PayloadKit

File Provider

com.apple.fileproviderd

The payload that configures file provider settings.

macOS 11.0+
Apple schemaexclusive

Not available with User Enrollment · Only one instance per profile

Configuration Keys (8)

KeyTypeTitle
AllowManagedFileProvidersToRequestAttribution

If 'true', enables file providers access to the path of the requesting process.

Default: false

booleanAllow Managed File Providers to Request Attribution
ManagementAllowsKnownFolderSyncing

macOS 15.2+

If 'false', the device prevents the File Provider extension from using desktop and documents synchronization in any app. This doesn't impact the ability for apps to utilize the File Provider extension for file and folder syncing with remote storage.

Default: true

boolean—
ManagementKnownFolderSyncingAllowList

macOS 15.2+

An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension desktop and documents synchronization. If present, and 'ManagementAllowsKnownFolderSyncing' is set to 'true', the device allows only the apps in this list to use desktop and documents synchronization. This key is ignored if 'ManagementAllowsKnownFolderSyncing' is set to 'false'. This setting doesn't impact the ability for apps to use File Provider extension volume access. The format of the app identifiers is "Bundle-ID (Team-ID)", for example 'com.example.app (ABCD1234)'.

array—
AllowListItemrequired

A composed app identifier. The format is "Bundle.Identifier (TeamIdentifier)".

string—
ManagementAllowsRemoteSyncing

macOS 26.4+

If 'false', the device prevents the File Provider extension from using synchronization in any app. Also, none of the other options will be evaluated. Synchronization will be totally disabled for any application.

Default: true

boolean—
ManagementRemoteSyncingAllowList

macOS 26.4+

An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension synchronization. If present, and 'ManagementAllowsRemoteSyncing' is set to 'true', the device allows only the apps in this list to use synchronization. This key is ignored if 'ManagementAllowsRemoteSyncing' is set to 'false'. If present, the other options will only be evaluated for the apps in this list. The format of the app identifiers is "Bundle-ID (Team-ID)", for example 'com.example.app (ABCD1234)'.

array—
AllowListItemrequired

A composed app identifier. The format is "Bundle.Identifier (TeamIdentifier)".

string—
ManagementAllowsExternalVolumeSyncing

macOS 26.4+

If 'false', the device only allows File Provider extension volume synchronization for the system "home" volume and any data separated volume, and prevents synchronization with any other volumes. If `true``, the device allows File Provider extension volume synchronization for the system "home" volume, any data separated volume, and any encrypted APFS volumes (on either internal or external media).

Default: true

boolean—
ManagementExternalVolumeSyncingAllowList

macOS 26.4+

An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension volume synchronization. If present, and 'ManagementAllowsExternalVolumeSyncing' is set to 'true', the device allows only the apps in this list to use volume synchronization. This key is ignored if 'ManagementAllowsExternalVolumeSyncing' is set to 'false'. The format of the app identifiers is "Bundle-ID (Team-ID)", for example 'com.example.app (ABCD1234)'.

array—
AllowListItemrequired

A composed app identifier. The format is "Bundle.Identifier (TeamIdentifier)".

string—
ManagementDomainAutoEnablementList

macOS 26.4+

An array of strings representing the composed identifiers of apps. The device automatically enables the File Provider domains for the corresponding apps. The device doesn't enable existing domains if enrollment happens after they are created. The device doesn't prevent the user from disabling these File Provider domains. Users need to manually enable File Provider domains in the Finder if their corresponding apps aren't listed here. The format of the app identifiers is "Bundle-ID (Team-ID)", for example 'com.example.app (ABCD1234)'.

array—
AllowListItemrequired

A composed app identifier. The format is "Bundle.Identifier (TeamIdentifier)".

string—