Privacy Preferences Policy Control
com.apple.TCC.configuration-profile-policy
The payload that configures privacy preferences.
Not available with User Enrollment · macOS: device channel only
Configuration Keys (1)
| Key | Type | Title |
|---|---|---|
ServicesrequiredA dictionary whose keys are limited to the privacy policy control services. In the case of conflicting specifications, the most restrictive setting (deny) is used. | dict | Services |
AccessibilitydeprecatedmacOS · deprecated 27.0 Specifies the policies for the app via the Accessibility subsystem. In macOS 27.0, the device shows a non-blocking notification for each application when this setting is applied, and it allows the user to make changes to the setting in the System Settings app. Deprecated: use the 'Privacy' key in the declarative management 'com.apple.configuration.app.settings' configuration. | array | Accessibility |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow (deprecated 26.2, removed 27.0) (Allow), Deny (Deny) | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
AppleEventsSpecifies the policies for the app sending restricted AppleEvents to another process. | array | AppleEvents |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
AEReceiverIdentifierrequiredThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | AEReceiverIdentifier |
AEReceiverIdentifierTyperequiredThe type of AEReceiverIdentifier value, either 'bundleID' or 'path'. This setting is required for AppleEvents service; not valid for other services. Range: Bundle ID (bundleID), Path (path) | string | AEReceiverIdentifierType |
AEReceiverCodeRequirementrequiredThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | AEReceiverCodeRequirement |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
BluetoothAlwaysdeprecatedmacOS 11.0+ · deprecated 27.0 Specifies the policies for the app to access Bluetooth devices. Deprecated: use the 'Privacy' key in the declarative management 'com.apple.configuration.app.settings' configuration. | array | Bluetooth Always |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | — |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
CalendarSpecifies the policies for calendar information managed by the Calendar.app. | array | Calendar |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
CameradeprecatedmacOS · deprecated 27.0 A system camera. A profile can't grant access to the camera; it can only deny it. | array | Camera |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
AddressBookSpecifies the policies for contact information managed by the Contacts.app. | array | Contacts |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
FileProviderPresencemacOS 10.15+ Allows a File Provider application to know when the user is using files managed by the File Provider. | array | — |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
ListenEventmacOS 10.15+ Allows the application to use CoreGraphics and HID APIs to listen to (receive) CGEvents and HID events from all processes. A profile can't grant access to these events; it can only deny it. | array | — |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Deny': Access is denied. 'AllowStandardUserToSetSystemService': Allows a standard (non-admin) user to configure the permissions for the specified app in the Privacy preferences for services that otherwise require admin authorization. Range: Deny, AllowStandardUserToSetSystemService | string | — |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
MediaLibrarymacOS 10.15+ Allows the application to access Apple Music, music and video activity, and the media library. | array | — |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
MicrophonedeprecatedmacOS · deprecated 27.0 A system microphone. A profile can't grant access to the microphone; it can only deny it. | array | Microphone |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
PhotosThe pictures managed by the Photos app in '~/Pictures/.photoslibrary'. | array | Photos |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
PostEventSpecifies the policies for the application to use CoreGraphics APIs to send CGEvents to the system event stream. | array | PostEvent |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
RemindersSpecifies the policies for reminders information managed by the Reminders app. | array | Reminders |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
SystemPolicyAllFilesAllows the application access to all protected files, including system administration files. | array | SystemPolicyAllFiles |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
ScreenCapturemacOS 10.15+ Allows the application to capture (read) the contents of the system display. A profile can't grant access to the contents; it can only deny it. | array | Screen & System Audio Recording |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Deny': Access is denied. 'AllowStandardUserToSetSystemService': Allows a standard (non-admin) user to configure the permissions for the specified app in the Privacy preferences for services that otherwise require admin authorization. Range: Deny, AllowStandardUserToSetSystemService | string | — |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
SpeechRecognitiondeprecatedmacOS 10.15+ · deprecated 27.0 Allows the application to use the system Speech Recognition facility and to send speech data to Apple. Deprecated: use the 'Privacy' key in the declarative management 'com.apple.configuration.app.settings' configuration. | array | Speech Recognition |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
SystemPolicyDesktopFoldermacOS 10.15+ Allows the application to access files in the user's Desktop folder. | array | Files and Folders: Desktop Folder |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
SystemPolicyDocumentsFoldermacOS 10.15+ Allows the application to access files in the user's Documents folder. | array | Files and Folders: Documents Folder |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
SystemPolicyDownloadsFoldermacOS 10.15+ Allows the application to access files in the user's Downloads folder. | array | Files and Folders: Downloads Folder |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
SystemPolicyNetworkVolumesmacOS 10.15+ Allows the application to access files on network volumes. | array | Files and Folders: Network Volumes |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
SystemPolicyRemovableVolumesmacOS 10.15+ Allows the application to access files on removable volumes. | array | Files and Folders: Removable Volumes |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
SystemPolicySysAdminFilesAllows the application access to some files used in system administration. | array | System Policy Sys Admin Files |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
SystemPolicyAppDatamacOS 14.0+ Specifies the policies for the app to access the data of other apps. | array | System Policy App Data |
IdentityDictA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | — |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: bundleID, path | string | — |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | — |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | — |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | — |
CommentNot used. | string | — |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
SystemPolicyAppBundlesmacOS 13.0+ Allows the application to update or delete other apps. | array | App Management |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. Note: This value is case-sensitive. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtain this value by running 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationmacOS 11.0+ The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied. Range: Allow, Deny | string | Authorization |
CommentNot used. | string | Comment |
AllowedIf `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both. | boolean | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
RemoteDesktopAllows the application to control the computer remotely. Available in macOS 14.7 and later. | array | Remote Desktop |
IdentityDictrequiredA dictionary listing apps and the privacy policy to apply to them. | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredObtained via the command 'codesign -display -r -'. | string | Code Requirement |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. Default: false | boolean | StaticCode |
AuthorizationThe 'Authorization' key is an optional replacement for the 'Allowed' key, which has one of the following possible values: 'Allow': Equivalent to a 'true' value for the 'Allowed' key 'Deny': Equivalent to a 'false' value for the 'Allowed' key Note: Every payload needs to include either 'Authorization' or 'Allowed', but not both. Available in macOS 14.7 and later. Range: Allow, Deny | string | — |
CommentNot used. | string | Comment |