Extensions device management payload settings for Apple devices

Use the Extensions payload to control which extensions are available for users of a Mac that enrolls in a device management service.

The Extensions payload supports the following. For more information, see Payload information.

  • Supported payload identifier: com.apple.NSExtension

  • Supported operating systems and channels: macOS device, macOS user.

  • Supported enrollment methods: Device Enrollment, Automated Device Enrollment.

  • Duplicates allowed: True—more than one Extensions payload can be delivered to a user or device.

You can use the settings in the table below with the Extensions payload.

Setting

Description

Required

Allowed extensions

Add the bundle identifier for each extension allowed to run on the Mac. Any extensions not listed are unable to run.

No

Disallow all extension points

Users can’t use any extension points for their Mac.

No

Allow all extension points

Users can use all extension points except ones you specify can’t be used.

No

Disallow some extensions points

Disallow specific extensions by their bundle identifier and also disallow specific extension points:

  • Action

  • Audio unit

  • Content blocker

  • Finder sync

  • Photo editing

  • Safari

  • Share

  • Shared links

  • Smart Card token

  • Today

  • Xcode source editor

No

Note: Each device management service developer implements these settings differently. To learn how various Extensions settings are applied to your devices and users, consult your developer’s device management service documentation.

Published Date: October 24, 2022
Morty Proxy This is a proxified and sanitized view of the page, visit original site.
Helpful?
Character limit: 250
Maximum character limit is 250.
Thanks for your feedback.
Morty Proxy This is a proxified and sanitized view of the page, visit original site.