PayloadKit

Extensible Single Sign-On

com.apple.extensiblesso

The payload that configures an app extension that performs single sign-on (SSO).

iOS 13.0+macOS 10.15+visionOS 1.1+
Apple schemacombined

Configuration Keys (12)

KeyTypeTitle
ExtensionIdentifierrequired

The bundle identifier of the app extension that performs SSO for the specified URLs.

Range: com.apple.AppSSOKerberos.KerberosExtension, com.microsoft.azureauthenticator.ssoextension, com.microsoft.CompanyPortalMac.ssoextension

stringExtension Identifier
Typerequired

The type of SSO.

Range: Credential, Redirect

string—
TeamIdentifierrequired

not on iOS, visionOS

The team identifier of the app extension. The device requires this key on macOS and ignores it elsewhere.

Depends on: ExtensionIdentifier ∈ [com.apple.AppSSOKerberos.KerberosExtension];

Range: apple

stringTeam Identifier
Hosts

An array of host or domain names that apps can authenticate through the app extension. Required for 'Credential' payloads. Ignored for 'Redirect' payloads. The system: Matches host or domain names case-insensitively Requires that all the host and domain names of all installed Extensible SSO payloads are unique Note: Host names that begin with a "." are wildcard suffixes that match all subdomains; otherwise the host name needs be an exact match.

Depends on: Type ∈ [Credential]

array—
hostnamerequired

A host or domain name, with or without a leading dot.

stringHostname / Domain name
Realmrequired

The realm name for 'Credential' payloads. Use proper capitalization for this value. Ignored for 'Redirect' payloads.

Depends on: ExtensionIdentifier ∈ [com.apple.AppSSOKerberos.KerberosExtension]

string—
URLs

An array of URL prefixes of identity providers where the app extension performs SSO. Required for 'Redirect' payloads. Ignored for 'Credential' payloads. The URLs need to begin with 'http://' or 'https://'. The system: Matches scheme and host name case-insensitively Doesn't allow query parameters and URL fragments Requires that the URLs of all installed Extensible SSO payloads are unique

Depends on: Type ∈ [Redirect]

arrayURLs
URLrequired

An http or https URL prefix.

stringURL
DeniedBundleIdentifiers

iOS 15.0+ · macOS 12.0+

An array of bundle identifiers of apps that don't use SSO provided by this extension.

arrayDenied Bundle Identifiers
bundleIdentifierrequired

The bundle identifier of the app.

stringBundle Identifier
ScreenLockedBehavior

iOS 15.0+ · macOS 12.0+

If set to 'Cancel', the system cancels authentication requests when the screen is locked. If set to 'DoNotHandle', the request continues without SSO instead. This doesn't apply to requests where 'userInterfaceEnabled' is 'false', or for background 'URLSession' requests.

Default: "Cancel"

Range: Cancel (Cancel), Do Not Handle (DoNotHandle)

stringScreen Locked Behavior
ExtensionData

A dictionary of arbitrary data passed through to the app extension.

Depends on: ExtensionIdentifier ∈ [com.apple.AppSSOKerberos.KerberosExtension]

dictKerberos Extension Data
allowAutomaticLogin

If 'false', the system doesn't allow saving passwords in the keychain.

Default: true

booleanAllow Automatic Login
allowPasswordChange

not on iOS, visionOS

If 'false', the system disables password changes.

Default: true

booleanAllow Password Change
usePlatformSSOTGT

macOS 13.0+ · not on iOS, visionOS

If 'true', the system requires this configuration uses a TGT from Platform SSO instead of requesting a new one.

Default: false

booleanUse Platform SSO TGT
allowPlatformSSOAuthFallback

macOS 13.0+ · not on iOS, visionOS

If 'true' and 'usePlatformSSOTGT' is 'true', the system allows the user to manually sign in.

Default: true

booleanAllow Platform SSO Authentication Fallback
performKerberosOnly

iOS 16.0+ · macOS 13.0+

If 'true', the Kerberos Extension handles Kerberos requests only. It doesn't check for password expiration, show the password expiration in the menu, check for external password changes, perform password sync, or retrieve the home directory.

Default: false

booleanPerform Kerberos Requests Only
cacheNamedeprecated

iOS · deprecated 15.0 · macOS · deprecated 12.0

The GSS name of the Kerberos cache to use. Rarely set by an administrator.

stringCache Name
certificateUUID

The PayloadUUID of a PKINIT certificate.

stringCertificate UUID
credentialBundleIdACL

A list of bundle IDs allowed to access the ticket-granting ticket (TGT).

arrayCredential Bundle ID ACL
credentialBundleIdACLItem

Bundle IDs allowed to access the TGT. These values are case sensitive.

stringBundle ID
credentialUseMode

iOS 14.0+ · macOS 11.0+

This setting affects how other processes use the Kerberos Extension credential. Allowed values: 'always': The system always uses the credential if the SPN matches the Kerberos Extension 'Hosts' array and the caller hasn't specified another credential. However, the system won't use the credential if the calling app isn't in the 'credentialBundleIDACL'. 'whenNotSpecified': The system only uses the extension credential if the SPN matches the Kerberos Extension 'Hosts' array. However, the system won't use the credential if the calling app isn't in the 'credentialBundleIDACL'. 'kerberosDefault': The system uses the default Kerberos processes to select credentials, and normally uses the default Kerberos credential. This is the same as turning off this capability.

Default: "always"

Range: Always (always), When Not Specified (whenNotSpecified), Kerberos Default (kerberosDefault)

stringCredential Use Mode
customUsernameLabel

iOS 14.0+ · macOS 11.0+

The custom user name label used in the Kerberos extension instead of "Username," such as "Company ID".

stringCustom Username Label
delayUserSetup

macOS 11.0+ · not on iOS, visionOS

If 'true', the system doesn't prompt the user to setup the Kerberos extension until either the administrator enables it with the 'app-sso' tool or the system receives a Kerberos challenge.

Default: false

booleanDelay User Setup
helpText

iOS 14.0+ · macOS 11.0+

The text to display to the user at the bottom of the Kerberos Login Window. You can also use this to display help information or disclaimer text.

stringHelp Text
isDefaultRealm

Specifies whether this is the default realm if there's more than one Kerberos extension configuration.

Default: false

booleanIs Default Realm
includeManagedAppsInBundleIdACL

iOS 14.0+ · macOS 12.0+

If 'true', the Kerberos extension allows only managed apps to access and use the credential. This is in addition to the 'credentialBundleIDACL', if you specify that value.

Default: false

booleanInclude Managed Apps in Bundle ID ACL
includeKerberosAppsInBundleIdACL

macOS 12.0+ · not on iOS, visionOS

If 'true', the Kerberos extension allows the standard Kerberos utilities including 'TicketViewer' and 'klist' to access and use the credential. This is in addition to 'includeManagedAppsInBundleIdACL' or the 'credentialBundleIdACL', if you specify those values.

Default: false

booleanInclude Kerberos Apps in Bundle ID ACL
monitorCredentialsCache

macOS 11.0+ · not on iOS, visionOS

If 'false', the system requests the credential on the next matching Kerberos challenge or network state change. If the credential is expired or missing, the system creates a new one.

Default: true

booleanMonitor Credential Cache
principalName

The principal (username) to use. You don't need to include the realm.

stringPrincipal Name
preferredKDCs

iOS 15.0+ · macOS 12.0+

The ordered list of preferred Key Distribution Centers (KDCs) to use for Kerberos traffic. Use this if the servers aren't discoverable through DNS. If you specify the servers, the system uses them for both connectivity checks and attempts to use them first for Kerberos traffic. If the servers don't respond, the device falls back to DNS discovery. Format each entry the same as it would be in a 'krb5.conf' file, for example: 'adserver1.example.com' 'tcp/adserver1.example.com:88' 'kkdcp://kerberosproxy.example.com:443/kkdcp'

arrayPreferred KDCs
preferredKDCrequired

A host or domain name in the format of [protocol/]hostname[:port][/path]

stringKey Distribution Center
pwChangeURL

not on iOS, visionOS

This URL will launch in the user's default web browser when they initiate a password change.

stringPassword Change URL
pwNotificationDays

not on iOS, visionOS

The number of days prior to password expiration when the system sends a notification of password expiration to the user.

Default: 15

integerPassword Notification Days
pwExpireOverridedeprecated

macOS · deprecated 12.0 · not on iOS, visionOS

The number of days that the system allows using passwords on this domain. For most domains, this calculation is automatic.

integerPassword Expiration Override
pwReqComplexity

not on iOS, visionOS

If 'true', the system requires passwords to meet Active Directory's definition of "complex".

Default: false

booleanPassword Requirement Complexity
pwReqHistory

not on iOS, visionOS

The number of prior passwords that the system disallows reuse on this domain.

integerPassword Requirement History
pwReqLength

not on iOS, visionOS

The minimum length of passwords on the domain.

integerPassword Requirement Length
pwReqMinAge

not on iOS, visionOS

The minimum age of passwords before the system allows changing them on this domain.

integerPassword Requirement Minimum Age
pwReqText

not on iOS, visionOS

The text version of the domain's password requirements. Only for use if 'pwReqComplexity' or 'pwReqLength' aren't specified.

stringPassword Requirement Text
pwReqRTFData

macOS 15.0+ · not on iOS, visionOS

The RTF file formatted version of the domain's password requirements. Only for use if 'pwReqComplexity' or 'pwReqLength' aren't specified.

data—
replicationTimedeprecated

macOS 11.0+ · deprecated 12.0 · not on iOS, visionOS

The time, in seconds, required to replicate changes in the Active Directory domain. The Kerberos extension uses this when checking password age after a change.

Default: 900

integerReplication Time
requireTLSForLDAP

iOS 14.0+ · macOS 11.0+

Require that LDAP connections use TLS.

Default: false

booleanRequire TLS for LDAP
requireUserPresence

If 'true', the system requires the user to provide Touch ID, Face ID or their passcode to access the keychain entry.

Default: false

booleanRequire User Presence
siteCode

The name of the Active Directory site the Kerberos extension should use. Most administrators don't need to modify this value, as the Kerberos extension can normally find the site automatically.

stringSite Code
syncLocalPassword

not on iOS, visionOS

If 'false', the system disables password sync. Note that this will not work if the user is logged in with a mobile account.

Default: false

booleanSync Local Password
useSiteAutoDiscovery

If 'false', the Kerberos extension doesn't automatically use LDAP and DNS to determine its AD site name.

Default: true

booleanUse Site Auto Discovery
domainRealmMapping

A custom domain-realm mapping for Kerberos. The system uses this when the DNS name of hosts doesn't match the realm name. Most administrators don't need to customize this.

dict—
Realm

The key should be the name of the realm, and the value is an array of DNS suffixes that map to the realm.

array—
RealmItem

Domains to map to the realm

string—
Enable_SSO_On_All_ManagedApps

Default: 0

Range: Disable (0), Enable (1)

integerEnable SSO on All Managed Apps
AppAllowList

Enable SSO for specific apps

stringApp Allow List
AppPrefixAllowList

Enable SSO for all apps with a specific bundle ID prefix

stringApp Prefix Allow List
AppBlockList

Disable SSO for specific apps

stringApp Block List
AppCookieSSOAllowList

Enable SSO through cookies for a specific application

stringApp Cookie SSO Allow List
browser_sso_interaction_enabled

Default: 0

Range: Disable (0), Enable (1)

integerAllow Users to Sign in from Unknown Applications using the Safari Browser
browser_sso_disable_mfa

Default: 0

Range: Enable (0), Disable (1)

integerDisable Asking for MFA During Initial Bootstrapping
disable_explicit_app_prompt

Default: 0

Range: Enable (0), Disable (1)

integerDisable OAuth2 Application Prompts
disable_explicit_app_prompt_and_autologin

Default: 0

Range: Enable (0), Disable (1)

integerDisable OAuth2 Application Prompts and Autologin
identityIssuerAutoSelectFilter

macOS 15.0+ · not on iOS, visionOS

A string with wildcards that can use used to filter the list of available SmartCards by issuer. e.g "*My CA2*". If there's one remaining, it will be auto-selected. If there more than one remaining, then the list is shorter.

string—
allowSmartCard

macOS 15.0+ · not on iOS, visionOS

If 'true', allow the user to switch the user interface to SmartCard mode.

Default: true

boolean—
allowPassword

macOS 15.0+ · not on iOS, visionOS

If 'true', allow the user to switch the user interface to Password mode.

Default: true

boolean—
startInSmartCardMode

macOS 15.0+ · not on iOS, visionOS

If 'true', the user interface will start in SmartCard mode.

Default: false

boolean—
AuthenticationMethoddeprecated

macOS 13.0+ · deprecated 14.0 · not on iOS, visionOS

The Platform SSO authentication method the extension uses. Requires that the SSO Extension also supports the method. Don't use this. Use the 'AuthenticationMethod' key in the 'PlatformSSO' dictionary instead.

Range: Password (Password), User Secure Enclave Key (UserSecureEnclaveKey), SmartCard (SmartCard), OpenID (OpenID)

stringAuthentication Method
PlatformSSO

macOS 14.0+ · not on iOS, visionOS

The dictionary to configure Platform SSO. Requires setting 'Type' to 'Redirect'.

dict—
AuthenticationMethod

The Platform SSO authentication method to use with the extension. Requires that the SSO Extension also support the method. 'OpenID' is available in macOS 27 and later.

Range: Password, UserSecureEnclaveKey, SmartCard, OpenID

string—
UseSharedDeviceKeys

macOS

If 'true', the system uses the same signing and encryption keys for all users. Only supported on the device channel.

Default: false

boolean—
AccountDisplayName

The display name for the account in notifications and authentication requests.

string—
LoginFrequency

The duration, in seconds, until the system requires a full login instead of a refresh. The default value is 64,800 (18 hours). The minimum value is 3600 (1 hour).

Default: 64800

Range: 3600 – —

integer—
EnableCreateUserAtLogin

Enables creating users at the Login Window with an 'AuthenticationMethod' of either 'Password' or 'SmartCard'. Requires that 'UseSharedDeviceKeys' is 'true'.

Default: false

boolean—
EnableAuthorization

Enables using identity provider accounts at authorization prompts. Requires that 'UseSharedDeviceKeys' is 'true'. The system assigns groups using 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.

Default: false

boolean—
TokenToUserMapping

The attribute mapping to use when creating users, or for authorization.

dict—
AccountName

The claim name to use for the user's account name.

string—
FullName

The claim name to use for the user's full name.

string—
NewUserAuthorizationMode

The permission to apply to newly created accounts at login. Allowed values: 'Standard': The account is a standard user. 'Admin': The system adds the account to the local administrators group. 'Groups': The system assigns groups to the account using 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'. 'Temporary': The system uses a temporary session configuration for newly created accounts at login.

Range: Standard, Admin, Groups, Temporary

string—
UserAuthorizationMode

The permission to apply to an account each time the user authenticates. Allowed values: 'Standard': The account is a standard user. 'Admin': The system adds the account to the local administrators group. 'Groups': The system assigns group to the account using 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.

Range: Standard, Admin, Groups

string—
AdministratorGroups

The list of groups to use for administrator access. The system requests membership during authentication.

array—
Group

The group name.

string—
AdditionalGroups

The list of created groups that don't have administrator access.

array—
Group

The group name.

string—
AuthorizationGroups

The pairing of Authorization Rights to group names. When using this, the system updates the Authorization Right to use the group.

dict—
{{key}}required
string—
{{value}}required

The key is an access right value, the value is the group to be associated with that access right.

string—
ANY

The key is an access right value, the value is the group to be associated with that access right.

string—
FileVaultPolicy

macOS 15.0+

The policy to apply when using Platform SSO at FileVault unlock on a Mac with Apple silicon. 'AttemptAuthentication': The device attempts Platform SSO authentication before proceeding. If offline, unlock continues if the local account password matches. If online and the credential is incorrect, then the device requires a successful Platform SSO authentication is required, even if taken offline. Only use when 'AuthenticationMethod' is 'Password'. 'RequireAuthentication': The device requires Platform SSO authentication before proceeding. If the device is offline and 'AllowOfflineGracePeriod' is enabled, then the device uses the offline 'OfflineGracePeriod' to determine if the user can proceed or not. If online and the credential is incorrect, then the device requires a valid Platform SSO authentication to proceed, regardless of the 'OfflineGracePeriod'. If the account isn't registered for Platform SSO and 'AllowAuthenticationGracePeriod' is enabled, then the device uses 'AuthenticationGracePeriod' to determine if the user can proceed or not. Only use when 'AuthenticationMethod' is 'Password'. 'AllowOfflineGracePeriod': The device allows the use of the 'OfflineGracePeriod'. If 'AllowOfflineGracePeriod' isn't set, then the device denies offline access. Only use when 'AuthenticationMethod' is 'Password' and 'RequireAuthentication' is enabled, or 'AuthenticationMethod' is 'OpenID'. 'AllowAuthenticationGracePeriod': The device allows the use of the 'AuthenticationGracePeriod' for other local accounts when 'RequireAuthentication' is enabled. The 'AuthenticationGracePeriod' starts when any of the policies are updated. If 'AllowAuthenticationGracePeriod' isn't set, then the device denies unregistered account access. Only use when 'AuthenticationMethod' is 'Password'. 'RequireTouchID': The device requires the use of Touch ID (and not Apple Watch) for FileVault unlock. Only use when 'AuthenticationMethod' is 'Password' or 'UserSecureEnclaveKey'. 'RequireTouchIDOrWatch': The device requires the use of Touch ID or Apple Watch for FileVault unlock. Only use when 'AuthenticationMethod' is 'Password' or 'UserSecureEnclaveKey'. 'AllowOpenIDForTouchIDFallback': The device allows web login as a fallback if Touch ID fails or isn't available. Only use when 'AuthenticationMethod' is 'Password' or 'UserSecureEnclaveKey'.

array—
policyrequired

The policy to apply.

Range: AttemptAuthentication, RequireAuthentication, AllowOfflineGracePeriod, AllowAuthenticationGracePeriod, RequireTouchID, RequireTouchIDOrWatch, AllowOpenIDForTouchIDFallback

string—
LoginPolicy

macOS 15.0+

The policy to apply when using Platform SSO at the Login Window. 'AttemptAuthentication': The device attempts Platform SSO authentication before proceeding. If offline, login continues if the local account password matches. If online and the credential is incorrect, then the device requires a successful Platform SSO authentication to proceed, even if taken offline. Only use when 'AuthenticationMethod' is 'Password'. 'RequireAuthentication': The device requires Platform SSO authentication before proceeding. If the device is offline and 'AllowOfflineGracePeriod' is enabled, then the device uses the offline 'OfflineGracePeriod' to determine if the user can proceed or not. If online and the credential is incorrect, then the device requires a valid Platform SSO authentication to proceed, regardless of the 'OfflineGracePeriod'. If the account isn't registered for Platform SSO and 'AllowAuthenticationGracePeriod' is enabled, then the device uses the 'AuthenticationGracePeriod' to determine if the user can proceed or not. Only use when 'AuthenticationMethod' is 'Password'. 'AllowOfflineGracePeriod': The device allows the use of the 'OfflineGracePeriod'. If 'AllowOfflineGracePeriod' isn't set, then the device denies offline access. Only use when 'AuthenticationMethod' is 'Password' and 'RequireAuthentication' is enabled, or 'AuthenticationMethod' is 'OpenID'. 'AllowAuthenticationGracePeriod': The device allows the use of the 'AuthenticationGracePeriod' for other local accounts when 'RequireAuthentication' is enabled. The 'AuthenticationGracePeriod' starts when any of the policies have been updated. If 'AllowAuthenticationGracePeriod' isn't set, then the device denies unregistered account access. Only use when 'AuthenticationMethod' is 'Password'. 'RequireTouchID': The device requires the use of Touch ID (and not Apple Watch) for login. Only use when 'AuthenticationMethod' is 'Password' or 'UserSecureEnclaveKey'. 'RequireTouchIDOrWatch': The device requires the use of Touch ID or Apple Watch for login. Only use when 'AuthenticationMethod' is 'Password' or 'UserSecureEnclaveKey'. 'AllowOpenIDForTouchIDFallback': The device allows web login as fallback if Touch ID fails or isn't available. Only use when 'AuthenticationMethod' is 'Password' or 'UserSecureEnclaveKey'.

array—
policyrequired

The policy to apply.

Range: AttemptAuthentication, RequireAuthentication, AllowOfflineGracePeriod, AllowAuthenticationGracePeriod, RequireTouchID, RequireTouchIDOrWatch, AllowOpenIDForTouchIDFallback

string—
UnlockPolicy

macOS 15.0+

The policy to apply when using Platform SSO at screensaver unlock. 'AttemptAuthentication': The device attempts Platform SSO authentication before proceeding. If offline, unlock will continue if the local account password matches. If online and the credential is incorrect, then the device requires a successful Platform SSO authentication to proceed, even if taken offline. Only use when 'AuthenticationMethod' is 'Password'. 'RequireAuthentication': The device requires Platform SSO authentication before proceeding. If the device is offline and 'AllowOfflineGracePeriod' is enabled, then the offline 'OfflineGracePeriod' is used to determine if the user can proceed or not. If online and the credential is incorrect, then the device requires a valid Platform SSO authentication to proceed regardless of the 'OfflineGracePeriod'. If the account isn't registered for Platform SSO and 'AllowAuthenticationGracePeriod' is enabled, then the device uses 'AuthenticationGracePeriod' to determine if the user can proceed or not. Only use when 'AuthenticationMethod' is 'Password'. 'AllowOfflineGracePeriod': The device allows the use of the 'OfflineGracePeriod'. If 'AllowOfflineGracePeriod' isn't set, then the device denies offline access. Only use when 'AuthenticationMethod' is 'Password' and 'RequireAuthentication' is enabled, or 'AuthenticationMethod' is 'OpenID'. 'AllowAuthenticationGracePeriod': The device allows the use of the 'AuthenticationGracePeriod' for other local accounts when 'RequireAuthentication' is enabled. The 'AuthenticationGracePeriod' starts when any of the policies have been updated. If 'AllowAuthenticationGracePeriod' isn't set, then the device denies the unregistered account access. Only use when 'AuthenticationMethod' is 'Password'. 'AllowTouchIDOrWatchForUnlock': The device allows Touch ID or Apple Watch to unlock the screensaver instead of Platform SSO authentication when 'RequireAuthentication' is enabled. Only use when 'AuthenticationMethod' is 'Password'. 'RequireTouchID': The device requires the use of Touch ID (and not Apple Watch) for unlock. Only use when 'AuthenticationMethod' is 'Password' or 'UserSecureEnclaveKey'. 'RequireTouchIDOrWatch': The device requires the use of Touch ID or Apple Watch for unlock. Only use when 'AuthenticationMethod' is 'Password' or 'UserSecureEnclaveKey'. 'AllowOpenIDForTouchIDFallback': The device allows web login as fallback if Touch ID fails or isn't available. Only use when 'AuthenticationMethod' is 'Password' or 'UserSecureEnclaveKey'.

array—
policyrequired

The policy to apply.

Range: AttemptAuthentication, RequireAuthentication, AllowOfflineGracePeriod, AllowAuthenticationGracePeriod, AllowTouchIDOrWatchForUnlock, RequireTouchID, RequireTouchIDOrWatch, AllowOpenIDForTouchIDFallback

string—
OfflineGracePeriod

macOS 15.0+

The amount of time (in seconds) after the last successful Platform SSO login for using a local account password offline. Required when setting 'AllowOfflineGracePeriod'.

integer—
AuthenticationGracePeriod

macOS 15.0+

The amount of time (in seconds) after receiving or updating a 'FileVaultPolicy', 'LoginPolicy', or 'UnlockPolicy' that the system can use unregistered local accounts. Required when 'AllowAuthenticationGracePeriod' is set.

integer—
NonPlatformSSOAccounts

macOS 15.0+

The list of local accounts that aren't subject to the 'FileVaultPolicy', 'LoginPolicy', or 'UnlockPolicy'. The accounts don't receive a prompt to register for Platform SSO.

array—
usernamerequired

A local account username.

string—
AllowDeviceIdentifiersInAttestation

macOS 15.4+

If 'true', the system includes the device UDID and serial number in Platform SSO attestations.

Default: false

boolean—
EnableCreateFirstUserDuringSetup

macOS 26.0+

If 'true', the device uses Platform SSO to create the first user account on the Mac during 'Setup Assistant'.

Default: true

boolean—
NewUserAuthenticationMethods

macOS 26.0+

The set of authentication methods to use for newly created accounts at login or during 'Setup Assistant'. The system uses 'Password' and 'SmartCard' if this key isn't present.

array—
NewUserAuthenticationMethod

An authentication method to use for newly created accounts at login or during 'Setup Assistant'. Allowed values: 'Password': The account uses a password for authentication. 'SmartCard': The account uses a smart card for authentication. 'AccessKey': The account uses an access key for authentication. 'OpenID': The account uses OpenID for authentication. Available in macOS 27 and later.

Range: Password, SmartCard, AccessKey, OpenID

string—
AccessKeyReaderGroupIdentifier

macOS 26.0+

The reader group identifier for use with the 'AccessKey'. The value needs to match the configured access key. Required if 'NewUserAuthenticationMethods' contains 'AccessKey'.

data—
AccessKeyTerminalIdentityUUID

macOS 26.0+

The 'PayloadUUID' of an identity payload to use as the 'Terminal' identity of the access key. The identity needs to be trusted by the access key. Required if 'NewUserAuthenticationMethods' includes 'AccessKey'. Allowed identity payload types: 'com.apple.security.pkcs12' 'com.apple.security.acme' 'com.apple.security.scep'

string—
AccessKeyReaderIssuerCertificateUUID

macOS 26.2+

The 'PayloadUUID' of a certificate payload for the issuer certificate of the 'Terminal' identity of the access key. Other specifications refer to the key as the "Reader CA Public Key". The key must be an elliptic curve key. Required if 'NewUserAuthenticationMethods' includes 'AccessKey'. The issuer of the Terminal identity of the access key needs to match this certificate, otherwise the device fails the authentication.

stringAccess Key Reader Issuer Certificate UUID
AllowAccessKeyExpressMode

macOS 26.0+

If 'true', the system uses the access key in express mode, and doesn't require authentication before use.

Default: false

boolean—
SynchronizeProfilePicture

macOS 26.0+

If 'true', the system requests the user's profile picture from the SSO extension.

Default: false

boolean—
TemporarySessionQuickLogin

macOS 26.0+

If 'true', the system uses a quicker Authenticated Guest Mode login to Mac behavior. The system erases user data from only select locations in the user home directory after each session completes. Once every eight hours the system erases the full user home directory after a session completes. Turn this on for shared environments that have a high frequency of short sessions.

Default: false

boolean—
EnableRegistrationDuringSetup

macOS 26.0+

If 'true', the system enables the PlatformSSO registration process during Setup Assistant on devices running macOS 26 and later. Set this key to 'true' when configuring PlatformSSO before enrollment using the 'com.apple.psso.required' error response.

Default: false

boolean—
WebLoginURLAllowList

macOS 27.0+

The set of allowed hosts that the system can load in the PSSO web view. Required if 'AuthenticationMethod' is 'OpenID', or 'NewUserAuthenticationMethods' contains 'OpenID'.

array—
Hosts

A host or host prefix.

string—
AllowWebLoginPasswordSync

macOS 27.0+

If 'true', the system detects the password during web login and synchronizes it to the local account password for the user.

Default: false

boolean—
RegistrationToken

macOS 13.0+ · not on iOS, visionOS

The token this device uses for registration with Platform SSO. Use it for silent registration with the Identity Provider. Requires that 'AuthenticationMethod' in 'PlatformSSO' isn't empty.

stringRegistration Token