omitempty" json:"certificateUUID,omitempty"`
	// If `false`, the Kerberos extension doesn't automatically use LDAP and DNS to determine
	// its AD site name.
	UseSiteAutoDiscovery *bool `plist:"useSiteAutoDiscovery,omitempty" json:"useSiteAutoDiscovery,omitempty"`
	// A list of bundle IDs allowed to access the ticket-granting ticket (TGT).
	CredentialBundleIdACL []string `plist:"credentialBundleIdACL,omitempty" json:"credentialBundleIdACL,omitempty"`
	// If `true`, the Kerberos extension allows only managed apps to access and use the
	// credential. This is in addition to the `credentialBundleIDACL`, if you specify that
	// value. Available in iOS 14 and later, and macOS 12 and later.
	IncludeManagedAppsInBundleIdACL *bool `plist:"includeManagedAppsInBundleIdACL,omitempty" json:"includeManagedAppsInBundleIdACL,omitempty"`
	// If `true`, the Kerberos extension allows the standard Kerberos utilities including
	// `TicketViewer` and `klist` to access and use the credential. This is in addition to
	// `includeManagedAppsInBundleIdACL` or the `credentialBundleIdACL`, if you specify those
	// values. Available in macOS 12 and later.
	IncludeKerberosAppsInBundleIdACL *bool `plist:"includeKerberosAppsInBundleIdACL,omitempty" json:"includeKerberosAppsInBundleIdACL,omitempty"`
	// A custom domain-realm mapping for Kerberos. The system uses this when the DNS name of
	// hosts doesn't match the realm name. Most administrators don't need to customize this.
	DomainRealmMapping *ExtensibleSingleSignOnKerberosExtensionDataDomainRealmMapping `plist:"domainRealmMapping,omitempty" json:"domainRealmMapping,omitempty"`
	// Specifies whether this is the default realm if there's more than one Kerberos extension
	// configuration.
	IsDefaultRealm *bool `plist:"isDefaultRealm,omitempty" json:"isDefaultRealm,omitempty"`
	// The custom user name label used in the Kerberos extension instead of "Username," such as
	// "Company ID". Available in macOS 11 and later.
	CustomUsernameLabel *string `plist:"customUsernameLabel,omitempty" json:"customUsernameLabel,omitempty"`
	// The text to display to the user at the bottom of the Kerberos Login Window. You can also
	// use this to display help information or disclaimer text. Available in iOS 14 and later,
	// and macOS 11 and later.
	HelpText *string `plist:"helpText,omitempty" json:"helpText,omitempty"`
	// If `false`, the system disables password changes. Available in macOS 10.15 and later.
	AllowPasswordChange *bool `plist:"allowPasswordChange,omitempty" json:"allowPasswordChange,omitempty"`
	// If `false`, the system doesn't allow saving passwords in the keychain.
	AllowAutomaticLogin *bool `plist:"allowAutomaticLogin,omitempty" json:"allowAutomaticLogin,omitempty"`
	// If `true`, the system requires the user to provide Touch ID, Face ID or their passcode
	// to access the keychain entry.
	RequireUserPresence *bool `plist:"requireUserPresence,omitempty" json:"requireUserPresence,omitempty"`
	// The number of days that the system allows using passwords on this domain. For most
	// domains, this calculation is automatic. Available in macOS 10.15 and later.
	PwExpireOverride *int64 `plist:"pwExpireOverride,omitempty" json:"pwExpireOverride,omitempty"`
	// The number of days prior to password expiration when the system sends a notification of
	// password expiration to the user. Available in macOS 10.15 and later.
	PwNotificationDays *int64 `plist:"pwNotificationDays,omitempty" json:"pwNotificationDays,omitempty"`
	// The minimum length of passwords on the domain.Available in macOS 10.15 and later.
	PwReqLength *int64 `plist:"pwReqLength,omitempty" json:"pwReqLength,omitempty"`
	// If `true`, the system requires passwords to meet Active Directory's definition of
	// "complex". Available in macOS 10.15 and later.
	PwReqComplexity *bool `plist:"pwReqComplexity,omitempty" json:"pwReqComplexity,omitempty"`
	// The minimum age of passwords before the system allows changing them on this domain.
	// Available in macOS 10.15 and later.
	PwReqMinAge *int64 `plist:"pwReqMinAge,omitempty" json:"pwReqMinAge,omitempty"`
	// The number of prior passwords that the system disallows reuse on this domain. Available
	// in macOS 10.15 and later.
	PwReqHistory *int64 `plist:"pwReqHistory,omitempty" json:"pwReqHistory,omitempty"`
	// The text version of the domain's password requirements. Only for use if
	// `pwReqComplexity` or `pwReqLength` aren't specified. Available in macOS 10.15 and later.
	PwReqText *string `plist:"pwReqText,omitempty" json:"pwReqText,omitempty"`
	// The RTF file formatted version of the domain's password requirements. Only for use if
	// `pwReqComplexity` or `pwReqLength` aren't specified. Available in macOS 15 and later.
	PwReqRTFData []byte `plist:"pwReqRTFData,omitempty" json:"pwReqRTFData,omitempty"`
	// This URL will launch in the user's default web browser when they initiate a password
	// change. Available in macOS 10.15 and later.
	PwChangeURL *string `plist:"pwChangeURL,omitempty" json:"pwChangeURL,omitempty"`
	// If `false`, the system disables password sync. Note that this will not work if the user
	// is logged in with a mobile account. Available in macOS 10.15 and later.
	SyncLocalPassword *bool `plist:"syncLocalPassword,omitempty" json:"syncLocalPassword,omitempty"`
	// The time, in seconds, required to replicate changes in the Active Directory domain. The
	// Kerberos extension uses this when checking password age after a change. Available in
	// macOS 11 and later.
	ReplicationTime *int64 `plist:"replicationTime,omitempty" json:"replicationTime,omitempty"`
	// If `true`, the system doesn't prompt the user to setup the Kerberos extension until
	// either the administrator enables it with the `app-sso` tool or the system receives a
	// Kerberos challenge. Available in macOS 11 and later.
	DelayUserSetup *bool `plist:"delayUserSetup,omitempty" json:"delayUserSetup,omitempty"`
	// If `false`, the system requests the credential on the next matching Kerberos challenge
	// or network state change. If the credential is expired or missing, the system creates a
	// new one. Available in macOS 11 and later.
	MonitorCredentialsCache *bool `plist:"monitorCredentialsCache,omitempty" json:"monitorCredentialsCache,omitempty"`
	// Require that LDAP connections use TLS. Available in macOS 11 and later.
	RequireTLSForLDAP *bool `plist:"requireTLSForLDAP,omitempty" json:"requireTLSForLDAP,omitempty"`
	// This setting affects how other processes use the Kerberos Extension credential. Allowed
	// values:
	CredentialUseMode *string `plist:"credentialUseMode,omitempty" json:"credentialUseMode,omitempty"`
	// The ordered list of preferred Key Distribution Centers (KDCs) to use for Kerberos
	// traffic. Use this if the servers aren't discoverable through DNS. If the servers are
	// specified, then the system uses them for both connectivity checks and attempts to use
	// them first for Kerberos traffic. If the servers don't respond, the device falls back to
	// DNS discovery. Format each entry the same as it would be in a `krb5.conf` file, for
	// example:
	PreferredKDCs []string `plist:"preferredKDCs,omitempty" json:"preferredKDCs,omitempty"`
	// If `true`, the system requires this configuration uses a TGT from Platform SSO instead
	// of requesting a new one. Available in macOS 13 and later.
	UsePlatformSSOTGT *bool `plist:"usePlatformSSOTGT,omitempty" json:"usePlatformSSOTGT,omitempty"`
	// If `true` and `usePlatformSSOTGT` is `true`, the system allows the user to manually sign
	// in. Available in macOS 13 and later.
	AllowPlatformSSOAuthFallback *bool `plist:"allowPlatformSSOAuthFallback,omitempty" json:"allowPlatformSSOAuthFallback,omitempty"`
	// If `true`, the Kerberos Extension handles Kerberos requests only. It doesn't check for
	// password expiration, show the password expiration in the menu, check for external
	// password changes, perform password sync, or retrieve the home directory. Available in
	// macOS 13 and later.
	PerformKerberosOnly *bool `plist:"performKerberosOnly,omitempty" json:"performKerberosOnly,omitempty"`
	// A string with wildcards that can use used to filter the list of available SmartCards by
	// issuer. e.g "\*My CA2\*". If there is one remaining, it will be auto-selected. If there
	// more than one remaining, then the list is shorter. Available in macOS 15 and later.
	IdentityIssuerAutoSelectFilter *string `plist:"identityIssuerAutoSelectFilter,omitempty" json:"identityIssuerAutoSelectFilter,omitempty"`
	// If `true`, allow the user to switch the user interface to SmartCard mode. Available in
	// macOS 15 and later.
	AllowSmartCard *bool `plist:"allowSmartCard,omitempty" json:"allowSmartCard,omitempty"`
	// If `true`, allow the user to switch the user interface to Password mode. Available in
	// macOS 15 and later.
	AllowPassword *bool `plist:"allowPassword,omitempty" json:"allowPassword,omitempty"`
	// If `true`, the user interface will start in SmartCard mode. Available in macOS 15 and
	// later.
	StartInSmartCardMode *bool `plist:"startInSmartCardMode,omitempty" json:"startInSmartCardMode,omitempty"`
}

ExtensibleSingleSignOnKerberosExtensionData: This is the dictionary used by the Apple built-in Kerberos extension.

type ExtensibleSingleSignOnKerberosExtensionDataDomainRealmMapping

type ExtensibleSingleSignOnKerberosExtensionDataDomainRealmMapping struct {
	// The key should be the name of the realm, and the value is an array of DNS suffixes that
	// map to the realm.
	Realm []string `plist:"Realm,omitempty" json:"Realm,omitempty"`
}

ExtensibleSingleSignOnKerberosExtensionDataDomainRealmMapping: A custom domain-realm mapping for Kerberos. The system uses this when the DNS name of hosts doesn't match the realm name. Most administrators don't need to customize this.

type ExtensibleSingleSignOnPlatformSSO

type ExtensibleSingleSignOnPlatformSSO struct {
	// The Platform SSO authentication method to use with the extension. Requires that the SSO
	// Extension also support the method.
	AuthenticationMethod *string `plist:"AuthenticationMethod,omitempty" json:"AuthenticationMethod,omitempty"`
	// If `true`, the system uses the same signing and encryption keys for all users. Only
	// supported on the device channel.
	UseSharedDeviceKeys *bool `plist:"UseSharedDeviceKeys,omitempty" json:"UseSharedDeviceKeys,omitempty"`
	// The display name for the account in notifications and authentication requests.
	AccountDisplayName *string `plist:"AccountDisplayName,omitempty" json:"AccountDisplayName,omitempty"`
	// The duration, in seconds, until the system requires a full login instead of a refresh.
	// The default value is 64,800 (18 hours). The minimum value is 3600 (1 hour).
	LoginFrequency *int64 `plist:"LoginFrequency,omitempty" json:"LoginFrequency,omitempty"`
	// Enables creating users at the Login Window with an `AuthenticationMethod` of either
	// `Password` or `SmartCard`. Requires that `UseSharedDeviceKeys` is `true`.
	EnableCreateUserAtLogin *bool `plist:"EnableCreateUserAtLogin,omitempty" json:"EnableCreateUserAtLogin,omitempty"`
	// If `true`, the device uses Platform SSO to create the first user account on the Mac
	// during `Setup Assistant`.
	EnableCreateFirstUserDuringSetup *bool `plist:"EnableCreateFirstUserDuringSetup,omitempty" json:"EnableCreateFirstUserDuringSetup,omitempty"`
	// Enables using identity provider accounts at authorization prompts. Requires that
	// `UseSharedDeviceKeys` is `true`. The system assigns groups using `AdministratorGroups`,
	// `AdditionalGroups`, or `AuthorizationGroups`.
	EnableAuthorization *bool `plist:"EnableAuthorization,omitempty" json:"EnableAuthorization,omitempty"`
	// The attribute mapping to use when creating users, or for authorization.
	TokenToUserMapping *ExtensibleSingleSignOnPlatformSSOTokenToUserMapping `plist:"TokenToUserMapping,omitempty" json:"TokenToUserMapping,omitempty"`
	// The set of authentication methods to use for newly created accounts at login or during
	// `Setup Assistant`. The system uses `Password` and `SmartCard` if this key isn't present.
	NewUserAuthenticationMethods []string `plist:"NewUserAuthenticationMethods,omitempty" json:"NewUserAuthenticationMethods,omitempty"`
	// The permission to apply to newly created accounts at login. Allowed values:
	NewUserAuthorizationMode *string `plist:"NewUserAuthorizationMode,omitempty" json:"NewUserAuthorizationMode,omitempty"`
	// The permission to apply to an account each time the user authenticates. Allowed values:
	UserAuthorizationMode *string `plist:"UserAuthorizationMode,omitempty" json:"UserAuthorizationMode,omitempty"`
	// The list of groups to use for administrator access. The system requests membership
	// during authentication.
	AdministratorGroups []string `plist:"AdministratorGroups,omitempty" json:"AdministratorGroups,omitempty"`
	// The list of created groups that don't have administrator access.
	AdditionalGroups []string `plist:"AdditionalGroups,omitempty" json:"AdditionalGroups,omitempty"`
	// The pairing of Authorization Rights to group names. When using this, the system updates
	// the Authorization Right to use the group.
	AuthorizationGroups map[string]string `plist:"AuthorizationGroups,omitempty" json:"AuthorizationGroups,omitempty"`
	// The reader group identifier for use with the `AccessKey`. The value needs to match the
	// configured access key. Required if `NewUserAuthenticationMethods` contains `AccessKey`.
	AccessKeyReaderGroupIdentifier []byte `plist:"AccessKeyReaderGroupIdentifier,omitempty" json:"AccessKeyReaderGroupIdentifier,omitempty"`
	// The `PayloadUUID` of an identity payload to use as the `Terminal` identity of the access
	// key. The identity needs to be trusted by the access key. Required if
	// `NewUserAuthenticationMethods` includes `AccessKey`. Allowed identity payload types:
	AccessKeyTerminalIdentityUUID *string `plist:"AccessKeyTerminalIdentityUUID,omitempty" json:"AccessKeyTerminalIdentityUUID,omitempty"`
	// The `PayloadUUID` of a certificate payload for the issuer certificate of the `Terminal`
	// identity of the access key. Other specifications refer to the key as the "Reader CA
	// Public Key". The key must be an elliptic curve key. Required if
	// `NewUserAuthenticationMethods` includes `AccessKey`. The issuer of the Terminal identity
	// of the access key needs to match this certificate, otherwise the device fails the
	// authentication.
	AccessKeyReaderIssuerCertificateUUID *string `plist:"AccessKeyReaderIssuerCertificateUUID,omitempty" json:"AccessKeyReaderIssuerCertificateUUID,omitempty"`
	// If `true`, the system uses the access key in express mode, and doesn't require
	// authentication before use.
	AllowAccessKeyExpressMode *bool `plist:"AllowAccessKeyExpressMode,omitempty" json:"AllowAccessKeyExpressMode,omitempty"`
	// The policy to apply when using Platform SSO at FileVault unlock on a Mac with Apple
	// silicon. Applies when `AuthenticationMethod` is `Password`. Available in macOS 15 and
	// later.
	FileVaultPolicy []string `plist:"FileVaultPolicy,omitempty" json:"FileVaultPolicy,omitempty"`
	// The policy to apply when using Platform SSO at the Login Window. Applies when
	// `AuthenticationMethod` is `Password`. Available in macOS 15 and later.
	LoginPolicy []string `plist:"LoginPolicy,omitempty" json:"LoginPolicy,omitempty"`
	// The policy to apply when using Platform SSO at screensaver unlock. Applies when
	// `AuthenticationMethod` is `Password`. Available in macOS 15 and later.
	UnlockPolicy []string `plist:"UnlockPolicy,omitempty" json:"UnlockPolicy,omitempty"`
	// The amount of time after the last successful Platform SSO login for using a local
	// account password offline. Required when setting `AllowOfflineGracePeriod`. Available in
	// macOS 15 and later.
	OfflineGracePeriod *int64 `plist:"OfflineGracePeriod,omitempty" json:"OfflineGracePeriod,omitempty"`
	// The amount of time after receiving or updating a `FileVaultPolicy`, `LoginPolicy`, or
	// `UnlockPolicy` that the system can use unregistered local accounts. Required when
	// `AllowAuthenticationGracePeriod` is set. Available in macOS 15 and later.
	AuthenticationGracePeriod *int64 `plist:"AuthenticationGracePeriod,omitempty" json:"AuthenticationGracePeriod,omitempty"`
	// The list of local accounts that aren't subject to the `FileVaultPolicy`, `LoginPolicy`,
	// or `UnlockPolicy`. The accounts don't receive a prompt to register for Platform SSO.
	// Available in macOS 15 and later.
	NonPlatformSSOAccounts []string `plist:"NonPlatformSSOAccounts,omitempty" json:"NonPlatformSSOAccounts,omitempty"`
	// If `true`, the system includes the device UDID and serial number in Platform SSO
	// attestations.
	AllowDeviceIdentifiersInAttestation *bool `plist:"AllowDeviceIdentifiersInAttestation,omitempty" json:"AllowDeviceIdentifiersInAttestation,omitempty"`
	// If `true`, the system requests the user's profile picture from the SSO extension.
	SynchronizeProfilePicture *bool `plist:"SynchronizeProfilePicture,omitempty" json:"SynchronizeProfilePicture,omitempty"`
	// If `true`, the system uses a quicker Authenticated Guest Mode login to Mac behavior. The
	// system erases user data from only select locations in the user home directory after each
	// session completes. Once every eight hours the system erases the full user home directory
	// after a session completes. Turn this on for shared environments that have a high
	// frequency of short sessions.
	TemporarySessionQuickLogin *bool `plist:"TemporarySessionQuickLogin,omitempty" json:"TemporarySessionQuickLogin,omitempty"`
	// If `true`, the system enables the PlatformSSO registration process during Setup
	// Assistant on devices running macOS 26 and later. Set this key to `true` when configuring
	// PlatformSSO before enrollment using the `com.apple.psso.required` error response.
	EnableRegistrationDuringSetup *bool `plist:"EnableRegistrationDuringSetup,omitempty" json:"EnableRegistrationDuringSetup,omitempty"`
}

ExtensibleSingleSignOnPlatformSSO: The dictionary to configure Platform SSO. Requires `Type` to be set to `Redirect`.

type ExtensibleSingleSignOnPlatformSSOTokenToUserMapping

type ExtensibleSingleSignOnPlatformSSOTokenToUserMapping struct {
	// The claim name to use for the user's account name.
	AccountName *string `plist:"AccountName,omitempty" json:"AccountName,omitempty"`
	// The claim name to use for the user's full name.
	FullName *string `plist:"FullName,omitempty" json:"FullName,omitempty"`
}

ExtensibleSingleSignOnPlatformSSOTokenToUserMapping: The attribute mapping to use when creating users, or for authorization.

type FDEFileVault

type FDEFileVault struct {
	// Set to `On` to enable FileVault and set to `Off` to disable FileVault. Payloads set to
	// `On` sent through MDM need to either include full authentication information in the
	// payload or have the `Defer` option set to `true`. When `Defer` is `true`, the system
	// prompts for the authentication information when the user enables FileVault.
	Enable string `plist:"Enable" json:"Enable"`
	// If `true`, the system defers enabling FileVault until the designated user logs out. For
	// details, see `fdesetup(8)`. Only a local user or a mobile account user can enable
	// FileVault.
	Defer *bool `plist:"Defer,omitempty" json:"Defer,omitempty"`
	// If `true`, the system enables a prompt for missing user name or password fields.
	UserEntersMissingInfo *bool `plist:"UserEntersMissingInfo,omitempty" json:"UserEntersMissingInfo,omitempty"`
	// If `true`, the system creates a personal recovery key and displays it to the user.
	UseRecoveryKey *bool `plist:"UseRecoveryKey,omitempty" json:"UseRecoveryKey,omitempty"`
	// If `false`, the system prevents display of the personal recovery key to the user after
	// the system enables FileVault.
	ShowRecoveryKey *bool `plist:"ShowRecoveryKey,omitempty" json:"ShowRecoveryKey,omitempty"`
	// The path to the location of the recovery key and computer information property list.
	OutputPath *string `plist:"OutputPath,omitempty" json:"OutputPath,omitempty"`
	// The DER-encoded certificate data if the system creates an institutional recovery key.
	// This key isn't supported on a Mac with Apple silicon.
	Certificate []byte `plist:"Certificate,omitempty" json:"Certificate,omitempty"`
	// The UUID of the payload within the same profile containing the asymmetric recovery key
	// certificate payload.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// The user name of the Open Directory user to add to FileVault.
	Username *string `plist:"Username,omitempty" json:"Username,omitempty"`
	// The password of the Open Directory user to add to FileVault. Use the
	// `UserEntersMissingInfo` key to prompt for this information.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// If `true` and you don't include certificate information in this payload, the system uses
	// the keychain created at `/Library/Keychains/FileVaultMaster.keychain` when it adds the
	// institutional recovery key.
	UseKeychain *bool `plist:"UseKeychain,omitempty" json:"UseKeychain,omitempty"`
	// The maximum number of times users can bypass enabling FileVault before the system
	// requires the user to enable it to log in. If the value is `0`, the system requires the
	// user to enable FileVault the next time they attempt to log in. Set this key to `-1` to
	// disable this feature.
	DeferForceAtUserLoginMaxBypassAttempts *int64 `plist:"DeferForceAtUserLoginMaxBypassAttempts,omitempty" json:"DeferForceAtUserLoginMaxBypassAttempts,omitempty"`
	// If `true`, the system prevents requests to enable FileVault at user logout time.
	DeferDontAskAtUserLogout *bool `plist:"DeferDontAskAtUserLogout,omitempty" json:"DeferDontAskAtUserLogout,omitempty"`
	// If `true`, and installation of this payload occurs after enrolling with MDM in Setup
	// Assistant, the system requests Setup Assistant to enable FileVault at setup time.
	ForceEnableInSetupAssistant *bool `plist:"ForceEnableInSetupAssistant,omitempty" json:"ForceEnableInSetupAssistant,omitempty"`
}

FDEFileVault: The payload that configures FileVault.

FDEFileVault corresponds to mdm/profiles/com.apple.MCX.FileVault2.yaml (FDE FileVault).

func (*FDEFileVault) PayloadTypeName

func (*FDEFileVault) PayloadTypeName() string

PayloadTypeName returns "com.apple.MCX.FileVault2".

func (*FDEFileVault) SchemaPath

func (*FDEFileVault) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*FDEFileVault) Validate

func (x *FDEFileVault) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type FDEFileVaultOptions

type FDEFileVaultOptions struct {
	// If `true`, the system won't disable FileVault.
	DontAllowFDEDisable *bool `plist:"dontAllowFDEDisable,omitempty" json:"dontAllowFDEDisable,omitempty"`
	// If `true`, the system won't enable FileVault.
	DontAllowFDEEnable *bool `plist:"dontAllowFDEEnable,omitempty" json:"dontAllowFDEEnable,omitempty"`
	// If `true`, the system won't store th FileVault key across restarts.
	DestroyFVKeyOnStandby *bool `plist:"DestroyFVKeyOnStandby,omitempty" json:"DestroyFVKeyOnStandby,omitempty"`
}

FDEFileVaultOptions: The payload that configures FileVault options.

FDEFileVaultOptions corresponds to mdm/profiles/com.apple.MCX(FileVault2).yaml (FDE FileVault Options).

func (*FDEFileVaultOptions) PayloadTypeName

func (*FDEFileVaultOptions) PayloadTypeName() string

PayloadTypeName returns "com.apple.MCX".

func (*FDEFileVaultOptions) SchemaPath

func (*FDEFileVaultOptions) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*FDEFileVaultOptions) Validate

func (x *FDEFileVaultOptions) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type FDERecoveryKeyEscrow

type FDERecoveryKeyEscrow struct {
	// The description of the location where the system escrows the recovery key. The system
	// inserts this text into the message the user sees when it enables FileVault.
	Location string `plist:"Location" json:"Location"`
	// The UUID of a payload within the same profile that contains the certificate that the
	// system uses to encrypt the recovery key. The referenced payload must be of type
	// `com.apple.security.pkcs1`.
	EncryptCertPayloadUUID string `plist:"EncryptCertPayloadUUID" json:"EncryptCertPayloadUUID"`
	// The string that's included in help text if the user appears to have forgotten the
	// password. Site admins can use this key to look up the escrowed key for the particular
	// computer.
	DeviceKey *string `plist:"DeviceKey,omitempty" json:"DeviceKey,omitempty"`
}

FDERecoveryKeyEscrow: The payload that configures FileVault recovery key escrow.

FDERecoveryKeyEscrow corresponds to mdm/profiles/com.apple.security.FDERecoveryKeyEscrow.yaml (FDE Recovery Key Escrow).

func (*FDERecoveryKeyEscrow) PayloadTypeName

func (*FDERecoveryKeyEscrow) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.FDERecoveryKeyEscrow".

func (*FDERecoveryKeyEscrow) SchemaPath

func (*FDERecoveryKeyEscrow) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*FDERecoveryKeyEscrow) Validate

func (x *FDERecoveryKeyEscrow) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type FDERecoveryKeyRedirection

type FDERecoveryKeyRedirection struct {
	// The URL to which FDE recovery keys should be sent instead of to Apple. The URL must
	// begin with https://.
	RedirectURL string `plist:"RedirectURL" json:"RedirectURL"`
	// The UUID of a payload within the same profile that contains a certificate used to
	// encrypt the recovery key when it's sent to the redirected URL. The referenced payload
	// must be of type \`com.apple.security.pkcs1\`.
	EncryptCertPayloadUUID string `plist:"EncryptCertPayloadUUID" json:"EncryptCertPayloadUUID"`
}

FDERecoveryKeyRedirection: The payload that configures FileVault recovery key redirection.

FDERecoveryKeyRedirection corresponds to mdm/profiles/com.apple.security.FDERecoveryRedirect.yaml (FDE Recovery Key Redirection).

func (*FDERecoveryKeyRedirection) PayloadTypeName

func (*FDERecoveryKeyRedirection) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.FDERecoveryRedirect".

func (*FDERecoveryKeyRedirection) SchemaPath

func (*FDERecoveryKeyRedirection) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*FDERecoveryKeyRedirection) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type FileProvider

type FileProvider struct {
	// If `false`, the device prevents the File Provider extension from using synchronization
	// in any app. Also, none of the other options will be evaluated. Synchronization will be
	// totally disabled for any application.
	ManagementAllowsRemoteSyncing *bool `plist:"ManagementAllowsRemoteSyncing,omitempty" json:"ManagementAllowsRemoteSyncing,omitempty"`
	// An array of strings representing the composed identifiers of apps. The device allows the
	// corresponding apps to use File Provider extension synchronization. If present, and
	// `ManagementAllowsRemoteSyncing` is set to `true`, the device allows only the apps in
	// this list to use synchronization. This key is ignored if `ManagementAllowsRemoteSyncing`
	// is set to `false`. If present, the other options will only be evaluated for the apps in
	// this list. The format of the app identifiers is "Bundle-ID (Team-ID)", for example
	// `com.example.app (ABCD1234)`.
	ManagementRemoteSyncingAllowList []string `plist:"ManagementRemoteSyncingAllowList,omitempty" json:"ManagementRemoteSyncingAllowList,omitempty"`
	// If `true`, enables file providers access to the path of the requesting process.
	AllowManagedFileProvidersToRequestAttribution *bool `` /* 126-byte string literal not displayed */
	// If `false`, the device prevents the File Provider extension from using desktop and
	// documents synchronization in any app. This does not impact the ability for apps to
	// utilize the File Provider extension for file and folder syncing with remote storage.
	ManagementAllowsKnownFolderSyncing *bool `plist:"ManagementAllowsKnownFolderSyncing,omitempty" json:"ManagementAllowsKnownFolderSyncing,omitempty"`
	// An array of strings representing the composed identifiers of apps. The device allows the
	// corresponding apps to use File Provider extension desktop and documents synchronization.
	// If present, and `ManagementAllowsKnownFolderSyncing` is set to `true`, the device allows
	// only the apps in this list to use desktop and documents synchronization. This key is
	// ignored if `ManagementAllowsKnownFolderSyncing` is set to `false`. This setting does not
	// impact the ability for apps to use File Provider extension volume access. The format of
	// the app identifiers is "Bundle-ID (Team-ID)", for example `com.example.app (ABCD1234)`.
	ManagementKnownFolderSyncingAllowList []string `plist:"ManagementKnownFolderSyncingAllowList,omitempty" json:"ManagementKnownFolderSyncingAllowList,omitempty"`
	// If `false`, the device only allows File Provider extension volume synchronization for
	// the system "home" volume and any data separated volume, and prevents synchronization
	// with any other volumes. If `true“, the device allows File Provider extension volume
	// synchronization for the system "home" volume, any data separated volume, and any
	// encrypted APFS volumes (on either internal or external media).
	ManagementAllowsExternalVolumeSyncing *bool `plist:"ManagementAllowsExternalVolumeSyncing,omitempty" json:"ManagementAllowsExternalVolumeSyncing,omitempty"`
	// An array of strings representing the composed identifiers of apps. The device allows the
	// corresponding apps to use File Provider extension volume synchronization. If present,
	// and `ManagementAllowsExternalVolumeSyncing` is set to `true`, the device allows only the
	// apps in this list to use volume synchronization. This key is ignored if
	// `ManagementAllowsExternalVolumeSyncing` is set to `false`. The format of the app
	// identifiers is "Bundle-ID (Team-ID)", for example `com.example.app (ABCD1234)`.
	ManagementExternalVolumeSyncingAllowList []string `plist:"ManagementExternalVolumeSyncingAllowList,omitempty" json:"ManagementExternalVolumeSyncingAllowList,omitempty"`
	// An array of strings representing the composed identifiers of apps. The device
	// automatically enables the File Provider domains for the corresponding apps. The device
	// doesn't enable existing domains if enrollment happens after they are created. The device
	// doesn't prevent the user from disabling these File Provider domains. Users need to
	// manually enable File Provider domains in the Finder if their corresponding apps aren't
	// listed here. The format of the app identifiers is "Bundle-ID (Team-ID)", for example
	// `com.example.app (ABCD1234)`.
	ManagementDomainAutoEnablementList []string `plist:"ManagementDomainAutoEnablementList,omitempty" json:"ManagementDomainAutoEnablementList,omitempty"`
}

FileProvider: The payload that configures file provider settings.

FileProvider corresponds to mdm/profiles/com.apple.fileproviderd.yaml (File Provider).

func (*FileProvider) PayloadTypeName

func (*FileProvider) PayloadTypeName() string

PayloadTypeName returns "com.apple.fileproviderd".

func (*FileProvider) SchemaPath

func (*FileProvider) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*FileProvider) Validate

func (x *FileProvider) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type Finder

type Finder struct {
	// If `true`, the system disables the Finder's burn support.
	ProhibitBurn *bool `plist:"ProhibitBurn,omitempty" json:"ProhibitBurn,omitempty"`
	// Specifies whether Finder should operate in Simple or Full mode.
	InterfaceLevel *string `plist:"InterfaceLevel,omitempty" json:"InterfaceLevel,omitempty"`
	// If `true`, the system disables Connect to Server.
	ProhibitConnectTo *bool `plist:"ProhibitConnectTo,omitempty" json:"ProhibitConnectTo,omitempty"`
	// If `true`, the system disables Eject.
	ProhibitEject *bool `plist:"ProhibitEject,omitempty" json:"ProhibitEject,omitempty"`
	// If `true`, the system disables Go to Folder.
	ProhibitGoToFolder *bool `plist:"ProhibitGoToFolder,omitempty" json:"ProhibitGoToFolder,omitempty"`
	// If `false`, the system doesn't show external hard drives on the Desktop.
	ShowExternalHardDrivesOnDesktop *bool `plist:"ShowExternalHardDrivesOnDesktop,omitempty" json:"ShowExternalHardDrivesOnDesktop,omitempty"`
	// If `false`, the system doesn't show internal hard drives on the Desktop.
	ShowHardDrivesOnDesktop *bool `plist:"ShowHardDrivesOnDesktop,omitempty" json:"ShowHardDrivesOnDesktop,omitempty"`
	// If `false`, the system doesn't show mounted file servers on the Desktop.
	ShowMountedServersOnDesktop *bool `plist:"ShowMountedServersOnDesktop,omitempty" json:"ShowMountedServersOnDesktop,omitempty"`
	// If `false`, the system doesn't show removable media items on the Desktop.
	ShowRemovableMediaOnDesktop *bool `plist:"ShowRemovableMediaOnDesktop,omitempty" json:"ShowRemovableMediaOnDesktop,omitempty"`
	// If `false`, the system doesn't warn the user before emptying the trash.
	WarnOnEmptyTrash *bool `plist:"WarnOnEmptyTrash,omitempty" json:"WarnOnEmptyTrash,omitempty"`
}

Finder: The payload that configures Finder settings.

Finder corresponds to mdm/profiles/com.apple.finder.yaml (Finder).

func (*Finder) PayloadTypeName

func (*Finder) PayloadTypeName() string

PayloadTypeName returns "com.apple.finder".

func (*Finder) SchemaPath

func (*Finder) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Finder) Validate

func (x *Finder) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type Firewall

type Firewall struct {
	// If `true`, the system enables the firewall.
	EnableFirewall bool `plist:"EnableFirewall" json:"EnableFirewall"`
	// If `true`, the system enables blocking all incoming connections.
	BlockAllIncoming *bool `plist:"BlockAllIncoming,omitempty" json:"BlockAllIncoming,omitempty"`
	// If `true`, the system enables stealth mode.
	EnableStealthMode *bool `plist:"EnableStealthMode,omitempty" json:"EnableStealthMode,omitempty"`
	// The list of apps with connections that the firewall controls.
	Applications []FirewallApplications `plist:"Applications,omitempty" json:"Applications,omitempty"`
	// If `true`, the system enables logging. Available in macOS 12 through macOS 14.6.
	EnableLogging *bool `plist:"EnableLogging,omitempty" json:"EnableLogging,omitempty"`
	// The type of logging. Available in macOS 12 and through macOS 14.6.
	LoggingOption *string `plist:"LoggingOption,omitempty" json:"LoggingOption,omitempty"`
	// If `true`, the system allows built-in software to receive incoming connections.
	// Available in macOS 12.3 and later.
	AllowSigned *bool `plist:"AllowSigned,omitempty" json:"AllowSigned,omitempty"`
	// If `true`, the system allows downloaded signed software to receive incoming connections.
	// Available in macOS 12.3 and later.
	AllowSignedApp *bool `plist:"AllowSignedApp,omitempty" json:"AllowSignedApp,omitempty"`
}

Firewall: The payload that configures the firewall.

Firewall corresponds to mdm/profiles/com.apple.security.firewall.yaml (Firewall).

func (*Firewall) PayloadTypeName

func (*Firewall) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.firewall".

func (*Firewall) SchemaPath

func (*Firewall) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Firewall) Validate

func (x *Firewall) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type FirewallApplications

type FirewallApplications struct {
	// The bundle identifier for the app.
	BundleID string `plist:"BundleID" json:"BundleID"`
	// If `true`, the system allows connections for the app.
	Allowed bool `plist:"Allowed" json:"Allowed"`
}

FirewallApplications: is generated from mdm/profiles/com.apple.security.firewall.yaml.

type Font

type Font struct {
	// The user-visible name for the font. This field is replaced by the actual name of the
	// font after installation. Each payload must contain exactly one font file in trueType
	// (.ttf) or OpenType (.otf) format. Collection formats (.ttc or .otc) are not supported.
	Name *string `plist:"Name,omitempty" json:"Name,omitempty"`
	// The contents of the font file.
	Font []byte `plist:"Font,omitempty" json:"Font,omitempty"`
}

Font: The payload that configures fonts.

Font corresponds to mdm/profiles/com.apple.font.yaml (Font).

func (*Font) PayloadTypeName

func (*Font) PayloadTypeName() string

PayloadTypeName returns "com.apple.font".

func (*Font) SchemaPath

func (*Font) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Font) Validate

func (x *Font) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type GlobalHTTPProxy

type GlobalHTTPProxy struct {
	// The proxy type. For a manual proxy type, the profile contains the proxy server address,
	// including its port, and optionally a user name and password. For an auto proxy type, you
	// can enter a PAC URL.
	ProxyType *string `plist:"ProxyType,omitempty" json:"ProxyType,omitempty"`
	// The proxy server's network address. The device requires this if `ProxyType` is set to
	// `Manual`, and ignores it if `ProxyType` is set to `Automatic`.
	ProxyServer *string `plist:"ProxyServer,omitempty" json:"ProxyServer,omitempty"`
	// The proxy server's port number. The device requires this if `ProxyType` is set to
	// `Manual`, and ignores this if `ProxyType` is set to `Automatic`.
	ProxyServerPort *int64 `plist:"ProxyServerPort,omitempty" json:"ProxyServerPort,omitempty"`
	// The user name used to authenticate to the proxy server. The device only uses this if
	// `ProxyType` is set to `Manual`, and ignores it if `ProxyType` is set to `Automatic`.
	ProxyUsername *string `plist:"ProxyUsername,omitempty" json:"ProxyUsername,omitempty"`
	// The password used to authenticate to the proxy server. The device only uses this if
	// `ProxyType` is set to `Manual`, and ignores it if `ProxyType` is set to `Automatic`.
	ProxyPassword *string `plist:"ProxyPassword,omitempty" json:"ProxyPassword,omitempty"`
	// The URL of the PAC file that defines the proxy configuration. Starting in iOS 13 and
	// macOS 10.15, only URLs that begin with `http://` or `https://` are allowed. This is only
	// used if `ProxyType` is set to `Automatic`, and is ignored if `ProxyType` is set to
	// `Manual`.
	ProxyPACURL *string `plist:"ProxyPACURL,omitempty" json:"ProxyPACURL,omitempty"`
	// If `true`, allows connecting directly to the destination if the proxy autoconfiguration
	// (PAC) file is unreachable.
	ProxyPACFallbackAllowed *bool `plist:"ProxyPACFallbackAllowed,omitempty" json:"ProxyPACFallbackAllowed,omitempty"`
	// If `true`, allows the device to bypass the proxy server to display the login page for
	// captive networks.
	ProxyCaptiveLoginAllowed *bool `plist:"ProxyCaptiveLoginAllowed,omitempty" json:"ProxyCaptiveLoginAllowed,omitempty"`
}

GlobalHTTPProxy: The payload that configures a global HTTP proxy.

GlobalHTTPProxy corresponds to mdm/profiles/com.apple.proxy.http.global.yaml (Global HTTP Proxy).

func (*GlobalHTTPProxy) PayloadTypeName

func (*GlobalHTTPProxy) PayloadTypeName() string

PayloadTypeName returns "com.apple.proxy.http.global".

func (*GlobalHTTPProxy) SchemaPath

func (*GlobalHTTPProxy) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*GlobalHTTPProxy) Validate

func (x *GlobalHTTPProxy) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type GlobalPreferences

type GlobalPreferences struct {
	// If `false`, disables fast user switching.
	MultipleSessionEnabled *bool `plist:"MultipleSessionEnabled,omitempty" json:"MultipleSessionEnabled,omitempty"`
	// The `autologout` delay, in seconds. A value of `0` means `autologout` is off. In some
	// cases, this delay may be restricted to values between 5 minutes and 24 hours.
	ComAppleAutologoutAutoLogOutDelay *float64 `plist:"com.apple.autologout.AutoLogOutDelay,omitempty" json:"com.apple.autologout.AutoLogOutDelay,omitempty"`
}

GlobalPreferences: The payload to configure global preferences.

GlobalPreferences corresponds to mdm/profiles/GlobalPreferences.yaml (Global Preferences).

func (*GlobalPreferences) PayloadTypeName

func (*GlobalPreferences) PayloadTypeName() string

PayloadTypeName returns ".GlobalPreferences".

func (*GlobalPreferences) SchemaPath

func (*GlobalPreferences) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*GlobalPreferences) Validate

func (x *GlobalPreferences) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type GoogleAccount

type GoogleAccount struct {
	// A user-visible description of the Google account, shown in the Mail and Settings apps.
	AccountDescription *string `plist:"AccountDescription,omitempty" json:"AccountDescription,omitempty"`
	// The user's full name for the Google account. This name appears in sent messages.
	AccountName *string `plist:"AccountName,omitempty" json:"AccountName,omitempty"`
	// The full Google email address for the account.
	EmailAddress string `plist:"EmailAddress" json:"EmailAddress"`
	// The communication service handler rules for this account.
	CommunicationServiceRules *GoogleAccountCommunicationServiceRules `plist:"CommunicationServiceRules,omitempty" json:"CommunicationServiceRules,omitempty"`
	// The VPNUUID of the per-app VPN the account uses for network communication. Available in
	// iOS 14 and later.
	VPNUUID *string `plist:"VPNUUID,omitempty" json:"VPNUUID,omitempty"`
}

GoogleAccount: The payload that configures a Google account.

GoogleAccount corresponds to mdm/profiles/com.apple.google-oauth.yaml (Google Account).

func (*GoogleAccount) PayloadTypeName

func (*GoogleAccount) PayloadTypeName() string

PayloadTypeName returns "com.apple.google-oauth".

func (*GoogleAccount) SchemaPath

func (*GoogleAccount) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*GoogleAccount) Validate

func (x *GoogleAccount) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type GoogleAccountCommunicationServiceRules

type GoogleAccountCommunicationServiceRules struct {
	// A dictionary that defines which app to use for audio calls from this account.
	DefaultServiceHandlers *GoogleAccountCommunicationServiceRulesDefaultServiceHandlers `plist:"DefaultServiceHandlers,omitempty" json:"DefaultServiceHandlers,omitempty"`
}

GoogleAccountCommunicationServiceRules: The communication service handler rules for this account.

type GoogleAccountCommunicationServiceRulesDefaultServiceHandlers

type GoogleAccountCommunicationServiceRulesDefaultServiceHandlers struct {
	// The bundle identifier for the default application that handles audio calls to contacts
	// from this account.
	AudioCall *string `plist:"AudioCall,omitempty" json:"AudioCall,omitempty"`
}

GoogleAccountCommunicationServiceRulesDefaultServiceHandlers: A dictionary that defines which app to use for audio calls from this account.

type HomeScreenLayout

type HomeScreenLayout struct {
	// An array of dictionaries, each of which must conform to the icon dictionary format. If
	// this key isn't present, the user's Dock is empty.
	Dock []HomeScreenLayoutIconItem `plist:"Dock,omitempty" json:"Dock,omitempty"`
	// An array of arrays of dictionaries, each of which must conform to the icon dictionary
	// format.
	Pages [][]HomeScreenLayoutPagesItemIconItem `plist:"Pages,omitempty" json:"Pages,omitempty"`
}

HomeScreenLayout: The payload that configures the Home Screen layout.

HomeScreenLayout corresponds to mdm/profiles/com.apple.homescreenlayout.yaml (Home Screen Layout).

func (*HomeScreenLayout) PayloadTypeName

func (*HomeScreenLayout) PayloadTypeName() string

PayloadTypeName returns "com.apple.homescreenlayout".

func (*HomeScreenLayout) SchemaPath

func (*HomeScreenLayout) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*HomeScreenLayout) Validate

func (x *HomeScreenLayout) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type HomeScreenLayoutIconItem

type HomeScreenLayoutIconItem struct {
	// The type of the Dock item.
	Type string `plist:"Type" json:"Type"`
	// The human-readable string shown to the user. This setting is valid only if the type is
	// `Folder`.
	DisplayName *string `plist:"DisplayName,omitempty" json:"DisplayName,omitempty"`
	// The bundle identifier of the app. This setting is required if the type is `Application`.
	BundleID *string `plist:"BundleID,omitempty" json:"BundleID,omitempty"`
	// An array of arrays of dictionaries, each conforming to the icon dictionary format. This
	// setting is valid only if the type is `Folder`.
	Pages [][]HomeScreenLayoutIconItem `plist:"Pages,omitempty" json:"Pages,omitempty"`
	// The URL of the existing web clip for this item. This setting is required if `type` is
	// `WebClip`. If more than one web clip exists with the same URL, the behavior is
	// undefined.
	URL *string `plist:"URL,omitempty" json:"URL,omitempty"`
}

HomeScreenLayoutIconItem: An array of dictionaries that conform to the icon dictionary format.

type HomeScreenLayoutPagesItemIconItem

type HomeScreenLayoutPagesItemIconItem struct {
	// The type of the Dock item.
	Type string `plist:"Type" json:"Type"`
	// The human-readable string shown to the user. This setting is valid only if the type is
	// `Folder`.
	DisplayName *string `plist:"DisplayName,omitempty" json:"DisplayName,omitempty"`
	// The bundle identifier of the app. This setting is required if the type is `Application`.
	BundleID *string `plist:"BundleID,omitempty" json:"BundleID,omitempty"`
	// An array of arrays of dictionaries, each conforming to the icon dictionary format. This
	// setting is valid only if the type is `Folder`.
	Pages [][]HomeScreenLayoutPagesItemIconItem `plist:"Pages,omitempty" json:"Pages,omitempty"`
	// The URL of the existing web clip for this item. This setting is required if `type` is
	// `WebClip`. If more than one web clip exists with the same URL, the behavior is
	// undefined.
	URL *string `plist:"URL,omitempty" json:"URL,omitempty"`
}

HomeScreenLayoutPagesItemIconItem: An array of dictionaries that conform to the icon dictionary format.

type Identification

type Identification struct {
	// The dictionary that contains details about the user.
	PayloadIdentification IdentificationPayloadIdentification `plist:"PayloadIdentification,omitempty" json:"PayloadIdentification,omitempty"`
}

Identification: The payload that configures the names of the account user.

Identification corresponds to mdm/profiles/com.apple.configurationprofile.identification.yaml (Identification).

func (*Identification) PayloadTypeName

func (*Identification) PayloadTypeName() string

PayloadTypeName returns "com.apple.configurationprofile.identification".

func (*Identification) SchemaPath

func (*Identification) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Identification) Validate

func (x *Identification) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type IdentificationPayloadIdentification

type IdentificationPayloadIdentification struct {
	// The UNIX user name for the accounts.
	UserName string `plist:"UserName" json:"UserName"`
	// The full name of the account.
	FullName string `plist:"FullName" json:"FullName"`
	// The address for the account.
	EmailAddress string `plist:"EmailAddress" json:"EmailAddress"`
	// The authorization method. Either the profile contains the password or the user provides
	// it.
	AuthMethod string `plist:"AuthMethod" json:"AuthMethod"`
	// The password for the account. Required when the `AuthMethod` is `Password`.
	Password string `plist:"Password" json:"Password"`
	// The custom instructions for the user, if needed.
	Prompt *string `plist:"Prompt,omitempty" json:"Prompt,omitempty"`
	// The additional descriptive text for the user prompt.
	PromptMessage *string `plist:"PromptMessage,omitempty" json:"PromptMessage,omitempty"`
}

IdentificationPayloadIdentification: The dictionary that contains details about the user.

type IdentityPreference

type IdentityPreference struct {
	// The email address (in RFC 822 format), DNS host name, or other name that uniquely
	// identifies a service requiring this identity.
	Name string `plist:"Name" json:"Name"`
	// The UUID of the certificate payload within the same profile to use for the identity
	// credential.
	PayloadCertificateUUID string `plist:"PayloadCertificateUUID" json:"PayloadCertificateUUID"`
}

IdentityPreference: The payload that configures the user's identity on the device.

IdentityPreference corresponds to mdm/profiles/com.apple.security.identitypreference.yaml (Identity Preference).

func (*IdentityPreference) PayloadTypeName

func (*IdentityPreference) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.identitypreference".

func (*IdentityPreference) SchemaPath

func (*IdentityPreference) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*IdentityPreference) Validate

func (x *IdentityPreference) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type JabberAccount

type JabberAccount struct {
	// The description of the account.
	JabberAccountDescription *string `plist:"JabberAccountDescription,omitempty" json:"JabberAccountDescription,omitempty"`
	// The server's address.
	JabberHostName string `plist:"JabberHostName" json:"JabberHostName"`
	// The user's user name.
	JabberUserName *string `plist:"JabberUserName,omitempty" json:"JabberUserName,omitempty"`
	// The user's password.
	JabberPassword *string `plist:"JabberPassword,omitempty" json:"JabberPassword,omitempty"`
	// If `true`, enables SSL.
	JabberUseSSL *bool `plist:"JabberUseSSL,omitempty" json:"JabberUseSSL,omitempty"`
	// The server's port.
	JabberPort *int64 `plist:"JabberPort,omitempty" json:"JabberPort,omitempty"`
	// The authentication method for the account.
	JabberAuthentication string `plist:"JabberAuthentication" json:"JabberAuthentication"`
}

JabberAccount: The payload that configures a Jabber account.

JabberAccount corresponds to mdm/profiles/com.apple.jabber.account.yaml (Jabber Account).

func (*JabberAccount) PayloadTypeName

func (*JabberAccount) PayloadTypeName() string

PayloadTypeName returns "com.apple.jabber.account".

func (*JabberAccount) SchemaPath

func (*JabberAccount) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*JabberAccount) Validate

func (x *JabberAccount) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type LDAP

type LDAP struct {
	// The description of the account.
	LDAPAccountDescription *string `plist:"LDAPAccountDescription,omitempty" json:"LDAPAccountDescription,omitempty"`
	// The server's address.
	LDAPAccountHostName string `plist:"LDAPAccountHostName" json:"LDAPAccountHostName"`
	// The user's user name.
	LDAPAccountUserName *string `plist:"LDAPAccountUserName,omitempty" json:"LDAPAccountUserName,omitempty"`
	// The user's password. Only use this in encrypted profiles.
	LDAPAccountPassword *string `plist:"LDAPAccountPassword,omitempty" json:"LDAPAccountPassword,omitempty"`
	// If `true`, the system enables SSL.
	LDAPAccountUseSSL *bool `plist:"LDAPAccountUseSSL,omitempty" json:"LDAPAccountUseSSL,omitempty"`
	// An array of search settings dictionaries.
	LDAPSearchSettings []LDAPLDAPSearchSettings `plist:"LDAPSearchSettings,omitempty" json:"LDAPSearchSettings,omitempty"`
	// The VPNUUID of the per-app VPN the account uses for network communication. Available in
	// iOS 14 and later.
	VPNUUID *string `plist:"VPNUUID,omitempty" json:"VPNUUID,omitempty"`
}

LDAP: The payload that configures a Lightweight Directory Access Protocol (LDAP) account.

LDAP corresponds to mdm/profiles/com.apple.ldap.account.yaml (LDAP).

func (*LDAP) PayloadTypeName

func (*LDAP) PayloadTypeName() string

PayloadTypeName returns "com.apple.ldap.account".

func (*LDAP) SchemaPath

func (*LDAP) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*LDAP) Validate

func (x *LDAP) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type LDAPLDAPSearchSettings

type LDAPLDAPSearchSettings struct {
	// The description of this search setting.
	LDAPSearchSettingDescription *string `plist:"LDAPSearchSettingDescription,omitempty" json:"LDAPSearchSettingDescription,omitempty"`
	// The path to the node where a search should start.
	LDAPSearchSettingSearchBase string `plist:"LDAPSearchSettingSearchBase" json:"LDAPSearchSettingSearchBase"`
	// The type of recursion to use in the search:
	LDAPSearchSettingScope *string `plist:"LDAPSearchSettingScope,omitempty" json:"LDAPSearchSettingScope,omitempty"`
}

LDAPLDAPSearchSettings: is generated from mdm/profiles/com.apple.ldap.account.yaml.

type LightsOutManagementLOM

type LightsOutManagementLOM struct {
	// The UUID certificate for the device. This key indicates the device can receive
	// `PowerON`, `PowerOFF`, and `Reset` requests from a LOM controller. This certificate must
	// contain the Key Usage attributes of Digital Signature, Key Encipherment and Data
	// Encipherment. As well as the Extended Key Usage attributes of Server Authentication and
	// Client Authentication.
	DeviceCertificateUUID *string `plist:"DeviceCertificateUUID,omitempty" json:"DeviceCertificateUUID,omitempty"`
	// The UUID certificate for the LOM controller. This key configures the device to accept
	// the `LOMDeviceRequestCommand` from MDM and then send it to the target device.
	ControllerCertificateUUID *string `plist:"ControllerCertificateUUID,omitempty" json:"ControllerCertificateUUID,omitempty"`
	// An array of payload UUIDs containing CA certificates that controllers use to evaluate
	// trust of device certificates.
	DeviceCACertificateUUIDs []string `plist:"DeviceCACertificateUUIDs,omitempty" json:"DeviceCACertificateUUIDs,omitempty"`
	// An array of payload UUIDs containing CA certificates that devices use to evaluate trust
	// of controller certificates.
	ControllerCACertificateUUIDs []string `plist:"ControllerCACertificateUUIDs,omitempty" json:"ControllerCACertificateUUIDs,omitempty"`
}

LightsOutManagementLOM: The payload that configures lights-out management (LOM) settings.

LightsOutManagementLOM corresponds to mdm/profiles/com.apple.lom.yaml (Lights Out Management (LOM)).

func (*LightsOutManagementLOM) PayloadTypeName

func (*LightsOutManagementLOM) PayloadTypeName() string

PayloadTypeName returns "com.apple.lom".

func (*LightsOutManagementLOM) SchemaPath

func (*LightsOutManagementLOM) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*LightsOutManagementLOM) Validate

func (x *LightsOutManagementLOM) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type LockScreenMessage

type LockScreenMessage struct {
	// The asset tag information for the device, displayed in the Login Window and Lock Screen.
	AssetTagInformation *string `plist:"AssetTagInformation,omitempty" json:"AssetTagInformation,omitempty"`
	// Deprecated. Use `LockScreenFootnote` instead.
	IfLostReturnToMessage *string `plist:"IfLostReturnToMessage,omitempty" json:"IfLostReturnToMessage,omitempty"`
	// The footnote displayed in the Login Window and Lock Screen.
	LockScreenFootnote *string `plist:"LockScreenFootnote,omitempty" json:"LockScreenFootnote,omitempty"`
}

LockScreenMessage: The payload that configures a Lock Screen message.

LockScreenMessage corresponds to mdm/profiles/com.apple.shareddeviceconfiguration.yaml (Lock Screen Message).

func (*LockScreenMessage) PayloadTypeName

func (*LockScreenMessage) PayloadTypeName() string

PayloadTypeName returns "com.apple.shareddeviceconfiguration".

func (*LockScreenMessage) SchemaPath

func (*LockScreenMessage) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*LockScreenMessage) Validate

func (x *LockScreenMessage) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type LoginItemsManagedItems

type LoginItemsManagedItems struct {
	// An array of login item dictionaries.
	AutoLaunchedApplicationDictionaryManaged []LoginItemsManagedItemsAutoLaunchedApplicationDictionaryManaged `plist:"AutoLaunchedApplicationDictionary-managed,omitempty" json:"AutoLaunchedApplicationDictionary-managed,omitempty"`
}

LoginItemsManagedItems: The payload that configures a device's login items.

LoginItemsManagedItems corresponds to mdm/profiles/com.apple.loginitems.managed.yaml (Login Items: Managed Items).

func (*LoginItemsManagedItems) PayloadTypeName

func (*LoginItemsManagedItems) PayloadTypeName() string

PayloadTypeName returns "com.apple.loginitems.managed".

func (*LoginItemsManagedItems) SchemaPath

func (*LoginItemsManagedItems) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*LoginItemsManagedItems) Validate

func (x *LoginItemsManagedItems) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type LoginItemsManagedItemsAutoLaunchedApplicationDictionaryManaged

type LoginItemsManagedItemsAutoLaunchedApplicationDictionaryManaged struct {
	// The URL or path string to the item's location.
	Path string `plist:"Path" json:"Path"`
	// If `true`, the system hides this item in the Users & Groups login items list.
	Hide *bool `plist:"Hide,omitempty" json:"Hide,omitempty"`
}

LoginItemsManagedItemsAutoLaunchedApplicationDictionaryManaged: A login item.

type LoginWindow

type LoginWindow struct {
	// If `true`, the system shows the name and password dialog. If `false`, the system
	// displays a list of users.
	SHOWFULLNAME *bool `plist:"SHOWFULLNAME,omitempty" json:"SHOWFULLNAME,omitempty"`
	// If `true`, the system shows only network and system users when showing a user list.
	HideLocalUsers *bool `plist:"HideLocalUsers,omitempty" json:"HideLocalUsers,omitempty"`
	// If `true`, the system shows network users when showing a user list.
	IncludeNetworkUser *bool `plist:"IncludeNetworkUser,omitempty" json:"IncludeNetworkUser,omitempty"`
	// If `true`, the system hides administrator users when showing a user list.
	HideAdminUsers *bool `plist:"HideAdminUsers,omitempty" json:"HideAdminUsers,omitempty"`
	// If `true`, the system displays "Other..." when it shows a list of users.
	SHOWOTHERUSERSMANAGED *bool `plist:"SHOWOTHERUSERS_MANAGED,omitempty" json:"SHOWOTHERUSERS_MANAGED,omitempty"`
	// The admin host info. If present in the payload, the system displays its value in the
	// Login Window as additional computer information. Before macOS 10.10, this string could
	// only contain host name, system version, or IP address. After macOS 10.10, setting this
	// key to any value allows the user to click the time area of the menu bar to toggle
	// through various computer information values.
	AdminHostInfo *string `plist:"AdminHostInfo,omitempty" json:"AdminHostInfo,omitempty"`
	// The list of user GUIDs or group GUIDs of users that the system allows to log in. An
	// asterisk (`*`) string specifies all users or groups. This only applies to network
	// accounts and mobile accounts.
	AllowList []string `plist:"AllowList,omitempty" json:"AllowList,omitempty"`
	// The list of user GUIDs or group GUIDs of users that the system disallows to log in. This
	// list takes priority over the list in the `AllowList` key. This only applies to network
	// accounts and mobile accounts.
	DenyList []string `plist:"DenyList,omitempty" json:"DenyList,omitempty"`
	// If `true`, the system hides mobile account users in a user list. In some cases, mobile
	// users show up as network users.
	HideMobileAccounts *bool `plist:"HideMobileAccounts,omitempty" json:"HideMobileAccounts,omitempty"`
	// If `true`, the system disables the Shut Down button.
	ShutDownDisabled *bool `plist:"ShutDownDisabled,omitempty" json:"ShutDownDisabled,omitempty"`
	// If `true`, the system disables the Restart item.
	RestartDisabled *bool `plist:"RestartDisabled,omitempty" json:"RestartDisabled,omitempty"`
	// If `true`, the system disables the Sleep button.
	SleepDisabled *bool `plist:"SleepDisabled,omitempty" json:"SleepDisabled,omitempty"`
	// If `true`, the system disregards the `>console` special user name, which provides a
	// command line UI.
	DisableConsoleAccess *bool `plist:"DisableConsoleAccess,omitempty" json:"DisableConsoleAccess,omitempty"`
	// The text to display in the Login Window.
	LoginwindowText *string `plist:"LoginwindowText,omitempty" json:"LoginwindowText,omitempty"`
	// If `true`, the system disables the Shut Down menu item when the user is logged in.
	ShutDownDisabledWhileLoggedIn *bool `plist:"ShutDownDisabledWhileLoggedIn,omitempty" json:"ShutDownDisabledWhileLoggedIn,omitempty"`
	// If `true`, the system disables the Restart menu item when the user is logged in.
	RestartDisabledWhileLoggedIn *bool `plist:"RestartDisabledWhileLoggedIn,omitempty" json:"RestartDisabledWhileLoggedIn,omitempty"`
	// If `true`, the system disables the Power Off menu item when the user is logged in.
	PowerOffDisabledWhileLoggedIn *bool `plist:"PowerOffDisabledWhileLoggedIn,omitempty" json:"PowerOffDisabledWhileLoggedIn,omitempty"`
	// If `true`, the system disables the Log Out menu item when the user is logged in.
	// Available in macOS 10.13 and later.
	LogOutDisabledWhileLoggedIn *bool `plist:"LogOutDisabledWhileLoggedIn,omitempty" json:"LogOutDisabledWhileLoggedIn,omitempty"`
	// If `true`, the system disables the immediate Screen Lock functions. Available in macOS
	// 10.13 and later.
	DisableScreenLockImmediate *bool `plist:"DisableScreenLockImmediate,omitempty" json:"DisableScreenLockImmediate,omitempty"`
	// If `true`, the system shows the Input Menu in the Login Window.
	ShowInputMenu *bool `plist:"showInputMenu,omitempty" json:"showInputMenu,omitempty"`
	// If `true`, the system disables the automatic login option when using FileVault.
	DisableFDEAutoLogin *bool `plist:"DisableFDEAutoLogin,omitempty" json:"DisableFDEAutoLogin,omitempty"`
	// The user short name for an existing user to set up auto login.
	AutologinUsername *string `plist:"AutologinUsername,omitempty" json:"AutologinUsername,omitempty"`
	// An optional user password to set up auto login. This must match the `AutologinUsername`
	// user's current password.
	AutologinPassword *string `plist:"AutologinPassword,omitempty" json:"AutologinPassword,omitempty"`
}

LoginWindow: The payload that configures Login Window behavior.

LoginWindow corresponds to mdm/profiles/com.apple.loginwindow.yaml (Login Window).

func (*LoginWindow) PayloadTypeName

func (*LoginWindow) PayloadTypeName() string

PayloadTypeName returns "com.apple.loginwindow".

func (*LoginWindow) SchemaPath

func (*LoginWindow) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*LoginWindow) Validate

func (x *LoginWindow) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type LoginWindowLoginItems

type LoginWindowLoginItems struct {
	// If `true`, the system prevents the user from disabling login item launches by using the
	// Shift key.
	DisableLoginItemsSuppression *bool `plist:"DisableLoginItemsSuppression,omitempty" json:"DisableLoginItemsSuppression,omitempty"`
}

LoginWindowLoginItems: The payload that configures login behavior.

LoginWindowLoginItems corresponds to mdm/profiles/loginwindow.yaml (Login Window: Login Items).

func (*LoginWindowLoginItems) PayloadTypeName

func (*LoginWindowLoginItems) PayloadTypeName() string

PayloadTypeName returns "loginwindow".

func (*LoginWindowLoginItems) SchemaPath

func (*LoginWindowLoginItems) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*LoginWindowLoginItems) Validate

func (x *LoginWindowLoginItems) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type LoginWindowScripts

type LoginWindowScripts struct {
	// An array of one or more dictionaries of scripts to run at user login time.
	Loginscripts []LoginWindowScriptsScriptsItems `plist:"loginscripts,omitempty" json:"loginscripts,omitempty"`
	// An array of one or more dictionaries of scripts to run at user logout time.
	Logoutscripts []LoginWindowScriptsScriptsItems `plist:"logoutscripts,omitempty" json:"logoutscripts,omitempty"`
	// If `true`, the system doesn't execute the login scripts during login.
	SkipLoginHook *bool `plist:"skipLoginHook,omitempty" json:"skipLoginHook,omitempty"`
	// If `true`, the system doesn't execute the logout scripts during logout.
	SkipLogoutHook *bool `plist:"skipLogoutHook,omitempty" json:"skipLogoutHook,omitempty"`
}

LoginWindowScripts: The payload that configures scripts to run at login and logout.

LoginWindowScripts corresponds to mdm/profiles/com.apple.mcxloginscripts.yaml (Login Window: Scripts).

func (*LoginWindowScripts) PayloadTypeName

func (*LoginWindowScripts) PayloadTypeName() string

PayloadTypeName returns "com.apple.mcxloginscripts".

func (*LoginWindowScripts) SchemaPath

func (*LoginWindowScripts) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*LoginWindowScripts) Validate

func (x *LoginWindowScripts) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type LoginWindowScriptsScriptsItems

type LoginWindowScriptsScriptsItems struct {
	// The filename for display purposes.
	Filename string `plist:"filename" json:"filename"`
	// The UTF-8 encoded data object representing the executable script.
	Filedata []byte `plist:"filedata,omitempty" json:"filedata,omitempty"`
}

LoginWindowScriptsScriptsItems: A dictionary of login scripts.

type MDM

type MDM struct {
	// The UUID of the certificate payload for the device's identity. It may also point to a
	// SCEP payload.
	IdentityCertificateUUID string `plist:"IdentityCertificateUUID" json:"IdentityCertificateUUID"`
	// The topic that MDM listens to for push notifications. The certificate that the server
	// uses to send push notifications must have the same topic in its subject. The topic must
	// begin with the 'com.apple.mgmt.' prefix.
	Topic string `plist:"Topic" json:"Topic"`
	// The URL that the device contacts to retrieve device management instructions. The URL
	// must begin with the `https://` URL scheme, and may contain a port number (`:1234`, for
	// example).
	ServerURL string `plist:"ServerURL" json:"ServerURL"`
	// The URL that the device should use to check in during installation. The URL must begin
	// with the `https://` URL scheme and may contain a port number (`:1234`, for example). If
	// not set, the system uses `ServerURL`.
	CheckInURL *string `plist:"CheckInURL,omitempty" json:"CheckInURL,omitempty"`
	// If 'true', each message coming from the device carries the additional 'Mdm-Signature'
	// HTTP header.
	SignMessage *bool `plist:"SignMessage,omitempty" json:"SignMessage,omitempty"`
	// Logical OR of the following bit flags:
	AccessRights *int64 `plist:"AccessRights,omitempty" json:"AccessRights,omitempty"`
	// If 'true', the device uses the development APNS servers. Otherwise, the device uses the
	// production servers. Set to 'false' if your Apple Push Notification Service certificate
	// was issued by the Apple Push Certificate Portal ('https://identity.apple.com/pushcert').
	// That portal only issues certificates for the production push environment.
	UseDevelopmentAPNS *bool `plist:"UseDevelopmentAPNS,omitempty" json:"UseDevelopmentAPNS,omitempty"`
	// The Managed Apple Account of the user. Previously required for profile-driven user
	// enrollment. Removed as of iOS 18 and macOS 15.
	ManagedAppleID *string `plist:"ManagedAppleID,omitempty" json:"ManagedAppleID,omitempty"`
	// The Managed Apple Account pre-assigned to the authenticated user. Required for
	// account-driven enrollments. Available in iOS 15 and later, and macOS 14 and later.
	AssignedManagedAppleID *string `plist:"AssignedManagedAppleID,omitempty" json:"AssignedManagedAppleID,omitempty"`
	// The enrollment mode the server indicates to use when enrolling. Required for
	// account-driven enrollment. Available in iOS 15 and macOS 14, and later.
	EnrollmentMode *string `plist:"EnrollmentMode,omitempty" json:"EnrollmentMode,omitempty"`
	// An array of strings, each containing the UUID of a certificate to use when evaluating
	// trust to the '.../connect/' URLs of MDM servers.
	ServerURLPinningCertificateUUIDs []string `plist:"ServerURLPinningCertificateUUIDs,omitempty" json:"ServerURLPinningCertificateUUIDs,omitempty"`
	// An array of strings, each containing the payload UUID of a certificate to use when
	// evaluating trust to the '.../checkin/' URLs of MDM servers.
	CheckInURLPinningCertificateUUIDs []string `plist:"CheckInURLPinningCertificateUUIDs,omitempty" json:"CheckInURLPinningCertificateUUIDs,omitempty"`
	// If 'true', the system fails the connection attempt unless it obtains a verified positive
	// response during certificate revocation checks. If 'false', the system performs
	// revocation checks on a best-attempt basis, where failure to reach the server isn't
	// considered fatal.
	PinningRevocationCheckRequired *bool `plist:"PinningRevocationCheckRequired,omitempty" json:"PinningRevocationCheckRequired,omitempty"`
	// A unique array of strings indicating server capabilities:
	ServerCapabilities []string `plist:"ServerCapabilities,omitempty" json:"ServerCapabilities,omitempty"`
	// If 'true', the device attempts to send a `Check-Out` message to the 'CheckInURL' when
	// the profile is removed.
	CheckOutWhenRemoved *bool `plist:"CheckOutWhenRemoved,omitempty" json:"CheckOutWhenRemoved,omitempty"`
	// This property specifies an iTunes Store ID for an app the system can install with the
	// InstallApplicationCommand, without any approval from the user. The MDM vendor or
	// managing organization generally provides this app, which enhances the management
	// experience for the user. The device shows the user details about this app in the
	// account-driven enrollment process prior to installing the MDM profile. Use this property
	// with account-driven MDM enrollments that normally require user approval for app installs
	// through MDM. Only account-driven enrollments support this property and other enrollment
	// types ignore it. Available in iOS 15.1 and later.
	RequiredAppIDForMDM *int64 `plist:"RequiredAppIDForMDM,omitempty" json:"RequiredAppIDForMDM,omitempty"`
	// If 'true', the system warns the user that they need to reboot into RecoveryOS and allow
	// the MDM to use the bootstrap token for authentication for certain sensitive operations
	// such as enabling kernel extensions or installing some types of software updates. If the
	// MDM doesn't need to perform these operations, it can leave this key set to 'false', and
	// the user isn't notified. The SettingsCommand.Command.Settings.MDMOptions.MDMOptions
	// command overrides this default value. This setting only applies to devices that have
	// 'BootstrapTokenRequiredForSoftwareUpdate' or
	// 'BootstrapTokenRequiredForKernelExtensionApproval' set to 'true' in their
	// SecurityInfoResponse.SecurityInfo. DEP-enrolled devices are automatically allowed to use
	// the bootstrap token for authentication. Available in macOS 11 and later.
	PromptUserToAllowBootstrapTokenForAuthentication *bool `` /* 132-byte string literal not displayed */
}

MDM: The payload that configures mobile device management (MDM) settings.

MDM corresponds to mdm/profiles/com.apple.mdm.yaml (MDM).

func (*MDM) PayloadTypeName

func (*MDM) PayloadTypeName() string

PayloadTypeName returns "com.apple.mdm".

func (*MDM) SchemaPath

func (*MDM) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*MDM) Validate

func (x *MDM) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type MacOSServerAccount

type MacOSServerAccount struct {
	// The server's address.
	HostName string `plist:"HostName" json:"HostName"`
	// The user's user name.
	UserName string `plist:"UserName" json:"UserName"`
	// The user's password.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// The description of the account.
	AccountDescription *string `plist:"AccountDescription,omitempty" json:"AccountDescription,omitempty"`
	// An array of dictionaries containing configured account types and relevant settings
	ConfiguredAccounts []MacOSServerAccountConfiguredAccounts `plist:"ConfiguredAccounts,omitempty" json:"ConfiguredAccounts,omitempty"`
}

MacOSServerAccount: The payload that configures a macOS Server account.

MacOSServerAccount corresponds to mdm/profiles/com.apple.osxserver.account.yaml (macOS Server Account).

func (*MacOSServerAccount) PayloadTypeName

func (*MacOSServerAccount) PayloadTypeName() string

PayloadTypeName returns "com.apple.osxserver.account".

func (*MacOSServerAccount) SchemaPath

func (*MacOSServerAccount) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*MacOSServerAccount) Validate

func (x *MacOSServerAccount) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type MacOSServerAccountConfiguredAccounts

type MacOSServerAccountConfiguredAccounts struct {
	// com.apple.osxserver.documents (the Documents account type).
	Type string `plist:"Type" json:"Type"`
	// Designates the port number to use when contacting the server. If no port number is
	// specified, the default port is used.
	Port *int64 `plist:"Port,omitempty" json:"Port,omitempty"`
}

MacOSServerAccountConfiguredAccounts: is generated from mdm/profiles/com.apple.osxserver.account.yaml.

type Mail

type Mail struct {
	// A user-visible description of the email account, shown in the Mail and Settings
	// applications.
	EmailAccountDescription *string `plist:"EmailAccountDescription,omitempty" json:"EmailAccountDescription,omitempty"`
	// The full user name for the account. The system displays this name in sent messages.
	EmailAccountName *string `plist:"EmailAccountName,omitempty" json:"EmailAccountName,omitempty"`
	// Defines the protocol to use for the account.
	EmailAccountType string `plist:"EmailAccountType" json:"EmailAccountType"`
	// The full email address for the account. If this string isn't present in the payload, the
	// device prompts the user for this string during interactive profile installation in
	// Settings or System Preferences.
	EmailAddress *string `plist:"EmailAddress,omitempty" json:"EmailAddress,omitempty"`
	// The authentication scheme for incoming mail.
	IncomingMailServerAuthentication string `plist:"IncomingMailServerAuthentication" json:"IncomingMailServerAuthentication"`
	// The incoming mail server host name.
	IncomingMailServerHostName string `plist:"IncomingMailServerHostName" json:"IncomingMailServerHostName"`
	// The incoming mail server port number. If not set, the system uses the default port for a
	// given protocol.
	IncomingMailServerPortNumber *int64 `plist:"IncomingMailServerPortNumber,omitempty" json:"IncomingMailServerPortNumber,omitempty"`
	// If `true`, the system enables SSL for authentication on the incoming mail server.
	IncomingMailServerUseSSL *bool `plist:"IncomingMailServerUseSSL,omitempty" json:"IncomingMailServerUseSSL,omitempty"`
	// The user name for the email account, usually the same as the email address up to the "@"
	// character. If not set and the account requires authentication for incoming email, the
	// device prompts the user for this string during interactive profile installation in
	// Settings or System Preferences.
	IncomingMailServerUsername *string `plist:"IncomingMailServerUsername,omitempty" json:"IncomingMailServerUsername,omitempty"`
	// The password for the incoming mail server. Only use this in encrypted profiles.
	IncomingPassword *string `plist:"IncomingPassword,omitempty" json:"IncomingPassword,omitempty"`
	// The password for the outgoing mail server. Only use this in encrypted profiles.
	OutgoingPassword *string `plist:"OutgoingPassword,omitempty" json:"OutgoingPassword,omitempty"`
	// If `true`, the system prompts the user only once for the password, which it uses for
	// both outgoing and incoming mail.
	OutgoingPasswordSameAsIncomingPassword *bool `plist:"OutgoingPasswordSameAsIncomingPassword,omitempty" json:"OutgoingPasswordSameAsIncomingPassword,omitempty"`
	// The authentication scheme for outgoing mail.
	OutgoingMailServerAuthentication string `plist:"OutgoingMailServerAuthentication" json:"OutgoingMailServerAuthentication"`
	// The outgoing mail server host name.
	OutgoingMailServerHostName string `plist:"OutgoingMailServerHostName" json:"OutgoingMailServerHostName"`
	// The outgoing mail server port number. If not set, the system uses ports 25, 587, and
	// 465, in that order.
	OutgoingMailServerPortNumber *int64 `plist:"OutgoingMailServerPortNumber,omitempty" json:"OutgoingMailServerPortNumber,omitempty"`
	// If `true`, the system enables SSL authentication on the outgoing mail server.
	OutgoingMailServerUseSSL *bool `plist:"OutgoingMailServerUseSSL,omitempty" json:"OutgoingMailServerUseSSL,omitempty"`
	// The user name for the email account, usually the same as the email address up to the "@"
	// character. If not set and the account requires authentication for outgoing email, the
	// device prompts the user for this string during interactive profile installation in
	// Settings or System Preferences.
	OutgoingMailServerUsername *string `plist:"OutgoingMailServerUsername,omitempty" json:"OutgoingMailServerUsername,omitempty"`
	// If `true`, the system prevents moving messages out of this email account and into
	// another account. It also prevents forwarding or replying from an account other than the
	// recipient of the message.
	PreventMove *bool `plist:"PreventMove,omitempty" json:"PreventMove,omitempty"`
	// If `true`, the system prevents this account from sending mail in any app other than the
	// Apple Mail app.
	PreventAppSheet *bool `plist:"PreventAppSheet,omitempty" json:"PreventAppSheet,omitempty"`
	// If `true`, the system enables S/MIME encryption. The system ignores this key in iOS 10.0
	// and later.
	SMIMEEnabled *bool `plist:"SMIMEEnabled,omitempty" json:"SMIMEEnabled,omitempty"`
	// If `true`, the system enables S/MIME signing for this account.
	SMIMESigningEnabled *bool `plist:"SMIMESigningEnabled,omitempty" json:"SMIMESigningEnabled,omitempty"`
	// The payload UUID of the identity certificate used to sign messages sent from this
	// account.
	SMIMESigningCertificateUUID *string `plist:"SMIMESigningCertificateUUID,omitempty" json:"SMIMESigningCertificateUUID,omitempty"`
	// If `true`, the system enables S/MIME encryption for this account.
	SMIMEEncryptionEnabled *bool `plist:"SMIMEEncryptionEnabled,omitempty" json:"SMIMEEncryptionEnabled,omitempty"`
	// The UUID of the identity certificate used to decrypt messages sent to this account. The
	// system attaches the public certificate to outgoing mail to allow the user to receive
	// encrypted mail. When the user sends encrypted mail, the system uses the public
	// certificate to encrypt the copy of the mail in their Sent mailbox.
	SMIMEEncryptionCertificateUUID *string `plist:"SMIMEEncryptionCertificateUUID,omitempty" json:"SMIMEEncryptionCertificateUUID,omitempty"`
	// If `true`, the system displays the per-message encryption switch in the Mail Compose UI.
	// Deprecated in iOS 12.0. Use `SMIMEEnableEncryptionPerMessageSwitch` instead.
	SMIMEEnablePerMessageSwitch *bool `plist:"SMIMEEnablePerMessageSwitch,omitempty" json:"SMIMEEnablePerMessageSwitch,omitempty"`
	// If `true`, the system excludes this account from Recent Addresses syncing.
	DisableMailRecentsSyncing *bool `plist:"disableMailRecentsSyncing,omitempty" json:"disableMailRecentsSyncing,omitempty"`
	// If `true`, the system enables this account to use Mail Drop.
	AllowMailDrop *bool `plist:"allowMailDrop,omitempty" json:"allowMailDrop,omitempty"`
	// The path prefix for the IMAP mail server.
	IncomingMailServerIMAPPathPrefix *string `plist:"IncomingMailServerIMAPPathPrefix,omitempty" json:"IncomingMailServerIMAPPathPrefix,omitempty"`
	// If `true`, the user can turn S/MIME signing on or off in Settings.
	SMIMESigningUserOverrideable *bool `plist:"SMIMESigningUserOverrideable,omitempty" json:"SMIMESigningUserOverrideable,omitempty"`
	// If `true`, the user can select the signing identity.
	SMIMESigningCertificateUUIDUserOverrideable *bool `plist:"SMIMESigningCertificateUUIDUserOverrideable,omitempty" json:"SMIMESigningCertificateUUIDUserOverrideable,omitempty"`
	// If `true`, the system enables S/MIME encryption by default.
	SMIMEEncryptByDefault *bool `plist:"SMIMEEncryptByDefault,omitempty" json:"SMIMEEncryptByDefault,omitempty"`
	// If `true`, the user can turn encryption by default on/off, and encryption is on.
	SMIMEEncryptByDefaultUserOverrideable *bool `plist:"SMIMEEncryptByDefaultUserOverrideable,omitempty" json:"SMIMEEncryptByDefaultUserOverrideable,omitempty"`
	// If `true`, the user can select the S/MIME encryption identity, and encryption is on.
	SMIMEEncryptionCertificateUUIDUserOverrideable *bool `` /* 128-byte string literal not displayed */
	// If `true`, the system displays the per-message encryption switch in the Mail Compose UI.
	SMIMEEnableEncryptionPerMessageSwitch *bool `plist:"SMIMEEnableEncryptionPerMessageSwitch,omitempty" json:"SMIMEEnableEncryptionPerMessageSwitch,omitempty"`
	// The VPNUUID of the per-app VPN the account uses for network communication. Available in
	// iOS 14 and later.
	VPNUUID *string `plist:"VPNUUID,omitempty" json:"VPNUUID,omitempty"`
}

Mail: The payload that configures a Mail account.

Mail corresponds to mdm/profiles/com.apple.mail.managed.yaml (Mail).

func (*Mail) PayloadTypeName

func (*Mail) PayloadTypeName() string

PayloadTypeName returns "com.apple.mail.managed".

func (*Mail) SchemaPath

func (*Mail) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Mail) Validate

func (x *Mail) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ManagedMenuExtras

type ManagedMenuExtras struct {
	// The number of seconds to delay after login before adding or removing menu extras. If the
	// delay is too short, the menu extras don't appear, or disappear from the menu bar.
	DelaySeconds *float64 `plist:"delaySeconds,omitempty" json:"delaySeconds,omitempty"`
	// The maximum wait, in seconds, for all menu extras to be added or removed.
	MaxWaitSeconds *float64 `plist:"maxWaitSeconds,omitempty" json:"maxWaitSeconds,omitempty"`
	// If `true`, enables the AirPort menu extra.
	AirPortMenu *bool `plist:"AirPort.menu,omitempty" json:"AirPort.menu,omitempty"`
	// If `true`, enables the Battery menu extra.
	BatteryMenu *bool `plist:"Battery.menu,omitempty" json:"Battery.menu,omitempty"`
	// If `true`, enables the Bluetooth menu extra.
	BluetoothMenu *bool `plist:"Bluetooth.menu,omitempty" json:"Bluetooth.menu,omitempty"`
	// If `true`, enables the CPU menu extra.
	CPUMenu *bool `plist:"CPU.menu,omitempty" json:"CPU.menu,omitempty"`
	// If `true`, enables the Clock menu extra.
	ClockMenu *bool `plist:"Clock.menu,omitempty" json:"Clock.menu,omitempty"`
	// If `true`, enables the Displays menu extra.
	DisplaysMenu *bool `plist:"Displays.menu,omitempty" json:"Displays.menu,omitempty"`
	// If `true`, enables the Eject menu extra.
	EjectMenu *bool `plist:"Eject.menu,omitempty" json:"Eject.menu,omitempty"`
	// If `true`, enables the Fax menu extra.
	FaxMenu *bool `plist:"Fax.menu,omitempty" json:"Fax.menu,omitempty"`
	// If `true`, enables the HomeSync menu extra.
	HomeSyncMenu *bool `plist:"HomeSync.menu,omitempty" json:"HomeSync.menu,omitempty"`
	// If `true`, enables the iChat menu extra.
	IChatMenu *bool `plist:"iChat.menu,omitempty" json:"iChat.menu,omitempty"`
	// If `true`, enables the Ink menu extra.
	InkMenu *bool `plist:"Ink.menu,omitempty" json:"Ink.menu,omitempty"`
	// If `true`, enables the IrDA menu extra.
	IrDAMenu *bool `plist:"IrDA.menu,omitempty" json:"IrDA.menu,omitempty"`
	// If `true`, enables the PCCard menu extra.
	PCCardMenu *bool `plist:"PCCard.menu,omitempty" json:"PCCard.menu,omitempty"`
	// If `true`, enables the PPP menu extra.
	PPPMenu *bool `plist:"PPP.menu,omitempty" json:"PPP.menu,omitempty"`
	// If `true`, enables the PPPoE menu extra.
	PPPoEMenu *bool `plist:"PPPoE.menu,omitempty" json:"PPPoE.menu,omitempty"`
	// If `true`, enables the Remote Desktop menu extra.
	RemoteDesktopMenu *bool `plist:"RemoteDesktop.menu,omitempty" json:"RemoteDesktop.menu,omitempty"`
	// If `true`, enables the Script menu extra.
	ScriptMenuMenu *bool `plist:"Script Menu.menu,omitempty" json:"Script Menu.menu,omitempty"`
	// If `true`, enables the Spaces menu extra.
	SpacesMenu *bool `plist:"Spaces.menu,omitempty" json:"Spaces.menu,omitempty"`
	// If `true`, enables the Sync menu extra.
	SyncMenu *bool `plist:"Sync.menu,omitempty" json:"Sync.menu,omitempty"`
	// If `true`, enables the Text Input menu extra.
	TextInputMenu *bool `plist:"TextInput.menu,omitempty" json:"TextInput.menu,omitempty"`
	// If `true`, enables the TimeMachine menu extra.
	TimeMachineMenu *bool `plist:"TimeMachine.menu,omitempty" json:"TimeMachine.menu,omitempty"`
	// If `true`, enables the Universal Access menu extra.
	UniversalAccessMenu *bool `plist:"UniversalAccess.menu,omitempty" json:"UniversalAccess.menu,omitempty"`
	// If `true`, enables the User menu extra.
	UserMenu *bool `plist:"User.menu,omitempty" json:"User.menu,omitempty"`
	// If `true`, enables the VPN menu extra.
	VPNMenu *bool `plist:"VPN.menu,omitempty" json:"VPN.menu,omitempty"`
	// If `true`, enables the Volume menu extra.
	VolumeMenu *bool `plist:"Volume.menu,omitempty" json:"Volume.menu,omitempty"`
	// If `true`, enables the WWAN menu extra.
	WWANMenu *bool `plist:"WWAN.menu,omitempty" json:"WWAN.menu,omitempty"`
}

ManagedMenuExtras: The payload that configures menu extras.

ManagedMenuExtras corresponds to mdm/profiles/com.apple.mcxMenuExtras.yaml (Managed Menu Extras).

func (*ManagedMenuExtras) PayloadTypeName

func (*ManagedMenuExtras) PayloadTypeName() string

PayloadTypeName returns "com.apple.mcxMenuExtras".

func (*ManagedMenuExtras) SchemaPath

func (*ManagedMenuExtras) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ManagedMenuExtras) Validate

func (x *ManagedMenuExtras) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ManagedPreferences

type ManagedPreferences struct {
	// The dictionary containing app preference domains. The key names are application
	// preference domain identifiers (for example, `com.example.my-app`), or the string
	// `.GlobalPreferences` for the global domain. The values are the corresponding forced and
	// set-once preferences.
	PayloadContent map[string]ManagedPreferencesPreferenceDomain `plist:"PayloadContent,omitempty" json:"PayloadContent,omitempty"`
}

ManagedPreferences: The payload that configures managed preferences.

ManagedPreferences corresponds to mdm/profiles/com.apple.ManagedClient.preferences.yaml (Managed Preferences).

func (*ManagedPreferences) PayloadTypeName

func (*ManagedPreferences) PayloadTypeName() string

PayloadTypeName returns "com.apple.ManagedClient.preferences".

func (*ManagedPreferences) SchemaPath

func (*ManagedPreferences) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ManagedPreferences) Validate

func (x *ManagedPreferences) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ManagedPreferencesPreferenceDomain

type ManagedPreferencesPreferenceDomain struct {
	// The dictionary of forced settings.
	Forced []ManagedPreferencesPreferenceDomainForced `plist:"Forced,omitempty" json:"Forced,omitempty"`
	// The dictionary of one-time settings.
	SetOnce []ManagedPreferencesPreferenceDomainSetOnce `plist:"Set-Once,omitempty" json:"Set-Once,omitempty"`
}

ManagedPreferencesPreferenceDomain: The dictionary containing app preference domains.

type ManagedPreferencesPreferenceDomainForced

type ManagedPreferencesPreferenceDomainForced struct {
	// The dictionary of settings.
	McxPreferenceSettings map[string]any `plist:"mcx_preference_settings,omitempty" json:"mcx_preference_settings,omitempty"`
}

ManagedPreferencesPreferenceDomainForced: is generated from mdm/profiles/com.apple.ManagedClient.preferences.yaml.

type ManagedPreferencesPreferenceDomainSetOnce

type ManagedPreferencesPreferenceDomainSetOnce struct {
	// The dictionary of settings.
	McxPreferenceSettings map[string]any `plist:"mcx_preference_settings,omitempty" json:"mcx_preference_settings,omitempty"`
}

ManagedPreferencesPreferenceDomainSetOnce: is generated from mdm/profiles/com.apple.ManagedClient.preferences.yaml.

type MediaManagementAllowedMedia

type MediaManagementAllowedMedia struct {
	// The media type dictionary that defines volumes to eject when the user logs out.
	LogoutEject *MediaManagementAllowedMediaMediaItems `plist:"logout-eject,omitempty" json:"logout-eject,omitempty"`
	// The media type dictionary that controls volume mounting.
	MountControls *MediaManagementAllowedMediaMediaItems `plist:"mount-controls,omitempty" json:"mount-controls,omitempty"`
	// The media type dictionary that controls volume unmounting.
	UnmountControls *MediaManagementAllowedMediaMediaItems `plist:"unmount-controls,omitempty" json:"unmount-controls,omitempty"`
}

MediaManagementAllowedMedia: The payload that configures media management.

MediaManagementAllowedMedia corresponds to mdm/profiles/com.apple.systemuiserver.yaml (Media Management: Allowed Media).

func (*MediaManagementAllowedMedia) PayloadTypeName

func (*MediaManagementAllowedMedia) PayloadTypeName() string

PayloadTypeName returns "com.apple.systemuiserver".

func (*MediaManagementAllowedMedia) SchemaPath

func (*MediaManagementAllowedMedia) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*MediaManagementAllowedMedia) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type MediaManagementAllowedMediaMediaItems

type MediaManagementAllowedMediaMediaItems struct {
	// Unused; set to an empty string.
	AllMedia *string `plist:"all-media,omitempty" json:"all-media,omitempty"`
	// A media action string or an array of media action strings.
	Cd []string `plist:"cd,omitempty" json:"cd,omitempty"`
	// A media action string or an array of media action strings.
	Dvd []string `plist:"dvd,omitempty" json:"dvd,omitempty"`
	// A media action string or an array of media action strings.
	Bd []string `plist:"bd,omitempty" json:"bd,omitempty"`
	// A media action string or an array of media action strings.
	Blankcd []string `plist:"blankcd,omitempty" json:"blankcd,omitempty"`
	// A media action string or an array of media action strings.
	Blankdvd []string `plist:"blankdvd,omitempty" json:"blankdvd,omitempty"`
	// A media action string or an array of media action strings.
	Blankbd []string `plist:"blankbd,omitempty" json:"blankbd,omitempty"`
	// A media action string or an array of media action strings.
	Dvdram []string `plist:"dvdram,omitempty" json:"dvdram,omitempty"`
	// A media action string or an array of media action strings.
	DiskImage []string `plist:"disk-image,omitempty" json:"disk-image,omitempty"`
	// A media action string or an array of media action strings.
	HarddiskInternal []string `plist:"harddisk-internal,omitempty" json:"harddisk-internal,omitempty"`
	// A string or an array of media action strings. Internally installed SD cards and USB
	// flash drives are included in the hard disk-external category.
	HarddiskExternal []string `plist:"harddisk-external,omitempty" json:"harddisk-external,omitempty"`
	// A media action string or an array of media action strings.
	Networkdisk []string `plist:"networkdisk,omitempty" json:"networkdisk,omitempty"`
}

MediaManagementAllowedMediaMediaItems: The media type dictionary that defines volumes to eject when the user logs out.

type MediaManagementDiscBurning

type MediaManagementDiscBurning struct {
	// Configure disc-burn. Allowed values: - `off`: The system disables disc burning. - `on`:
	// The system allows normal default operation. Setting this key to `on` doesn't enable disc
	// burn support if other mechanisms or preferences disabled it. Needs to be enabled with
	// the `Finder` profile. - `authenticate`: The system requires authentication.
	BurnSupport string `plist:"BurnSupport" json:"BurnSupport"`
}

MediaManagementDiscBurning: The payload that configures disc-burning settings.

MediaManagementDiscBurning corresponds to mdm/profiles/com.apple.DiscRecording.yaml (Media Management: Disc Burning).

func (*MediaManagementDiscBurning) PayloadTypeName

func (*MediaManagementDiscBurning) PayloadTypeName() string

PayloadTypeName returns "com.apple.DiscRecording".

func (*MediaManagementDiscBurning) SchemaPath

func (*MediaManagementDiscBurning) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*MediaManagementDiscBurning) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type MobileAccounts

type MobileAccounts struct {
	// If `true`, the system creates the mobile account at login time.
	ComAppleCachedaccountsCreateAtLogin *bool `plist:"com.apple.cachedaccounts.CreateAtLogin,omitempty" json:"com.apple.cachedaccounts.CreateAtLogin,omitempty"`
	// If `true`, the system asks the user whether to create the mobile account and it allows
	// the user to not create it.
	ComAppleCachedaccountsWarnOnCreate *bool `plist:"com.apple.cachedaccounts.WarnOnCreate,omitempty" json:"com.apple.cachedaccounts.WarnOnCreate,omitempty"`
	// If `true`, the system allows the user to stop the prompts about mobile account creation
	// every time the user logs in. This key is only valid if
	// `com.apple.cachedaccounts.WarnOnCreate` is `true`.
	CachedaccountsWarnOnCreateAllowNever *bool `plist:"cachedaccounts.WarnOnCreate.allowNever,omitempty" json:"cachedaccounts.WarnOnCreate.allowNever,omitempty"`
	// The minimum number of seconds a mobile account can exist before the system makes an
	// automatic attempt to remove the mobile account. Set to `0` to attempt removing it at the
	// next login or logout. Set to `-1` to never attempt removing the mobile account.
	CachedaccountsExpiryDeleteDisusedSeconds *int64 `plist:"cachedaccounts.expiry.delete.disusedSeconds,omitempty" json:"cachedaccounts.expiry.delete.disusedSeconds,omitempty"`
	// If `true`, the system bypasses the secure token authorization dialog. This dialog only
	// appears on APFS volumes.
	CachedaccountsAskForSecureTokenAuthBypass *bool `plist:"cachedaccounts.askForSecureTokenAuthBypass,omitempty" json:"cachedaccounts.askForSecureTokenAuthBypass,omitempty"`
}

MobileAccounts: The payload that configures mobile accounts on the device.

MobileAccounts corresponds to mdm/profiles/com.apple.MCX(Mobililty).yaml (Mobile Accounts).

func (*MobileAccounts) PayloadTypeName

func (*MobileAccounts) PayloadTypeName() string

PayloadTypeName returns "com.apple.MCX".

func (*MobileAccounts) SchemaPath

func (*MobileAccounts) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*MobileAccounts) Validate

func (x *MobileAccounts) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type NSExtensionManagement

type NSExtensionManagement struct {
	// An array of bundle identifiers for allowed extensions.
	AllowedExtensions []string `plist:"AllowedExtensions,omitempty" json:"AllowedExtensions,omitempty"`
	// An array of bundle identifiers for extensions that the system doesn't allow to run.
	DeniedExtensions []string `plist:"DeniedExtensions,omitempty" json:"DeniedExtensions,omitempty"`
	// An array of extension points for extensions that the system doesn't allow to run.
	DeniedExtensionPoints []string `plist:"DeniedExtensionPoints,omitempty" json:"DeniedExtensionPoints,omitempty"`
}

NSExtensionManagement: The payload that configures the extensions that the system allows or disallows to run on the device.

NSExtensionManagement corresponds to mdm/profiles/com.apple.NSExtension.yaml (NSExtension Management).

func (*NSExtensionManagement) PayloadTypeName

func (*NSExtensionManagement) PayloadTypeName() string

PayloadTypeName returns "com.apple.NSExtension".

func (*NSExtensionManagement) SchemaPath

func (*NSExtensionManagement) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*NSExtensionManagement) Validate

func (x *NSExtensionManagement) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type NetworkProxyConfiguration

type NetworkProxyConfiguration struct {
	// The dictionary containing all the proxies for this device.
	Proxies NetworkProxyConfigurationProxies `plist:"Proxies,omitempty" json:"Proxies,omitempty"`
}

NetworkProxyConfiguration: The payload that configures network proxies for a device.

NetworkProxyConfiguration corresponds to mdm/profiles/com.apple.SystemConfiguration.yaml (Network Proxy Configuration).

func (*NetworkProxyConfiguration) PayloadTypeName

func (*NetworkProxyConfiguration) PayloadTypeName() string

PayloadTypeName returns "com.apple.SystemConfiguration".

func (*NetworkProxyConfiguration) SchemaPath

func (*NetworkProxyConfiguration) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*NetworkProxyConfiguration) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type NetworkProxyConfigurationProxies

type NetworkProxyConfigurationProxies struct {
	// If `true`, enables FTP proxy.
	FTPEnable *int64 `plist:"FTPEnable,omitempty" json:"FTPEnable,omitempty"`
	// If `true`, enables passive FTP mode.
	FTPPassive *int64 `plist:"FTPPassive,omitempty" json:"FTPPassive,omitempty"`
	// The FTP proxy port.
	FTPPort *int64 `plist:"FTPPort,omitempty" json:"FTPPort,omitempty"`
	// The host name or IP address for the FTP proxy.
	FTPProxy *string `plist:"FTPProxy,omitempty" json:"FTPProxy,omitempty"`
	// If `true`, enables gopher proxy.
	GopherEnable *int64 `plist:"GopherEnable,omitempty" json:"GopherEnable,omitempty"`
	// The gopher proxy port.
	GopherPort *int64 `plist:"GopherPort,omitempty" json:"GopherPort,omitempty"`
	// The host name or IP address for the gopher proxy.
	GopherProxy *string `plist:"GopherProxy,omitempty" json:"GopherProxy,omitempty"`
	// If `true`, enables web proxy.
	HTTPEnable *int64 `plist:"HTTPEnable,omitempty" json:"HTTPEnable,omitempty"`
	// The web proxy port.
	HTTPPort *int64 `plist:"HTTPPort,omitempty" json:"HTTPPort,omitempty"`
	// The host name or IP address for the web proxy.
	HTTPProxy *string `plist:"HTTPProxy,omitempty" json:"HTTPProxy,omitempty"`
	// If `true`, enables secure web proxy.
	HTTPSEnable *int64 `plist:"HTTPSEnable,omitempty" json:"HTTPSEnable,omitempty"`
	// The secure web proxy port.
	HTTPSPort *int64 `plist:"HTTPSPort,omitempty" json:"HTTPSPort,omitempty"`
	// The host name or IP address for the secure web proxy.
	HTTPSProxy *string `plist:"HTTPSProxy,omitempty" json:"HTTPSProxy,omitempty"`
	// If `true`, enables automatic proxy configuration.
	ProxyAutoConfigEnable *int64 `plist:"ProxyAutoConfigEnable,omitempty" json:"ProxyAutoConfigEnable,omitempty"`
	// The automatic proxy configuration URL.
	ProxyAutoConfigURLString *string `plist:"ProxyAutoConfigURLString,omitempty" json:"ProxyAutoConfigURLString,omitempty"`
	// If 1, allows client to log into captive portal network.
	ProxyCaptiveLoginAllowed *int64 `plist:"ProxyCaptiveLoginAllowed,omitempty" json:"ProxyCaptiveLoginAllowed,omitempty"`
	// If `true`, enable streaming proxy.
	RTSPEnable *int64 `plist:"RTSPEnable,omitempty" json:"RTSPEnable,omitempty"`
	// The streaming proxy port.
	RTSPPort *int64 `plist:"RTSPPort,omitempty" json:"RTSPPort,omitempty"`
	// The host name or IP address for the streaming proxy.
	RTSPProxy *string `plist:"RTSPProxy,omitempty" json:"RTSPProxy,omitempty"`
	// If `true`, enable the SOCKS proxy.
	SOCKSEnable *int64 `plist:"SOCKSEnable,omitempty" json:"SOCKSEnable,omitempty"`
	// The SOCKS proxy port.
	SOCKSPortinteger *int64 `plist:"SOCKSPortinteger,omitempty" json:"SOCKSPortinteger,omitempty"`
	// The host name or IP address for the SOCKS proxy.
	SOCKSProxy *string `plist:"SOCKSProxy,omitempty" json:"SOCKSProxy,omitempty"`
	// If `1`, enables fallback. Default is `1`.
	FallBackAllowed *int64 `plist:"FallBackAllowed,omitempty" json:"FallBackAllowed,omitempty"`
	// The list of hosts and domains that should bypass proxy settings.
	ExceptionsList []string `plist:"ExceptionsList,omitempty" json:"ExceptionsList,omitempty"`
}

NetworkProxyConfigurationProxies: The dictionary containing all the proxies for this device.

type NetworkUsageRules

type NetworkUsageRules struct {
	// An array of application rules, that apply to only managed apps.
	ApplicationRules []NetworkUsageRulesApplicationRules `plist:"ApplicationRules,omitempty" json:"ApplicationRules,omitempty"`
	// An array of SIM rules, that apply to all apps.
	SIMRules []NetworkUsageRulesSIMRules `plist:"SIMRules,omitempty" json:"SIMRules,omitempty"`
}

NetworkUsageRules: The payload that configures network-usage rules.

NetworkUsageRules corresponds to mdm/profiles/com.apple.networkusagerules.yaml (Network Usage Rules).

func (*NetworkUsageRules) PayloadTypeName

func (*NetworkUsageRules) PayloadTypeName() string

PayloadTypeName returns "com.apple.networkusagerules".

func (*NetworkUsageRules) SchemaPath

func (*NetworkUsageRules) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*NetworkUsageRules) Validate

func (x *NetworkUsageRules) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type NetworkUsageRulesApplicationRules

type NetworkUsageRulesApplicationRules struct {
	// A list of managed app identifiers, as strings, that must follow the associated rules. If
	// this key is missing, the rules apply to all managed apps on the device.
	AppIdentifierMatches []string `plist:"AppIdentifierMatches,omitempty" json:"AppIdentifierMatches,omitempty"`
	// If `false`, disables cellular data while roaming for all matching managed apps.
	AllowRoamingCellularData *bool `plist:"AllowRoamingCellularData,omitempty" json:"AllowRoamingCellularData,omitempty"`
	// If `false`, disables cellular data for all matching managed apps.
	AllowCellularData *bool `plist:"AllowCellularData,omitempty" json:"AllowCellularData,omitempty"`
}

NetworkUsageRulesApplicationRules: The application rules dictionary.

type NetworkUsageRulesSIMRules

type NetworkUsageRulesSIMRules struct {
	// One or more ICCIDs of SIM cards for which the `WiFiAssistPolicy` applies. All ICCIDs in
	// all installed Network Usage Rules payloads must be unique. An example ICCID is
	// `89310410106543789301`.
	ICCIDs []string `plist:"ICCIDs,omitempty" json:"ICCIDs,omitempty"`
	// The Wi-Fi Assist policy to apply to the SIM cards specified in the ICCIDs. Allowed
	// values:
	WiFiAssistPolicy int64 `plist:"WiFiAssistPolicy" json:"WiFiAssistPolicy"`
}

NetworkUsageRulesSIMRules: The policy for individual SIM cards.

type Notifications

type Notifications struct {
	// An array of notification settings dictionaries.
	NotificationSettings []NotificationsNotificationSettings `plist:"NotificationSettings,omitempty" json:"NotificationSettings,omitempty"`
}

Notifications: The payload that configures notifications.

Notifications corresponds to mdm/profiles/com.apple.notificationsettings.yaml (Notifications).

func (*Notifications) PayloadTypeName

func (*Notifications) PayloadTypeName() string

PayloadTypeName returns "com.apple.notificationsettings".

func (*Notifications) SchemaPath

func (*Notifications) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Notifications) Validate

func (x *Notifications) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type NotificationsNotificationSettings

type NotificationsNotificationSettings struct {
	// The bundle identifier of the app to which to apply these notification settings.
	BundleIdentifier string `plist:"BundleIdentifier" json:"BundleIdentifier"`
	// If `true`, enables notifications for this app.
	NotificationsEnabled *bool `plist:"NotificationsEnabled,omitempty" json:"NotificationsEnabled,omitempty"`
	// If `true`, enables notifications in the notification center for this app.
	ShowInNotificationCenter *bool `plist:"ShowInNotificationCenter,omitempty" json:"ShowInNotificationCenter,omitempty"`
	// If `true`, enables notifications on the Lock Screen for this app.
	ShowInLockScreen *bool `plist:"ShowInLockScreen,omitempty" json:"ShowInLockScreen,omitempty"`
	// The type of alert for notifications for this app:
	AlertType *int64 `plist:"AlertType,omitempty" json:"AlertType,omitempty"`
	// If `true`, enables badges for this app.
	BadgesEnabled *bool `plist:"BadgesEnabled,omitempty" json:"BadgesEnabled,omitempty"`
	// If `true`, enables sounds for this app.
	SoundsEnabled *bool `plist:"SoundsEnabled,omitempty" json:"SoundsEnabled,omitempty"`
	// If `true`, enables notifications in CarPlay for this app.
	ShowInCarPlay *bool `plist:"ShowInCarPlay,omitempty" json:"ShowInCarPlay,omitempty"`
	// If `true`, enables critical alerts that can ignore Do Not Disturb and ringer settings
	// for this app.
	CriticalAlertEnabled *bool `plist:"CriticalAlertEnabled,omitempty" json:"CriticalAlertEnabled,omitempty"`
	// The type of grouping for notifications for this app:
	GroupingType *int64 `plist:"GroupingType,omitempty" json:"GroupingType,omitempty"`
	// The type previews for notifications. This key overrides the value at
	// Settings>Notifications>Show Previews.
	PreviewType *int64 `plist:"PreviewType,omitempty" json:"PreviewType,omitempty"`
}

NotificationsNotificationSettings: is generated from mdm/profiles/com.apple.notificationsettings.yaml.

type ParentalControlDictationAndProfanity

type ParentalControlDictationAndProfanity struct {
	// If `false`, suppresses profanity. Use `forceAssistantProfanityFilter` in Restrictions
	// instead.
	ProfanityAllowed *bool `plist:"Profanity Allowed,omitempty" json:"Profanity Allowed,omitempty"`
	// If `false`, disables dictation. Use `allowDictation` in Restrictions instead.
	IronwoodAllowed *bool `plist:"Ironwood Allowed,omitempty" json:"Ironwood Allowed,omitempty"`
}

ParentalControlDictationAndProfanity: The payload that configures parental control for dictation and profanity.

ParentalControlDictationAndProfanity corresponds to mdm/profiles/com.apple.ironwood.support.yaml (Parental Control: Dictation and Profanity).

func (*ParentalControlDictationAndProfanity) PayloadTypeName

func (*ParentalControlDictationAndProfanity) PayloadTypeName() string

PayloadTypeName returns "com.apple.ironwood.support".

func (*ParentalControlDictationAndProfanity) SchemaPath

SchemaPath returns the Apple schema file this type was generated from.

func (*ParentalControlDictationAndProfanity) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ParentalControlsApplicationRestrictions

type ParentalControlsApplicationRestrictions struct {
	// If `true`, enables app access restrictions.
	FamilyControlsEnabled bool `plist:"familyControlsEnabled" json:"familyControlsEnabled"`
	// The allow list of app item dictionaries.
	WhiteList []ParentalControlsApplicationRestrictionsApplicationItem `plist:"whiteList,omitempty" json:"whiteList,omitempty"`
	// The paths to apps in the deny list. This property is deprecated in macOS 10.15 and
	// later.
	PathBlackList []string `plist:"pathBlackList,omitempty" json:"pathBlackList,omitempty"`
	// The paths to apps in the allow list. This property is deprecated in macOS 10.15 and
	// later.
	PathWhiteList []string `plist:"pathWhiteList,omitempty" json:"pathWhiteList,omitempty"`
}

ParentalControlsApplicationRestrictions: The payload that configures parental controls for apps.

ParentalControlsApplicationRestrictions corresponds to mdm/profiles/com.apple.applicationaccess.new.yaml (Parental Controls: Application Restrictions).

func (*ParentalControlsApplicationRestrictions) PayloadTypeName

PayloadTypeName returns "com.apple.applicationaccess.new".

func (*ParentalControlsApplicationRestrictions) SchemaPath

SchemaPath returns the Apple schema file this type was generated from.

func (*ParentalControlsApplicationRestrictions) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ParentalControlsApplicationRestrictionsApplicationItem

type ParentalControlsApplicationRestrictionsApplicationItem struct {
	// The bundle ID of the app.
	BundleID string `plist:"bundleID" json:"bundleID"`
	// The identifier of the app. Obtain this value from the Security framework using
	// `SecCodeCopyDesignatedRequirement`.
	AppID []byte `plist:"appID,omitempty" json:"appID,omitempty"`
	// The signature for an unsigned binary.
	DetachedSignature []byte `plist:"detachedSignature,omitempty" json:"detachedSignature,omitempty"`
	// If `true`, this app isn't added to the allow list.
	Disabled *bool `plist:"disabled,omitempty" json:"disabled,omitempty"`
	// An array of nested helper applications.
	SubApps []ParentalControlsApplicationRestrictionsApplicationItem `plist:"subApps,omitempty" json:"subApps,omitempty"`
	// The name used for display purposes.
	DisplayName *string `plist:"displayName,omitempty" json:"displayName,omitempty"`
}

ParentalControlsApplicationRestrictionsApplicationItem: A dictionary defining an app for parental control.

type ParentalControlsContentFilter

type ParentalControlsContentFilter struct {
	// If `true`, enables web content filters.
	RestrictWeb bool `plist:"restrictWeb" json:"restrictWeb"`
	// If `true`, filters content automatically.
	UseContentFilter *bool `plist:"useContentFilter,omitempty" json:"useContentFilter,omitempty"`
	// If `true`, enables web content filters.
	AllowListEnabled *bool `plist:"allowListEnabled,omitempty" json:"allowListEnabled,omitempty"`
	// Use `allowListEnabled` instead.
	WhitelistEnabled *bool `plist:"whitelistEnabled,omitempty" json:"whitelistEnabled,omitempty"`
	// An array of sites that defines an allow list. If specified, this defines additional
	// allowed sites besides those in the automated allow list and deny list, including
	// disallowed adult sites.
	SiteAllowList []ParentalControlsContentFilterSiteAllowList `plist:"siteAllowList,omitempty" json:"siteAllowList,omitempty"`
	// Use `siteAllowList` instead.
	SiteWhitelist []ParentalControlsContentFilterSiteWhitelist `plist:"siteWhitelist,omitempty" json:"siteWhitelist,omitempty"`
	// The array of URLs that defines an allow list. When `restrictWeb` and `useContentFilter`
	// are enabled, only URLs in the allow list are available to the user.
	FilterAllowList []string `plist:"filterAllowList,omitempty" json:"filterAllowList,omitempty"`
	// Use `filterAllowList` instead.
	FilterWhitelist []string `plist:"filterWhitelist,omitempty" json:"filterWhitelist,omitempty"`
	// The array of URLs that defines a deny list. When `restrictWeb` and `useContentFilter`
	// are enabled, no URLs in the deny list are available to the user.
	FilterDenyList []string `plist:"filterDenyList,omitempty" json:"filterDenyList,omitempty"`
	// Use `filterDenyList` instead.
	FilterBlacklist []string `plist:"filterBlacklist,omitempty" json:"filterBlacklist,omitempty"`
}

ParentalControlsContentFilter: The payload that configures the parental control web content filters.

ParentalControlsContentFilter corresponds to mdm/profiles/com.apple.familycontrols.contentfilter.yaml (Parental Controls: Content Filter).

func (*ParentalControlsContentFilter) PayloadTypeName

func (*ParentalControlsContentFilter) PayloadTypeName() string

PayloadTypeName returns "com.apple.familycontrols.contentfilter".

func (*ParentalControlsContentFilter) SchemaPath

func (*ParentalControlsContentFilter) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ParentalControlsContentFilter) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ParentalControlsContentFilterSiteAllowList

type ParentalControlsContentFilterSiteAllowList struct {
	// The site prefix, including the `http(s)` scheme.
	Address string `plist:"address" json:"address"`
	// The site page title.
	PageTitle *string `plist:"pageTitle,omitempty" json:"pageTitle,omitempty"`
}

ParentalControlsContentFilterSiteAllowList: A dictionary defining a site for the allow list.

type ParentalControlsContentFilterSiteWhitelist

type ParentalControlsContentFilterSiteWhitelist struct {
	// The site prefix, including http(s) scheme.
	Address string `plist:"address" json:"address"`
	// The site page title.
	PageTitle *string `plist:"pageTitle,omitempty" json:"pageTitle,omitempty"`
}

ParentalControlsContentFilterSiteWhitelist: A dictionary defining a site for the allow list.

type ParentalControlsDashboardWidgetRestrictions

type ParentalControlsDashboardWidgetRestrictions struct {
	// If `true`, enables the widget allow list.
	WhiteListEnabled bool `plist:"whiteListEnabled" json:"whiteListEnabled"`
	// An array of widget item dictionaries that are allowed.
	WhiteList []ParentalControlsDashboardWidgetRestrictionsWhiteList `plist:"WhiteList,omitempty" json:"WhiteList,omitempty"`
}

ParentalControlsDashboardWidgetRestrictions: The payload that configures allowed dashboard widgets.

ParentalControlsDashboardWidgetRestrictions corresponds to mdm/profiles/com.apple.dashboard.yaml (Parental Controls: Dashboard Widget Restrictions).

func (*ParentalControlsDashboardWidgetRestrictions) PayloadTypeName

PayloadTypeName returns "com.apple.dashboard".

func (*ParentalControlsDashboardWidgetRestrictions) SchemaPath

SchemaPath returns the Apple schema file this type was generated from.

func (*ParentalControlsDashboardWidgetRestrictions) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ParentalControlsDashboardWidgetRestrictionsWhiteList

type ParentalControlsDashboardWidgetRestrictionsWhiteList struct {
	// The type of allow list item. Set to `bundleID` to use a widget's bundle ID as its main
	// ID.
	Type string `plist:"Type" json:"Type"`
	// The bundle ID of a widget.
	ID string `plist:"ID" json:"ID"`
}

ParentalControlsDashboardWidgetRestrictionsWhiteList: The widget item dictionary.

type ParentalControlsDictionary

type ParentalControlsDictionary struct {
	// If `true`, enables parental controls dictionary restrictions.
	ParentalControl bool `plist:"parentalControl" json:"parentalControl"`
}

ParentalControlsDictionary: The payload that configures parental control dictionary restrictions.

ParentalControlsDictionary corresponds to mdm/profiles/com.apple.Dictionary.yaml (Parental Controls: Dictionary).

func (*ParentalControlsDictionary) PayloadTypeName

func (*ParentalControlsDictionary) PayloadTypeName() string

PayloadTypeName returns "com.apple.Dictionary".

func (*ParentalControlsDictionary) SchemaPath

func (*ParentalControlsDictionary) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ParentalControlsDictionary) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ParentalControlsGameCenter

type ParentalControlsGameCenter struct {
	// If `true`, enables Game Center.
	GKFeatureGameCenterAllowed *bool `plist:"GKFeatureGameCenterAllowed,omitempty" json:"GKFeatureGameCenterAllowed,omitempty"`
	// If `true`, allows account modifications.
	GKFeatureAccountModificationAllowed *bool `plist:"GKFeatureAccountModificationAllowed,omitempty" json:"GKFeatureAccountModificationAllowed,omitempty"`
	// If `true`, allows adding Game Center friends.
	GKFeatureAddingGameCenterFriendsAllowed *bool `plist:"GKFeatureAddingGameCenterFriendsAllowed,omitempty" json:"GKFeatureAddingGameCenterFriendsAllowed,omitempty"`
	// If `true`, allows multiplayer gaming.
	GKFeatureMultiplayerGamingAllowed *bool `plist:"GKFeatureMultiplayerGamingAllowed,omitempty" json:"GKFeatureMultiplayerGamingAllowed,omitempty"`
}

ParentalControlsGameCenter: The payload that configures Game Center parental controls.

ParentalControlsGameCenter corresponds to mdm/profiles/com.apple.gamed.yaml (Parental Controls: Game Center).

func (*ParentalControlsGameCenter) PayloadTypeName

func (*ParentalControlsGameCenter) PayloadTypeName() string

PayloadTypeName returns "com.apple.gamed".

func (*ParentalControlsGameCenter) SchemaPath

func (*ParentalControlsGameCenter) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ParentalControlsGameCenter) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ParentalControlsTimeLimits

type ParentalControlsTimeLimits struct {
	// If `true`, enables time limits.
	FamilyControlsEnabled bool `plist:"familyControlsEnabled" json:"familyControlsEnabled"`
	// The time limits to enforce if `familyControlsEnabled` is enabled.
	TimeLimits *ParentalControlsTimeLimitsTimeLimits `plist:"time-limits,omitempty" json:"time-limits,omitempty"`
}

ParentalControlsTimeLimits: The payload that configures parental control time limits.

ParentalControlsTimeLimits corresponds to mdm/profiles/com.apple.familycontrols.timelimits.v2.yaml (Parental Controls: Time Limits).

func (*ParentalControlsTimeLimits) PayloadTypeName

func (*ParentalControlsTimeLimits) PayloadTypeName() string

PayloadTypeName returns "com.apple.familycontrols.timelimits.v2".

func (*ParentalControlsTimeLimits) SchemaPath

func (*ParentalControlsTimeLimits) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ParentalControlsTimeLimits) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ParentalControlsTimeLimitsAllowance

type ParentalControlsTimeLimitsAllowance struct {
	// If `true`, enable these settings.
	Enabled bool `plist:"enabled" json:"enabled"`
	// The type of day range, which has the following possible values:
	RangeType int64 `plist:"rangeType" json:"rangeType"`
	// The curfew start time, in the format '%d:%d:%d'.
	Start *string `plist:"start,omitempty" json:"start,omitempty"`
	// The curfew end time, in the format `%d:%d:%d`.
	End *string `plist:"end,omitempty" json:"end,omitempty"`
	// The allowance for that day, in seconds.
	SecondsPerDay *int64 `plist:"secondsPerDay,omitempty" json:"secondsPerDay,omitempty"`
}

ParentalControlsTimeLimitsAllowance: The weekday allowance settings.

type ParentalControlsTimeLimitsTimeLimits

type ParentalControlsTimeLimitsTimeLimits struct {
	// The weekday allowance settings.
	WeekdayAllowance *ParentalControlsTimeLimitsAllowance `plist:"weekday-allowance,omitempty" json:"weekday-allowance,omitempty"`
	// The weekday curfew settings.
	WeekdayCurfew *ParentalControlsTimeLimitsAllowance `plist:"weekday-curfew,omitempty" json:"weekday-curfew,omitempty"`
	// The weekend allowance settings.
	WeekendAllowance *ParentalControlsTimeLimitsAllowance `plist:"weekend-allowance,omitempty" json:"weekend-allowance,omitempty"`
	// The weekend curfew settings.
	WeekendCurfew *ParentalControlsTimeLimitsAllowance `plist:"weekend-curfew,omitempty" json:"weekend-curfew,omitempty"`
}

ParentalControlsTimeLimitsTimeLimits: The time limits to enforce if `familyControlsEnabled` is enabled.

type Passcode

type Passcode struct {
	// If `false`, the system prevents use of a simple passcode. A simple passcode contains
	// repeated characters, or increasing or decreasing characters, such as `123` or `CBA`.
	AllowSimple *bool `plist:"allowSimple,omitempty" json:"allowSimple,omitempty"`
	// If `true`, the system forces the user to enter a PIN.
	ForcePIN *bool `plist:"forcePIN,omitempty" json:"forcePIN,omitempty"`
	// The number of failed passcode attempts that the system allows the user before it erases
	// or locks the device. After six failed attempts, the device imposes a time delay before
	// the user can enter a passcode again. The time delay increases with each failed attempt.
	// On macOS, set `minutesUntilFailedLoginReset` to define the time delay. The time delay
	// begins after the sixth attempt, so if `MaximumFailedAttempts` is six or lower, the
	// system has no time delay and triggers the erase or lock as soon as the user exceeds the
	// limit.
	MaxFailedAttempts *int64 `plist:"maxFailedAttempts,omitempty" json:"maxFailedAttempts,omitempty"`
	// The maximum number of minutes for which the device can be idle without the user
	// unlocking it, before the system locks it. When this limit is reached, the system locks
	// the device and the passcode is required to unlock it. The user can edit this setting,
	// but the value can't exceed the `maxInactivity` value.
	MaxInactivity *int64 `plist:"maxInactivity,omitempty" json:"maxInactivity,omitempty"`
	// The number of days for which the passcode can remain unchanged. After this number of
	// days, the system forces the user to change the passcode before it unlocks the device.
	MaxPINAgeInDays *int64 `plist:"maxPINAgeInDays,omitempty" json:"maxPINAgeInDays,omitempty"`
	// The minimum number of complex characters that a passcode needs to contain. A _complex_
	// character is a character other than a number or a letter, such as `&`, `%`, `$`, and
	// `#`.
	MinComplexChars *int64 `plist:"minComplexChars,omitempty" json:"minComplexChars,omitempty"`
	// The minimum overall length of the passcode. This value is independent of the value for
	// `minComplexChars`.
	MinLength *int64 `plist:"minLength,omitempty" json:"minLength,omitempty"`
	// If `true`, the system requires alphabetic characters instead of only numeric characters.
	RequireAlphanumeric *bool `plist:"requireAlphanumeric,omitempty" json:"requireAlphanumeric,omitempty"`
	// This value defines _N_, where the new passcode must be unique within the last _N_
	// entries in the passcode history.
	PinHistory *int64 `plist:"pinHistory,omitempty" json:"pinHistory,omitempty"`
	// The maximum grace period, in minutes, to unlock the phone without entering a passcode.
	// The default is `0`, which is no grace period and requires a passcode immediately. On
	// macOS, the system translates this grace period value to screen-saver settings.
	MaxGracePeriod *int64 `plist:"maxGracePeriod,omitempty" json:"maxGracePeriod,omitempty"`
	// The number of minutes before the system resets the login after the maximum number of
	// unsuccessful login attempts is reached. This key requires setting `maxFailedAttempts`.
	// Available in macOS 10.10 and later.
	MinutesUntilFailedLoginReset *int64 `plist:"minutesUntilFailedLoginReset,omitempty" json:"minutesUntilFailedLoginReset,omitempty"`
	// If `true`, the system causes a password reset to occur the next time the user tries to
	// authenticate. If this key is set in a device profile, the setting takes effect for all
	// users, and admin authentications may fail until the admin user password is also reset.
	// Available in macOS 10.13 and later.
	ChangeAtNextAuth *bool `plist:"changeAtNextAuth,omitempty" json:"changeAtNextAuth,omitempty"`
	// Specifies a regular expression, and its description, used to enforce password
	// compliance. Use the simpler passcode restrictions whenever possible, and rely on regular
	// expression matching only when necessary. Mistakes in regular expressions can lead to
	// frustrating user experiences, such as unsatisfiable passcode policies, or policy
	// descriptions that don't match the enforced policy.
	CustomRegex *PasscodeCustomRegex `plist:"customRegex,omitempty" json:"customRegex,omitempty"`
}

Passcode: The payload that configures a passcode policy.

Passcode corresponds to mdm/profiles/com.apple.mobiledevice.passwordpolicy.yaml (Passcode).

func (*Passcode) PayloadTypeName

func (*Passcode) PayloadTypeName() string

PayloadTypeName returns "com.apple.mobiledevice.passwordpolicy".

func (*Passcode) SchemaPath

func (*Passcode) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Passcode) Validate

func (x *Passcode) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type PasscodeCustomRegex

type PasscodeCustomRegex struct {
	// A regular expression string that the system matches against the password to determine
	// whether it complies with a policy. The regular expression uses the ICU syntax
	// ([https://unicode-org.github.io/icu/userguide/strings/regexp.html](https://unicode-org.github.io/icu/userguide/strings/regexp.html)).
	// The string must not exceed 2048 characters in length.
	PasswordContentRegex string `plist:"passwordContentRegex" json:"passwordContentRegex"`
	// Contains a dictionary of keys for supported OS language IDs (for example, "en-US"), and
	// whose values represent a localized description of the policy enforced by the regular
	// expression. Use the special `default` key can for languages that aren't contained in the
	// dictionary.
	PasswordContentDescription map[string]string `plist:"passwordContentDescription,omitempty" json:"passwordContentDescription,omitempty"`
}

PasscodeCustomRegex: Specifies a regular expression, and its description, used to enforce password compliance. Use the simpler passcode restrictions whenever possible, and rely on regular expression matching only when necessary. Mistakes in regular expressions can lead to frustrating user experiences, such as unsatisfiable passcode policies, or policy descriptions that don't match the enforced policy.

type Payload

type Payload interface {
	// PayloadTypeName returns the wire identifier from Apple's schema.
	PayloadTypeName() string
	// SchemaPath returns the schema file the type was generated from.
	SchemaPath() string
	// Validate checks the value against the schema for the target.
	Validate(t support.Target) error
}

Payload is implemented by every top-level type in this package.

type Printing

type Printing struct {
	// If `true`, requires an administrator password to add printers.
	RequireAdminToAddPrinters *bool `plist:"RequireAdminToAddPrinters,omitempty" json:"RequireAdminToAddPrinters,omitempty"`
	// If `true`, allows printers that connect directly to a user's computer.
	AllowLocalPrinters *bool `plist:"AllowLocalPrinters,omitempty" json:"AllowLocalPrinters,omitempty"`
	// If `true`, requires an administrator password to print locally.
	RequireAdminToPrintLocally *bool `plist:"RequireAdminToPrintLocally,omitempty" json:"RequireAdminToPrintLocally,omitempty"`
	// If `true`, shows only managed printers.
	ShowOnlyManagedPrinters *bool `plist:"ShowOnlyManagedPrinters,omitempty" json:"ShowOnlyManagedPrinters,omitempty"`
	// If `true`, prints the page footer (including the user name and date).
	PrintFooter *bool `plist:"PrintFooter,omitempty" json:"PrintFooter,omitempty"`
	// If `true`, includes the MAC address.
	PrintMACAddress *bool `plist:"PrintMACAddress,omitempty" json:"PrintMACAddress,omitempty"`
	// The footer font size.
	FooterFontSize *string `plist:"FooterFontSize,omitempty" json:"FooterFontSize,omitempty"`
	// The footer font name.
	FooterFontName *string `plist:"FooterFontName,omitempty" json:"FooterFontName,omitempty"`
	// The default printer for the user.
	DefaultPrinter *PrintingDefaultPrinter `plist:"DefaultPrinter,omitempty" json:"DefaultPrinter,omitempty"`
	// The printers available to a user.
	UserPrinterList *PrintingUserPrinterList `plist:"UserPrinterList,omitempty" json:"UserPrinterList,omitempty"`
}

Printing: The payload that configures printers.

Printing corresponds to mdm/profiles/com.apple.mcxprinting.yaml (Printing).

func (*Printing) PayloadTypeName

func (*Printing) PayloadTypeName() string

PayloadTypeName returns "com.apple.mcxprinting".

func (*Printing) SchemaPath

func (*Printing) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Printing) Validate

func (x *Printing) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type PrintingDefaultPrinter

type PrintingDefaultPrinter struct {
	// The device URI.
	DeviceURI *string `plist:"DeviceURI,omitempty" json:"DeviceURI,omitempty"`
	// The display name.
	DisplayName *string `plist:"DisplayName,omitempty" json:"DisplayName,omitempty"`
}

PrintingDefaultPrinter: The default printer for the user.

type PrintingUserPrinterList

type PrintingUserPrinterList struct {
	// A dictionary of printer details.
	Printer *PrintingUserPrinterListPrinter `plist:"Printer,omitempty" json:"Printer,omitempty"`
}

PrintingUserPrinterList: The printers available to a user.

type PrintingUserPrinterListPrinter

type PrintingUserPrinterListPrinter struct {
	// The device URI.
	DeviceURI *string `plist:"DeviceURI,omitempty" json:"DeviceURI,omitempty"`
	// The display name.
	DisplayName *string `plist:"DisplayName,omitempty" json:"DisplayName,omitempty"`
	// The printer's location.
	Location *string `plist:"Location,omitempty" json:"Location,omitempty"`
	// The printer's model.
	Model *string `plist:"Model,omitempty" json:"Model,omitempty"`
	// If `true`, locks the printer.
	PrinterLocked *bool `plist:"PrinterLocked,omitempty" json:"PrinterLocked,omitempty"`
	// The printer's PPDURL.
	PPDURL *string `plist:"PPDURL,omitempty" json:"PPDURL,omitempty"`
}

PrintingUserPrinterListPrinter: A dictionary of printer details.

type PrivacyPreferencesPolicyControl

type PrivacyPreferencesPolicyControl struct {
	// A dictionary whose keys are limited to the privacy policy control services. In the case
	// of conflicting specifications, the most restrictive setting (deny) is used.
	Services PrivacyPreferencesPolicyControlServices `plist:"Services,omitempty" json:"Services,omitempty"`
}

PrivacyPreferencesPolicyControl: The payload that configures privacy preferences.

PrivacyPreferencesPolicyControl corresponds to mdm/profiles/com.apple.TCC.configuration-profile-policy.yaml (Privacy Preferences Policy Control).

func (*PrivacyPreferencesPolicyControl) PayloadTypeName

func (*PrivacyPreferencesPolicyControl) PayloadTypeName() string

PayloadTypeName returns "com.apple.TCC.configuration-profile-policy".

func (*PrivacyPreferencesPolicyControl) SchemaPath

SchemaPath returns the Apple schema file this type was generated from.

func (*PrivacyPreferencesPolicyControl) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type PrivacyPreferencesPolicyControlIdentity

type PrivacyPreferencesPolicyControlIdentity struct {
	// The bundle ID or installation path of the binary.
	Identifier string `plist:"Identifier" json:"Identifier"`
	// The type of identifier value. Application bundles must be identified by bundle ID.
	// Nonbundled binaries must be identified by installation path. Helper tools embedded
	// within an application bundle automatically inherit the permissions of their enclosing
	// app bundle.
	IdentifierType string `plist:"IdentifierType" json:"IdentifierType"`
	// Obtained via the command `codesign -display -r -`.
	CodeRequirement string `plist:"CodeRequirement" json:"CodeRequirement"`
	// If `true`, statically validate the code requirement. Used only if the process
	// invalidates its dynamic code signature.
	StaticCode *bool `plist:"StaticCode,omitempty" json:"StaticCode,omitempty"`
	// If `true`, access is granted; otherwise, the process doesn't have access. The user isn't
	// prompted and can't change this value.
	Allowed *bool `plist:"Allowed,omitempty" json:"Allowed,omitempty"`
	// The `Authorization` key is an optional replacement for the `Allowed` key, which has one
	// of the following possible values:
	Authorization *string `plist:"Authorization,omitempty" json:"Authorization,omitempty"`
	// Not used.
	Comment *string `plist:"Comment,omitempty" json:"Comment,omitempty"`
	// The identifier of the process receiving an AppleEvent sent by the Identifier process.
	// This identifier is required for AppleEvents service; not valid for other services.
	AEReceiverIdentifier *string `plist:"AEReceiverIdentifier,omitempty" json:"AEReceiverIdentifier,omitempty"`
	// The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is
	// required for AppleEvents service; not valid for other services.
	AEReceiverIdentifierType *string `plist:"AEReceiverIdentifierType,omitempty" json:"AEReceiverIdentifierType,omitempty"`
	// The code requirement for the receiving binary. This code requirement is required for
	// AppleEvents service; not valid for other services.
	AEReceiverCodeRequirement *string `plist:"AEReceiverCodeRequirement,omitempty" json:"AEReceiverCodeRequirement,omitempty"`
}

PrivacyPreferencesPolicyControlIdentity: A dictionary listing apps and the privacy policy to apply to them.

type PrivacyPreferencesPolicyControlServices

type PrivacyPreferencesPolicyControlServices struct {
	// Specifies the policies for contact information managed by the Contacts.app.
	AddressBook []PrivacyPreferencesPolicyControlIdentity `plist:"AddressBook,omitempty" json:"AddressBook,omitempty"`
	// Specifies the policies for calendar information managed by the Calendar.app.
	Calendar []PrivacyPreferencesPolicyControlIdentity `plist:"Calendar,omitempty" json:"Calendar,omitempty"`
	// Specifies the policies for reminders information managed by the Reminders app.
	Reminders []PrivacyPreferencesPolicyControlIdentity `plist:"Reminders,omitempty" json:"Reminders,omitempty"`
	// The pictures managed by the Photos app in `~/Pictures/.photoslibrary`.
	Photos []PrivacyPreferencesPolicyControlIdentity `plist:"Photos,omitempty" json:"Photos,omitempty"`
	// A system camera. Access to the camera can't be given in a profile; it can only be
	// denied.
	Camera []PrivacyPreferencesPolicyControlIdentity `plist:"Camera,omitempty" json:"Camera,omitempty"`
	// A system microphone. Access to the microphone can't be given in a profile; it can only
	// be denied.
	Microphone []PrivacyPreferencesPolicyControlIdentity `plist:"Microphone,omitempty" json:"Microphone,omitempty"`
	// Specifies the policies for the app via the Accessibility subsystem. The ability to grant
	// access by this profile is deprecated as of macOS 26.2, and will be removed in macOS
	// 27.0.
	Accessibility []PrivacyPreferencesPolicyControlIdentity `plist:"Accessibility,omitempty" json:"Accessibility,omitempty"`
	// Specifies the policies for the application to use CoreGraphics APIs to send CGEvents to
	// the system event stream.
	PostEvent []PrivacyPreferencesPolicyControlIdentity `plist:"PostEvent,omitempty" json:"PostEvent,omitempty"`
	// Allows the application access to all protected files, including system administration
	// files.
	SystemPolicyAllFiles []PrivacyPreferencesPolicyControlIdentity `plist:"SystemPolicyAllFiles,omitempty" json:"SystemPolicyAllFiles,omitempty"`
	// Allows the application access to some files used in system administration.
	SystemPolicySysAdminFiles []PrivacyPreferencesPolicyControlIdentity `plist:"SystemPolicySysAdminFiles,omitempty" json:"SystemPolicySysAdminFiles,omitempty"`
	// Specifies the policies for the app sending restricted AppleEvents to another process.
	AppleEvents []PrivacyPreferencesPolicyControlIdentity `plist:"AppleEvents,omitempty" json:"AppleEvents,omitempty"`
	// Allows the application to access Apple Music, music and video activity, and the media
	// library.
	MediaLibrary []PrivacyPreferencesPolicyControlIdentity `plist:"MediaLibrary,omitempty" json:"MediaLibrary,omitempty"`
	// Allows a File Provider application to know when the user is using files managed by the
	// File Provider.
	FileProviderPresence []PrivacyPreferencesPolicyControlIdentity `plist:"FileProviderPresence,omitempty" json:"FileProviderPresence,omitempty"`
	// Allows the application to use CoreGraphics and HID APIs to listen to (receive) CGEvents
	// and HID events from all processes. Access to these events can't be given in a profile;
	// it can only be denied.
	ListenEvent []PrivacyPreferencesPolicyControlIdentity `plist:"ListenEvent,omitempty" json:"ListenEvent,omitempty"`
	// Allows the application to capture (read) the contents of the system display. Access to
	// the contents can't be given in a profile; it can only be denied.
	ScreenCapture []PrivacyPreferencesPolicyControlIdentity `plist:"ScreenCapture,omitempty" json:"ScreenCapture,omitempty"`
	// Allows the application to use the system Speech Recognition facility and to send speech
	// data to Apple.
	SpeechRecognition []PrivacyPreferencesPolicyControlIdentity `plist:"SpeechRecognition,omitempty" json:"SpeechRecognition,omitempty"`
	// Allows the application to access files in the user's Desktop folder.
	SystemPolicyDesktopFolder []PrivacyPreferencesPolicyControlIdentity `plist:"SystemPolicyDesktopFolder,omitempty" json:"SystemPolicyDesktopFolder,omitempty"`
	// Allows the application to access files in the user's Documents folder.
	SystemPolicyDocumentsFolder []PrivacyPreferencesPolicyControlIdentity `plist:"SystemPolicyDocumentsFolder,omitempty" json:"SystemPolicyDocumentsFolder,omitempty"`
	// Allows the application to access files in the user's Downloads folder.
	SystemPolicyDownloadsFolder []PrivacyPreferencesPolicyControlIdentity `plist:"SystemPolicyDownloadsFolder,omitempty" json:"SystemPolicyDownloadsFolder,omitempty"`
	// Allows the application to access files on network volumes.
	SystemPolicyNetworkVolumes []PrivacyPreferencesPolicyControlIdentity `plist:"SystemPolicyNetworkVolumes,omitempty" json:"SystemPolicyNetworkVolumes,omitempty"`
	// Allows the application to access files on removable volumes.
	SystemPolicyRemovableVolumes []PrivacyPreferencesPolicyControlIdentity `plist:"SystemPolicyRemovableVolumes,omitempty" json:"SystemPolicyRemovableVolumes,omitempty"`
	// Allows the application to update or delete other apps. Available in macOS 13 and later.
	SystemPolicyAppBundles []PrivacyPreferencesPolicyControlIdentity `plist:"SystemPolicyAppBundles,omitempty" json:"SystemPolicyAppBundles,omitempty"`
	// Specifies the policies for the app to access the data of other apps.
	SystemPolicyAppData []PrivacyPreferencesPolicyControlIdentity `plist:"SystemPolicyAppData,omitempty" json:"SystemPolicyAppData,omitempty"`
	// Specifies the policies for the app to access Bluetooth devices.
	BluetoothAlways []PrivacyPreferencesPolicyControlIdentity `plist:"BluetoothAlways,omitempty" json:"BluetoothAlways,omitempty"`
}

PrivacyPreferencesPolicyControlServices: A dictionary whose keys are limited to the privacy policy control services. In the case of conflicting specifications, the most restrictive setting (deny) is used.

type ProfileRemovalPassword

type ProfileRemovalPassword struct {
	// The password to allow removing the profile.
	RemovalPassword *string `plist:"RemovalPassword,omitempty" json:"RemovalPassword,omitempty"`
}

ProfileRemovalPassword: The payload that configures profile removal.

ProfileRemovalPassword corresponds to mdm/profiles/com.apple.profileRemovalPassword.yaml (Profile Removal Password).

func (*ProfileRemovalPassword) PayloadTypeName

func (*ProfileRemovalPassword) PayloadTypeName() string

PayloadTypeName returns "com.apple.profileRemovalPassword".

func (*ProfileRemovalPassword) SchemaPath

func (*ProfileRemovalPassword) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ProfileRemovalPassword) Validate

func (x *ProfileRemovalPassword) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type Relay

type Relay struct {
	// An array of dictionaries that describe one or more relay servers that the system can
	// chain together.
	Relays []RelayRelays `plist:"Relays,omitempty" json:"Relays,omitempty"`
	// A list of domain strings that the system uses to determine which connection to route
	// through the servers in `Relays`.
	MatchDomains []string `plist:"MatchDomains,omitempty" json:"MatchDomains,omitempty"`
	// A list of domain strings to exclude from routing through the servers in `Relays`. Any
	// connection that matches a domain in the list exactly or is a subdomain of the listed
	// domain won't use the relay server.
	ExcludedDomains []string `plist:"ExcludedDomains,omitempty" json:"ExcludedDomains,omitempty"`
	// A list of Fully Qualified Domain Names (FQDNs) to be routed through the servers
	// contained in `Relays`. Any connection that matches an FQDN in the list exactly uses the
	// relay servers. If this list and `MatchDomains` are empty, the system routes traffic to
	// all domains to the relay servers, except those that match an excluded domain or excluded
	// FQDN.
	MatchFQDNs []string `plist:"MatchFQDNs,omitempty" json:"MatchFQDNs,omitempty"`
	// A list of Fully Qualified Domain Names (FQDNs) to exclude from routing through the
	// servers contained in `Relays`. Any connection that matches an FQDN in the list exactly
	// won't use the relay server. When `MatchDomains` is also present, any FQDN listed in the
	// list should be a subdomain of at least one `MatchDomain` value, otherwise it will not
	// have any effect.
	ExcludedFQDNs []string `plist:"ExcludedFQDNs,omitempty" json:"ExcludedFQDNs,omitempty"`
	// A globally unique identifier for this relay configuration. The system uses this UUID to
	// route managed apps through the servers in `Relays`. This key is required for user
	// enrollment.
	RelayUUID *string `plist:"RelayUUID,omitempty" json:"RelayUUID,omitempty"`
	// If `true`, the device allows the user to disable this network relay configuration.
	UIToggleEnabled *bool `plist:"UIToggleEnabled,omitempty" json:"UIToggleEnabled,omitempty"`
	// If `true`, the device allows the relay to failover to the default system DNS resolver.
	AllowDNSFailover *bool `plist:"AllowDNSFailover,omitempty" json:"AllowDNSFailover,omitempty"`
}

Relay: The payload that configures relay settings.

Relay corresponds to mdm/profiles/com.apple.relay.managed.yaml (Relay).

func (*Relay) PayloadTypeName

func (*Relay) PayloadTypeName() string

PayloadTypeName returns "com.apple.relay.managed".

func (*Relay) SchemaPath

func (*Relay) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Relay) Validate

func (x *Relay) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type RelayRelays

type RelayRelays struct {
	// The URL or URI template, as defined in RFC 9298, of a relay server that's reachable
	// using HTTP/3 and supports proxying TCP and UDP using the CONNECT method.
	HTTP3RelayURL *string `plist:"HTTP3RelayURL,omitempty" json:"HTTP3RelayURL,omitempty"`
	// The URL or URI template, as defined in RFC 9298, of a relay server that's reachable
	// using HTTP/2 and supports proxying TCP and UDP using the CONNECT method.
	HTTP2RelayURL *string `plist:"HTTP2RelayURL,omitempty" json:"HTTP2RelayURL,omitempty"`
	// A dictionary that contains custom HTTP header keys and values to add to each request.
	// The dictionary key name represents the HTTP header field name to use, and the dictionary
	// value is the string to use as the HTTP header field value.
	AdditionalHTTPHeaderFields map[string]string `plist:"AdditionalHTTPHeaderFields,omitempty" json:"AdditionalHTTPHeaderFields,omitempty"`
	// The UUID that points to an identity certificate payload, which the system uses to
	// authenticate the user to the relay server.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// An array of DER-encoded raw public keys that the system uses to authenticate the server
	// during a TLS handshake. The server needs to use one of the keys in the handshake to
	// authenticate.
	RawPublicKeys [][]byte `plist:"RawPublicKeys,omitempty" json:"RawPublicKeys,omitempty"`
}

RelayRelays: is generated from mdm/profiles/com.apple.relay.managed.yaml.

type Restrictions

type Restrictions struct {
	// If `false`, the system disables modification of accounts, such as Apple Accounts, and
	// internet-based accounts, such as Mail, Contacts, and Calendar.
	AllowAccountModification *bool `plist:"allowAccountModification,omitempty" json:"allowAccountModification,omitempty"`
	// If `false`, the system disables activity continuation. Support for this restriction on
	// unsupervised devices and with Managed Apple Accounts is deprecated. In a future release,
	// this restriction will begin requiring supervision and will apply to personal Apple
	// Accounts only.
	AllowActivityContinuation *bool `plist:"allowActivityContinuation,omitempty" json:"allowActivityContinuation,omitempty"`
	// If `false`, the system prohibits adding friends to Game Center. Requires a supervised
	// device in iOS 13 and later.
	AllowAddingGameCenterFriends *bool `plist:"allowAddingGameCenterFriends,omitempty" json:"allowAddingGameCenterFriends,omitempty"`
	// If `false`, the system disables AirDrop.
	AllowAirDrop *bool `plist:"allowAirDrop,omitempty" json:"allowAirDrop,omitempty"`
	// If `false`, the system disables incoming AirPlay requests.
	AllowAirPlayIncomingRequests *bool `plist:"allowAirPlayIncomingRequests,omitempty" json:"allowAirPlayIncomingRequests,omitempty"`
	// If `false`, the system disables AirPrint.
	AllowAirPrint *bool `plist:"allowAirPrint,omitempty" json:"allowAirPrint,omitempty"`
	// If `false`, the system disables Keychain storage of user name and password for AirPrint.
	AllowAirPrintCredentialsStorage *bool `plist:"allowAirPrintCredentialsStorage,omitempty" json:"allowAirPrintCredentialsStorage,omitempty"`
	// If `false`, the system disables iBeacon discovery of AirPrint printers, which prevents
	// spurious AirPrint Bluetooth beacons from phishing for network traffic.
	AllowAirPrintiBeaconDiscovery *bool `plist:"allowAirPrintiBeaconDiscovery,omitempty" json:"allowAirPrintiBeaconDiscovery,omitempty"`
	// If `false`, the system disables changing settings for cellular data usage for apps.
	AllowAppCellularDataModification *bool `plist:"allowAppCellularDataModification,omitempty" json:"allowAppCellularDataModification,omitempty"`
	// If `false`, the system prevents a user from adding any App Clips, and removes any
	// existing App Clips on the device.
	AllowAppClips *bool `plist:"allowAppClips,omitempty" json:"allowAppClips,omitempty"`
	// If `false`, the system disables the App Store and removes its icon from the Home Screen.
	// Users are unable to install or update their apps. This applies to App Store apps,
	// marketplace apps, and locally installed apps (using Configurator, Xcode, and so forth).
	AllowAppInstallation *bool `plist:"allowAppInstallation,omitempty" json:"allowAppInstallation,omitempty"`
	// If `false`, the system disables Apple Intelligence reports.
	AllowAppleIntelligenceReport *bool `plist:"allowAppleIntelligenceReport,omitempty" json:"allowAppleIntelligenceReport,omitempty"`
	// If `false`, the system limits Apple personalized advertising.
	AllowApplePersonalizedAdvertising *bool `plist:"allowApplePersonalizedAdvertising,omitempty" json:"allowApplePersonalizedAdvertising,omitempty"`
	// If `false`, the system disables removal of apps from an iOS device. This applies to App
	// Store apps, marketplace apps, and locally installed apps (using Configurator, Xcode, and
	// so forth).
	AllowAppRemoval *bool `plist:"allowAppRemoval,omitempty" json:"allowAppRemoval,omitempty"`
	// If `false`, disables the ability for the user to hide apps. It doesn't affect the user's
	// ability to leave it in the App Library, while removing it from the Home Screen.
	AllowAppsToBeHidden *bool `plist:"allowAppsToBeHidden,omitempty" json:"allowAppsToBeHidden,omitempty"`
	// If `false`, disables the ability for the user to lock apps. Because hiding apps also
	// requires locking them, disallowing locking also disallows hiding.
	AllowAppsToBeLocked *bool `plist:"allowAppsToBeLocked,omitempty" json:"allowAppsToBeLocked,omitempty"`
	// If `false`, the system prevents modifying the Remote Management Sharing setting in
	// System Settings.
	AllowARDRemoteManagementModification *bool `plist:"allowARDRemoteManagementModification,omitempty" json:"allowARDRemoteManagementModification,omitempty"`
	// If `false`, the system disables Siri.
	AllowAssistant *bool `plist:"allowAssistant,omitempty" json:"allowAssistant,omitempty"`
	// If `false`, the system prevents Siri from querying user-generated content from the web.
	AllowAssistantUserGeneratedContent *bool `plist:"allowAssistantUserGeneratedContent,omitempty" json:"allowAssistantUserGeneratedContent,omitempty"`
	// If `false`, the system disables Siri when the device is locked. The system ignores this
	// restriction if the device doesn't have a passcode set.
	AllowAssistantWhileLocked *bool `plist:"allowAssistantWhileLocked,omitempty" json:"allowAssistantWhileLocked,omitempty"`
	// If `false`, the system disables keyboard autocorrection.
	AllowAutoCorrection *bool `plist:"allowAutoCorrection,omitempty" json:"allowAutoCorrection,omitempty"`
	// If `false`, disables auto dim on iPads with OLED displays.
	AllowAutoDim *bool `plist:"allowAutoDim,omitempty" json:"allowAutoDim,omitempty"`
	// If `false`, the system prevents automatic downloading of apps purchased on other
	// devices. This setting doesn't affect updates to existing apps.
	AllowAutomaticAppDownloads *bool `plist:"allowAutomaticAppDownloads,omitempty" json:"allowAutomaticAppDownloads,omitempty"`
	// If `false`, the system disables Apple TV's automatic screen saver.
	AllowAutomaticScreenSaver *bool `plist:"allowAutomaticScreenSaver,omitempty" json:"allowAutomaticScreenSaver,omitempty"`
	// If `false`, the system disallows auto unlock. Support for this restriction on
	// unsupervised devices is deprecated.
	AllowAutoUnlock *bool `plist:"allowAutoUnlock,omitempty" json:"allowAutoUnlock,omitempty"`
	// If `false`, the system prevents modification of Bluetooth settings.
	AllowBluetoothModification *bool `plist:"allowBluetoothModification,omitempty" json:"allowBluetoothModification,omitempty"`
	// If `false`, the system prevents modifying Bluetooth settings in System Settings.
	AllowBluetoothSharingModification *bool `plist:"allowBluetoothSharingModification,omitempty" json:"allowBluetoothSharingModification,omitempty"`
	// If `false`, the system removes the Book Store tab from the Books app.
	AllowBookstore *bool `plist:"allowBookstore,omitempty" json:"allowBookstore,omitempty"`
	// If `false`, the system prevents the user from downloading Apple Books media that's
	// tagged as erotica. Support for this restriction on unsupervised devices is deprecated.
	AllowBookstoreErotica *bool `plist:"allowBookstoreErotica,omitempty" json:"allowBookstoreErotica,omitempty"`
	// If `false`, disables call recording.
	AllowCallRecording *bool `plist:"allowCallRecording,omitempty" json:"allowCallRecording,omitempty"`
	// If `false`, the system disables the camera and removes its icon from the Home Screen,
	// and users are unable to take photographs. Support for this restriction on unsupervised
	// devices is deprecated.
	AllowCamera *bool `plist:"allowCamera,omitempty" json:"allowCamera,omitempty"`
	// If `false`, the system prevents users from changing settings related to their cellular
	// plan (available only on select carriers).
	AllowCellularPlanModification *bool `plist:"allowCellularPlanModification,omitempty" json:"allowCellularPlanModification,omitempty"`
	// If `false`, the system disables the use of iMessage with supervised devices. If the
	// device supports text messaging, the user can still send and receive text messages.
	AllowChat *bool `plist:"allowChat,omitempty" json:"allowChat,omitempty"`
	// If `false`, the system disables iCloud Contacts services.
	AllowCloudAddressBook *bool `plist:"allowCloudAddressBook,omitempty" json:"allowCloudAddressBook,omitempty"`
	// If `false`, the system disables backing up the device to iCloud. Support for this
	// restriction on unsupervised devices is deprecated.
	AllowCloudBackup *bool `plist:"allowCloudBackup,omitempty" json:"allowCloudBackup,omitempty"`
	// If `false`, the system disables iCloud Bookmark sync.
	AllowCloudBookmarks *bool `plist:"allowCloudBookmarks,omitempty" json:"allowCloudBookmarks,omitempty"`
	// If `false`, the system disables iCloud Calendar services.
	AllowCloudCalendar *bool `plist:"allowCloudCalendar,omitempty" json:"allowCloudCalendar,omitempty"`
	// If `false`, the system disables iCloud Desktop and Document services.
	AllowCloudDesktopAndDocuments *bool `plist:"allowCloudDesktopAndDocuments,omitempty" json:"allowCloudDesktopAndDocuments,omitempty"`
	// If `false`, the system disables document and key-value syncing to iCloud. Requires a
	// supervised device in iOS 13 and later, and Shared iPad doesn't support it. Support for
	// this restriction on unsupervised devices and with Managed Apple Accounts is deprecated.
	AllowCloudDocumentSync *bool `plist:"allowCloudDocumentSync,omitempty" json:"allowCloudDocumentSync,omitempty"`
	// If `false`, the system disallows iCloud Freeform services.
	AllowCloudFreeform *bool `plist:"allowCloudFreeform,omitempty" json:"allowCloudFreeform,omitempty"`
	// If `false`, the system disables iCloud Keychain synchronization. Support for this
	// restriction on unsupervised devices and with Managed Apple Accounts is deprecated.
	AllowCloudKeychainSync *bool `plist:"allowCloudKeychainSync,omitempty" json:"allowCloudKeychainSync,omitempty"`
	// If `false`, the system disables iCloud Mail services.
	AllowCloudMail *bool `plist:"allowCloudMail,omitempty" json:"allowCloudMail,omitempty"`
	// If `false`, the system disables iCloud Notes services.
	AllowCloudNotes *bool `plist:"allowCloudNotes,omitempty" json:"allowCloudNotes,omitempty"`
	// If `false`, the system disables iCloud Photo Library. The system removes any photos from
	// local storage that aren't fully downloaded from iCloud Photo Library to the device.
	// Support for this restriction on unsupervised devices and with Managed Apple Accounts is
	// deprecated.
	AllowCloudPhotoLibrary *bool `plist:"allowCloudPhotoLibrary,omitempty" json:"allowCloudPhotoLibrary,omitempty"`
	// If `false`, the system disables iCloud Private Relay. Support for this restriction on
	// unsupervised devices and with Managed Apple Accounts is deprecated.
	AllowCloudPrivateRelay *bool `plist:"allowCloudPrivateRelay,omitempty" json:"allowCloudPrivateRelay,omitempty"`
	// If `false`, the system disables iCloud Reminder services.
	AllowCloudReminders *bool `plist:"allowCloudReminders,omitempty" json:"allowCloudReminders,omitempty"`
	// If `false`, the system disables content caching. This restriction is not supported on
	// the user channel.
	AllowContentCaching *bool `plist:"allowContentCaching,omitempty" json:"allowContentCaching,omitempty"`
	// If `false`, the system disables QuickPath keyboard.
	AllowContinuousPathKeyboard *bool `plist:"allowContinuousPathKeyboard,omitempty" json:"allowContinuousPathKeyboard,omitempty"`
	// If `false`, disables default browser preference modification. The MDM Settings command
	// to set the default browser preference still works when applying this.
	AllowDefaultBrowserModification *bool `plist:"allowDefaultBrowserModification,omitempty" json:"allowDefaultBrowserModification,omitempty"`
	// If `false`, disables default calling app preference modification. The MDM Settings
	// command to set the default calling app preference still works when applying this.
	AllowDefaultCallingAppModification *bool `plist:"allowDefaultCallingAppModification,omitempty" json:"allowDefaultCallingAppModification,omitempty"`
	// If `false`, disables default messaging app preference modification. The MDM Settings
	// command to set the default messaging app preference still works when applying this.
	AllowDefaultMessagingAppModification *bool `plist:"allowDefaultMessagingAppModification,omitempty" json:"allowDefaultMessagingAppModification,omitempty"`
	// If `false`, the system disables definition lookup.
	AllowDefinitionLookup *bool `plist:"allowDefinitionLookup,omitempty" json:"allowDefinitionLookup,omitempty"`
	// If `false`, the system prevents the user from changing the device name.
	AllowDeviceNameModification *bool `plist:"allowDeviceNameModification,omitempty" json:"allowDeviceNameModification,omitempty"`
	// If `false`, the system prevents the device from automatically sleeping.
	AllowDeviceSleep *bool `plist:"allowDeviceSleep,omitempty" json:"allowDeviceSleep,omitempty"`
	// If `false`, the system prevents the device from automatically submitting diagnostic
	// reports to Apple.
	AllowDiagnosticSubmission *bool `plist:"allowDiagnosticSubmission,omitempty" json:"allowDiagnosticSubmission,omitempty"`
	// If `false`, the system disables changing the diagnostic submission and app analytics
	// settings in the Diagnostics & Usage UI in Settings.
	AllowDiagnosticSubmissionModification *bool `plist:"allowDiagnosticSubmissionModification,omitempty" json:"allowDiagnosticSubmissionModification,omitempty"`
	// If `false`, the system disallows dictation input.
	AllowDictation *bool `plist:"allowDictation,omitempty" json:"allowDictation,omitempty"`
	// If present, the system exempts apps with bundle IDs in the array from the `allowCamera`
	// restriction. The system doesn't grant these apps access to the camera automatically;
	// they're only exempted from the `allowCamera` restriction. This key has no effect when
	// the camera isn't restricted. Multiple payloads combine using an intersect operation.
	// Requires a supervised device.
	AllowedCameraRestrictionBundleIDs []string `plist:"allowedCameraRestrictionBundleIDs,omitempty" json:"allowedCameraRestrictionBundleIDs,omitempty"`
	// An array of strings, but currently restricted to a single element. If present, Apple
	// Intelligence allows use of only the given external integration workspace ID, and
	// requires a sign-in to make requests. The user is required to sign in to integrations
	// that support signing in. Multiple payloads combine using an intersect operation. This
	// means the allowed set of workspace IDs can become the empty set if multiple payloads
	// specify conflicting values.
	AllowedExternalIntelligenceWorkspaceIDs []string `plist:"allowedExternalIntelligenceWorkspaceIDs,omitempty" json:"allowedExternalIntelligenceWorkspaceIDs,omitempty"`
	// If `false`, the system disables the Enable Restrictions option in the Restrictions UI in
	// Settings. If `false` in iOS 12 and later, the system disables the Enable ScreenTime
	// option in the ScreenTime UI in Settings and disables ScreenTime if already enabled.
	AllowEnablingRestrictions *bool `plist:"allowEnablingRestrictions,omitempty" json:"allowEnablingRestrictions,omitempty"`
	// If `false`, the system removes the Trust Enterprise Developer button in Settings >
	// General > VPN & Device Management, which prevents provisioning apps by universal
	// provisioning profiles. This restriction applies to free developer accounts and
	// enterprise app developers that aren't implicitly trusted by apps that install through
	// MDM. This restriction doesn't revoke previously granted trust.
	AllowEnterpriseAppTrust *bool `plist:"allowEnterpriseAppTrust,omitempty" json:"allowEnterpriseAppTrust,omitempty"`
	// If `false`, the system disables backup of Enterprise books.
	AllowEnterpriseBookBackup *bool `plist:"allowEnterpriseBookBackup,omitempty" json:"allowEnterpriseBookBackup,omitempty"`
	// If `false`, the system disables sync of Enterprise books, notes, and highlights.
	AllowEnterpriseBookMetadataSync *bool `plist:"allowEnterpriseBookMetadataSync,omitempty" json:"allowEnterpriseBookMetadataSync,omitempty"`
	// If `false`, the system disables the Erase All Content and Settings option in the Reset
	// UI.
	AllowEraseContentAndSettings *bool `plist:"allowEraseContentAndSettings,omitempty" json:"allowEraseContentAndSettings,omitempty"`
	// If `false`, the system disables modifications of eSIMs.
	AllowESIMModification *bool `plist:"allowESIMModification,omitempty" json:"allowESIMModification,omitempty"`
	// If `false`, prevents the transfer of an eSIM from the device on which the restriction is
	// installed to a different device.
	AllowESIMOutgoingTransfers *bool `plist:"allowESIMOutgoingTransfers,omitempty" json:"allowESIMOutgoingTransfers,omitempty"`
	// If `false`, the system hides explicit music or video content purchased from the iTunes
	// Store. The system marks explicit content as such by content providers, such as record
	// labels, when sold through the iTunes Store. Explicit content in the News and Podcast
	// apps is also hidden.
	AllowExplicitContent *bool `plist:"allowExplicitContent,omitempty" json:"allowExplicitContent,omitempty"`
	// If `false`, disables the use of external, cloud-based intelligence services with Siri.
	// In iOS, this restriction is temporarily allowed on unsupervised and user enrollments. In
	// a future release, this restriction will require supervision, and will be ignored on
	// unsupervised devices.
	AllowExternalIntelligenceIntegrations *bool `plist:"allowExternalIntelligenceIntegrations,omitempty" json:"allowExternalIntelligenceIntegrations,omitempty"`
	// If `false`, forces external intelligence providers into anonymous mode. If a user is
	// already signed in to an external intelligence provider, applying this restriction signs
	// them out when attempting the next request.
	AllowExternalIntelligenceIntegrationsSignIn *bool `plist:"allowExternalIntelligenceIntegrationsSignIn,omitempty" json:"allowExternalIntelligenceIntegrationsSignIn,omitempty"`
	// If `false`, the system prevents modifying File Sharing setting in System Settings.
	AllowFileSharingModification *bool `plist:"allowFileSharingModification,omitempty" json:"allowFileSharingModification,omitempty"`
	// If `false`, the system prevents connecting to network drives in the Files app.
	AllowFilesNetworkDriveAccess *bool `plist:"allowFilesNetworkDriveAccess,omitempty" json:"allowFilesNetworkDriveAccess,omitempty"`
	// If `false`, the system prevents connecting to any connected USB devices in the Files
	// app.
	AllowFilesUSBDriveAccess *bool `plist:"allowFilesUSBDriveAccess,omitempty" json:"allowFilesUSBDriveAccess,omitempty"`
	// If `false`, the system disables Find My Device in the Find My app.
	AllowFindMyDevice *bool `plist:"allowFindMyDevice,omitempty" json:"allowFindMyDevice,omitempty"`
	// If `false`, the system disables Find My Friends in the Find My app.
	AllowFindMyFriends *bool `plist:"allowFindMyFriends,omitempty" json:"allowFindMyFriends,omitempty"`
	// If `false`, the system disables changes to Find My Friends.
	AllowFindMyFriendsModification *bool `plist:"allowFindMyFriendsModification,omitempty" json:"allowFindMyFriendsModification,omitempty"`
	// If `false`, the system prevents Touch ID, Face ID, or Optic ID from unlocking a device.
	// Support for this restriction on unsupervised devices is deprecated.
	AllowFingerprintForUnlock *bool `plist:"allowFingerprintForUnlock,omitempty" json:"allowFingerprintForUnlock,omitempty"`
	// If `false`, the system prevents the user from modifying Touch ID or Face ID.
	AllowFingerprintModification *bool `plist:"allowFingerprintModification,omitempty" json:"allowFingerprintModification,omitempty"`
	// If `false`, the system disables Game Center, and the system removes its icon from the
	// Home Screen.
	AllowGameCenter *bool `plist:"allowGameCenter,omitempty" json:"allowGameCenter,omitempty"`
	// If `false`, prohibits creating new Genmoji.
	AllowGenmoji *bool `plist:"allowGenmoji,omitempty" json:"allowGenmoji,omitempty"`
	// If `false`, the system disables global background fetch activity when an iOS phone is
	// roaming. Support for this restriction on unsupervised devices is deprecated.
	AllowGlobalBackgroundFetchWhenRoaming *bool `plist:"allowGlobalBackgroundFetchWhenRoaming,omitempty" json:"allowGlobalBackgroundFetchWhenRoaming,omitempty"`
	// If `false`, the system disables host pairing with the exception of the supervision host.
	// If there's no configured supervision host certificate, the system disables all pairing.
	// Host pairing lets the administrator control whether an iOS device can pair with a host
	// Mac or PC.
	AllowHostPairing *bool `plist:"allowHostPairing,omitempty" json:"allowHostPairing,omitempty"`
	// If `false`, prohibits the use of image generation.
	AllowImagePlayground *bool `plist:"allowImagePlayground,omitempty" json:"allowImagePlayground,omitempty"`
	// If `false`, prohibits the use of Image Wand.
	AllowImageWand *bool `plist:"allowImageWand,omitempty" json:"allowImageWand,omitempty"`
	// If `false`, the system prohibits in-app purchasing. Support for this restriction on
	// unsupervised devices is deprecated.
	AllowInAppPurchases *bool `plist:"allowInAppPurchases,omitempty" json:"allowInAppPurchases,omitempty"`
	// If `false`, the system prevents modifying the Internet Sharing setting in System
	// Settings.
	AllowInternetSharingModification *bool `plist:"allowInternetSharingModification,omitempty" json:"allowInternetSharingModification,omitempty"`
	// If `false`, prohibits the use of iPhone Mirroring. In macOS, this prevents the Mac from
	// mirroring any iPhone. In iOS, this prevents the iPhone from mirroring to any Mac.
	AllowiPhoneMirroring *bool `plist:"allowiPhoneMirroring,omitempty" json:"allowiPhoneMirroring,omitempty"`
	// If `false`, the system disallows iPhone widgets on a Mac that signs in with the same
	// Apple Account for iCloud.
	AllowiPhoneWidgetsOnMac *bool `plist:"allowiPhoneWidgetsOnMac,omitempty" json:"allowiPhoneWidgetsOnMac,omitempty"`
	// If `false`, the system disables the iTunes Music Store and removes its icon from the
	// Home Screen. Users can't preview, purchase, or download content. Requires a supervised
	// device in iOS 13 and later.
	AllowiTunes *bool `plist:"allowiTunes,omitempty" json:"allowiTunes,omitempty"`
	// If `false`, the system disables iTunes file sharing services.
	AllowiTunesFileSharing *bool `plist:"allowiTunesFileSharing,omitempty" json:"allowiTunesFileSharing,omitempty"`
	// If `false`, the system disables keyboard shortcuts.
	AllowKeyboardShortcuts *bool `plist:"allowKeyboardShortcuts,omitempty" json:"allowKeyboardShortcuts,omitempty"`
	// If present, the system only shows or can launch apps with bundle IDs in the array.
	// Include the value `com.apple.webapp` to allow all webclips. This applies to App Store
	// apps, marketplace apps, and locally installed apps (using Configurator, Xcode, and so
	// forth).
	AllowListedAppBundleIDs []string `plist:"allowListedAppBundleIDs,omitempty" json:"allowListedAppBundleIDs,omitempty"`
	// If `false`, the system disables live voicemail on the device.
	AllowLiveVoicemail *bool `plist:"allowLiveVoicemail,omitempty" json:"allowLiveVoicemail,omitempty"`
	// If `false`, the system prevents creating users in System Settings.
	AllowLocalUserCreation *bool `plist:"allowLocalUserCreation,omitempty" json:"allowLocalUserCreation,omitempty"`
	// If `false`, the system prevents Control Center from appearing on the Lock Screen.
	AllowLockScreenControlCenter *bool `plist:"allowLockScreenControlCenter,omitempty" json:"allowLockScreenControlCenter,omitempty"`
	// If `false`, the system disables the Notifications history view on the Lock Screen, so
	// users can't view past notifications. However, they can still see notifications when they
	// arrive.
	AllowLockScreenNotificationsView *bool `plist:"allowLockScreenNotificationsView,omitempty" json:"allowLockScreenNotificationsView,omitempty"`
	// If `false`, the system disables the Today view in Notification Center on the Lock
	// Screen.
	AllowLockScreenTodayView *bool `plist:"allowLockScreenTodayView,omitempty" json:"allowLockScreenTodayView,omitempty"`
	// If `false`, the system disables Mail Privacy Protection on the device.
	AllowMailPrivacyProtection *bool `plist:"allowMailPrivacyProtection,omitempty" json:"allowMailPrivacyProtection,omitempty"`
	// If `false`, disables smart replies in Mail.
	AllowMailSmartReplies *bool `plist:"allowMailSmartReplies,omitempty" json:"allowMailSmartReplies,omitempty"`
	// If `false`, disables the ability to create summaries of email messages manually. This
	// doesn't affect automatic summary generation.
	AllowMailSummary *bool `plist:"allowMailSummary,omitempty" json:"allowMailSummary,omitempty"`
	// If `false`, the system prevents managed apps from using iCloud sync.
	AllowManagedAppsCloudSync *bool `plist:"allowManagedAppsCloudSync,omitempty" json:"allowManagedAppsCloudSync,omitempty"`
	// If `true`, the system allows managed apps to write contacts to unmanaged accounts. If
	// `allowOpenFromManagedToUnmanaged` is `true`, this restriction has no effect.
	AllowManagedToWriteUnmanagedContacts *bool `plist:"allowManagedToWriteUnmanagedContacts,omitempty" json:"allowManagedToWriteUnmanagedContacts,omitempty"`
	// If `false`, the system prevents installation of alternative marketplace apps from the
	// web and prevents any installed alternative marketplace apps from installing apps.
	AllowMarketplaceAppInstallation *bool `plist:"allowMarketplaceAppInstallation,omitempty" json:"allowMarketplaceAppInstallation,omitempty"`
	// If `false`, prevents modification of Media Sharing settings.
	AllowMediaSharingModification *bool `plist:"allowMediaSharingModification,omitempty" json:"allowMediaSharingModification,omitempty"`
	// If `false`, the system prohibits multiplayer gaming.
	AllowMultiplayerGaming *bool `plist:"allowMultiplayerGaming,omitempty" json:"allowMultiplayerGaming,omitempty"`
	// If `false`, the system disables the Music service, and the Music app reverts to classic
	// mode.
	AllowMusicService *bool `plist:"allowMusicService,omitempty" json:"allowMusicService,omitempty"`
	// If `false`, the system disables News.
	AllowNews *bool `plist:"allowNews,omitempty" json:"allowNews,omitempty"`
	// If `false`, the system disables NFC.
	AllowNFC *bool `plist:"allowNFC,omitempty" json:"allowNFC,omitempty"`
	// If `false`, disables transcription in Notes.
	AllowNotesTranscription *bool `plist:"allowNotesTranscription,omitempty" json:"allowNotesTranscription,omitempty"`
	// If `false`, disables transcription summarization in Notes.
	AllowNotesTranscriptionSummary *bool `plist:"allowNotesTranscriptionSummary,omitempty" json:"allowNotesTranscriptionSummary,omitempty"`
	// If `false`, the system disables modification of notification settings.
	AllowNotificationsModification *bool `plist:"allowNotificationsModification,omitempty" json:"allowNotificationsModification,omitempty"`
	// If `false`, documents in managed apps and accounts open only in other managed apps and
	// accounts.
	AllowOpenFromManagedToUnmanaged *bool `plist:"allowOpenFromManagedToUnmanaged,omitempty" json:"allowOpenFromManagedToUnmanaged,omitempty"`
	// If `false`, documents in unmanaged apps and accounts open only in other unmanaged apps
	// and accounts.
	AllowOpenFromUnmanagedToManaged *bool `plist:"allowOpenFromUnmanagedToManaged,omitempty" json:"allowOpenFromUnmanagedToManaged,omitempty"`
	// If `false`, the system disables over-the-air PKI updates. Setting this restriction to
	// `false` doesn't disable CRL and OCSP checks.
	AllowOTAPKIUpdates *bool `plist:"allowOTAPKIUpdates,omitempty" json:"allowOTAPKIUpdates,omitempty"`
	// If `false`, the system disables pairing with an Apple Watch, and the system unpairs any
	// currently paired Apple Watch and erases its content.
	AllowPairedWatch *bool `plist:"allowPairedWatch,omitempty" json:"allowPairedWatch,omitempty"`
	// If `false`, the system hides Passbook notifications from the Lock Screen.
	AllowPassbookWhileLocked *bool `plist:"allowPassbookWhileLocked,omitempty" json:"allowPassbookWhileLocked,omitempty"`
	// If `false`, the system prevents adding, changing, or removing the passcode. The system
	// ignores this restriction on Shared iPad.
	AllowPasscodeModification *bool `plist:"allowPasscodeModification,omitempty" json:"allowPasscodeModification,omitempty"`
	// If `false`, the system disables:
	AllowPasswordAutoFill *bool `plist:"allowPasswordAutoFill,omitempty" json:"allowPasswordAutoFill,omitempty"`
	// If `false`, the system disables requesting passwords from nearby devices.
	AllowPasswordProximityRequests *bool `plist:"allowPasswordProximityRequests,omitempty" json:"allowPasswordProximityRequests,omitempty"`
	// If `false`, the system disables sharing passwords with the AirDrop passwords feature, or
	// with the Passwords app.
	AllowPasswordSharing *bool `plist:"allowPasswordSharing,omitempty" json:"allowPasswordSharing,omitempty"`
	// If `false`, the system disables modifications of the personal hotspot setting.
	AllowPersonalHotspotModification *bool `plist:"allowPersonalHotspotModification,omitempty" json:"allowPersonalHotspotModification,omitempty"`
	// If false, prevents the system from generating text in the user's handwriting.
	AllowPersonalizedHandwritingResults *bool `plist:"allowPersonalizedHandwritingResults,omitempty" json:"allowPersonalizedHandwritingResults,omitempty"`
	// If `false`, the system disables Photo Stream.
	AllowPhotoStream *bool `plist:"allowPhotoStream,omitempty" json:"allowPhotoStream,omitempty"`
	// If `false`, the system disables podcasts.
	AllowPodcasts *bool `plist:"allowPodcasts,omitempty" json:"allowPodcasts,omitempty"`
	// If `false`, the system disables predictive keyboards.
	AllowPredictiveKeyboard *bool `plist:"allowPredictiveKeyboard,omitempty" json:"allowPredictiveKeyboard,omitempty"`
	// If `false`, the system prevents modifying Printer Sharing settings in System Settings.
	AllowPrinterSharingModification *bool `plist:"allowPrinterSharingModification,omitempty" json:"allowPrinterSharingModification,omitempty"`
	// If `false`, disables the prompt to set up new devices that are nearby. Starting with iOS
	// 26.3, this also prevents exporting iOS data to set up new Android devices.
	AllowProximitySetupToNewDevice *bool `plist:"allowProximitySetupToNewDevice,omitempty" json:"allowProximitySetupToNewDevice,omitempty"`
	// If `false`, the system disables Apple Music Radio.
	AllowRadioService *bool `plist:"allowRadioService,omitempty" json:"allowRadioService,omitempty"`
	// If `false`, the system prohibits installation of Background Security Improvements.
	AllowRapidSecurityResponseInstallation *bool `plist:"allowRapidSecurityResponseInstallation,omitempty" json:"allowRapidSecurityResponseInstallation,omitempty"`
	// If `false`, the system prohibits removal of Background Security Improvements.
	AllowRapidSecurityResponseRemoval *bool `plist:"allowRapidSecurityResponseRemoval,omitempty" json:"allowRapidSecurityResponseRemoval,omitempty"`
	// If `false`, prevents the use of RCS messaging.
	AllowRCSMessaging *bool `plist:"allowRCSMessaging,omitempty" json:"allowRCSMessaging,omitempty"`
	// If `false`, the system prevents modifying Remote Apple Events Sharing settings in System
	// Settings.
	AllowRemoteAppleEventsModification *bool `plist:"allowRemoteAppleEventsModification,omitempty" json:"allowRemoteAppleEventsModification,omitempty"`
	// If `false`, the system disables pairing Apple TV for use with the Control Center widget.
	AllowRemoteAppPairing *bool `plist:"allowRemoteAppPairing,omitempty" json:"allowRemoteAppPairing,omitempty"`
	// If `false`, the system disables remote screen observation by the Classroom app. Nest
	// this key beneath `allowScreenShot` as a subrestriction. If `allowScreenShot` is `false`,
	// the Classroom app doesn't observe remote screens. Requires a supervised device until iOS
	// 13 and macOS 10.15. Allowed for user enrollments in macOS 12 and later.
	AllowRemoteScreenObservation *bool `plist:"allowRemoteScreenObservation,omitempty" json:"allowRemoteScreenObservation,omitempty"`
	// If `false`, disables Rosetta usage awareness. When Rosetta usage awareness is active, a
	// pop-up dialog is displayed to the user when an app that is using Rosetta is launched.
	// The pop-up dialog indicates that Rosetta will be removed in a future version of the
	// operating system so that the user can contact the app vendor regarding a replacement for
	// the current app.
	AllowRosettaUsageAwareness *bool `plist:"allowRosettaUsageAwareness,omitempty" json:"allowRosettaUsageAwareness,omitempty"`
	// If `false`, the system disables the Safari web browser app, and the system removes its
	// icon from the Home Screen. This setting also prevents users from opening web clips.
	// Requires a supervised device in iOS 13 and later.
	AllowSafari *bool `plist:"allowSafari,omitempty" json:"allowSafari,omitempty"`
	// If `false`, the system disables the ability to clear browsing history in Safari.
	AllowSafariHistoryClearing *bool `plist:"allowSafariHistoryClearing,omitempty" json:"allowSafariHistoryClearing,omitempty"`
	// If `false`, the system disables the ability to use private browsing in Safari.
	AllowSafariPrivateBrowsing *bool `plist:"allowSafariPrivateBrowsing,omitempty" json:"allowSafariPrivateBrowsing,omitempty"`
	// If `false`, the system disables the ability to summarize content in Safari.
	AllowSafariSummary *bool `plist:"allowSafariSummary,omitempty" json:"allowSafariSummary,omitempty"`
	// If `false`, the system prohibits the connection to and use of satellite services.
	AllowSatelliteConnection *bool `plist:"allowSatelliteConnection,omitempty" json:"allowSatelliteConnection,omitempty"`
	// If `false`, the system disables saving a screenshot of the display and capturing a
	// screen recording. It also disables the Classroom app from observing remote screens.
	AllowScreenShot *bool `plist:"allowScreenShot,omitempty" json:"allowScreenShot,omitempty"`
	// If `false`, the system makes temporary sessions unavailable on Shared iPad.
	AllowSharedDeviceTemporarySession *bool `plist:"allowSharedDeviceTemporarySession,omitempty" json:"allowSharedDeviceTemporarySession,omitempty"`
	// If `false`, the system disables Shared Photo Stream. Support for this restriction on
	// unsupervised devices is deprecated.
	AllowSharedStream *bool `plist:"allowSharedStream,omitempty" json:"allowSharedStream,omitempty"`
	// If `false`, the system disables the keyboard spell checker.
	AllowSpellCheck *bool `plist:"allowSpellCheck,omitempty" json:"allowSpellCheck,omitempty"`
	// If `false`, the system disables Spotlight Internet search results in Siri Suggestions.
	// Support for this restriction on unsupervised devices is deprecated.
	AllowSpotlightInternetResults *bool `plist:"allowSpotlightInternetResults,omitempty" json:"allowSpotlightInternetResults,omitempty"`
	// If `false`, the system prevents modification of Startup Disk settings in System
	// Settings.
	AllowStartupDiskModification *bool `plist:"allowStartupDiskModification,omitempty" json:"allowStartupDiskModification,omitempty"`
	// If `false`, the system disables the removal of system apps from the device.
	AllowSystemAppRemoval *bool `plist:"allowSystemAppRemoval,omitempty" json:"allowSystemAppRemoval,omitempty"`
	// If `false`, the system prevents modification of Time Machine settings in System
	// Settings. This restriction is not supported on the user channel.
	AllowTimeMachineBackup *bool `plist:"allowTimeMachineBackup,omitempty" json:"allowTimeMachineBackup,omitempty"`
	// If `false`, the system disables the App Store and removes its icon from the Home Screen.
	// However, users can continue to install or update their apps either locally (via
	// Configurator, Xcode, and so forth), or using alternative marketplace apps.
	AllowUIAppInstallation *bool `plist:"allowUIAppInstallation,omitempty" json:"allowUIAppInstallation,omitempty"`
	// If `false`, the system prohibits the user from installing configuration profiles and
	// certificates interactively.
	AllowUIConfigurationProfileInstallation *bool `plist:"allowUIConfigurationProfileInstallation,omitempty" json:"allowUIConfigurationProfileInstallation,omitempty"`
	// If `false`, the system disables Universal Control.
	AllowUniversalControl *bool `plist:"allowUniversalControl,omitempty" json:"allowUniversalControl,omitempty"`
	// If `true`, the system allows unmanaged apps to read from managed contacts accounts. If
	// `allowOpenFromManagedToUnmanaged` is `true`, this restriction has no effect.
	AllowUnmanagedToReadManagedContacts *bool `plist:"allowUnmanagedToReadManagedContacts,omitempty" json:"allowUnmanagedToReadManagedContacts,omitempty"`
	// If `true`, the system allows unpaired devices to boot devices into recovery.
	AllowUnpairedExternalBootToRecovery *bool `plist:"allowUnpairedExternalBootToRecovery,omitempty" json:"allowUnpairedExternalBootToRecovery,omitempty"`
	// If `false`, the system automatically rejects untrusted HTTPS certificates without
	// prompting the user.
	AllowUntrustedTLSPrompt *bool `plist:"allowUntrustedTLSPrompt,omitempty" json:"allowUntrustedTLSPrompt,omitempty"`
	// If `false`, the system allows iOS devices to always connect to USB accessories while
	// locked. In macOS, allows new USB and Thunderbolt accessories, and SD cards to connect
	// without authorization. If the system has Lockdown mode enabled, it ignores this value.
	// This restriction is not supported on the user channel.
	AllowUSBRestrictedMode *bool `plist:"allowUSBRestrictedMode,omitempty" json:"allowUSBRestrictedMode,omitempty"`
	// If `false`, the system hides the FaceTime app. Requires a supervised device in iOS 13
	// and later.
	AllowVideoConferencing *bool `plist:"allowVideoConferencing,omitempty" json:"allowVideoConferencing,omitempty"`
	// If `false`, disables the ability for a remote FaceTime session to request control of the
	// device.
	AllowVideoConferencingRemoteControl *bool `plist:"allowVideoConferencingRemoteControl,omitempty" json:"allowVideoConferencingRemoteControl,omitempty"`
	// If `false`, the system disables visual intelligence summarization.
	AllowVisualIntelligenceSummary *bool `plist:"allowVisualIntelligenceSummary,omitempty" json:"allowVisualIntelligenceSummary,omitempty"`
	// If `false`, the system disables voice dialing if the device is locked with a passcode.
	AllowVoiceDialing *bool `plist:"allowVoiceDialing,omitempty" json:"allowVoiceDialing,omitempty"`
	// If `false`, the system allows only managed apps to create VPN configurations. Prior to
	// iOS 18, the system also allows unmanaged apps to create VPN configurations.
	AllowVPNCreation *bool `plist:"allowVPNCreation,omitempty" json:"allowVPNCreation,omitempty"`
	// If `false`, the system prevents changing the wallpaper.
	AllowWallpaperModification *bool `plist:"allowWallpaperModification,omitempty" json:"allowWallpaperModification,omitempty"`
	// If `false`, the device prevents installation of apps directly from the web.
	AllowWebDistributionAppInstallation *bool `plist:"allowWebDistributionAppInstallation,omitempty" json:"allowWebDistributionAppInstallation,omitempty"`
	// If `false`, disables Apple Intelligence writing tools.
	AllowWritingTools *bool `plist:"allowWritingTools,omitempty" json:"allowWritingTools,omitempty"`
	// If present, the system allows apps identified by the bundle IDs listed in the array to
	// autonomously enter Single App Mode.
	AutonomousSingleAppModePermittedAppIDs []string `plist:"autonomousSingleAppModePermittedAppIDs,omitempty" json:"autonomousSingleAppModePermittedAppIDs,omitempty"`
	// Use `blockedAppBundleIDs` instead.
	BlacklistedAppBundleIDs []string `plist:"blacklistedAppBundleIDs,omitempty" json:"blacklistedAppBundleIDs,omitempty"`
	// If present, the system prevents showing or launching apps with bundle IDs in the array.
	// Include the value `com.apple.webapp` to restrict all webclips. This applies to App Store
	// apps, marketplace apps, and locally installed apps (using Configurator, Xcode, and so
	// forth).
	BlockedAppBundleIDs []string `plist:"blockedAppBundleIDs,omitempty" json:"blockedAppBundleIDs,omitempty"`
	// An array of strings representing ICCIDs of cellular plans. The device prevents use of
	// any matching cellular networks in iMessage and FaceTime. The array must contain no more
	// than 4 ICCID strings.
	DeniedICCIDsForiMessageFaceTime []string `plist:"deniedICCIDsForiMessageFaceTime,omitempty" json:"deniedICCIDsForiMessageFaceTime,omitempty"`
	// An array of strings representing ICCIDs of cellular plans. The device prevents use of
	// any matching cellular networks with RCS messaging. The array must contain no more than 4
	// ICCID strings.
	DeniedICCIDsForRCS []string `plist:"deniedICCIDsForRCS,omitempty" json:"deniedICCIDsForRCS,omitempty"`
	// The value, in seconds, after which the fingerprint unlock requires a password to
	// authenticate. The default value is 48 hours.
	EnforcedFingerprintTimeout *int64 `plist:"enforcedFingerprintTimeout,omitempty" json:"enforcedFingerprintTimeout,omitempty"`
	// How many days to delay a software update on the device. With this restriction in place,
	// the user doesn't see a software update until the specified number of days after the
	// software update release date. The restrictions `forceDelayedAppSoftwareUpdates` and
	// `forceDelayedSoftwareUpdates` use this value.
	EnforcedSoftwareUpdateDelay *int64 `plist:"enforcedSoftwareUpdateDelay,omitempty" json:"enforcedSoftwareUpdateDelay,omitempty"`
	// This restriction allows the administrator to set the number of days to delay a major
	// software upgrade on the device. When this restriction is in place, the user sees a
	// software upgrade only after the specified delay after the release of the software
	// upgrade. This value controls the delay for `forceDelayedMajorSoftwareUpdates`.
	EnforcedSoftwareUpdateMajorOSDeferredInstallDelay *int64 `` /* 134-byte string literal not displayed */
	// This restriction allows the administrator to set the number of days to delay a minor OS
	// software update on the device. When this restriction is in place, the user sees a
	// software update only after the specified delay after the release of the software update.
	// This value controls the delay for `forceDelayedSoftwareUpdates`.
	EnforcedSoftwareUpdateMinorOSDeferredInstallDelay *int64 `` /* 134-byte string literal not displayed */
	// This restriction allows the administrator to set the number of days to delay an app
	// software update on the device. When this restriction is in place, the user sees a non-OS
	// software update only after the specified delay after the release of the software. This
	// value controls the delay for `forceDelayedAppSoftwareUpdates`.
	EnforcedSoftwareUpdateNonOSDeferredInstallDelay *int64 `` /* 130-byte string literal not displayed */
	// If `true`, the system considers AirDrop to be an unmanaged drop target.
	ForceAirDropUnmanaged *bool `plist:"forceAirDropUnmanaged,omitempty" json:"forceAirDropUnmanaged,omitempty"`
	// If `true`, the system forces all devices sending AirPlay requests to this device to use
	// a pairing password. This key isn't supported in tvOS 10.2 and later. Use the AirPlay
	// Security Payload instead.
	ForceAirPlayIncomingRequestsPairingPassword *bool `plist:"forceAirPlayIncomingRequestsPairingPassword,omitempty" json:"forceAirPlayIncomingRequestsPairingPassword,omitempty"`
	// If `true`, the system forces all devices receiving AirPlay requests from this device to
	// use a pairing password.
	ForceAirPlayOutgoingRequestsPairingPassword *bool `plist:"forceAirPlayOutgoingRequestsPairingPassword,omitempty" json:"forceAirPlayOutgoingRequestsPairingPassword,omitempty"`
	// If `true`, the system requires trusted certificates for TLS printing communication.
	ForceAirPrintTrustedTLSRequirement *bool `plist:"forceAirPrintTrustedTLSRequirement,omitempty" json:"forceAirPrintTrustedTLSRequirement,omitempty"`
	// If `true`, the system forces the use of the profanity filter for Siri and dictation.
	// Requires a supervised device in iOS.
	ForceAssistantProfanityFilter *bool `plist:"forceAssistantProfanityFilter,omitempty" json:"forceAssistantProfanityFilter,omitempty"`
	// If `true`, the user needs to authenticate before the system can autofill passwords or
	// credit card information in Safari and apps. If this restriction isn't enforced, the user
	// can toggle this feature in Settings. Only supported on devices with Face ID or Touch ID.
	ForceAuthenticationBeforeAutoFill *bool `plist:"forceAuthenticationBeforeAutoFill,omitempty" json:"forceAuthenticationBeforeAutoFill,omitempty"`
	// If `true`, the system enables the Set Automatically feature in Date & Time and the user
	// can't disable it. The system updates the device's time zone only when the device can
	// determine its location using a cellular connection or Wi-Fi with location services
	// enabled.
	ForceAutomaticDateAndTime *bool `plist:"forceAutomaticDateAndTime,omitempty" json:"forceAutomaticDateAndTime,omitempty"`
	// If `true`, then the system bypasses the presentation of a screen capture alert.
	ForceBypassScreenCaptureAlert *bool `plist:"forceBypassScreenCaptureAlert,omitempty" json:"forceBypassScreenCaptureAlert,omitempty"`
	// If `true`, the system automatically gives permission to the teacher's requests without
	// prompting the student.
	ForceClassroomAutomaticallyJoinClasses *bool `plist:"forceClassroomAutomaticallyJoinClasses,omitempty" json:"forceClassroomAutomaticallyJoinClasses,omitempty"`
	// If `true`, a student enrolled in an unmanaged course through Classroom needs to request
	// permission from the teacher to leave the course.
	ForceClassroomRequestPermissionToLeaveClasses *bool `` /* 126-byte string literal not displayed */
	// If `true`, the system allows the teacher to lock apps or the device without prompting
	// the student.
	ForceClassroomUnpromptedAppAndDeviceLock *bool `plist:"forceClassroomUnpromptedAppAndDeviceLock,omitempty" json:"forceClassroomUnpromptedAppAndDeviceLock,omitempty"`
	// If `true` and `ScreenObservationPermissionModificationAllowed` is also `true` in the
	// Education payload, a student enrolled in a managed course through the Classroom app
	// automatically gives permission to that course teacher's requests to observe the
	// student's screen without prompting the student.
	ForceClassroomUnpromptedScreenObservation *bool `plist:"forceClassroomUnpromptedScreenObservation,omitempty" json:"forceClassroomUnpromptedScreenObservation,omitempty"`
	// If `true`, the system delays user visibility of non-OS software updates. Control
	// visibility of operating system updates through `forceDelayedSoftwareUpdates`. The delay
	// is 30 days unless you set `enforcedSoftwareUpdateDelay` to another value.
	ForceDelayedAppSoftwareUpdates *bool `plist:"forceDelayedAppSoftwareUpdates,omitempty" json:"forceDelayedAppSoftwareUpdates,omitempty"`
	// If `true`, the system delays user visibility of major OS updates.
	ForceDelayedMajorSoftwareUpdates *bool `plist:"forceDelayedMajorSoftwareUpdates,omitempty" json:"forceDelayedMajorSoftwareUpdates,omitempty"`
	// If `true`, the system delays user visibility of software updates. In macOS, the system
	// allows seed build updates without delay. The delay is 30 days unless you set
	// `enforcedSoftwareUpdateDelay` to another value.
	ForceDelayedSoftwareUpdates *bool `plist:"forceDelayedSoftwareUpdates,omitempty" json:"forceDelayedSoftwareUpdates,omitempty"`
	// If `true`, the system encrypts all backups.
	ForceEncryptedBackup *bool `plist:"forceEncryptedBackup,omitempty" json:"forceEncryptedBackup,omitempty"`
	// If `true`, the system forces the user to enter their iTunes password for each
	// transaction.
	ForceITunesStorePasswordEntry *bool `plist:"forceITunesStorePasswordEntry,omitempty" json:"forceITunesStorePasswordEntry,omitempty"`
	// If `true`, the system limits ad tracking. Additionally, it disables app tracking and the
	// Allow Apps to Request to Track setting.
	ForceLimitAdTracking *bool `plist:"forceLimitAdTracking,omitempty" json:"forceLimitAdTracking,omitempty"`
	// If `true`, the system disables connections to Siri servers for the purposes of
	// dictation.
	ForceOnDeviceOnlyDictation *bool `plist:"forceOnDeviceOnlyDictation,omitempty" json:"forceOnDeviceOnlyDictation,omitempty"`
	// If `true`, the device can't connect to Siri servers for the purposes of translation.
	ForceOnDeviceOnlyTranslation *bool `plist:"forceOnDeviceOnlyTranslation,omitempty" json:"forceOnDeviceOnlyTranslation,omitempty"`
	// If `true`, the system preserves eSIM when it erases the device due to too many failed
	// password attempts or the Erase All Content and Settings option in Settings > General >
	// Reset.
	ForcePreserveESIMOnErase *bool `plist:"forcePreserveESIMOnErase,omitempty" json:"forcePreserveESIMOnErase,omitempty"`
	// If `true`, the system forces a paired Apple Watch to use Wrist Detection.
	ForceWatchWristDetection *bool `plist:"forceWatchWristDetection,omitempty" json:"forceWatchWristDetection,omitempty"`
	// If `true`, the system prevents turning off Wi-Fi in Settings or Control Center, even by
	// entering or leaving Airplane Mode. It doesn't prevent selecting which Wi-Fi network to
	// use. and later.
	ForceWiFiPowerOn *bool `plist:"forceWiFiPowerOn,omitempty" json:"forceWiFiPowerOn,omitempty"`
	// If `true`, the system limits the device to only join Wi-Fi networks set up through a
	// configuration profile.
	ForceWiFiToAllowedNetworksOnly *bool `plist:"forceWiFiToAllowedNetworksOnly,omitempty" json:"forceWiFiToAllowedNetworksOnly,omitempty"`
	// Use `forceWiFiToAllowedNetworksOnly` instead.
	ForceWiFiWhitelisting *bool `plist:"forceWiFiWhitelisting,omitempty" json:"forceWiFiWhitelisting,omitempty"`
	// The maximum level of app content allowed on the device. Starting with iOS 26.2, this
	// rating may apply to certain system apps.
	RatingApps *int64 `plist:"ratingApps,omitempty" json:"ratingApps,omitempty"`
	// If present, the system exempts apps with bundle IDs in the array from age-based rating
	// restrictions. The system uses intersection combine rules to combine multiple payloads
	// and any exceptions that parental control apps provide, including ScreenTime.
	RatingAppsExemptedBundleIDs []string `plist:"ratingAppsExemptedBundleIDs,omitempty" json:"ratingAppsExemptedBundleIDs,omitempty"`
	// The maximum level of movie content allowed on the device. Support for this restriction
	// on unsupervised devices is deprecated.
	RatingMovies *int64 `plist:"ratingMovies,omitempty" json:"ratingMovies,omitempty"`
	// The two-letter key that profile tools use to display the proper ratings for the given
	// region. The client doesn't recognize or report this data.
	RatingRegion *string `plist:"ratingRegion,omitempty" json:"ratingRegion,omitempty"`
	// The maximum level of TV content allowed on the device. Support for this restriction on
	// unsupervised devices is deprecated.
	RatingTVShows *int64 `plist:"ratingTVShows,omitempty" json:"ratingTVShows,omitempty"`
	// If `true`, copy-and-paste functionality is limited by the
	// `allowOpenFromManagedToUnmanaged` and `allowOpenFromUnmanagedToManaged` restrictions.
	RequireManagedPasteboard *bool `plist:"requireManagedPasteboard,omitempty" json:"requireManagedPasteboard,omitempty"`
	// Defines the conditions under which the device accepts cookies. The user-facing settings
	// changed in iOS 11, although the possible values remain the same. Support for this
	// restriction on unsupervised devices is deprecated. Allowed values:
	SafariAcceptCookies *float64 `plist:"safariAcceptCookies,omitempty" json:"safariAcceptCookies,omitempty"`
	// If `false`, the system disables Safari AutoFill for passwords, contact info, and credit
	// cards, and also prevents using the Keychain for AutoFill. Requires a supervised device
	// in iOS 13 and later.
	SafariAllowAutoFill *bool `plist:"safariAllowAutoFill,omitempty" json:"safariAllowAutoFill,omitempty"`
	// If `false`, Safari doesn't execute JavaScript. This restriction will require supervision
	// in a future release.
	SafariAllowJavaScript *bool `plist:"safariAllowJavaScript,omitempty" json:"safariAllowJavaScript,omitempty"`
	// If `false`, Safari doesn't allow pop-up windows. Support for this restriction on
	// unsupervised devices is deprecated.
	SafariAllowPopups *bool `plist:"safariAllowPopups,omitempty" json:"safariAllowPopups,omitempty"`
	// If `true`, the system enables Safari fraud warning.
	SafariForceFraudWarning *bool `plist:"safariForceFraudWarning,omitempty" json:"safariForceFraudWarning,omitempty"`
	// Use `allowListedAppBundleIDs` instead.
	WhitelistedAppBundleIDs []string `plist:"whitelistedAppBundleIDs,omitempty" json:"whitelistedAppBundleIDs,omitempty"`
}

Restrictions: The payload that configures restrictions on a device.

Restrictions corresponds to mdm/profiles/com.apple.applicationaccess.yaml (Restrictions).

func (*Restrictions) PayloadTypeName

func (*Restrictions) PayloadTypeName() string

PayloadTypeName returns "com.apple.applicationaccess".

func (*Restrictions) SchemaPath

func (*Restrictions) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Restrictions) Validate

func (x *Restrictions) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SCEP

type SCEP struct {
	// A dictionary containing the SCEP information.
	PayloadContent SCEPPayloadContent `plist:"PayloadContent,omitempty" json:"PayloadContent,omitempty"`
}

SCEP: The payload that configures Simple Certificate Enrollment Protocol (SCEP) settings.

SCEP corresponds to mdm/profiles/com.apple.security.scep.yaml (SCEP).

func (*SCEP) PayloadTypeName

func (*SCEP) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.scep".

func (*SCEP) SchemaPath

func (*SCEP) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SCEP) Validate

func (x *SCEP) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SCEPPayloadContent

type SCEPPayloadContent struct {
	// The SCEP URL. See Over-the-Air Profile Delivery and Configuration for more information
	// about SCEP.
	URL string `plist:"URL" json:"URL"`
	// A string that's understood by the SCEP server; for example, a domain name like
	// example.org. If a certificate authority has multiple CA certificates, this field can be
	// used to distinguish which is required.
	Name *string `plist:"Name,omitempty" json:"Name,omitempty"`
	// The representation of an X.500 name as an array of OID and value.
	Subject [][][]string `plist:"Subject,omitempty" json:"Subject,omitempty"`
	// A preshared secret.
	Challenge *string `plist:"Challenge,omitempty" json:"Challenge,omitempty"`
	// The key size, in bits.
	Keysize *int64 `plist:"Keysize,omitempty" json:"Keysize,omitempty"`
	// Always `RSA`.
	KeyType *string `plist:"Key Type,omitempty" json:"Key Type,omitempty"`
	// A bitmask indicating the use of the key. Possible values:
	KeyUsage *int64 `plist:"Key Usage,omitempty" json:"Key Usage,omitempty"`
	// The fingerprint of the Certificate Authority certificate.
	CAFingerprint []byte `plist:"CAFingerprint,omitempty" json:"CAFingerprint,omitempty"`
	// The number of times the device should retry if the server sends a PENDING response.
	Retries *int64 `plist:"Retries,omitempty" json:"Retries,omitempty"`
	// The number of seconds to wait between subsequent retries. The first retry is attempted
	// without this delay.
	RetryDelay *int64 `plist:"RetryDelay,omitempty" json:"RetryDelay,omitempty"`
	// The SCEP payload can specify an optional `SubjectAltName` dictionary that provides
	// values required by the CA for issuing a certificate. You can specify a single string or
	// an array of strings for each key. The values you specify depend on the CA you're using,
	// but might include DNS name, URL, or email values. For an example, see Sample
	// Configuration Profile or Over-the-Air Profile Delivery and Configuration.
	SubjectAltName *SCEPPayloadContentSubjectAltName `plist:"SubjectAltName,omitempty" json:"SubjectAltName,omitempty"`
	// If `false`, the system disables exporting the private key from the keychain.
	KeyIsExtractable *bool `plist:"KeyIsExtractable,omitempty" json:"KeyIsExtractable,omitempty"`
	// If `true`, all apps have access to the private key.
	AllowAllAppsAccess *bool `plist:"AllowAllAppsAccess,omitempty" json:"AllowAllAppsAccess,omitempty"`
}

SCEPPayloadContent: A dictionary containing the SCEP information.

type SCEPPayloadContentSubjectAltName

type SCEPPayloadContentSubjectAltName struct {
	// The RFC 822 (email address) string.
	Rfc822Name *string `plist:"rfc822Name,omitempty" json:"rfc822Name,omitempty"`
	// The DNS name.
	DNSName *string `plist:"dNSName,omitempty" json:"dNSName,omitempty"`
	// The Uniform Resource Identifier.
	UniformResourceIdentifier *string `plist:"uniformResourceIdentifier,omitempty" json:"uniformResourceIdentifier,omitempty"`
	// The NT principal name. Use an other name OID set to `1.3.6.1.4.1.311.20.2.3`.
	NtPrincipalName *string `plist:"ntPrincipalName,omitempty" json:"ntPrincipalName,omitempty"`
}

SCEPPayloadContentSubjectAltName: The SCEP payload can specify an optional `SubjectAltName` dictionary that provides values required by the CA for issuing a certificate. You can specify a single string or an array of strings for each key. The values you specify depend on the CA you're using, but might include DNS name, URL, or email values. For an example, see Sample Configuration Profile or Over-the-Air Profile Delivery and Configuration.

type Screensaver

type Screensaver struct {
	// If `true`, the user is prompted for a password when the screen saver is unlocked or
	// stopped. When you use this prompt, you must also provide `askForPasswordDelay`.
	// Available in macOS 10.13 and later.
	AskForPassword *bool `plist:"askForPassword,omitempty" json:"askForPassword,omitempty"`
	// The number of seconds to delay before the password will be required to unlock or stop
	// the screen saver (the grace period). A value of `2147483647` (for example, `0x7FFFFFFF`)
	// disables this requirement. To use this option, you must set `askForPassword` to `true`.
	// Available in macOS 10.13 and later.
	AskForPasswordDelay *int64 `plist:"askForPasswordDelay,omitempty" json:"askForPasswordDelay,omitempty"`
	// The number of seconds of inactivity before the screen saver activates (0 = Never
	// activate).
	IdleTime *int64 `plist:"idleTime,omitempty" json:"idleTime,omitempty"`
	// The full path to the screen-saver module to use.
	LoginWindowModulePath *string `plist:"loginWindowModulePath,omitempty" json:"loginWindowModulePath,omitempty"`
	// The name of the screen saver module.
	ModuleName string `plist:"moduleName" json:"moduleName"`
}

Screensaver: The payload that configures the screen saver.

Screensaver corresponds to mdm/profiles/com.apple.screensaver.yaml (Screensaver).

func (*Screensaver) PayloadTypeName

func (*Screensaver) PayloadTypeName() string

PayloadTypeName returns "com.apple.screensaver".

func (*Screensaver) SchemaPath

func (*Screensaver) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Screensaver) Validate

func (x *Screensaver) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ScreensaverUser

type ScreensaverUser struct {
	// The name of the screen saver module.
	ModuleName string `plist:"moduleName" json:"moduleName"`
	// A full path to the screen saver module to use.
	ModulePath *string `plist:"modulePath,omitempty" json:"modulePath,omitempty"`
	// The number of seconds of inactivity before the screen saver activates (`0` = Never
	// activate).
	IdleTime *int64 `plist:"idleTime,omitempty" json:"idleTime,omitempty"`
}

ScreensaverUser: The payload that configures a user's screen saver settings.

ScreensaverUser corresponds to mdm/profiles/com.apple.screensaver.user.yaml (Screensaver User).

func (*ScreensaverUser) PayloadTypeName

func (*ScreensaverUser) PayloadTypeName() string

PayloadTypeName returns "com.apple.screensaver.user".

func (*ScreensaverUser) SchemaPath

func (*ScreensaverUser) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ScreensaverUser) Validate

func (x *ScreensaverUser) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SecurityPreferences

type SecurityPreferences struct {
	// If `true`, disables user changes to the password.
	DontAllowPasswordResetUI *bool `plist:"dontAllowPasswordResetUI,omitempty" json:"dontAllowPasswordResetUI,omitempty"`
	// If `true`, disables user changes to the lock message.
	DontAllowLockMessageUI *bool `plist:"dontAllowLockMessageUI,omitempty" json:"dontAllowLockMessageUI,omitempty"`
	// If `true`, disables user changes to the firewall settings.
	DontAllowFireWallUI *bool `plist:"dontAllowFireWallUI,omitempty" json:"dontAllowFireWallUI,omitempty"`
}

SecurityPreferences: The payload that configures security preferences.

SecurityPreferences corresponds to mdm/profiles/com.apple.preference.security.yaml (Security Preferences).

func (*SecurityPreferences) PayloadTypeName

func (*SecurityPreferences) PayloadTypeName() string

PayloadTypeName returns "com.apple.preference.security".

func (*SecurityPreferences) SchemaPath

func (*SecurityPreferences) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SecurityPreferences) Validate

func (x *SecurityPreferences) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ServiceManagementManagedLoginItems

type ServiceManagementManagedLoginItems struct {
	// An array of service management rules.
	Rules []ServiceManagementManagedLoginItemsRules `plist:"Rules,omitempty" json:"Rules,omitempty"`
}

ServiceManagementManagedLoginItems: This payload that configures managed login items, which auto-enables and auto-allows matched items.

ServiceManagementManagedLoginItems corresponds to mdm/profiles/com.apple.servicemanagement.yaml (Service Management - Managed Login Items).

func (*ServiceManagementManagedLoginItems) PayloadTypeName

func (*ServiceManagementManagedLoginItems) PayloadTypeName() string

PayloadTypeName returns "com.apple.servicemanagement".

func (*ServiceManagementManagedLoginItems) SchemaPath

SchemaPath returns the Apple schema file this type was generated from.

func (*ServiceManagementManagedLoginItems) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ServiceManagementManagedLoginItemsRules

type ServiceManagementManagedLoginItemsRules struct {
	// The type of comparison to make.
	RuleType string `plist:"RuleType" json:"RuleType"`
	// The value to compare with each login item's value, to determine if this rule is a match.
	RuleValue string `plist:"RuleValue" json:"RuleValue"`
	// An optional description of the rule.
	Comment *string `plist:"Comment,omitempty" json:"Comment,omitempty"`
	// An additional constraint to limit the scope of the rule that the system tests after
	// matching the `RuleType` and `RuleValue`.
	TeamIdentifier *string `plist:"TeamIdentifier,omitempty" json:"TeamIdentifier,omitempty"`
}

ServiceManagementManagedLoginItemsRules: A specification for matching one or more login items.

type SetupAssistant

type SetupAssistant struct {
	// If `true`, the system skips the Apple Account setup pane.
	SkipCloudSetup *bool `plist:"SkipCloudSetup,omitempty" json:"SkipCloudSetup,omitempty"`
	// If `true`, the system skips the Siri setup pane.
	SkipSiriSetup *bool `plist:"SkipSiriSetup,omitempty" json:"SkipSiriSetup,omitempty"`
	// If `true`, the system skips the Privacy consent pane.
	SkipPrivacySetup *bool `plist:"SkipPrivacySetup,omitempty" json:"SkipPrivacySetup,omitempty"`
	// If `true`, the system skips the iCloud Storage pane.
	SkipiCloudStorageSetup *bool `plist:"SkipiCloudStorageSetup,omitempty" json:"SkipiCloudStorageSetup,omitempty"`
	// If `true`, the system skips the True Tone Display pane.
	SkipTrueTone *bool `plist:"SkipTrueTone,omitempty" json:"SkipTrueTone,omitempty"`
	// If `true`, the system skips the Choose Your Look pane.
	SkipAppearance *bool `plist:"SkipAppearance,omitempty" json:"SkipAppearance,omitempty"`
	// If `true`, the system skips the Touch ID setup pane.
	SkipTouchIDSetup *bool `plist:"SkipTouchIDSetup,omitempty" json:"SkipTouchIDSetup,omitempty"`
	// If `true`, the system skips the Screen Time pane.
	SkipScreenTime *bool `plist:"SkipScreenTime,omitempty" json:"SkipScreenTime,omitempty"`
	// If `true`, the system skips the Accessibility pane.
	SkipAccessibility *bool `plist:"SkipAccessibility,omitempty" json:"SkipAccessibility,omitempty"`
	// An array of strings that describe the setup items to skip. `SkipKeys` provides a list of
	// valid strings and their meanings. Available in iOS 14 and later, and macOS 15 and later.
	SkipSetupItems []string `plist:"SkipSetupItems,omitempty" json:"SkipSetupItems,omitempty"`
	// If `true`, the system skips the Unlock With Apple Watch pane.
	SkipUnlockWithWatch *bool `plist:"SkipUnlockWithWatch,omitempty" json:"SkipUnlockWithWatch,omitempty"`
	// If 'true', the system skips the Wallpaper selection window.
	SkipWallpaper *bool `plist:"SkipWallpaper,omitempty" json:"SkipWallpaper,omitempty"`
}

SetupAssistant: The payload that configures Setup Assistant settings.

SetupAssistant corresponds to mdm/profiles/com.apple.SetupAssistant.managed.yaml (Setup Assistant).

func (*SetupAssistant) PayloadTypeName

func (*SetupAssistant) PayloadTypeName() string

PayloadTypeName returns "com.apple.SetupAssistant.managed".

func (*SetupAssistant) SchemaPath

func (*SetupAssistant) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SetupAssistant) Validate

func (x *SetupAssistant) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type ShareKit

type ShareKit struct {
	// The list of plugin IDs that show up in the user's Share menu. If this array exists, only
	// these items are permitted.
	SHKAllowedShareServices []string `plist:"SHKAllowedShareServices,omitempty" json:"SHKAllowedShareServices,omitempty"`
	// The list of plugin IDs that won't show up in the user's Share menu. This key is used
	// only if there is no `SHKAllowedShareServices` key.
	SHKDeniedShareServices []string `plist:"SHKDeniedShareServices,omitempty" json:"SHKDeniedShareServices,omitempty"`
}

ShareKit: The payload that configures ShareKit.

ShareKit corresponds to mdm/profiles/com.apple.ShareKitHelper.yaml (ShareKit).

func (*ShareKit) PayloadTypeName

func (*ShareKit) PayloadTypeName() string

PayloadTypeName returns "com.apple.ShareKitHelper".

func (*ShareKit) SchemaPath

func (*ShareKit) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*ShareKit) Validate

func (x *ShareKit) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SingleSignOn

type SingleSignOn struct {
	// The human-readable name for the account.
	Name string `plist:"Name" json:"Name"`
	// The Kerberos dictionary.
	Kerberos *SingleSignOnKerberos `plist:"Kerberos,omitempty" json:"Kerberos,omitempty"`
}

SingleSignOn: The payload that configures single sign-on (SSO).

SingleSignOn corresponds to mdm/profiles/com.apple.sso.yaml (Single Sign-On).

func (*SingleSignOn) PayloadTypeName

func (*SingleSignOn) PayloadTypeName() string

PayloadTypeName returns "com.apple.sso".

func (*SingleSignOn) SchemaPath

func (*SingleSignOn) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SingleSignOn) Validate

func (x *SingleSignOn) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SingleSignOnKerberos

type SingleSignOnKerberos struct {
	// The principal name. If not provided, the system prompts the user for one during profile
	// installation. Required for MDM installation.
	PrincipalName *string `plist:"PrincipalName,omitempty" json:"PrincipalName,omitempty"`
	// The `PayloadUUID` of an identity certificate payload that the system can use to renew
	// the Kerberos credential without user interaction. Set the payload type to either
	// `com.apple.security.pkcs12` or `com.apple.security.scep` in the certificate payload. The
	// configuration file needs to contain both the SSO payload and the identity certificate
	// payload.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// The properly capitalized realm name.
	Realm string `plist:"Realm" json:"Realm"`
	// The list of URL prefixes to match in order to use this account for Kerberos
	// authentication over HTTP. If this key is missing, the system makes the account eligible
	// to match all `http://` and `https://` URLs.
	URLPrefixMatches []string `plist:"URLPrefixMatches,omitempty" json:"URLPrefixMatches,omitempty"`
	// The list of app identifiers that the system allows to use this login. If this field
	// missing, the system matches all app identifiers with this login.
	AppIdentifierMatches []string `plist:"AppIdentifierMatches,omitempty" json:"AppIdentifierMatches,omitempty"`
}

SingleSignOnKerberos: The Kerberos dictionary.

type SmartCard

type SmartCard struct {
	// If `false`, users don't get the pairing dialog, although existing pairings still work.
	UserPairing *bool `plist:"UserPairing,omitempty" json:"UserPairing,omitempty"`
	// If `false`, the system disables smart cards for logins, authorizations, and screen saver
	// unlocking. It is still allowed for other functions, such as signing emails and accessing
	// the web. A restart is required for a setting change to take effect.
	AllowSmartCard *bool `plist:"allowSmartCard,omitempty" json:"allowSmartCard,omitempty"`
	// Configures the certificate trust check and has one of the following possible values:
	CheckCertificateTrust *int64 `plist:"checkCertificateTrust,omitempty" json:"checkCertificateTrust,omitempty"`
	// If `true`, a user can pair with only one smart card, although existing pairings are
	// allowed if already set up.
	OneCardPerUser *bool `plist:"oneCardPerUser,omitempty" json:"oneCardPerUser,omitempty"`
	// If `1`, the system enables the screen saver when the smart card is removed. Available in
	// macOS 10.13.4 and later.
	TokenRemovalAction *int64 `plist:"tokenRemovalAction,omitempty" json:"tokenRemovalAction,omitempty"`
	// If `true`, a user can only log in or authenticate with a smart card. Available in macOS
	// 10.13.2 and later.
	EnforceSmartCard *bool `plist:"enforceSmartCard,omitempty" json:"enforceSmartCard,omitempty"`
}

SmartCard: The payload that configures a smart card.

SmartCard corresponds to mdm/profiles/com.apple.security.smartcard.yaml (SmartCard).

func (*SmartCard) PayloadTypeName

func (*SmartCard) PayloadTypeName() string

PayloadTypeName returns "com.apple.security.smartcard".

func (*SmartCard) SchemaPath

func (*SmartCard) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SmartCard) Validate

func (x *SmartCard) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SoftwareUpdate

type SoftwareUpdate struct {
	// The URL of the software update catalog. This property is not supported in macOS 11 and
	// later.
	CatalogURL *string `plist:"CatalogURL,omitempty" json:"CatalogURL,omitempty"`
	// If `true`, prerelease software can be installed on this computer.
	AllowPreReleaseInstallation *bool `plist:"AllowPreReleaseInstallation,omitempty" json:"AllowPreReleaseInstallation,omitempty"`
	// If `true`, restrict app installations to admin users. This key has the same function as
	// the `restrict-store-require-admin-to-install` key in the `com.apple.appstore` payload.
	RestrictSoftwareUpdateRequireAdminToInstall *bool `` /* 134-byte string literal not displayed */
	// If `false`, restricts the "Install macOS Updates" option and prevents the user from
	// changing the option.
	AutomaticallyInstallMacOSUpdates *bool `plist:"AutomaticallyInstallMacOSUpdates,omitempty" json:"AutomaticallyInstallMacOSUpdates,omitempty"`
	// If `false`, deselects the "Install app updates from the App Store" option and prevents
	// the user from changing the option.
	AutomaticallyInstallAppUpdates *bool `plist:"AutomaticallyInstallAppUpdates,omitempty" json:"AutomaticallyInstallAppUpdates,omitempty"`
	// If `false`, deselects the "Check for updates" option and prevents the user from changing
	// the option.
	AutomaticCheckEnabled *bool `plist:"AutomaticCheckEnabled,omitempty" json:"AutomaticCheckEnabled,omitempty"`
	// If `false`, deselects the "Download new updates when available from the App Store"
	// option and prevents the user from changing the option.
	AutomaticDownload *bool `plist:"AutomaticDownload,omitempty" json:"AutomaticDownload,omitempty"`
	// If `false`, disables the automatic installation of critical updates and prevents the
	// user from changing the "Install system data files and security updates" option.
	CriticalUpdateInstall *bool `plist:"CriticalUpdateInstall,omitempty" json:"CriticalUpdateInstall,omitempty"`
	// If `false`, restricts the automatic installation of configuration data.
	ConfigDataInstall *bool `plist:"ConfigDataInstall,omitempty" json:"ConfigDataInstall,omitempty"`
}

SoftwareUpdate: The payload that configures the software update policy.

SoftwareUpdate corresponds to mdm/profiles/com.apple.SoftwareUpdate.yaml (Software Update).

func (*SoftwareUpdate) PayloadTypeName

func (*SoftwareUpdate) PayloadTypeName() string

PayloadTypeName returns "com.apple.SoftwareUpdate".

func (*SoftwareUpdate) SchemaPath

func (*SoftwareUpdate) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SoftwareUpdate) Validate

func (x *SoftwareUpdate) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SubscribedCalendars

type SubscribedCalendars struct {
	// The description of the account.
	SubCalAccountDescription *string `plist:"SubCalAccountDescription,omitempty" json:"SubCalAccountDescription,omitempty"`
	// The server's address.
	SubCalAccountHostName string `plist:"SubCalAccountHostName" json:"SubCalAccountHostName"`
	// The user's user name.
	SubCalAccountUsername *string `plist:"SubCalAccountUsername,omitempty" json:"SubCalAccountUsername,omitempty"`
	// The user's password.
	SubCalAccountPassword *string `plist:"SubCalAccountPassword,omitempty" json:"SubCalAccountPassword,omitempty"`
	// If `true`, the system enables SSL.
	SubCalAccountUseSSL *bool `plist:"SubCalAccountUseSSL,omitempty" json:"SubCalAccountUseSSL,omitempty"`
	// The VPNUUID of the per-app VPN the account uses for network communication. Available in
	// iOS 14 and later.
	VPNUUID *string `plist:"VPNUUID,omitempty" json:"VPNUUID,omitempty"`
}

SubscribedCalendars: The payload that configures subscribed calendars.

SubscribedCalendars corresponds to mdm/profiles/com.apple.subscribedcalendar.account.yaml (Subscribed Calendars).

func (*SubscribedCalendars) PayloadTypeName

func (*SubscribedCalendars) PayloadTypeName() string

PayloadTypeName returns "com.apple.subscribedcalendar.account".

func (*SubscribedCalendars) SchemaPath

func (*SubscribedCalendars) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SubscribedCalendars) Validate

func (x *SubscribedCalendars) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SystemExtensions

type SystemExtensions struct {
	// If `false`, restricts users from approving additional system extensions that
	// configuration profiles don't explicitly allow.
	AllowUserOverrides *bool `plist:"AllowUserOverrides,omitempty" json:"AllowUserOverrides,omitempty"`
	// An array of team identifiers that defines valid, signed system extensions that are
	// allowable to load. Approved system extensions are those signed with any of the specified
	// team identifiers.
	AllowedTeamIdentifiers []string `plist:"AllowedTeamIdentifiers,omitempty" json:"AllowedTeamIdentifiers,omitempty"`
	// A dictionary that maps a team identifier to an array of strings, where each string is a
	// type of system extension that you can install for that team identifier. The allowed
	// extension types are `DriverExtension`, `NetworkExtension`, and
	// `EndpointSecurityExtension`.
	AllowedSystemExtensionTypes map[string][]string `plist:"AllowedSystemExtensionTypes,omitempty" json:"AllowedSystemExtensionTypes,omitempty"`
	// A dictionary of approved system extensions on the computer. The dictionary maps the team
	// identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines
	// the system extension to install.
	AllowedSystemExtensions map[string][]string `plist:"AllowedSystemExtensions,omitempty" json:"AllowedSystemExtensions,omitempty"`
	// A dictionary of system extensions that are allowed to remove themselves from the
	// machine. The dictionary maps team identifiers (keys) to arrays of bundle identifiers,
	// where the bundle identifier defines the system extension. An application using the
	// `OSSystemExtensionDeactivationRequest` API can deactivate the specified system
	// extensions without requiring an administrator to authorize the operation.
	RemovableSystemExtensions map[string][]string `plist:"RemovableSystemExtensions,omitempty" json:"RemovableSystemExtensions,omitempty"`
	// A dictionary of system extensions on the computer. The dictionary maps the team
	// identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines
	// the system extension which can't be disabled or uninstalled when SIP is enabled. It's an
	// error for the same mapping to appear in the dictionary values corresponding to
	// `RemovableSystemExtensions` and `NonRemovableSystemExtensions` keys.
	NonRemovableSystemExtensions map[string][]string `plist:"NonRemovableSystemExtensions,omitempty" json:"NonRemovableSystemExtensions,omitempty"`
	// A dictionary of system extensions on the computer. The dictionary maps the team
	// identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines
	// the system extension which can't be disabled or uninstalled from System Settings or
	// Finder. The set of system extensions between `RemovableSystemExtensions` and
	// `NonRemovableFromUISystemExtensions` can to overlap.
	NonRemovableFromUISystemExtensions map[string][]string `plist:"NonRemovableFromUISystemExtensions,omitempty" json:"NonRemovableFromUISystemExtensions,omitempty"`
}

SystemExtensions: The payload that configures system extensions.

SystemExtensions corresponds to mdm/profiles/com.apple.system-extension-policy.yaml (System Extensions).

func (*SystemExtensions) PayloadTypeName

func (*SystemExtensions) PayloadTypeName() string

PayloadTypeName returns "com.apple.system-extension-policy".

func (*SystemExtensions) SchemaPath

func (*SystemExtensions) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SystemExtensions) Validate

func (x *SystemExtensions) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SystemLogging

type SystemLogging struct {
	// Not to be used.
	Processes map[string]any `plist:"Processes,omitempty" json:"Processes,omitempty"`
	// A dictionary enabling the logging level for subsystems. See `Customizing Logging
	// Behavior While Debugging` for more details about the format of the dictionary.
	Subsystems map[string]any `plist:"Subsystems,omitempty" json:"Subsystems,omitempty"`
	// This dictionary has one key, `Enable-Private-Data`. Setting that value to `true` enables
	// private data logging for the entire system.
	System map[string]any `plist:"System,omitempty" json:"System,omitempty"`
}

SystemLogging: The payload that configures system logging.

SystemLogging corresponds to mdm/profiles/com.apple.system.logging.yaml (System Logging).

func (*SystemLogging) PayloadTypeName

func (*SystemLogging) PayloadTypeName() string

PayloadTypeName returns "com.apple.system.logging".

func (*SystemLogging) SchemaPath

func (*SystemLogging) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SystemLogging) Validate

func (x *SystemLogging) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SystemMigration

type SystemMigration struct {
	// The list of custom behavior dictionaries.
	CustomBehavior []SystemMigrationCustomBehavior `plist:"CustomBehavior,omitempty" json:"CustomBehavior,omitempty"`
}

SystemMigration: The payload that configures system migration.

SystemMigration corresponds to mdm/profiles/com.apple.systemmigration.yaml (System Migration).

func (*SystemMigration) PayloadTypeName

func (*SystemMigration) PayloadTypeName() string

PayloadTypeName returns "com.apple.systemmigration".

func (*SystemMigration) SchemaPath

func (*SystemMigration) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SystemMigration) Validate

func (x *SystemMigration) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SystemMigrationCustomBehavior

type SystemMigrationCustomBehavior struct {
	// The context that custom paths apply to.
	Context string `plist:"Context" json:"Context"`
	// The list of custom behavior path dictionaries.
	Paths []SystemMigrationCustomBehaviorPaths `plist:"Paths,omitempty" json:"Paths,omitempty"`
}

SystemMigrationCustomBehavior: The custom behavior dictionary.

type SystemMigrationCustomBehaviorPaths

type SystemMigrationCustomBehaviorPaths struct {
	// The path to the migrating file or directory on the source system.
	SourcePath string `plist:"SourcePath" json:"SourcePath"`
	// If `true`, the source path is located within a user home directory.
	SourcePathInUserHome bool `plist:"SourcePathInUserHome" json:"SourcePathInUserHome"`
	// The path to the destination file or directory on the target system.
	TargetPath string `plist:"TargetPath" json:"TargetPath"`
	// If `true`, the target path is located within a user home directory.
	TargetPathInUserHome bool `plist:"TargetPathInUserHome" json:"TargetPathInUserHome"`
}

SystemMigrationCustomBehaviorPaths: The custom behavior path dictionary.

type SystemPolicyControl

type SystemPolicyControl struct {
	// If `true`, enables Gatekeeper. If `false`, disables Gatekeeper.
	EnableAssessment *bool `plist:"EnableAssessment,omitempty" json:"EnableAssessment,omitempty"`
	// If `true`, enables Gatekeeper's "Mac App Store and identified developers" option.
	AllowIdentifiedDevelopers *bool `plist:"AllowIdentifiedDevelopers,omitempty" json:"AllowIdentifiedDevelopers,omitempty"`
	// If `false`, prevents Gatekeeper from prompting the user to upload blocked malware to
	// Apple for purposes of improving malware detection.
	EnableXProtectMalwareUpload *bool `plist:"EnableXProtectMalwareUpload,omitempty" json:"EnableXProtectMalwareUpload,omitempty"`
}

SystemPolicyControl: The payload that configures the system policy for assessments.

SystemPolicyControl corresponds to mdm/profiles/com.apple.systempolicy.control.yaml (System Policy Control).

func (*SystemPolicyControl) PayloadTypeName

func (*SystemPolicyControl) PayloadTypeName() string

PayloadTypeName returns "com.apple.systempolicy.control".

func (*SystemPolicyControl) SchemaPath

func (*SystemPolicyControl) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SystemPolicyControl) Validate

func (x *SystemPolicyControl) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SystemPolicyKernelExtensions

type SystemPolicyKernelExtensions struct {
	// If `true`, nonadministrative users can approve additional kernel extensions in the
	// Security & Privacy preferences.
	AllowNonAdminUserApprovals *bool `plist:"AllowNonAdminUserApprovals,omitempty" json:"AllowNonAdminUserApprovals,omitempty"`
	// If `true`, users can approve additional kernel extensions that configuration profiles
	// don't explicitly allow.
	AllowUserOverrides *bool `plist:"AllowUserOverrides,omitempty" json:"AllowUserOverrides,omitempty"`
	// The array of team identifiers that define which validly signed kernel extensions can
	// load.
	AllowedTeamIdentifiers []string `plist:"AllowedTeamIdentifiers,omitempty" json:"AllowedTeamIdentifiers,omitempty"`
	// The dictionary that represents a set of kernel extensions that the system always allows
	// to load on the computer. The dictionary maps team identifiers (keys) to arrays of bundle
	// identifiers.
	AllowedKernelExtensions map[string][]string `plist:"AllowedKernelExtensions,omitempty" json:"AllowedKernelExtensions,omitempty"`
}

SystemPolicyKernelExtensions: The payload that configures the kernel extension policies.

SystemPolicyKernelExtensions corresponds to mdm/profiles/com.apple.syspolicy.kernel-extension-policy.yaml (System Policy - Kernel Extensions).

func (*SystemPolicyKernelExtensions) PayloadTypeName

func (*SystemPolicyKernelExtensions) PayloadTypeName() string

PayloadTypeName returns "com.apple.syspolicy.kernel-extension-policy".

func (*SystemPolicyKernelExtensions) SchemaPath

func (*SystemPolicyKernelExtensions) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SystemPolicyKernelExtensions) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SystemPolicyManaged

type SystemPolicyManaged struct {
	// If `true`, disables the Finder's contextual menu item.
	DisableOverride *bool `plist:"DisableOverride,omitempty" json:"DisableOverride,omitempty"`
}

SystemPolicyManaged: The payload that configures the Finder's contextual menu to bypass the system policy.

SystemPolicyManaged corresponds to mdm/profiles/com.apple.systempolicy.managed.yaml (System Policy Managed).

func (*SystemPolicyManaged) PayloadTypeName

func (*SystemPolicyManaged) PayloadTypeName() string

PayloadTypeName returns "com.apple.systempolicy.managed".

func (*SystemPolicyManaged) SchemaPath

func (*SystemPolicyManaged) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SystemPolicyManaged) Validate

func (x *SystemPolicyManaged) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SystemPolicyRule

type SystemPolicyRule struct {
	// The policy requirement. This key must follow the syntax described in [Code Signing
	// Requirement
	// Language](https://developer.apple.com/library/archive/documentation/Security/Conceptual/CodeSigningGuide/RequirementLang/RequirementLang.html#//apple_ref/doc/uid/TP40005929-CH5).
	Requirement *string `plist:"Requirement,omitempty" json:"Requirement,omitempty"`
	// This string appears in the System Policy UI. If it's missing, `PayloadDisplayName` or
	// `PayloadDescription` is entered into this field before the rule is added to the System
	// Policy database.
	Comment *string `plist:"Comment,omitempty" json:"Comment,omitempty"`
	// The rule's priority.
	Priority *float64 `plist:"Priority,omitempty" json:"Priority,omitempty"`
	// The expiration date for rules being processed.
	Expiration *time.Time `plist:"Expiration,omitempty" json:"Expiration,omitempty"`
	// The type of operation.
	OperationType *string `plist:"OperationType,omitempty" json:"OperationType,omitempty"`
	// The single leaf certificate for the app that is in the allow list.
	LeafCertificate []byte `plist:"LeafCertificate,omitempty" json:"LeafCertificate,omitempty"`
}

SystemPolicyRule: The payload that configures the system policy.

SystemPolicyRule corresponds to mdm/profiles/com.apple.systempolicy.rule.yaml (System Policy Rule).

func (*SystemPolicyRule) PayloadTypeName

func (*SystemPolicyRule) PayloadTypeName() string

PayloadTypeName returns "com.apple.systempolicy.rule".

func (*SystemPolicyRule) SchemaPath

func (*SystemPolicyRule) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SystemPolicyRule) Validate

func (x *SystemPolicyRule) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type SystemPreferences

type SystemPreferences struct {
	// The list of enabled System Preferences panes.
	EnabledPreferencePanes []string `plist:"EnabledPreferencePanes,omitempty" json:"EnabledPreferencePanes,omitempty"`
	// The list of disabled System Preferences panes.
	DisabledPreferencePanes []string `plist:"DisabledPreferencePanes,omitempty" json:"DisabledPreferencePanes,omitempty"`
	// The list of disabled System Settings extensions. All other items will be enabled. When
	// `DisabledSystemSettings` is specified, the device ignores `DisabledPreferencePanes` and
	// `EnabledPreferencePanes`.
	DisabledSystemSettings []string `plist:"DisabledSystemSettings,omitempty" json:"DisabledSystemSettings,omitempty"`
}

SystemPreferences: The payload that configures the preference panes.

SystemPreferences corresponds to mdm/profiles/com.apple.systempreferences.yaml (System Preferences).

func (*SystemPreferences) PayloadTypeName

func (*SystemPreferences) PayloadTypeName() string

PayloadTypeName returns "com.apple.systempreferences".

func (*SystemPreferences) SchemaPath

func (*SystemPreferences) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*SystemPreferences) Validate

func (x *SystemPreferences) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type TVRemote

type TVRemote struct {
	// The array of valid devices that Apple TV can connect to.
	AllowedRemotes []TVRemoteAllowedRemotes `plist:"AllowedRemotes,omitempty" json:"AllowedRemotes,omitempty"`
	// The array of valid Apple TV identifiers that the remote can connect to.
	AllowedTVs []TVRemoteAllowedTVs `plist:"AllowedTVs,omitempty" json:"AllowedTVs,omitempty"`
}

TVRemote: The payload that configures the Apple TV remote.

TVRemote corresponds to mdm/profiles/com.apple.tvremote.yaml (TV Remote).

func (*TVRemote) PayloadTypeName

func (*TVRemote) PayloadTypeName() string

PayloadTypeName returns "com.apple.tvremote".

func (*TVRemote) SchemaPath

func (*TVRemote) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*TVRemote) Validate

func (x *TVRemote) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type TVRemoteAllowedRemotes

type TVRemoteAllowedRemotes struct {
	// The MAC address of a permitted iOS device that can control this Apple TV. Use the format
	// `xx:xx:xx:xx:xx:xx`, which isn't case-sensitive.
	RemoteDeviceID string `plist:"RemoteDeviceID" json:"RemoteDeviceID"`
}

TVRemoteAllowedRemotes: The array of valid devices that Apple TV can connect to.

type TVRemoteAllowedTVs

type TVRemoteAllowedTVs struct {
	// The MAC address of an Apple TV device that the system permits this iOS device to
	// control. Use the format `xx:xx:xx:xx:xx:xx`, which isn't case-sensitive.
	TVDeviceID string `plist:"TVDeviceID" json:"TVDeviceID"`
	// The name of an Apple TV device that the system permits this iOS device to control.
	TVDeviceName *string `plist:"TVDeviceName,omitempty" json:"TVDeviceName,omitempty"`
}

TVRemoteAllowedTVs: The array of valid Apple TV identifiers that the remote can connect to.

type TimeMachine

type TimeMachine struct {
	// If `true`, performs automatic backups at regular intervals.
	AutoBackup *bool `plist:"AutoBackup,omitempty" json:"AutoBackup,omitempty"`
	// If `true`, backs up only the startup volume by default.
	BackupAllVolumes *bool `plist:"BackupAllVolumes,omitempty" json:"BackupAllVolumes,omitempty"`
	// The URL of the backup destination.
	BackupDestURL string `plist:"BackupDestURL" json:"BackupDestURL"`
	// The backup size limit, in megabytes. Set to 0 for unlimited.
	BackupSizeMB *int64 `plist:"BackupSizeMB,omitempty" json:"BackupSizeMB,omitempty"`
	// If `true`, skips system files and folders by default.
	BackupSkipSys *bool `plist:"BackupSkipSys,omitempty" json:"BackupSkipSys,omitempty"`
	// If `true`, create local backup snapshots when not connected to the network.
	MobileBackups *bool `plist:"MobileBackups,omitempty" json:"MobileBackups,omitempty"`
	// The list of paths to back up besides the startup volume.
	BasePaths []string `plist:"BasePaths,omitempty" json:"BasePaths,omitempty"`
	// The path to skip from start volume.
	SkipPaths []string `plist:"SkipPaths,omitempty" json:"SkipPaths,omitempty"`
}

TimeMachine: The payload that configures Time Machine.

TimeMachine corresponds to mdm/profiles/com.apple.MCX.TimeMachine.yaml (Time Machine).

func (*TimeMachine) PayloadTypeName

func (*TimeMachine) PayloadTypeName() string

PayloadTypeName returns "com.apple.MCX.TimeMachine".

func (*TimeMachine) SchemaPath

func (*TimeMachine) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*TimeMachine) Validate

func (x *TimeMachine) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type TimeServer

type TimeServer struct {
	// The NTP server to connect to. In macOS 10.13 and later, only one time server is
	// supported.
	TimeServer *string `plist:"timeServer,omitempty" json:"timeServer,omitempty"`
	// The time zone path location string in `/usr/share/zoneinfo/`; for example,
	// `America/Denver` or `Zulu`.
	TimeZone *string `plist:"timeZone,omitempty" json:"timeZone,omitempty"`
}

TimeServer: The payload that configures the time server.

TimeServer corresponds to mdm/profiles/com.apple.MCX(TimeServer).yaml (Time Server).

func (*TimeServer) PayloadTypeName

func (*TimeServer) PayloadTypeName() string

PayloadTypeName returns "com.apple.MCX".

func (*TimeServer) SchemaPath

func (*TimeServer) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*TimeServer) Validate

func (x *TimeServer) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type TopLevel

type TopLevel struct {
	// The reverse-DNS style identifier (`com.example.myprofile`, for example) that identifies
	// the profile. The system uses this string to determine whether to replace an existing
	// profile or add it as a new profile.
	PayloadIdentifier string `plist:"PayloadIdentifier" json:"PayloadIdentifier"`
	// The globally unique identifier for the profile. The actual content is unimportant. In
	// macOS, you can use `uuidgen` to generate reasonable UUIDs.
	PayloadUUID string `plist:"PayloadUUID" json:"PayloadUUID"`
	// The type of payload. The only supported value is `Configuration`.
	PayloadType string `plist:"PayloadType" json:"PayloadType"`
	// The version number of the profile format, which needs to be `1`. This number represents
	// the version of the configuration profile as a whole, not of the individual profiles
	// within it.
	PayloadVersion int64 `plist:"PayloadVersion" json:"PayloadVersion"`
	// The array of payload dictionaries. If `IsEncrypted` is `true`, this array isn't needed.
	PayloadContent []TopLevelPayloadContent `plist:"PayloadContent,omitempty" json:"PayloadContent,omitempty"`
	// Enabled if `IsEncrypted` is `true`.
	EncryptedPayloadContent []byte `plist:"EncryptedPayloadContent,omitempty" json:"EncryptedPayloadContent,omitempty"`
	// The description of the profile, shown on the Detail screen for the profile. Make this
	// description detailed enough to help the user decide whether to install the profile.
	PayloadDescription *string `plist:"PayloadDescription,omitempty" json:"PayloadDescription,omitempty"`
	// The human-readable name for the profile, which doesn't need to be unique. The system
	// displays this value on the Detail screen.
	PayloadDisplayName *string `plist:"PayloadDisplayName,omitempty" json:"PayloadDisplayName,omitempty"`
	// The human-readable string that contains the name of the organization that provided the
	// profile.
	PayloadOrganization *string `plist:"PayloadOrganization,omitempty" json:"PayloadOrganization,omitempty"`
	// If present and set to `true`, the user can't delete the profile unless the profile has a
	// removal password and the user provides it.
	PayloadRemovalDisallowed *bool `plist:"PayloadRemovalDisallowed,omitempty" json:"PayloadRemovalDisallowed,omitempty"`
	// A string that defines whether to install the profile for the system or the user. In many
	// cases, it determines the location of certificate items, such as keychains. Though it's
	// not possible to declare different payload scopes, payloads like VPN can automatically
	// install their items in both scopes, if needed.
	PayloadScope *string `plist:"PayloadScope,omitempty" json:"PayloadScope,omitempty"`
	// The date when the system automatically removes the profile.
	RemovalDate *time.Time `plist:"RemovalDate,omitempty" json:"RemovalDate,omitempty"`
	// The number of seconds until the profile is automatically removed. If the `RemovalDate`
	// key is present, the system uses whichever field yields the earliest date.
	DurationUntilRemoval *float64 `plist:"DurationUntilRemoval,omitempty" json:"DurationUntilRemoval,omitempty"`
	// The date when a profile is no longer valid and the system presents an update button to
	// the user.
	PayloadExpirationDate *time.Time `plist:"PayloadExpirationDate,omitempty" json:"PayloadExpirationDate,omitempty"`
	// The type of platform of the target device. Specifying the platform type helps prevent
	// unintended installations.
	TargetDeviceType *int64 `plist:"TargetDeviceType,omitempty" json:"TargetDeviceType,omitempty"`
	// A dictionary that includes:
	ConsentText *TopLevelConsentText `plist:"ConsentText,omitempty" json:"ConsentText,omitempty"`
}

TopLevel: The top-level payload properties for all profiles.

TopLevel corresponds to mdm/profiles/TopLevel.yaml (Top Level).

func (*TopLevel) PayloadTypeName

func (*TopLevel) PayloadTypeName() string

PayloadTypeName returns "TopLevel".

func (*TopLevel) SchemaPath

func (*TopLevel) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*TopLevel) Validate

func (x *TopLevel) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type TopLevelConsentText

type TopLevelConsentText struct {
	// The dictionary containing a key that consists of the IETF BCP 47 identifier for a
	// language (for example, en or jp) and a value that consists of the agreement localized to
	// that language.
	ConsentTextItem map[string]string `plist:"ConsentTextItem,omitempty" json:"ConsentTextItem,omitempty"`
}

TopLevelConsentText: A dictionary that includes:

type TopLevelPayloadContent

type TopLevelPayloadContent struct {
	// A payload item as defined by each payload type.
	ANY any `plist:"ANY,omitempty" json:"ANY,omitempty"`
}

TopLevelPayloadContent: The payload-specific content for this profile.

type UserPreferences

type UserPreferences struct {
	// If `true`, disables the iCloud password for local accounts.
	DisableUsingiCloudPassword *bool `plist:"DisableUsingiCloudPassword,omitempty" json:"DisableUsingiCloudPassword,omitempty"`
}

UserPreferences: The payload that configures iCloud password preferences.

UserPreferences corresponds to mdm/profiles/com.apple.preferences.users.yaml (User Preferences).

func (*UserPreferences) PayloadTypeName

func (*UserPreferences) PayloadTypeName() string

PayloadTypeName returns "com.apple.preference.users".

func (*UserPreferences) SchemaPath

func (*UserPreferences) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*UserPreferences) Validate

func (x *UserPreferences) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type VPN

type VPN struct {
	// The type of the VPN, which defines which settings are appropriate for this VPN payload.
	VPNType string `plist:"VPNType" json:"VPNType"`
	// An identifier for a vendor-specified configuration dictionary when the value for
	// `VPNType` is `VPN`.
	VPNSubType *string `plist:"VPNSubType,omitempty" json:"VPNSubType,omitempty"`
	// The description of the VPN connection that the system displays on the device. Not
	// available in watchOS.
	UserDefinedName string `plist:"UserDefinedName" json:"UserDefinedName"`
	// The vendor-specific configuration dictionary, which the system reads only when
	// `VPNSubType` has a value. Not available in watchOS.
	VendorConfig *VPNVendorConfig `plist:"VendorConfig,omitempty" json:"VendorConfig,omitempty"`
	// The dictionary to use when `VPNType` is `VPN`.
	VPN *VPNVPN `plist:"VPN,omitempty" json:"VPN,omitempty"`
	// The dictionary that contains IPv4 settings. Not available in watchOS.
	IPv4 *VPNIPv4 `plist:"IPv4,omitempty" json:"IPv4,omitempty"`
	// The dictionary to use when `VPNType` is `L2TP` or `PTPP`. Not available in watchOS.
	PPP *VPNPPP `plist:"PPP,omitempty" json:"PPP,omitempty"`
	// The dictionary that contains IPSec settings. Not available in watchOS.
	IPSec *VPNIPSec `plist:"IPSec,omitempty" json:"IPSec,omitempty"`
	// The dictionary to use when `VPNType` is `IKEv2`.
	IKEv2 *VPNIKEv2 `plist:"IKEv2,omitempty" json:"IKEv2,omitempty"`
	// A dictionary to use for all VPN types.
	DNS *VPNDNS `plist:"DNS,omitempty" json:"DNS,omitempty"`
	// The dictionary to use to configure `Proxies` for use with `VPN`.
	Proxies *VPNProxies `plist:"Proxies,omitempty" json:"Proxies,omitempty"`
	// The dictionary to use when `VPNType` is `AlwaysOn`. Not available in tvOS or watchOS.
	AlwaysOn *VPNAlwaysOn `plist:"AlwaysOn,omitempty" json:"AlwaysOn,omitempty"`
	// The dictionary to use when `VPNType` is `TransparentProxy`. Available in macOS 14 and
	// later.
	TransparentProxy *VPNTransparentProxy `plist:"TransparentProxy,omitempty" json:"TransparentProxy,omitempty"`
}

VPN: The payload that configures a VPN.

VPN corresponds to mdm/profiles/com.apple.vpn.managed.yaml (VPN).

func (*VPN) PayloadTypeName

func (*VPN) PayloadTypeName() string

PayloadTypeName returns "com.apple.vpn.managed".

func (*VPN) SchemaPath

func (*VPN) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*VPN) Validate

func (x *VPN) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type VPNAlwaysOn

type VPNAlwaysOn struct {
	// If `1`, allows the user to disable the VPN configuration.
	UIToggleEnabled *int64 `plist:"UIToggleEnabled,omitempty" json:"UIToggleEnabled,omitempty"`
	// An array that contains an arbitrary number of tunnel configurations.
	TunnelConfigurations []VPNAlwaysOnTunnelConfigurations `plist:"TunnelConfigurations,omitempty" json:"TunnelConfigurations,omitempty"`
	// An array that contains an arbitrary number of service exceptions.
	ServiceExceptions []VPNAlwaysOnServiceExceptions `plist:"ServiceExceptions,omitempty" json:"ServiceExceptions,omitempty"`
	// An array that contains an arbitrary number of apps whose connections occur outside the
	// VPN.
	ApplicationExceptions []VPNAlwaysOnApplicationExceptions `plist:"ApplicationExceptions,omitempty" json:"ApplicationExceptions,omitempty"`
	// If `1`, allows traffic from Captive Web Sheet outside the VPN tunnel.
	AllowCaptiveWebSheet *int64 `plist:"AllowCaptiveWebSheet,omitempty" json:"AllowCaptiveWebSheet,omitempty"`
	// If `1`, allows traffic from all captive networking apps outside the VPN tunnel to
	// perform captive network handling.
	AllowAllCaptiveNetworkPlugins *int64 `plist:"AllowAllCaptiveNetworkPlugins,omitempty" json:"AllowAllCaptiveNetworkPlugins,omitempty"`
	// The array of captive networking apps whose traffic is allowed outside the VPN tunnel, to
	// perform captive network handling. Used only when `AllowAllCaptiveNetworkPlugins` is
	// `false`.
	AllowedCaptiveNetworkPlugins []VPNAlwaysOnAllowedCaptiveNetworkPlugins `plist:"AllowedCaptiveNetworkPlugins,omitempty" json:"AllowedCaptiveNetworkPlugins,omitempty"`
}

VPNAlwaysOn: The dictionary to use when `VPNType` is `AlwaysOn`. Not available in tvOS or watchOS.

type VPNAlwaysOnAllowedCaptiveNetworkPlugins

type VPNAlwaysOnAllowedCaptiveNetworkPlugins struct {
	// The bundle identifier for the app that's allowed on the captive network.
	BundleIdentifier string `plist:"BundleIdentifier" json:"BundleIdentifier"`
}

VPNAlwaysOnAllowedCaptiveNetworkPlugins: is generated from mdm/profiles/com.apple.vpn.managed.yaml.

type VPNAlwaysOnApplicationExceptions

type VPNAlwaysOnApplicationExceptions struct {
	// The app's bundle identifier.
	BundleIdentifier string `plist:"BundleIdentifier" json:"BundleIdentifier"`
	// Limit the exception to only the specified list of protocols, with support for `UDP`
	// only.
	LimitToProtocols []string `plist:"LimitToProtocols,omitempty" json:"LimitToProtocols,omitempty"`
}

VPNAlwaysOnApplicationExceptions: is generated from mdm/profiles/com.apple.vpn.managed.yaml.

type VPNAlwaysOnServiceExceptions

type VPNAlwaysOnServiceExceptions struct {
	// The name of a service that's exempt from Always On VPN.
	ServiceName string `plist:"ServiceName" json:"ServiceName"`
	// The action to take with network connections from the named service.
	Action string `plist:"Action" json:"Action"`
}

VPNAlwaysOnServiceExceptions: is generated from mdm/profiles/com.apple.vpn.managed.yaml.

type VPNAlwaysOnTunnelConfigurations

type VPNAlwaysOnTunnelConfigurations struct {
	// The type of connection, which needs to be `IKEv2`.
	ProtocolType string `plist:"ProtocolType" json:"ProtocolType"`
	// The interfaces to apply this configuration to.
	Interfaces []string `plist:"Interfaces,omitempty" json:"Interfaces,omitempty"`
}

VPNAlwaysOnTunnelConfigurations: is generated from mdm/profiles/com.apple.vpn.managed.yaml.

type VPNDNS

type VPNDNS struct {
	// The transport protocol to communicate with the DNS server.
	DNSProtocol string `plist:"DNSProtocol" json:"DNSProtocol"`
	// The URI template of a DNS-over-HTTPS server, as defined in RFC 8484, which needs to use
	// the `https://` scheme. The system uses the hostname or address in the URL to validate
	// the server certificate. If `ServerAddresses` isn't specified, the system uses the
	// hostname or address in the URL to determine the server addresses. This key is required
	// if the `DNSProtocol` is `HTTPS`.
	ServerURL *string `plist:"ServerURL,omitempty" json:"ServerURL,omitempty"`
	// The hostname of a DNS-over-TLS server to validate the server certificate, as defined in
	// RFC 7858. If `ServerAddresses` isn't specified, the system uses the hostname to
	// determine the server addresses. This key is required if the `DNSProtocol` is `TLS`.
	ServerName *string `plist:"ServerName,omitempty" json:"ServerName,omitempty"`
	// The array of DNS server IP address strings. These IP addresses can be a mixture of IPv4
	// and IPv6 addresses.
	ServerAddresses []string `plist:"ServerAddresses,omitempty" json:"ServerAddresses,omitempty"`
	// The list of domain strings used to fully qualify single-label host names.
	SearchDomains []string `plist:"SearchDomains,omitempty" json:"SearchDomains,omitempty"`
	// The primary domain of the tunnel.
	DomainName *string `plist:"DomainName,omitempty" json:"DomainName,omitempty"`
	// The list of domain strings used to determine which DNS queries use the DNS resolver
	// settings in `ServerAddresses`. The system uses this key to create a split DNS
	// configuration where it resolves only hosts in certain domains using the tunnel's DNS
	// resolver. The system uses the default resolver for hosts that aren't in one of the
	// domains in this list.
	SupplementalMatchDomains []string `plist:"SupplementalMatchDomains,omitempty" json:"SupplementalMatchDomains,omitempty"`
	// If `0`, append the domains in the `SupplementalMatchDomains` list to the resolver's list
	// of search domains.
	SupplementalMatchDomainsNoSearch *int64 `plist:"SupplementalMatchDomainsNoSearch,omitempty" json:"SupplementalMatchDomainsNoSearch,omitempty"`
	// That UUID that points to an identity certificate payload. The system uses this identity
	// to authenticate the user to the DNS resolver.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
}

VPNDNS: A dictionary to use for all VPN types.

type VPNIKEv2

type VPNIKEv2 struct {
	// The IP address or host name of the VPN server.
	RemoteAddress string `plist:"RemoteAddress" json:"RemoteAddress"`
	// Identifier of the IKEv2 client.
	LocalIdentifier string `plist:"LocalIdentifier" json:"LocalIdentifier"`
	// The remote identifier.
	RemoteIdentifier string `plist:"RemoteIdentifier" json:"RemoteIdentifier"`
	// The type of authentication method for the VPN.
	AuthenticationMethod string `plist:"AuthenticationMethod" json:"AuthenticationMethod"`
	// The type of `PayloadCertificateUUID` to use for IKEv2 machine authentication. If this
	// key is included, the system requires a value for `ServerCertificateIssuerCommonName`.
	CertificateType *string `plist:"CertificateType,omitempty" json:"CertificateType,omitempty"`
	// The UUID of the certificate payload within the same profile to use as the account
	// credential. If the value of `AuthenticationMethod` is `Certificate`, the system sends
	// this certificate out for IKEv2 machine authentication. If extended authentication (EAP)
	// is used, the system sends this certificate out for EAP-TLS authentication.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// The password to use for the account credentials. Only used if `AuthenticationMethod` is
	// `Password`.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// If the VPNSubType field contains the bundle identifier of an app that contains multiple
	// VPN providers of the same type (app-proxy or packet-tunnel), then the system uses this
	// field to choose which provider to use for this configuration. If the VPN provider is
	// implemented as a System Extension, then this field is required.
	ProviderBundleIdentifier *string `plist:"ProviderBundleIdentifier,omitempty" json:"ProviderBundleIdentifier,omitempty"`
	// If the VPN provider is implemented as a System Extension, then this field is required.
	// Available in macOS 10.15 and later, tvOS 17 and later, and watchOS 10 and later.
	ProviderDesignatedRequirement *string `plist:"ProviderDesignatedRequirement,omitempty" json:"ProviderDesignatedRequirement,omitempty"`
	// If `AuthenticationMethod` is `SharedSecret`, this value is used for IKE authentication.
	SharedSecret *string `plist:"SharedSecret,omitempty" json:"SharedSecret,omitempty"`
	// If `1`, enables EAP-only authentication.
	ExtendedAuthEnabled *int64 `plist:"ExtendedAuthEnabled,omitempty" json:"ExtendedAuthEnabled,omitempty"`
	// The user name to use for authentication.
	AuthName *string `plist:"AuthName,omitempty" json:"AuthName,omitempty"`
	// The password to use for authentication.
	AuthPassword *string `plist:"AuthPassword,omitempty" json:"AuthPassword,omitempty"`
	// If `1`, enables VPN up on demand.
	OnDemandEnabled *int64 `plist:"OnDemandEnabled,omitempty" json:"OnDemandEnabled,omitempty"`
	// If `1`, the system disables the Connect On Demand toggle in Settings for this
	// configuration.
	OnDemandUserOverrideDisabled *int64 `plist:"OnDemandUserOverrideDisabled,omitempty" json:"OnDemandUserOverrideDisabled,omitempty"`
	// A list of rules that determine when and how to use an OnDemand VPN.
	OnDemandRules []VPNOnDemandRulesElement `plist:"OnDemandRules,omitempty" json:"OnDemandRules,omitempty"`
	// One of the following:
	DeadPeerDetectionRate *string `plist:"DeadPeerDetectionRate,omitempty" json:"DeadPeerDetectionRate,omitempty"`
	// Common Name of the server certificate issuer. If set, this field causes IKE to send a
	// certificate request based on this certificate issuer to the server. This key is required
	// if the `CertificateType` key is included and the `ExtendedAuthEnabled` key is `1`.
	ServerCertificateIssuerCommonName *string `plist:"ServerCertificateIssuerCommonName,omitempty" json:"ServerCertificateIssuerCommonName,omitempty"`
	// The common name of the server certificate. The system uses this name to validate the
	// certificate sent by the IKE server. If not set, the system uses the remote identifier to
	// validate the certificate.
	ServerCertificateCommonName *string `plist:"ServerCertificateCommonName,omitempty" json:"ServerCertificateCommonName,omitempty"`
	// The minimum TLS version to use with EAP-TLS authentication.
	TLSMinimumVersion *string `plist:"TLSMinimumVersion,omitempty" json:"TLSMinimumVersion,omitempty"`
	// The maximum TLS version to use with EAP-TLS authentication.
	TLSMaximumVersion *string `plist:"TLSMaximumVersion,omitempty" json:"TLSMaximumVersion,omitempty"`
	// If `1`, negotiations should use IKEv2 Configuration Attribute `INTERNAL_IP4_SUBNET` and
	// `INTERNAL_IP6_SUBNET`.
	UseConfigurationAttributeInternalIPSubnet *int64 `plist:"UseConfigurationAttributeInternalIPSubnet,omitempty" json:"UseConfigurationAttributeInternalIPSubnet,omitempty"`
	// If `1`, the system disables MOBIKE.
	DisableMOBIKE *int64 `plist:"DisableMOBIKE,omitempty" json:"DisableMOBIKE,omitempty"`
	// If `1`, the system disables IKEv2 redirect. If not set, the system redirects an IKEv2
	// connection when it receives a redirect request from the server.
	DisableRedirect *int64 `plist:"DisableRedirect,omitempty" json:"DisableRedirect,omitempty"`
	// If `1`, the VPN disconnects automatically after a period defined by
	// `DisconnectOnIdleTimer`.
	DisconnectOnIdle *int64 `plist:"DisconnectOnIdle,omitempty" json:"DisconnectOnIdle,omitempty"`
	// Only used if `DisconnectOnIdle` is `1`. The number of seconds before the VPN
	// disconnects. On watchOS, maximum allowed value is 15 seconds
	DisconnectOnIdleTimer *int64 `plist:"DisconnectOnIdleTimer,omitempty" json:"DisconnectOnIdleTimer,omitempty"`
	// If `1`, enables NAT keepalive offload for Always On VPN IKEv2 connections. The device
	// sends keepalive packets to maintain NAT mappings for IKEv2 connections that have a NAT
	// on the path. It sends keepalive packets at regular intervals when the device is awake.
	// If `NATKeepAliveOffloadEnable` is `1`, the system offloads keepalive packets to hardware
	// while the device is asleep.
	NATKeepAliveOffloadEnable *int64 `plist:"NATKeepAliveOffloadEnable,omitempty" json:"NATKeepAliveOffloadEnable,omitempty"`
	// The NAT Keepalive interval for Always On VPN IKEv2 connections. This value controls the
	// interval that the device sends keepalive offload packets. The minimum value is 20
	// seconds. If no key is specified, the default is 20 seconds over Wi-Fi and 110 seconds
	// over a cellular interface.
	NATKeepAliveInterval *int64 `plist:"NATKeepAliveInterval,omitempty" json:"NATKeepAliveInterval,omitempty"`
	// If `1`, enables Perfect Forward Secrecy (PFS) for IKEv2 Connections.
	EnablePFS *int64 `plist:"EnablePFS,omitempty" json:"EnablePFS,omitempty"`
	// If `1`, the system performs a certificate revocation check for IKEv2 connections. This
	// is a best-effort revocation check and server response timeouts won't cause it to fail.
	EnableCertificateRevocationCheck *int64 `plist:"EnableCertificateRevocationCheck,omitempty" json:"EnableCertificateRevocationCheck,omitempty"`
	// If `1`, the system enables a tunnel over cellular data to carry traffic that's eligible
	// for Wi-Fi Assist and also requires VPN.
	EnableFallback *int64 `plist:"EnableFallback,omitempty" json:"EnableFallback,omitempty"`
	// The Maximum Transmission Unit (MTU) specifies the maximum size in bytes of each packet
	// that the system sends over the IKEv2 VPN interface. Available in iOS 14 and later, and
	// macOS 11 and later.
	MTU *int64 `plist:"MTU,omitempty" json:"MTU,omitempty"`
	// If the value of this key is `app-proxy`, the VPN service tunnels traffic at the
	// application layer. If the value of this key is `packet-tunnel`, the VPN service tunnels
	// traffic at the IP layer.
	ProviderType *string `plist:"ProviderType,omitempty" json:"ProviderType,omitempty"`
	// If `1`, then the system routes all network traffic through the VPN, with some
	// controllable exclusions, such as `ExcludeLocalNetworks`, `ExcludeCellularServices`, and
	// `ExcludeAPNs` properties. The system always excludes the following traffic from the
	// tunnel:
	IncludeAllNetworks *int64 `plist:"IncludeAllNetworks,omitempty" json:"IncludeAllNetworks,omitempty"`
	// If `1`, all the VPN's non-default routes take precedence over any locally-defined
	// routes. If `IncludeAllNetworks` is `1`, the system ignores `EnforceRoutes`.
	EnforceRoutes *int64 `plist:"EnforceRoutes,omitempty" json:"EnforceRoutes,omitempty"`
	// If `1` and either `IncludeAllNetworks` or `EnforceRoutes` are `1`, then the system
	// routes local network traffic outside of the VPN. The default for this value is `0` on
	// macOS and `1` on iOS.
	ExcludeLocalNetworks *int64 `plist:"ExcludeLocalNetworks,omitempty" json:"ExcludeLocalNetworks,omitempty"`
	// If `1` and `IncludeAllNetworks` is `1`, the system excludes internet-routable network
	// traffic for cellular services (VoLTE, Wi-Fi Calling, IMS, MMS, Visual Voicemail, etc.)
	// from the tunnel. Note that some cellular carriers route cellular services traffic
	// directly to the carrier network, bypassing the internet. Such cellular services traffic
	// is always excluded from the tunnel.
	ExcludeCellularServices *int64 `plist:"ExcludeCellularServices,omitempty" json:"ExcludeCellularServices,omitempty"`
	// If `1` and `IncludeAllNetworks` is `1`, the system excludes network traffic for the
	// Apple Push Notification service (APNs) from the tunnel.
	ExcludeAPNs *int64 `plist:"ExcludeAPNs,omitempty" json:"ExcludeAPNs,omitempty"`
	// If set to `1` and `IncludeAllNetworks` is set to `1`, the device excludes network
	// traffic used for communicating with devices connected via USB or Wi-Fi from the tunnel.
	ExcludeDeviceCommunication *int64 `plist:"ExcludeDeviceCommunication,omitempty" json:"ExcludeDeviceCommunication,omitempty"`
	// The Post-quantum Pre-shared key (PPK) the device uses for this VPN. This key is is used
	// with VPN servers that support RFC 8784. If this key is present `PPKIdentifier` must also
	// be present.
	PPK []byte `plist:"PPK,omitempty" json:"PPK,omitempty"`
	// The identifier for the Post-quantum Pre-shared key (PPK) the device uses for this VPN.
	// This key is is used with VPN servers that support RFC 8784. If this key is present `PPK`
	// must also be present.
	PPKIdentifier *string `plist:"PPKIdentifier,omitempty" json:"PPKIdentifier,omitempty"`
	// If set to `1`, the VPN doesn't establish a connection if the server doesn't support RFC
	// 8784 or doesn't accept the PPK identifier specified in `PPKIdentifier`. The device
	// ignores this key if `PPK` and `PPKIdentifier` are not present.
	PPKMandatory *int64 `plist:"PPKMandatory,omitempty" json:"PPKMandatory,omitempty"`
	// If set to `0`, the VPN doesn't establish a connection if the server does not support or
	// doesn't allow post-quantum key exchanges. Thd device ignores this key if
	// `PostQuantumKeyExchangeMethods` is not present in `IKESecurityAssociationParameters` or
	// `ChildSecurityAssociationParameters`.
	AllowPostQuantumKeyExchangeFallback *int64 `plist:"AllowPostQuantumKeyExchangeFallback,omitempty" json:"AllowPostQuantumKeyExchangeFallback,omitempty"`
	// If set to `1`, the device doesn't allow DES, 3DES, and Diffie-Hellman groups less than
	// 14. Also the device requires the encryption algorithm specified for the IKE SA to be at
	// least as cryptographically strong as the algorithm specified for the child SA. The
	// device rejects this profile payload if these requirements are not met.
	EnforceStrictAlgorithmSelection *int64 `plist:"EnforceStrictAlgorithmSelection,omitempty" json:"EnforceStrictAlgorithmSelection,omitempty"`
	// These parameters apply to Child Security Association unless
	// `ChildSecurityAssociationParameters` is specified.
	IKESecurityAssociationParameters *VPNSecurityAssociationParameters `plist:"IKESecurityAssociationParameters,omitempty" json:"IKESecurityAssociationParameters,omitempty"`
	// The `ChildSecurityAssociationParameters` dictionaries.
	ChildSecurityAssociationParameters *VPNSecurityAssociationParameters `plist:"ChildSecurityAssociationParameters,omitempty" json:"ChildSecurityAssociationParameters,omitempty"`
}

VPNIKEv2: The dictionary to use when `VPNType` is `IKEv2`.

type VPNIPSec

type VPNIPSec struct {
	// The IP address or host name of the VPN server.
	RemoteAddress *string `plist:"RemoteAddress,omitempty" json:"RemoteAddress,omitempty"`
	// The authentication method for L2TP and Cisco IPSec.
	AuthenticationMethod *string `plist:"AuthenticationMethod,omitempty" json:"AuthenticationMethod,omitempty"`
	// The user name for the VPN account for Cisco IPSec.
	XAuthName *string `plist:"XAuthName,omitempty" json:"XAuthName,omitempty"`
	// The VPN account password for Cisco IPSec.
	XAuthPassword *string `plist:"XAuthPassword,omitempty" json:"XAuthPassword,omitempty"`
	// If `1`, enables Xauth for Cisco IPSec VPNs.
	XAuthEnabled *int64 `plist:"XAuthEnabled,omitempty" json:"XAuthEnabled,omitempty"`
	// A string that either has the value "Prompt" or isn't present.
	XAuthPasswordEncryption *string `plist:"XAuthPasswordEncryption,omitempty" json:"XAuthPasswordEncryption,omitempty"`
	// The name of the group. For hybrid authentication, the string needs to end with "hybrid".
	LocalIdentifier *string `plist:"LocalIdentifier,omitempty" json:"LocalIdentifier,omitempty"`
	// Present only if `AuthenticationMethod` is `SharedSecret`. The value is `KeyID`. The
	// system uses this value for L2TP and Cisco IPSec VPNs.
	LocalIdentifierType *string `plist:"LocalIdentifierType,omitempty" json:"LocalIdentifierType,omitempty"`
	// The shared secret for this VPN account.
	SharedSecret []byte `plist:"SharedSecret,omitempty" json:"SharedSecret,omitempty"`
	// The UUID of the certificate payload within the same profile to use for the account
	// credentials.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// If `true`, prompts for a PIN when connecting to Cisco IPSec VPNs.
	PromptForVPNPIN *bool `plist:"PromptForVPNPIN,omitempty" json:"PromptForVPNPIN,omitempty"`
	// If `1`, disconnect after an on-demand connection idles.
	DisconnectOnIdle *int64 `plist:"DisconnectOnIdle,omitempty" json:"DisconnectOnIdle,omitempty"`
	// The length of time to wait before disconnecting an on-demand connection.
	DisconnectOnIdleTimer *int64 `plist:"DisconnectOnIdleTimer,omitempty" json:"DisconnectOnIdleTimer,omitempty"`
	// If `1`, enables bringing the VPN connection up on demand.
	OnDemandEnabled *int64 `plist:"OnDemandEnabled,omitempty" json:"OnDemandEnabled,omitempty"`
	// Deprecated. A list of domain names. In iOS 7 and later, if this key is present, the
	// system treats associated domain names as though they're associated with the
	// `OnDemandMatchDomainsOnRetry` key. This behavior can be overridden by `OnDemandRules`.
	OnDemandMatchDomainsAlways []string `plist:"OnDemandMatchDomainsAlways,omitempty" json:"OnDemandMatchDomainsAlways,omitempty"`
	// Deprecated. A list of domain names. In iOS 7 and later, this key is deprecated (but
	// still supported) in favor of `EvaluateConnection` actions in the `OnDemandRules`
	// dictionaries.
	OnDemandMatchDomainsNever []string `plist:"OnDemandMatchDomainsNever,omitempty" json:"OnDemandMatchDomainsNever,omitempty"`
	// Deprecated. A list of domain names. In iOS 7 and later, this field is deprecated (but
	// still supported) in favor of `EvaluateConnection` actions in the `OnDemandRules`
	// dictionaries.
	OnDemandMatchDomainsOnRetry []string `plist:"OnDemandMatchDomainsOnRetry,omitempty" json:"OnDemandMatchDomainsOnRetry,omitempty"`
	// The on-demand rules dictionary.
	OnDemandRules []VPNOnDemandRulesElement `plist:"OnDemandRules,omitempty" json:"OnDemandRules,omitempty"`
}

VPNIPSec: The dictionary that contains IPSec settings. Not available in watchOS.

type VPNIPv4

type VPNIPv4 struct {
	// If `1`, the system sends all network traffic over VPN. Only applies to Cisco IPsec and
	// L2TP VPN types.
	OverridePrimary *int64 `plist:"OverridePrimary,omitempty" json:"OverridePrimary,omitempty"`
}

VPNIPv4: The dictionary that contains IPv4 settings. Not available in watchOS.

type VPNOnDemandRulesElement

type VPNOnDemandRulesElement struct {
	// The action to take if this dictionary matches the current network. Possible values are:
	// - `Allow`: Deprecated. Allow VPN On Demand to connect if triggered. - `Connect`:
	// Unconditionally initiate a VPN connection on the next network attempt. - `Disconnect`:
	// Tear down the VPN connection and don't reconnect on demand as long as this dictionary
	// matches. - `EvaluateConnection`: Evaluate the ActionParameters array for each connection
	// attempt. - `Ignore`: Leave any existing VPN connection up, but don't reconnect on demand
	// as long as this dictionary matches. Only the `Disconnect` action is available on watchOS
	// 10 and later.
	Action string `plist:"Action" json:"Action"`
	// An array of dictionaries that provides rules similar to the `OnDemandRules` dictionary,
	// but evaluated on each connection instead of when the network changes. This value is only
	// for use with dictionaries in which the `Action` value is `EvaluateConnection`. The
	// system evaluates these dictionaries in order and the first dictionary that matches
	// determines the behavior. Not available in watchOS.
	ActionParameters []VPNOnDemandRulesElementActionParameters `plist:"ActionParameters,omitempty" json:"ActionParameters,omitempty"`
	// An array of domain names. This rule matches if any of the domain names in the specified
	// list matches any domain in the device's search domains list. The system supports a
	// wildcard (`*`) prefix. For example, `*.example.com` matches against either
	// `mydomain.example.com` or `yourdomain.example.com`.
	DNSDomainMatch []string `plist:"DNSDomainMatch,omitempty" json:"DNSDomainMatch,omitempty"`
	// An array of IP addresses. This rule matches if any of the network's specified DNS
	// servers match any entry in the array. The system supports matching with a single
	// wildcard. For example, `17.*` matches any DNS server in the `17.0.0.0/8` subnet.
	DNSServerAddressMatch []string `plist:"DNSServerAddressMatch,omitempty" json:"DNSServerAddressMatch,omitempty"`
	// An interface type. If specified, this rule matches only if the primary network interface
	// hardware matches the specified type.
	InterfaceTypeMatch *string `plist:"InterfaceTypeMatch,omitempty" json:"InterfaceTypeMatch,omitempty"`
	// An array of SSIDs to match against the current network. If the network isn't a Wi-Fi
	// network or if the SSID doesn't appear in this array, the match fails. Omit this key and
	// the corresponding array to match against any SSID.
	SSIDMatch []string `plist:"SSIDMatch,omitempty" json:"SSIDMatch,omitempty"`
	// A URL to probe. This rule matches when this URL is successfully fetched (returns a `200`
	// HTTP status code) without redirection. Not available in watchOS.
	URLStringProbe *string `plist:"URLStringProbe,omitempty" json:"URLStringProbe,omitempty"`
}

VPNOnDemandRulesElement: is generated from mdm/profiles/com.apple.vpn.managed.yaml.

type VPNOnDemandRulesElementActionParameters

type VPNOnDemandRulesElementActionParameters struct {
	// The domains to apply this evaluation.
	Domains []string `plist:"Domains,omitempty" json:"Domains,omitempty"`
	// Defines the VPN behavior for the specified domains. Allowed values are: *
	// 'ConnectIfNeeded': The specified domains should trigger a VPN connection attempt if
	// domain name resolution fails, such as when the DNS server indicates that it can't
	// resolve the domain, responds with a redirection to a different server, or fails to
	// respond (timeout). * 'NeverConnect': The specified domains should never trigger a VPN
	// connection attempt.
	DomainAction string `plist:"DomainAction" json:"DomainAction"`
	// An array of IP addresses of DNS servers to use for resolving the specified domains.
	// These servers don't need to be part of the device's current network configuration. If
	// these DNS servers aren't reachable, the system establishes a VPN connection. These DNS
	// servers need to be either internal DNS servers or trusted external DNS servers. This key
	// is valid only if the value of 'DomainAction' is 'ConnectIfNeeded'.
	RequiredDNSServers []string `plist:"RequiredDNSServers,omitempty" json:"RequiredDNSServers,omitempty"`
	// An HTTP or HTTPS (preferred) URL to probe, using a GET request. If the URL's hostname
	// can't be resolved, if the server is unreachable, or if the server doesn't respond with a
	// 200 HTTP status code, a VPN connection is established in response. This key is valid
	// only if the value of 'DomainAction' is 'ConnectIfNeeded'.
	RequiredURLStringProbe *string `plist:"RequiredURLStringProbe,omitempty" json:"RequiredURLStringProbe,omitempty"`
}

VPNOnDemandRulesElementActionParameters: A dictionary that provides rules similar to the OnDemandRules dictionary, but evaluated on each connection instead of when the network changes. These dictionaries are evaluated in order, and the behavior is determined by the first dictionary that matches. The keys allowed in each dictionary are described below. Note: This array is used only for dictionaries in which EvaluateConnection is the Action value.

type VPNPPP

type VPNPPP struct {
	// The VPN account user name. This key is for use with L2TP and PPTP networks.
	AuthName *string `plist:"AuthName,omitempty" json:"AuthName,omitempty"`
	// If `TokenCard` is `1`, use this password for authentication. This key is for use with
	// L2TP and PPTP networks.
	AuthPassword *string `plist:"AuthPassword,omitempty" json:"AuthPassword,omitempty"`
	// If `1`, uses a token card such as an RSA SecurID card for connecting. This key is for
	// use with L2TP networks.
	TokenCard *int64 `plist:"TokenCard,omitempty" json:"TokenCard,omitempty"`
	// The IP address or host name of VPN server. This key is for use with L2TP and PPTP
	// networks.
	CommRemoteAddress *string `plist:"CommRemoteAddress,omitempty" json:"CommRemoteAddress,omitempty"`
	// An array of authentication plugins. For use of RSA SecurID, this array should only have
	// one value: `EAP-RSA`. This key is for use with L2TP and PPTP networks.
	AuthEAPPlugins []string `plist:"AuthEAPPlugins,omitempty" json:"AuthEAPPlugins,omitempty"`
	// An array of authentication protocols. For use of RSA SecurID, this array should have one
	// value, `EAP`. This key is for use with L2TP and PPTP networks.
	AuthProtocol []string `plist:"AuthProtocol,omitempty" json:"AuthProtocol,omitempty"`
	// If `1` and `CCPEnabled` is also `1`, enables CCPMPPE128 encryption.
	CCPMPPE40Enabled *int64 `plist:"CCPMPPE40Enabled,omitempty" json:"CCPMPPE40Enabled,omitempty"`
	// If `1` and `CCPEnabled` is also `1`, enables CCPMPPE40 encryption.
	CCPMPPE128Enabled *int64 `plist:"CCPMPPE128Enabled,omitempty" json:"CCPMPPE128Enabled,omitempty"`
	// If `1`, enables encryption on the connection. This key is for use with PPTP networks.
	CCPEnabled *int64 `plist:"CCPEnabled,omitempty" json:"CCPEnabled,omitempty"`
	// If `1`, disconnects after an on demand connection idles.
	DisconnectOnIdle *int64 `plist:"DisconnectOnIdle,omitempty" json:"DisconnectOnIdle,omitempty"`
	// The length of time to wait before disconnecting an on demand connection
	DisconnectOnIdleTimer *int64 `plist:"DisconnectOnIdleTimer,omitempty" json:"DisconnectOnIdleTimer,omitempty"`
}

VPNPPP: The dictionary to use when `VPNType` is `L2TP` or `PTPP`. Not available in watchOS.

type VPNProxies

type VPNProxies struct {
	// If `true`, enables automatic proxy configuration.
	ProxyAutoConfigEnable *int64 `plist:"ProxyAutoConfigEnable,omitempty" json:"ProxyAutoConfigEnable,omitempty"`
	// If `true`, enables proxy auto discovery.
	ProxyAutoDiscoveryEnable *int64 `plist:"ProxyAutoDiscoveryEnable,omitempty" json:"ProxyAutoDiscoveryEnable,omitempty"`
	// The URL to the location of the proxy auto-configuration file. Used only when
	// `ProxyAutoConfigEnable` is `true`.
	ProxyAutoConfigURLString *string `plist:"ProxyAutoConfigURLString,omitempty" json:"ProxyAutoConfigURLString,omitempty"`
	// An array of domains that defines which hosts use proxy settings for hosts.
	SupplementalMatchDomains []string `plist:"SupplementalMatchDomains,omitempty" json:"SupplementalMatchDomains,omitempty"`
	// If `1`, enables proxy for HTTP traffic.
	HTTPEnable *int64 `plist:"HTTPEnable,omitempty" json:"HTTPEnable,omitempty"`
	// The host name of the HTTP proxy.
	HTTPProxy *string `plist:"HTTPProxy,omitempty" json:"HTTPProxy,omitempty"`
	// The port number of the HTTP proxy. This field is required if `HTTPProxy` is specified.
	HTTPPort *int64 `plist:"HTTPPort,omitempty" json:"HTTPPort,omitempty"`
	// The user name used for authentication.
	HTTPProxyUsername *string `plist:"HTTPProxyUsername,omitempty" json:"HTTPProxyUsername,omitempty"`
	// The password used for authentication.
	HTTPProxyPassword *string `plist:"HTTPProxyPassword,omitempty" json:"HTTPProxyPassword,omitempty"`
	// If `true`, enables proxy for HTTPS traffic.
	HTTPSEnable *int64 `plist:"HTTPSEnable,omitempty" json:"HTTPSEnable,omitempty"`
	// The host name of the HTTPS proxy.
	HTTPSProxy *string `plist:"HTTPSProxy,omitempty" json:"HTTPSProxy,omitempty"`
	// The port number of the HTTPS proxy. This field is required if `HTTPSProxy` is specified.
	HTTPSPort *int64 `plist:"HTTPSPort,omitempty" json:"HTTPSPort,omitempty"`
}

VPNProxies: The dictionary to use to configure `Proxies` for use with `VPN`.

type VPNSecurityAssociationParameters

type VPNSecurityAssociationParameters struct {
	// The encryption algorithm.
	EncryptionAlgorithm *string `plist:"EncryptionAlgorithm,omitempty" json:"EncryptionAlgorithm,omitempty"`
	// The integrity algorithm.
	IntegrityAlgorithm *string `plist:"IntegrityAlgorithm,omitempty" json:"IntegrityAlgorithm,omitempty"`
	// The Diffie-Hellman group.
	DiffieHellmanGroup *int64 `plist:"DiffieHellmanGroup,omitempty" json:"DiffieHellmanGroup,omitempty"`
	// An array of strings representing postquantum key exchange methods the device uses during
	// SA establishment and rekey. You can specify up to seven items, which correspond to
	// ADDKE1 - ADDKE7 from RFC 9370.
	PostQuantumKeyExchangeMethods []int64 `plist:"PostQuantumKeyExchangeMethods,omitempty" json:"PostQuantumKeyExchangeMethods,omitempty"`
	// The SA lifetime (rekey interval) in minutes.
	LifeTimeInMinutes *int64 `plist:"LifeTimeInMinutes,omitempty" json:"LifeTimeInMinutes,omitempty"`
}

VPNSecurityAssociationParameters: These parameters apply to Child Security Association unless `ChildSecurityAssociationParameters` is specified.

type VPNTransparentProxy

type VPNTransparentProxy struct {
	// The type of authentication method to use: `Password`, `Certificate`, or
	// `Password+Certificate`.
	AuthenticationMethod *string `plist:"AuthenticationMethod,omitempty" json:"AuthenticationMethod,omitempty"`
	// If `1`, the VPN disconnects automatically disconnect after a period defined by
	// `DisconnectOnIdleTimer`.
	DisconnectOnIdle *int64 `plist:"DisconnectOnIdle,omitempty" json:"DisconnectOnIdle,omitempty"`
	// The number of seconds before the VPN disconnects. This value is only used if
	// `DisconnectOnIdle` is `1`.
	DisconnectOnIdleTimer *int64 `plist:"DisconnectOnIdleTimer,omitempty" json:"DisconnectOnIdleTimer,omitempty"`
	// If `1`, then all the VPN's non-default routes take precedence over any locally-defined
	// routes. If `IncludeAllNetworks` is `1`, the system ignores the value of `EnforceRoutes`.
	EnforceRoutes *int64 `plist:"EnforceRoutes,omitempty" json:"EnforceRoutes,omitempty"`
	// If `1`, the system brings up the VPN on demand.
	OnDemandEnabled *int64 `plist:"OnDemandEnabled,omitempty" json:"OnDemandEnabled,omitempty"`
	// Determines when and how the system uses an OnDemand VPN.
	OnDemandRules []VPNOnDemandRulesElement `plist:"OnDemandRules,omitempty" json:"OnDemandRules,omitempty"`
	// The UUID of the identity certificate as the account credential. If
	// `AuthenticationMethod` is `Certificate`, and extended authentication (EAP) isn't used,
	// this certificate is sent out for IKE client authentication. If extended authentication
	// is used, this certificate can be used for EAP-TLS.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// The password to use for the account credentials. Only used if `AuthenticationMethod` is
	// `Password`.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// If the VPNSubType field contains the bundle identifier of an app that contains multiple
	// VPN providers of the same type (app-proxy or packet-tunnel), then the system uses this
	// field to choose which provider to use for this configuration. If the VPN provider is
	// implemented as a System Extension, then this field is required.
	ProviderBundleIdentifier *string `plist:"ProviderBundleIdentifier,omitempty" json:"ProviderBundleIdentifier,omitempty"`
	// If the VPN provider is implemented as a System Extension, then this field is required.
	ProviderDesignatedRequirement *string `plist:"ProviderDesignatedRequirement,omitempty" json:"ProviderDesignatedRequirement,omitempty"`
	// If the value of this key is `app-proxy`, the VPN service tunnels traffic at the
	// application layer. If the value of this key is `packet-tunnel`, the VPN service tunnels
	// traffic at the IP layer.
	ProviderType *string `plist:"ProviderType,omitempty" json:"ProviderType,omitempty"`
	// A positive integer.
	Order *int64 `plist:"Order,omitempty" json:"Order,omitempty"`
}

VPNTransparentProxy: The dictionary to use when `VPNType` is `TransparentProxy`. Available in macOS 14 and later.

type VPNVPN

type VPNVPN struct {
	// The VPN account username.
	AuthName *string `plist:"AuthName,omitempty" json:"AuthName,omitempty"`
	// The VPN account password. Only use this if `AuthenticationMethod` is set to `Password`.
	AuthPassword *string `plist:"AuthPassword,omitempty" json:"AuthPassword,omitempty"`
	// The IP address or hostname of the VPN server.
	RemoteAddress string `plist:"RemoteAddress" json:"RemoteAddress"`
	// The authentication method to use.
	AuthenticationMethod *string `plist:"AuthenticationMethod,omitempty" json:"AuthenticationMethod,omitempty"`
	// The UUID of the certificate payload within the same profile to use for account
	// credentials.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// The bundle identifier for the VPN provider. Not available in watchOS.
	ProviderBundleIdentifier *string `plist:"ProviderBundleIdentifier,omitempty" json:"ProviderBundleIdentifier,omitempty"`
	// If the VPN provider is implemented as a system extension, this field is required. Not
	// available in watchOS.
	ProviderDesignatedRequirement *string `plist:"ProviderDesignatedRequirement,omitempty" json:"ProviderDesignatedRequirement,omitempty"`
	// If `1`, disconnects after an on-demand connection idles.
	DisconnectOnIdle *int64 `plist:"DisconnectOnIdle,omitempty" json:"DisconnectOnIdle,omitempty"`
	// The length of time to wait, in seconds, before disconnecting an on-demand connection. In
	// watchOS, the maximum allowed value is `15`.
	DisconnectOnIdleTimer *int64 `plist:"DisconnectOnIdleTimer,omitempty" json:"DisconnectOnIdleTimer,omitempty"`
	// The type of VPN service. If the value is `app-proxy`, the service tunnels traffic at the
	// app level. If the value is `packet-tunnel`, the service tunnels traffic at the IP layer.
	// Not available in watchOS.
	ProviderType *string `plist:"ProviderType,omitempty" json:"ProviderType,omitempty"`
	// If `1“, routes all traffic through the VPN, with some exclusions. Several of the
	// exclusions can be controlled with the `ExcludeLocalNetworks`, `ExcludeCellularServices`,
	// `ExcludeAPNs` and `ExcludeDeviceCommunication` properties. The following traffic is
	// always excluded from the tunnel:
	IncludeAllNetworks *int64 `plist:"IncludeAllNetworks,omitempty" json:"IncludeAllNetworks,omitempty"`
	// If `1`, all the VPN's non-default routes take precedence over any locally defined
	// routes.
	EnforceRoutes *int64 `plist:"EnforceRoutes,omitempty" json:"EnforceRoutes,omitempty"`
	// If `1` and `IncludeAllNetworks` is `1`, routes all local network traffic outside the
	// VPN. Not available in watchOS.
	ExcludeLocalNetworks *int64 `plist:"ExcludeLocalNetworks,omitempty" json:"ExcludeLocalNetworks,omitempty"`
	// If `1` and `IncludeAllNetworks` is `1`, then the system excludes internet-routable
	// network traffic for cellular services (VoLTE, Wi-Fi Calling, IMS, MMS, Visual Voicemail,
	// etc.) from the tunnel. Note that some cellular carriers route cellular services traffic
	// directly to the carrier network, bypassing the internet. Such cellular services traffic
	// is always excluded from the tunnel. Not available in watchOS.
	ExcludeCellularServices *int64 `plist:"ExcludeCellularServices,omitempty" json:"ExcludeCellularServices,omitempty"`
	// If `1` and `IncludeAllNetworks` is `1`, then the system excludes the network traffic for
	// the Apple Push Notification service (APNs) from the tunnel. Not available in watchOS.
	ExcludeAPNs *int64 `plist:"ExcludeAPNs,omitempty" json:"ExcludeAPNs,omitempty"`
	// If set to `1` and `IncludeAllNetworks` is set to `1`, the device excludes network
	// traffic used for communicating with devices connected via USB or Wi-Fi from the tunnel.
	ExcludeDeviceCommunication *int64 `plist:"ExcludeDeviceCommunication,omitempty" json:"ExcludeDeviceCommunication,omitempty"`
	// If `1`, enables VPN On Demand.
	OnDemandEnabled *int64 `plist:"OnDemandEnabled,omitempty" json:"OnDemandEnabled,omitempty"`
	// If `1`, the Connect On Demand toggle in Settings is disabled for this configuration.
	// Available in iOS 14 and later. Not available in watchOS.
	OnDemandUserOverrideDisabled *int64 `plist:"OnDemandUserOverrideDisabled,omitempty" json:"OnDemandUserOverrideDisabled,omitempty"`
	// A list of domain names. The system treats associated domain names as though they're
	// associated with the `OnDemandMatchDomainsOnRetry` key. This behavior can be overridden
	// by `OnDemandRules`.
	OnDemandMatchDomainsAlways []string `plist:"OnDemandMatchDomainsAlways,omitempty" json:"OnDemandMatchDomainsAlways,omitempty"`
	// A list of domain names. If the host name ends with one of these domain names, the system
	// doesn't start the VPN automatically. The system uses this value to exclude a subdomain
	// within an included domain.
	OnDemandMatchDomainsNever []string `plist:"OnDemandMatchDomainsNever,omitempty" json:"OnDemandMatchDomainsNever,omitempty"`
	// A list of domain names. If the host name ends with one of these domain names and a DNS
	// query for that domain name fails, the system starts the VPN automatically.
	OnDemandMatchDomainsOnRetry []string `plist:"OnDemandMatchDomainsOnRetry,omitempty" json:"OnDemandMatchDomainsOnRetry,omitempty"`
	// An array of dictionaries defining On Demand Rules.
	OnDemandRules []VPNOnDemandRulesElement `plist:"OnDemandRules,omitempty" json:"OnDemandRules,omitempty"`
}

VPNVPN: The dictionary to use when `VPNType` is `VPN`.

type VPNVendorConfig

type VPNVendorConfig struct {
	// The Kerberos realm name, which needs to be properly capitalized. Valid only for Juniper
	// SSL and Pulse Secure. Not available in watchOS.
	Realm *string `plist:"Realm,omitempty" json:"Realm,omitempty"`
	// The role to select when connecting to the server. Valid only for Juniper SSL and Pulse
	// Secure. Not available in watchOS.
	Role *string `plist:"Role,omitempty" json:"Role,omitempty"`
	// The group to connect to on the head end. Valid for Cisco AnyConnect and Cisco Legacy
	// AnyConnect. Not available in watchOS.
	Group *string `plist:"Group,omitempty" json:"Group,omitempty"`
	// The login group or domain. Valid only for SonicWALL Mobile Connect. Not available in
	// watchOS.
	LoginGroupOrDomain *string `plist:"LoginGroupOrDomain,omitempty" json:"LoginGroupOrDomain,omitempty"`
}

VPNVendorConfig: The vendor-specific configuration dictionary, which the system reads only when `VPNSubType` has a value. Not available in watchOS.

type WebClip

type WebClip struct {
	// If `true`, the system prevents SpringBoard from adding shine to the icon.
	Precomposed *bool `plist:"Precomposed,omitempty" json:"Precomposed,omitempty"`
	// If `true`, the system launches the web clip as a full-screen web app.
	FullScreen *bool `plist:"FullScreen,omitempty" json:"FullScreen,omitempty"`
	// The URL of the web clip.
	URL string `plist:"URL" json:"URL"`
	// The PNG icon to show on the Home Screen. If not set, the system displays a white square.
	// For best results, provide a square image that's no larger than 400 x 400 pixels and less
	// than 1 MB when uncompressed. The graphics file is automatically scaled and cropped to
	// fit, if necessary, and converted to PNG format. Web clip icons are 144 x 144 pixels for
	// iPad devices with a Retina display, and 114 x 114 pixels for iPhone devices. To prevent
	// the device from adding a shine to the image, set `Precomposed` to `true`.
	Icon []byte `plist:"Icon,omitempty" json:"Icon,omitempty"`
	// If `true`, the system enables removing the web clip.
	IsRemovable *bool `plist:"IsRemovable,omitempty" json:"IsRemovable,omitempty"`
	// The name of the web clip that the system displays on the Home Screen.
	Label string `plist:"Label" json:"Label"`
	// If `true`, a full screen web clip can navigate to an external web site without showing
	// Safari UI. Otherwise, Safari UI appears when navigating away from the web clip's URL.
	// This key has no effect when `FullScreen` is `false`. Available in iOS 14 and later.
	IgnoreManifestScope *bool `plist:"IgnoreManifestScope,omitempty" json:"IgnoreManifestScope,omitempty"`
	// The application bundle identifier of the application that opens the URL. To use this
	// property, install the profile through MDM. Available in iOS 14 and later.
	TargetApplicationBundleIdentifier *string `plist:"TargetApplicationBundleIdentifier,omitempty" json:"TargetApplicationBundleIdentifier,omitempty"`
}

WebClip: The profile that configures web clips on the device.

WebClip corresponds to mdm/profiles/com.apple.webClip.managed.yaml (Web Clip).

func (*WebClip) PayloadTypeName

func (*WebClip) PayloadTypeName() string

PayloadTypeName returns "com.apple.webClip.managed".

func (*WebClip) SchemaPath

func (*WebClip) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*WebClip) Validate

func (x *WebClip) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type WebContentFilter

type WebContentFilter struct {
	// The type of filter, built-in or plug-in. In macOS, the system only supports the plug-in
	// value.
	FilterType *string `plist:"FilterType,omitempty" json:"FilterType,omitempty"`
	// If `true`, this payload enforces a policy which requires retention of browsing history.
	// This causes Safari to disable clearing of browsing history, and prevents the use of
	// private browsing mode because that mode doesn't keep browsing history.
	SafariHistoryRetentionEnabled *bool `plist:"SafariHistoryRetentionEnabled,omitempty" json:"SafariHistoryRetentionEnabled,omitempty"`
	// If `true`, the system enables automatic filtering. Use when `FilterType` is `BuiltIn`.
	AutoFilterEnabled *bool `plist:"AutoFilterEnabled,omitempty" json:"AutoFilterEnabled,omitempty"`
	// An array or URLs that are accessible whether or not the automatic filter allows access.
	// Use when `FilterType` is `BuiltIn`. Requires that `AutoFilterEnabled` is `true`.
	PermittedURLs []string `plist:"PermittedURLs,omitempty" json:"PermittedURLs,omitempty"`
	// Use `DenyListURLs` instead.
	BlacklistedURLs []string `plist:"BlacklistedURLs,omitempty" json:"BlacklistedURLs,omitempty"`
	// An array of URLs that are inaccessible. Use when `FilterType` is `BuiltIn`. Limit the
	// number of these URLs to no more than 500.
	DenyListURLs []string `plist:"DenyListURLs,omitempty" json:"DenyListURLs,omitempty"`
	// If `true`, the device hides the `DenyListURLs` item in the profiles that display in
	// Settings > General > VPN & Device Management.
	HideDenyListURLs *bool `plist:"HideDenyListURLs,omitempty" json:"HideDenyListURLs,omitempty"`
	// Use `AllowListBookmarks` instead.
	WhitelistedBookmarks []WebContentFilterWhitelistedBookmarks `plist:"WhitelistedBookmarks,omitempty" json:"WhitelistedBookmarks,omitempty"`
	// An array of dictionaries that define the pages that the user can bookmark or visit. Use
	// when `FilterType` is `BuiltIn`.
	AllowListBookmarks []WebContentFilterAllowListBookmarks `plist:"AllowListBookmarks,omitempty" json:"AllowListBookmarks,omitempty"`
	// The display name for this filtering configuration. Required when `FilterType` is
	// `Plugin`.
	UserDefinedName *string `plist:"UserDefinedName,omitempty" json:"UserDefinedName,omitempty"`
	// The bundle ID of the plug-in that provides filtering service. Required when `FilterType`
	// is `Plugin`. Otherwise, it ignores this value. Consult your filtering solution vendor to
	// determine what to specify for this value. Required when `FilterType` is `Plugin`.
	PluginBundleID *string `plist:"PluginBundleID,omitempty" json:"PluginBundleID,omitempty"`
	// The server address, which may be the IP address, hostname, or URL. Use when `FilterType`
	// is `Plugin`.
	ServerAddress *string `plist:"ServerAddress,omitempty" json:"ServerAddress,omitempty"`
	// The user name for the service. Use when `FilterType` is `Plugin`.
	UserName *string `plist:"UserName,omitempty" json:"UserName,omitempty"`
	// The password for the service. Use when `FilterType` is `Plugin`.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// The UUID of the certificate payload within the same profile that the system uses to
	// authenticate the user. Use when `FilterType` is `Plugin`.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// The organization string to pass to the third-party plug-in. Use when `FilterType` is
	// `Plugin`.
	Organization *string `plist:"Organization,omitempty" json:"Organization,omitempty"`
	// The custom dictionary that the filtering service plug-in needs. Use when `FilterType` is
	// `Plugin`.
	VendorConfig map[string]any `plist:"VendorConfig,omitempty" json:"VendorConfig,omitempty"`
	// If `true`, the system enables filtering WebKit traffic. Use when `FilterType` is
	// `Plugin`.
	FilterBrowsers *bool `plist:"FilterBrowsers,omitempty" json:"FilterBrowsers,omitempty"`
	// If `true`, enables the filtering of socket traffic. Use when `FilterType` is `Plugin`.
	FilterSockets *bool `plist:"FilterSockets,omitempty" json:"FilterSockets,omitempty"`
	// The designated requirement string that the system embeds in the code signature of the
	// filter data provider system extension. This string identifies the filter data provider
	// when the filter starts running. Required if `FilterSockets` is `true`.
	FilterDataProviderDesignatedRequirement *string `plist:"FilterDataProviderDesignatedRequirement,omitempty" json:"FilterDataProviderDesignatedRequirement,omitempty"`
	// The bundle identifier string of the filter data provider system extension. This string
	// identifies the filter data provider when the filter starts running. Required if
	// `FilterSockets` is `true`.
	FilterDataProviderBundleIdentifier *string `plist:"FilterDataProviderBundleIdentifier,omitempty" json:"FilterDataProviderBundleIdentifier,omitempty"`
	// If `true` and `FilterType` is `Plugin`, the system enables filtering network packets.
	// Use when `FilterType` is `Plugin`.
	FilterPackets *bool `plist:"FilterPackets,omitempty" json:"FilterPackets,omitempty"`
	// The designated requirement string that the system embeds in the code signature of the
	// filter packet provider system extension. This string identifies the filter packet
	// provider when the filter starts running. Required if `FilterPackets` is `true`.
	FilterPacketProviderDesignatedRequirement *string `plist:"FilterPacketProviderDesignatedRequirement,omitempty" json:"FilterPacketProviderDesignatedRequirement,omitempty"`
	// The bundle identifier string of the filter packet provider system extension. This string
	// identifies the filter packet provider when the filter starts running. Required if
	// `FilterPackets` is `true`.
	FilterPacketProviderBundleIdentifier *string `plist:"FilterPacketProviderBundleIdentifier,omitempty" json:"FilterPacketProviderBundleIdentifier,omitempty"`
	// The system uses this value to derive the relative order of content filters. Filters with
	// a grade of `firewall` see network traffic before filters with a grade of `inspector`.
	// However, the system doesn't define the order of filters within a grade.
	FilterGrade *string `plist:"FilterGrade,omitempty" json:"FilterGrade,omitempty"`
	// A globally unique identifier for this content filter configuration. The content filter
	// processes network traffic for managed apps with the same `ContentFilterUUID` in their
	// app attributes. Use when `FilterType` is `Plugin`.This key must be present for
	// unsupervised devices and user enrollment.
	ContentFilterUUID *string `plist:"ContentFilterUUID,omitempty" json:"ContentFilterUUID,omitempty"`
	// If `true`, the system filters URL requests. Use when `FilterType` is `Plugin`. Available
	// in iOS 26 and macOS 26, and later.
	FilterURLs *bool `plist:"FilterURLs,omitempty" json:"FilterURLs,omitempty"`
	// A dictionary containing URL filter parameters. Required when `FilterURLs` is `true`.
	// Available in iOS 26 and macOS 26 and later.
	URLFilterParameters *WebContentFilterURLFilterParameters `plist:"URLFilterParameters,omitempty" json:"URLFilterParameters,omitempty"`
}

WebContentFilter: The payload that configures web content filters.

WebContentFilter corresponds to mdm/profiles/com.apple.webcontent-filter.yaml (Web Content Filter).

func (*WebContentFilter) PayloadTypeName

func (*WebContentFilter) PayloadTypeName() string

PayloadTypeName returns "com.apple.webcontent-filter".

func (*WebContentFilter) SchemaPath

func (*WebContentFilter) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*WebContentFilter) Validate

func (x *WebContentFilter) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type WebContentFilterAllowListBookmarks

type WebContentFilterAllowListBookmarks struct {
	// The URL of the bookmark in the allow list.
	URL string `plist:"URL" json:"URL"`
	// The title of the bookmark.
	Title string `plist:"Title" json:"Title"`
}

WebContentFilterAllowListBookmarks: is generated from mdm/profiles/com.apple.webcontent-filter.yaml.

type WebContentFilterURLFilterParameters

type WebContentFilterURLFilterParameters struct {
	// The designated requirement string in the code signature of the URL filter control
	// provider app extension. The system uses this string to identify the URL filter control
	// provider when the filter starts running. Required in macOS.
	URLFilterControlProviderDesignatedRequirement *string `` /* 126-byte string literal not displayed */
	// The bundle identifier string of the URL filter control provider app extension. The
	// system uses this string to identify the URL filter control provider when the filter
	// starts running.
	URLFilterControlProviderBundleIdentifier string `plist:"URLFilterControlProviderBundleIdentifier" json:"URLFilterControlProviderBundleIdentifier"`
	// The URL containing the domain name of the private information retrieval server.
	PIRServerURL string `plist:"PIRServerURL" json:"PIRServerURL"`
	// The URL containing the domain name of Privacy Pass Issuer.
	PIRPrivacyPassIssuerURL string `plist:"PIRPrivacyPassIssuerURL" json:"PIRPrivacyPassIssuerURL"`
	// The per-user authentication token string, which is an HTTP bearer token for the person
	// using your app. The system uses this token to attest that it is a valid user when
	// requesting anonymous authentication tokens for PIR exchanges.
	PIRAuthenticationToken string `plist:"PIRAuthenticationToken" json:"PIRAuthenticationToken"`
	// If `true`, the system blocks URLs if the filter is enabled, but it fails to make any
	// filtering decision; for example, if there's a communication failure with the PIR server.
	// If `false`, the system allows URLs if the filter is enabled, but it fails to make any
	// filtering decision.
	URLFilterFailClosed *bool `plist:"URLFilterFailClosed,omitempty" json:"URLFilterFailClosed,omitempty"`
	// The time interval in seconds that the system uses to periodically run the
	// `NEURLFilterControlProvider` app extension. The default value is 86400 seconds (1 day).
	// The minimum allowed value is 2700 seconds (45 minutes). The system allows
	// `NEURLFilterControlProvider` implementations to download prefilter Bloom filter data
	// onto the device periodically at the specified interval. Implementations need to allow
	// for a slight difference between the scheduled time and the actual runtime of the task,
	// due to the scheduling mechanism on the system.
	URLPrefilterFetchFrequency *int64 `plist:"URLPrefilterFetchFrequency,omitempty" json:"URLPrefilterFetchFrequency,omitempty"`
}

WebContentFilterURLFilterParameters: A dictionary containing URL filter parameters. Required when `FilterURLs` is `true`. Available in iOS 26 and macOS 26 and later.

type WebContentFilterWhitelistedBookmarks

type WebContentFilterWhitelistedBookmarks struct {
	// The URL of the bookmark in the allow list.
	URL string `plist:"URL" json:"URL"`
	// The title of the bookmark.
	Title string `plist:"Title" json:"Title"`
}

WebContentFilterWhitelistedBookmarks: is generated from mdm/profiles/com.apple.webcontent-filter.yaml.

type WiFi

type WiFi struct {
	// If `true`, the device joins the network automatically.
	AutoJoin *bool `plist:"AutoJoin,omitempty" json:"AutoJoin,omitempty"`
	// The SSID of the Wi-Fi network to use. In iOS 7.0 and later, the SSID is optional if a
	// value exists for `DomainName` value.
	SSIDSTR *string `plist:"SSID_STR,omitempty" json:"SSID_STR,omitempty"`
	// If `true`, defines this network as hidden.
	HIDDENNETWORK *bool `plist:"HIDDEN_NETWORK,omitempty" json:"HIDDEN_NETWORK,omitempty"`
	// The proxy type, if any, to use. If you choose the manual proxy type, you need the proxy
	// server address, including its port and optionally a user name and password into the
	// proxy server. If you choose the auto proxy type, you can enter a proxy autoconfiguration
	// (PAC) URL.
	ProxyType *string `plist:"ProxyType,omitempty" json:"ProxyType,omitempty"`
	// The encryption type for the network.
	EncryptionType *string `plist:"EncryptionType,omitempty" json:"EncryptionType,omitempty"`
	// The password for the access point.
	Password *string `plist:"Password,omitempty" json:"Password,omitempty"`
	// The UUID of the certificate payload within the same profile to use for the client
	// credential.
	PayloadCertificateUUID *string `plist:"PayloadCertificateUUID,omitempty" json:"PayloadCertificateUUID,omitempty"`
	// The enterprise network configuration.
	EAPClientConfiguration *WiFiEAPClientConfiguration `plist:"EAPClientConfiguration,omitempty" json:"EAPClientConfiguration,omitempty"`
	// The operator name to display when connected to this network. Used only with Wi-Fi
	// Hotspot 2.0 access points.
	DisplayedOperatorName *string `plist:"DisplayedOperatorName,omitempty" json:"DisplayedOperatorName,omitempty"`
	// The primary domain of the tunnel.
	DomainName *string `plist:"DomainName,omitempty" json:"DomainName,omitempty"`
	// An array of Roaming Consortium Organization Identifiers used for Wi-Fi Hotspot 2.0
	// negotiation.
	RoamingConsortiumOIs []string `plist:"RoamingConsortiumOIs,omitempty" json:"RoamingConsortiumOIs,omitempty"`
	// If `true`, allows connection to roaming service providers.
	ServiceProviderRoamingEnabled *bool `plist:"ServiceProviderRoamingEnabled,omitempty" json:"ServiceProviderRoamingEnabled,omitempty"`
	// If `true`, the device treats the network as a hotspot.
	IsHotspot *bool `plist:"IsHotspot,omitempty" json:"IsHotspot,omitempty"`
	// The HESSID used for Wi-Fi Hotspot 2.0 negotiation.
	HESSID *string `plist:"HESSID,omitempty" json:"HESSID,omitempty"`
	// An array of Network Access Identifier Realm names used for Wi-Fi Hotspot 2.0
	// negotiation.
	NAIRealmNames []string `plist:"NAIRealmNames,omitempty" json:"NAIRealmNames,omitempty"`
	// An array of Mobile Country Code/Mobile Network Code (MCC/MNC) pairs used for Wi-Fi
	// Hotspot 2.0 negotiation. Each string must contain exactly six digits.
	MCCAndMNCs []string `plist:"MCCAndMNCs,omitempty" json:"MCCAndMNCs,omitempty"`
	// If `true`, the system bypasses Captive Network detection when the device connects to the
	// network.
	CaptiveBypass *bool `plist:"CaptiveBypass,omitempty" json:"CaptiveBypass,omitempty"`
	// A dictionary that contains the list of apps that the system allows to benefit from L2
	// and L3 marking. When this dictionary isn't present, the system allows all apps to use L2
	// and L3 marking when the Wi-Fi network supports Cisco QoS fast lane.
	QoSMarkingPolicy *WiFiQoSMarkingPolicy `plist:"QoSMarkingPolicy,omitempty" json:"QoSMarkingPolicy,omitempty"`
	// An array of strings that contain the type of connection mode to attach.
	SetupModes []string `plist:"SetupModes,omitempty" json:"SetupModes,omitempty"`
	// If `true`, enables IPv6 on this interface.
	EnableIPv6 *bool `plist:"EnableIPv6,omitempty" json:"EnableIPv6,omitempty"`
	// If `true`, allows for two-factor authentication for EAP-TTLS, PEAP, or EAP-FAST. If
	// `false`, allows for zero-factor authentication for EAP-TLS.
	TLSCertificateRequired *bool `plist:"TLSCertificateRequired,omitempty" json:"TLSCertificateRequired,omitempty"`
	// The proxy server's network address.
	ProxyServer *string `plist:"ProxyServer,omitempty" json:"ProxyServer,omitempty"`
	// The proxy server's port number.
	ProxyServerPort *int64 `plist:"ProxyServerPort,omitempty" json:"ProxyServerPort,omitempty"`
	// The user name used to authenticate to the proxy server.
	ProxyUsername *string `plist:"ProxyUsername,omitempty" json:"ProxyUsername,omitempty"`
	// The password used to authenticate to the proxy server.
	ProxyPassword *string `plist:"ProxyPassword,omitempty" json:"ProxyPassword,omitempty"`
	// The URL of the PAC file that defines the proxy configuration.
	ProxyPACURL *string `plist:"ProxyPACURL,omitempty" json:"ProxyPACURL,omitempty"`
	// If `true`, allows connecting directly to the destination if the PAC file is unreachable.
	ProxyPACFallbackAllowed *bool `plist:"ProxyPACFallbackAllowed,omitempty" json:"ProxyPACFallbackAllowed,omitempty"`
	// If `true,` disables MAC address randomization for a Wi-Fi network while associated with
	// that network. This feature also shows a privacy warning in Settings indicating that the
	// network has reduced privacy protections.
	DisableAssociationMACRandomization *bool `plist:"DisableAssociationMACRandomization,omitempty" json:"DisableAssociationMACRandomization,omitempty"`
	// If `true`, the device makes this network available for joining before the device is
	// unlocked for the first time following a reboot, on a device configured for return to
	// service. Any network credentials are placed into Class D storage within the keychain,
	// and information about the network is stored on disk in Class D.
	AllowJoinBeforeFirstUnlock *bool `plist:"AllowJoinBeforeFirstUnlock,omitempty" json:"AllowJoinBeforeFirstUnlock,omitempty"`
}

WiFi: The payload that configures Wi-Fi settings.

WiFi corresponds to mdm/profiles/com.apple.wifi.managed.yaml (Wi-Fi).

func (*WiFi) PayloadTypeName

func (*WiFi) PayloadTypeName() string

PayloadTypeName returns "com.apple.wifi.managed".

func (*WiFi) SchemaPath

func (*WiFi) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*WiFi) Validate

func (x *WiFi) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type WiFiEAPClientConfiguration

type WiFiEAPClientConfiguration struct {
	// The EAP types that the system accepts. Allowed values:
	AcceptEAPTypes []int64 `plist:"AcceptEAPTypes,omitempty" json:"AcceptEAPTypes,omitempty"`
	// The user name for the account. If you don't specify a value, the system prompts the user
	// during login.
	UserName *string `plist:"UserName,omitempty" json:"UserName,omitempty"`
	// The user's password. If you don't specify a value, the system prompts the user during
	// login.
	UserPassword *string `plist:"UserPassword,omitempty" json:"UserPassword,omitempty"`
	// An array of the UUID of each certificate payload in the same profile to trust for
	// authentication. Use this key to prevent the device from asking the user whether to trust
	// the listed certificates. Dynamic trust (the certificate dialogue) is in a disabled state
	// if you specify this property without also enabling 'TLSAllowTrustExceptions'.
	PayloadCertificateAnchorUUID []string `plist:"PayloadCertificateAnchorUUID,omitempty" json:"PayloadCertificateAnchorUUID,omitempty"`
	// An array of trusted certificates. Each entry in the array must contain certificate data
	// that represents an anchor certificate used for verifying the server certificate.
	TLSTrustedCertificates []string `plist:"TLSTrustedCertificates,omitempty" json:"TLSTrustedCertificates,omitempty"`
	// The list of accepted server certificate common names. If a server presents a certificate
	// that isn't in this list, the system doesn't trust it. If you specify this property, the
	// system disables dynamic trust (the certificate dialog) unless you also specify
	// 'TLSAllowTrustExceptions' with the value 'true'. If necessary, use wildcards to specify
	// the name, such as 'wpa.*.example.com'.
	TLSTrustedServerNames []string `plist:"TLSTrustedServerNames,omitempty" json:"TLSTrustedServerNames,omitempty"`
	// If 'true', allows a dynamic trust decision by the user. The dynamic trust is the
	// certificate dialogue that appears when the system doesn't trust a certificate. If
	// 'false', the authentication fails if the system doesn't already trust the certificate.
	// As of iOS 8, Apple no longer supports this key.
	TLSAllowTrustExceptions *bool `plist:"TLSAllowTrustExceptions,omitempty" json:"TLSAllowTrustExceptions,omitempty"`
	// If 'true', allows for two-factor authentication for EAP-TTLS, PEAP, or EAP-FAST. If
	// 'false', allows for zero-factor authentication for EAP-TLS. If you don't specify a
	// value, the default is 'true' for EAP-TLS, and 'false' for other EAP types.
	TLSCertificateIsRequired *bool `plist:"TLSCertificateIsRequired,omitempty" json:"TLSCertificateIsRequired,omitempty"`
	// The inner authentication that the TTLS module uses.
	TTLSInnerAuthentication *string `plist:"TTLSInnerAuthentication,omitempty" json:"TTLSInnerAuthentication,omitempty"`
	// The minimum TLS version for EAP authentication.
	TLSMinimumVersion *string `plist:"TLSMinimumVersion,omitempty" json:"TLSMinimumVersion,omitempty"`
	// The maximum TLS version for EAP authentication.
	TLSMaximumVersion *string `plist:"TLSMaximumVersion,omitempty" json:"TLSMaximumVersion,omitempty"`
	// A name that hides the user's true name. The user's actual name appears only inside the
	// encrypted tunnel. For example, you might set this to anonymous or anon, or
	// anon@mycompany.net. It can increase security because an attacker can't see the
	// authenticating user's name in the clear. This key is only relevant to TTLS, PEAP, and
	// EAP-FAST. This field is required if 'TLSMinimumVersion' is '1.3'.
	OuterIdentity *string `plist:"OuterIdentity,omitempty" json:"OuterIdentity,omitempty"`
	// If 'true', the device uses an existing PAC if it's present. Otherwise, the server must
	// present its identity using a certificate.
	EAPFASTUsePAC *bool `plist:"EAPFASTUsePAC,omitempty" json:"EAPFASTUsePAC,omitempty"`
	// If 'true', allows PAC provisioning.
	EAPFASTProvisionPAC *bool `plist:"EAPFASTProvisionPAC,omitempty" json:"EAPFASTProvisionPAC,omitempty"`
	// If 'true', provisions the device anonymously. Note that there are known
	// machine-in-the-middle attacks for anonymous provisioning.
	EAPFASTProvisionPACAnonymously *bool `plist:"EAPFASTProvisionPACAnonymously,omitempty" json:"EAPFASTProvisionPACAnonymously,omitempty"`
	// The minimum number of RAND values to accept from the server. For use with EAP-SIM only.
	EAPSIMNumberOfRANDs *int64 `plist:"EAPSIMNumberOfRANDs,omitempty" json:"EAPSIMNumberOfRANDs,omitempty"`
	// Set this string to 'ActiveDirectory' to use the AD computer name and password
	// credentials. If using this property, you can't use
	// 'SystemModeUseOpenDirectoryCredentials'.
	SystemModeCredentialsSource *string `plist:"SystemModeCredentialsSource,omitempty" json:"SystemModeCredentialsSource,omitempty"`
	// If 'true', the system mode connection tries to use the Open Directory credentials. If
	// using this property, you can't use 'SystemModeCredentialsSource'.
	SystemModeUseOpenDirectoryCredentials *bool `plist:"SystemModeUseOpenDirectoryCredentials,omitempty" json:"SystemModeUseOpenDirectoryCredentials,omitempty"`
	// If 'true', the user receives a prompt for a password each time they connect to the
	// network.
	OneTimeUserPassword *bool `plist:"OneTimeUserPassword,omitempty" json:"OneTimeUserPassword,omitempty"`
}

WiFiEAPClientConfiguration: The enterprise network configuration.

type WiFiManagedSettings

type WiFiManagedSettings struct {
	// If `true`, requires administrator authorization to enable IBSS.
	RequireAdminForIBSS *bool `plist:"RequireAdminForIBSS,omitempty" json:"RequireAdminForIBSS,omitempty"`
	// If `true`, requires administrator authorization for network changes.
	RequireAdminForAirPortNetworkChange *bool `plist:"RequireAdminForAirPortNetworkChange,omitempty" json:"RequireAdminForAirPortNetworkChange,omitempty"`
	// If `true`, requires administrator authorization to turn Wi-Fi on or off.
	RequireAdminToTurnAirPortOnOff *bool `plist:"RequireAdminToTurnAirPortOnOff,omitempty" json:"RequireAdminToTurnAirPortOnOff,omitempty"`
}

WiFiManagedSettings: The payload that configures managed Wi-Fi settings.

WiFiManagedSettings corresponds to mdm/profiles/com.apple.MCX(WiFi).yaml (Wi-Fi Managed Settings).

func (*WiFiManagedSettings) PayloadTypeName

func (*WiFiManagedSettings) PayloadTypeName() string

PayloadTypeName returns "com.apple.MCX".

func (*WiFiManagedSettings) SchemaPath

func (*WiFiManagedSettings) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*WiFiManagedSettings) Validate

func (x *WiFiManagedSettings) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type WiFiQoSMarkingPolicy

type WiFiQoSMarkingPolicy struct {
	// An array of app bundle identifiers that defines the allow list for L2 and L3 marking for
	// traffic that goes to the Wi-Fi network. If the array isn't present, but the
	// `QoSMarkingPolicy` key is present — even empty — no apps can use L2 and L3 marking.
	QoSMarkingAllowListAppIdentifiers []string `plist:"QoSMarkingAllowListAppIdentifiers,omitempty" json:"QoSMarkingAllowListAppIdentifiers,omitempty"`
	// Use `QoSMarkingAllowListAppIdentifiers` instead.
	QoSMarkingWhitelistedAppIdentifiers []string `plist:"QoSMarkingWhitelistedAppIdentifiers,omitempty" json:"QoSMarkingWhitelistedAppIdentifiers,omitempty"`
	// If `true`, adds audio and video traffic of built-in audio or video services, such as
	// FaceTime and Wi-Fi Calling, to the allow list for L2 and L3 marking for traffic that
	// goes to the Wi-Fi network.
	QoSMarkingAppleAudioVideoCalls *bool `plist:"QoSMarkingAppleAudioVideoCalls,omitempty" json:"QoSMarkingAppleAudioVideoCalls,omitempty"`
	// If `true`, disables L3 marking and only uses L2 marking for traffic that goes to the
	// Wi-Fi network.
	QoSMarkingEnabled *bool `plist:"QoSMarkingEnabled,omitempty" json:"QoSMarkingEnabled,omitempty"`
}

WiFiQoSMarkingPolicy: A dictionary that contains the list of apps that the system allows to benefit from L2 and L3 marking. When this dictionary isn't present, the system allows all apps to use L2 and L3 marking when the Wi-Fi network supports Cisco QoS fast lane.

type X8021XFirstActiveEthernet

type X8021XFirstActiveEthernet struct {
	// Keys relevant to 802.1x configuration. User enrollment payloads do not support the
	// various proxy keys including ProxyType, ProxyServer, ProxyServerPort, ProxyUsername,
	// ProxyPassword,, ProxyPACURL and ProxyPACFallbackAllowed.
	ANY any `plist:"ANY,omitempty" json:"ANY,omitempty"`
}

X8021XFirstActiveEthernet: The payload that configures the first wired, active Ethernet interface.

X8021XFirstActiveEthernet corresponds to mdm/profiles/com.apple.firstactiveethernet.managed.yaml (802.1X: First Active Ethernet).

func (*X8021XFirstActiveEthernet) PayloadTypeName

func (*X8021XFirstActiveEthernet) PayloadTypeName() string

PayloadTypeName returns "com.apple.firstactiveethernet.managed".

func (*X8021XFirstActiveEthernet) SchemaPath

func (*X8021XFirstActiveEthernet) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*X8021XFirstActiveEthernet) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type X8021XFirstEthernet

type X8021XFirstEthernet struct {
	// Keys relevant to 802.1x configuration. User enrollment payloads do not support the
	// various proxy keys including ProxyType, ProxyServer, ProxyServerPort, ProxyUsername,
	// ProxyPassword,, ProxyPACURL and ProxyPACFallbackAllowed.
	ANY any `plist:"ANY,omitempty" json:"ANY,omitempty"`
}

X8021XFirstEthernet: The payload that configures the first wired Ethernet interface.

X8021XFirstEthernet corresponds to mdm/profiles/com.apple.firstethernet.managed.yaml (802.1X: First Ethernet).

func (*X8021XFirstEthernet) PayloadTypeName

func (*X8021XFirstEthernet) PayloadTypeName() string

PayloadTypeName returns "com.apple.firstethernet.managed".

func (*X8021XFirstEthernet) SchemaPath

func (*X8021XFirstEthernet) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*X8021XFirstEthernet) Validate

func (x *X8021XFirstEthernet) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type X8021XGlobalEthernet

type X8021XGlobalEthernet struct {
	// Keys relevant to 802.1X configuration. User enrollment payloads don't support the
	// various proxy keys, including `ProxyType`, `ProxyServer`, `ProxyServerPort`,
	// `ProxyUsername`, `ProxyPassword`, `ProxyPACURL` and `ProxyPACFallbackAllowed`.
	ANY any `plist:"ANY,omitempty" json:"ANY,omitempty"`
}

X8021XGlobalEthernet: The payload that configures the default fallback global Ethernet interface.

X8021XGlobalEthernet corresponds to mdm/profiles/com.apple.globalethernet.managed.yaml (802.1X: Global Ethernet).

func (*X8021XGlobalEthernet) PayloadTypeName

func (*X8021XGlobalEthernet) PayloadTypeName() string

PayloadTypeName returns "com.apple.globalethernet.managed".

func (*X8021XGlobalEthernet) SchemaPath

func (*X8021XGlobalEthernet) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*X8021XGlobalEthernet) Validate

func (x *X8021XGlobalEthernet) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type X8021XSecondActiveEthernet

type X8021XSecondActiveEthernet struct {
	// Keys relevant to 802.1x configuration. User enrollment payloads do not support the
	// various proxy keys including ProxyType, ProxyServer, ProxyServerPort, ProxyUsername,
	// ProxyPassword,, ProxyPACURL and ProxyPACFallbackAllowed.
	ANY any `plist:"ANY,omitempty" json:"ANY,omitempty"`
}

X8021XSecondActiveEthernet: The payload that configures the second wired, active Ethernet interface.

X8021XSecondActiveEthernet corresponds to mdm/profiles/com.apple.secondactiveethernet.managed.yaml (802.1X: Second Active Ethernet).

func (*X8021XSecondActiveEthernet) PayloadTypeName

func (*X8021XSecondActiveEthernet) PayloadTypeName() string

PayloadTypeName returns "com.apple.secondactiveethernet.managed".

func (*X8021XSecondActiveEthernet) SchemaPath

func (*X8021XSecondActiveEthernet) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*X8021XSecondActiveEthernet) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type X8021XSecondEthernet

type X8021XSecondEthernet struct {
	// Keys relevant to 802.1x configuration. User enrollment payloads do not support the
	// various proxy keys including ProxyType, ProxyServer, ProxyServerPort, ProxyUsername,
	// ProxyPassword,, ProxyPACURL and ProxyPACFallbackAllowed.
	ANY any `plist:"ANY,omitempty" json:"ANY,omitempty"`
}

X8021XSecondEthernet: The payload that configures the second wired Ethernet interface.

X8021XSecondEthernet corresponds to mdm/profiles/com.apple.secondethernet.managed.yaml (802.1X: Second Ethernet).

func (*X8021XSecondEthernet) PayloadTypeName

func (*X8021XSecondEthernet) PayloadTypeName() string

PayloadTypeName returns "com.apple.secondethernet.managed".

func (*X8021XSecondEthernet) SchemaPath

func (*X8021XSecondEthernet) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*X8021XSecondEthernet) Validate

func (x *X8021XSecondEthernet) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type X8021XThirdActiveEthernet

type X8021XThirdActiveEthernet struct {
	// Keys relevant to 802.1x configuration. User enrollment payloads do not support the
	// various proxy keys including ProxyType, ProxyServer, ProxyServerPort, ProxyUsername,
	// ProxyPassword,, ProxyPACURL and ProxyPACFallbackAllowed.
	ANY any `plist:"ANY,omitempty" json:"ANY,omitempty"`
}

X8021XThirdActiveEthernet: The payload that configures the third wired, active Ethernet interface.

X8021XThirdActiveEthernet corresponds to mdm/profiles/com.apple.thirdactiveethernet.managed.yaml (802.1X: Third Active Ethernet).

func (*X8021XThirdActiveEthernet) PayloadTypeName

func (*X8021XThirdActiveEthernet) PayloadTypeName() string

PayloadTypeName returns "com.apple.thirdactiveethernet.managed".

func (*X8021XThirdActiveEthernet) SchemaPath

func (*X8021XThirdActiveEthernet) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*X8021XThirdActiveEthernet) Validate

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type X8021XThirdEthernet

type X8021XThirdEthernet struct {
	// Keys relevant to 802.1x configuration. User enrollment payloads do not support the
	// various proxy keys including ProxyType, ProxyServer, ProxyServerPort, ProxyUsername,
	// ProxyPassword,, ProxyPACURL and ProxyPACFallbackAllowed.
	ANY any `plist:"ANY,omitempty" json:"ANY,omitempty"`
}

X8021XThirdEthernet: The payload that configures the third wired Ethernet interface.

X8021XThirdEthernet corresponds to mdm/profiles/com.apple.thirdethernet.managed.yaml (802.1X: Third Ethernet).

func (*X8021XThirdEthernet) PayloadTypeName

func (*X8021XThirdEthernet) PayloadTypeName() string

PayloadTypeName returns "com.apple.thirdethernet.managed".

func (*X8021XThirdEthernet) SchemaPath

func (*X8021XThirdEthernet) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*X8021XThirdEthernet) Validate

func (x *X8021XThirdEthernet) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type Xsan

type Xsan struct {
	// The name of the SAN. This key is required for all Xsan SANs. The name must exactly match
	// the name of the SAN defined in the metadata server.
	SanName string `plist:"sanName" json:"sanName"`
	// An array of LDAP URLs where Xsan systems can obtain SAN configuration updates. There
	// should be one entry for each Xsan MDC.
	SanConfigURLs []string `plist:"sanConfigURLs,omitempty" json:"sanConfigURLs,omitempty"`
	// An array of storage area network (SAN) File System Name Server coordinators. The list
	// should contain the same addresses in the same order as the metadata controller (MDC)
	// `/Library/Preferences/Xsan/fsnameservers` file.
	Fsnameservers []string `plist:"fsnameservers,omitempty" json:"fsnameservers,omitempty"`
	// The authentication method for the SAN. This key is required for all Xsan SANs. It's
	// optional for StorNext SANs but should be set if the StorNext SAN uses an `auth_secret`
	// file.
	SanAuthMethod *string `plist:"sanAuthMethod,omitempty" json:"sanAuthMethod,omitempty"`
	// The shared secret used for Xsan network authentication. This key is required when the
	// `sanAuthMethod` key is present. The value should equal the content of the MDC's
	// `/Library/Preferences/Xsan/.auth_secret` file.
	SharedSecret string `plist:"sharedSecret" json:"sharedSecret"`
}

Xsan: The payload that configures an Xsan client system.

Xsan corresponds to mdm/profiles/com.apple.xsan.yaml (Xsan).

func (*Xsan) PayloadTypeName

func (*Xsan) PayloadTypeName() string

PayloadTypeName returns "com.apple.xsan".

func (*Xsan) SchemaPath

func (*Xsan) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*Xsan) Validate

func (x *Xsan) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

type XsanPreferences

type XsanPreferences struct {
	// An array of Xsan or StorNext volume names. The Xsan client attempts to automatically
	// mount these volumes at startup. The system administrator can mount additional volumes
	// manually by using the `xsanctl(8)` mount command.
	OnlyMount []string `plist:"onlyMount,omitempty" json:"onlyMount,omitempty"`
	// An array of Xsan or StorNext volume names. If no `onlyMount` array is present, the Xsan
	// client automatically attempts to mount all SAN volumes except the volumes in this array.
	// The system administrator can mount those volumes manually by using the `xsanctl(8)`
	// mount command.
	DenyMount []string `plist:"denyMount,omitempty" json:"denyMount,omitempty"`
	// An array of StorNext volume names. If the Xsan client is attempting to mount a volume
	// named in this array, the client only mounts the volume if its logical units (LUNs) are
	// available through Fibre Channel. It doesn't attempt to mount the volume using
	// Distributed LAN Client (DLC).
	DenyDLC []string `plist:"denyDLC,omitempty" json:"denyDLC,omitempty"`
	// An array of StorNext volume names. If the Xsan client is attempting to mount a volume
	// named in this array, the Xsan client attempts to mount the volume using DLC. If DLC
	// isn't available, the client attempts to mount the volume if its LUNs are available
	// through Fibre Channel. The volume name must not also appear in `denyDLC`.
	PreferDLC []string `plist:"preferDLC,omitempty" json:"preferDLC,omitempty"`
	// If `true`, use the DLC for all volumes.
	UseDLC *bool `plist:"useDLC,omitempty" json:"useDLC,omitempty"`
}

XsanPreferences: The payload that configures the Xsan preferences that define the volumes that automatically mount at startup.

XsanPreferences corresponds to mdm/profiles/com.apple.xsan.preferences.yaml (Xsan Preferences).

func (*XsanPreferences) PayloadTypeName

func (*XsanPreferences) PayloadTypeName() string

PayloadTypeName returns "com.apple.xsan.preferences".

func (*XsanPreferences) SchemaPath

func (*XsanPreferences) SchemaPath() string

SchemaPath returns the Apple schema file this type was generated from.

func (*XsanPreferences) Validate

func (x *XsanPreferences) Validate(t support.Target) error

Validate checks x against the schema. With a non-zero target it also checks that every present key is supported on that OS version and enrollment context.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL