PayloadKit

System Extensions

com.apple.system-extension-policy

The payload that configures system extensions.

macOS 10.15+
Apple schemacombined

Not available with User Enrollment · macOS: device channel only

Configuration Keys (7)

KeyTypeTitle
AllowUserOverrides

If 'false', restricts users from approving additional system extensions that configuration profiles don't explicitly allow.

Default: true

booleanAllow users to approve system extensions
AllowedTeamIdentifiers

An array of team identifiers that defines valid, signed system extensions that are allowable to load. Approved system extensions are those signed with any of the specified team identifiers. To avoid requiring an administrator to authorize the operation, you can activate system extensions that this key specifies using 'OSSystemExtensionActivationRequest API'. It's an error for the same team identifier to appear in both this array and as a key in the 'AllowedSystemExtensions' dictionary.

arrayAllowed Team Identifiers
AllowedTeamIdentifiersItem
stringTeam Identifier
AllowedSystemExtensions

A dictionary of approved system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension to install. To avoid requiring an administrator to authorize the operation, you can activate system extensions that this key specifies using 'OSSystemExtensionActivationRequest API'. It's an error for the same team identifier to appear in both the 'AllowedTeamIdentifiers' array and as a key in this dictionary.

dictAllowed System Extensions
{{key}}
stringTeam Identifier
{{value}}

The mapping of team identifiers to arrays of bundle identifiers, where the bundle identifier defines the system extension to install.

arrayBundle Identifier
AllowedSystemExtensionsItemsrequired

Allowed system extension bundle ID

stringBundle Identifier
ANY

The mapping of team identifiers to arrays of bundle identifiers, where the bundle identifier defines the system extension to install.

array—
AllowedSystemExtensionsItemsrequired

Allowed system extension bundle ID

string—
AllowedSystemExtensionTypes

A dictionary that maps a team identifier to an array of strings, where each string is a type of system extension that you can install for that team identifier. The allowed extension types are 'DriverExtension', 'NetworkExtension', and 'EndpointSecurityExtension'. If there's no entry for a specified team identifier in the dictionary, the system allows all extension types.

dictAllowed System Extension Types
{{key}}
stringTeam Identifier
{{value}}

The mapping of team identifier to an array of strings, where each string is a type of system extension that you can install for that team identifier.

arraySystem Extension Types
AllowedSystemExtensionTypesItemsrequired

Permitted System Extension Type

Range: Driver (DriverExtension), Network (NetworkExtension), Endpoint Security (EndpointSecurityExtension)

stringSystem Extension Type
ANY

The mapping of team identifier to an array of strings, where each string is a type of system extension that you can install for that team identifier.

array—
AllowedSystemExtensionTypesItemsrequired

Permitted System Extension Type

string—
RemovableSystemExtensions

macOS 12.0+

A dictionary of system extensions that are allowed to remove themselves from the machine. The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension. An application using the 'OSSystemExtensionDeactivationRequest' API can deactivate the specified system extensions without requiring an administrator to authorize the operation.

dictRemovable System Extensions
{{key}}
stringTeam Identifier
{{value}}

The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension.

arrayBundle Identifier
RemovableSystemExtensionsItemsrequired

Removed system extension bundle ID

stringBundle Identifier
ANY

The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension.

array—
RemovableSystemExtensionsItemsrequired

Removed system extension bundle ID

string—
NonRemovableSystemExtensions

macOS 15.0+

A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which can't be disabled or uninstalled when SIP is enabled. It's an error for the same mapping to appear in the dictionary values corresponding to 'RemovableSystemExtensions' and 'NonRemovableSystemExtensions' keys.

dict—
{{key}}
string—
{{value}}

System extension bundle identifiers

array—
NonRemovableSystemExtensionsItemsrequired

Non Removable system extension bundle ID

string—
ANY

System extension bundle identifiers

array—
NonRemovableSystemExtensionsItemsrequired

Non Removable system extension bundle ID

string—
NonRemovableFromUISystemExtensions

macOS 15.0+

A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which can't be disabled or uninstalled from System Settings or Finder. The set of system extensions between 'RemovableSystemExtensions' and 'NonRemovableFromUISystemExtensions' can't overlap.

dict—
{{key}}
string—
{{value}}

System extension bundle identifiers

array—
NonRemovableFromUISystemExtensionsItemsrequired

Non Removable from UI system extension bundle ID

string—
ANY

System extension bundle identifiers

array—
NonRemovableFromUISystemExtensionsItemsrequired

Non Removable from UI system extension bundle ID

string—