PayloadKit

App Store

com.apple.appstore

The payload that configures macOS App Store restrictions.

macOS 10.9+
Apple schemaexclusive

Not available with User Enrollment · Only one instance per profile

3 of 5 settings are available in the Intune Settings Catalog. Remaining settings require a custom .mobileconfig profile.

DDM recommended — 3 of 5 settings support Declarative Device Management

Apple recommends DDM over legacy profiles. DDM declarations are autonomous — the device enforces them without server round-trips. In Intune, use Settings Catalog → Declarative Device Management to configure these settings.

Configuration Keys (5)

KeyTypeTitleDDM
restrict-store-require-admin-to-installdeprecated

macOS 10.9+ · deprecated 10.14

If 'true', the system restricts app installations to admin users only. Deprecated in macOS 10.14. Use the 'com.apple.SoftwareUpdate' payload key 'restrict-software-update-require-admin-to-install' instead.

Default: false

booleanRequire Admin To Install
restrict-store-softwareupdate-only

macOS 10.10+

If 'true', the system prevents App Store from launching. Restricts installations to software updates only in macOS 10.10 through 10.13.

Default: false

booleanRestrict app installations to software updates only
restrict-store-disable-app-adoption

macOS 10.10+

If 'true', the system disables app adoption by users.

Default: false

booleanDisable App Adoption by users
DisableSoftwareUpdateNotifications

macOS 10.10+

If 'true', the system disables software update notifications.

Default: false

booleanDisable software update notifications
restrict-store-mdm-install-softwareupdate-only

Restrict app installations to MDM-installed apps and software updates

booleanRestrict app installations to MDM-installed apps and software updates