Relay device management payload settings for Apple devices

You can configure Relay settings for users of an iPhone, iPad, Shared iPad, Mac, or Apple Vision Pro that enrolls in a device management service. Use the Relay payload to support secure and transparent tunneling of traffic—the advanced alternative to VPN when accessing internal resources.

The Relay payload supports the following. For more information, see Payload information.

  • Supported payload identifier: com.apple.relay.managed

  • Supported operating systems and channels: iOS 17, iPadOS 17, Shared iPad device, macOS 14 device, macOS 14 user, visionOS 1.1.

  • Supported enrollment methods: Device Enrollment, Automated Device Enrollment.

  • Duplicates allowed: True—more than one Relay payload can be delivered to a user or device.

You can use the settings in the table below with the Relay payload.

Setting

Description

Required

Relays

An array of dictionaries that describes one or more relay servers that can be chained together.

Yes

RelayUUID

A globally-unique identifier for this relay configuration. This UUID is used to route managed apps through the servers contained in Relays.

No

Match domains

A list of domain strings used to determine which connection should be routed through the servers contained in Relays. Any connection that matches the domain exactly or that’s a subdomain of the listed domain uses the relay servers, unless they match an excluded domain. If no domains are listed, traffic to all domains, except those matching an excluded domain, is routed to the relay servers.

Devices with iOS 18.4, iPadOS 18.4, macOS 18.4, tvOS 18.4, visionOS 2.4, or later, support FQDNs (hostnames) in addition to domain-based rules. The following options are available:

  • If your organization specifies MatchDomains, excluded FQDNs need to be subdomains to take effect.

  • If your organization doesn’t specify MatchDomains or FQDNs, all traffic (except excluded domains) goes through the relay. Organizations can also exclude FQDNs. Exact matches bypass the relay.

No

Excluded domains

A list of domain strings that shouldn’t be routed through the servers contained in Relays. Any connection that matches the domain exactly or that is a subdomain of the listed domain don’t use the relay server.

No

Note: Each device management service developer implements these settings differently. To learn how Relay settings are applied to your devices and users, consult your developer’s device management service documentation.

Published Date: March 7, 2024
Morty Proxy This is a proxified and sanitized view of the page, visit original site.
T'ha sigut útil?
Límit de caràcters: 250
El límit de caràcters és de 250.
Gràcies per la teva opinió.
Morty Proxy This is a proxified and sanitized view of the page, visit original site.