PayloadKit

System Policy - Kernel Extensions

com.apple.syspolicy.kernel-extension-policy

The payload that configures the kernel extension policies.

macOS 10.13.2+
Apple schemaexclusive

Not available with User Enrollment · macOS: device channel only

Configuration Keys (4)

KeyTypeTitle
AllowUserOverrides

If 'true', users can approve additional kernel extensions that configuration profiles don't explicitly allow.

Default: false

booleanAllow users to approve kernel extensions
AllowNonAdminUserApprovals

macOS 11.0+

If 'true', nonadministrative users can approve additional kernel extensions in the Security & Privacy preferences.

Default: false

booleanAllow non-admin users to approve kernel extensions
AllowedTeamIdentifiers

The array of team identifiers that define which validly signed kernel extensions can load.

arrayAllowed Team Identifiers
AllowedTeamIdentifiersItem
stringTeam Identifier
AllowedKernelExtensions

The dictionary that represents a set of kernel extensions that the system always allows to load on the computer. The dictionary maps team identifiers (keys) to arrays of bundle identifiers.

dictAllowed Kernel Extensions
{{value}}

The kernel extension data.

arrayBundle Identifier
AllowedKernelExtensionsItems

Kernel extension data.

stringBundle Identifier
{{key}}
stringTeam Identifier
ANY

The kernel extension data.

array—
AllowedKernelExtensionsItemsrequired

Kernel extension data.

string—