PayloadKit

Privacy Preferences Policy Control

com.apple.TCC.configuration-profile-policy

The payload that configures privacy preferences.

macOS 10.14+
Apple schemacombined

Not available with User Enrollment · macOS: device channel only

Configuration Keys (1)

KeyTypeTitle
Servicesrequired

A dictionary whose keys are limited to the privacy policy control services. In the case of conflicting specifications, the most restrictive setting (deny) is used.

dictServices
Accessibilitydeprecated

macOS · deprecated 27.0

Specifies the policies for the app via the Accessibility subsystem. In macOS 27.0, the device shows a non-blocking notification for each application when this setting is applied, and it allows the user to make changes to the setting in the System Settings app. Deprecated: use the 'Privacy' key in the declarative management 'com.apple.configuration.app.settings' configuration.

arrayAccessibility
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow (deprecated 26.2, removed 27.0) (Allow), Deny (Deny)

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
AppleEvents

Specifies the policies for the app sending restricted AppleEvents to another process.

arrayAppleEvents
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
AEReceiverIdentifierrequired

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

stringAEReceiverIdentifier
AEReceiverIdentifierTyperequired

The type of AEReceiverIdentifier value, either 'bundleID' or 'path'. This setting is required for AppleEvents service; not valid for other services.

Range: Bundle ID (bundleID), Path (path)

stringAEReceiverIdentifierType
AEReceiverCodeRequirementrequired

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

stringAEReceiverCodeRequirement
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
BluetoothAlwaysdeprecated

macOS 11.0+ · deprecated 27.0

Specifies the policies for the app to access Bluetooth devices. Deprecated: use the 'Privacy' key in the declarative management 'com.apple.configuration.app.settings' configuration.

arrayBluetooth Always
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

string—
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
Calendar

Specifies the policies for calendar information managed by the Calendar.app.

arrayCalendar
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
Cameradeprecated

macOS · deprecated 27.0

A system camera. A profile can't grant access to the camera; it can only deny it.

arrayCamera
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
AddressBook

Specifies the policies for contact information managed by the Contacts.app.

arrayContacts
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
FileProviderPresence

macOS 10.15+

Allows a File Provider application to know when the user is using files managed by the File Provider.

array—
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
ListenEvent

macOS 10.15+

Allows the application to use CoreGraphics and HID APIs to listen to (receive) CGEvents and HID events from all processes. A profile can't grant access to these events; it can only deny it.

array—
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Deny': Access is denied. 'AllowStandardUserToSetSystemService': Allows a standard (non-admin) user to configure the permissions for the specified app in the Privacy preferences for services that otherwise require admin authorization.

Range: Deny, AllowStandardUserToSetSystemService

string—
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
MediaLibrary

macOS 10.15+

Allows the application to access Apple Music, music and video activity, and the media library.

array—
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
Microphonedeprecated

macOS · deprecated 27.0

A system microphone. A profile can't grant access to the microphone; it can only deny it.

arrayMicrophone
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
Photos

The pictures managed by the Photos app in '~/Pictures/.photoslibrary'.

arrayPhotos
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
PostEvent

Specifies the policies for the application to use CoreGraphics APIs to send CGEvents to the system event stream.

arrayPostEvent
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
Reminders

Specifies the policies for reminders information managed by the Reminders app.

arrayReminders
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
SystemPolicyAllFiles

Allows the application access to all protected files, including system administration files.

arraySystemPolicyAllFiles
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
ScreenCapture

macOS 10.15+

Allows the application to capture (read) the contents of the system display. A profile can't grant access to the contents; it can only deny it.

arrayScreen & System Audio Recording
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Deny': Access is denied. 'AllowStandardUserToSetSystemService': Allows a standard (non-admin) user to configure the permissions for the specified app in the Privacy preferences for services that otherwise require admin authorization.

Range: Deny, AllowStandardUserToSetSystemService

string—
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
SpeechRecognitiondeprecated

macOS 10.15+ · deprecated 27.0

Allows the application to use the system Speech Recognition facility and to send speech data to Apple. Deprecated: use the 'Privacy' key in the declarative management 'com.apple.configuration.app.settings' configuration.

arraySpeech Recognition
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
SystemPolicyDesktopFolder

macOS 10.15+

Allows the application to access files in the user's Desktop folder.

arrayFiles and Folders: Desktop Folder
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
SystemPolicyDocumentsFolder

macOS 10.15+

Allows the application to access files in the user's Documents folder.

arrayFiles and Folders: Documents Folder
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
SystemPolicyDownloadsFolder

macOS 10.15+

Allows the application to access files in the user's Downloads folder.

arrayFiles and Folders: Downloads Folder
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
SystemPolicyNetworkVolumes

macOS 10.15+

Allows the application to access files on network volumes.

arrayFiles and Folders: Network Volumes
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
SystemPolicyRemovableVolumes

macOS 10.15+

Allows the application to access files on removable volumes.

arrayFiles and Folders: Removable Volumes
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
SystemPolicySysAdminFiles

Allows the application access to some files used in system administration.

arraySystem Policy Sys Admin Files
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
SystemPolicyAppData

macOS 14.0+

Specifies the policies for the app to access the data of other apps.

arraySystem Policy App Data
IdentityDict

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

string—
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: bundleID, path

string—
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

string—
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

boolean—
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

string—
Comment

Not used.

string—
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
SystemPolicyAppBundles

macOS 13.0+

Allows the application to update or delete other apps.

arrayApp Management
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary. Note: This value is case-sensitive.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtain this value by running 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

macOS 11.0+

The 'Authorization' has one of the following possible values: 'Allow': Access is granted. 'Deny': Access is denied.

Range: Allow, Deny

stringAuthorization
Comment

Not used.

stringComment
Allowed

If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. > Note: > Every payload needs to include either `Authorization` or `Allowed`, but not both.

boolean—
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string—
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string—
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string—
RemoteDesktop

Allows the application to control the computer remotely. Available in macOS 14.7 and later.

arrayRemote Desktop
IdentityDictrequired

A dictionary listing apps and the privacy policy to apply to them.

dict—
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

Obtained via the command 'codesign -display -r -'.

stringCode Requirement
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

Default: false

booleanStaticCode
Authorization

The 'Authorization' key is an optional replacement for the 'Allowed' key, which has one of the following possible values: 'Allow': Equivalent to a 'true' value for the 'Allowed' key 'Deny': Equivalent to a 'false' value for the 'Allowed' key Note: Every payload needs to include either 'Authorization' or 'Allowed', but not both. Available in macOS 14.7 and later.

Range: Allow, Deny

string—
Comment

Not used.

stringComment