PayloadKit

Allowed Media and Menu Bar Extras

com.apple.systemuiserver

The payload that configures media management.

macOS 10.7+ · deprecated 11.0
Apple schemacombined

Not available with User Enrollment · Only one instance per profile

Configuration Keys (5)

KeyTypeTitle
PFC_SegmentedControl_0required
string—
mount-controls

The media type dictionary that controls volume mounting.

dictVolume Mount Controls
harddisk-external

A string or an array of media action strings. The hard disk-external category includes internally installed SD cards and USB flash drives. This key is the default for media types that don't fall into other categories.

arrayExternal Disk
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
harddisk-internal

A media action string or an array of media action strings.

arrayInternal Disk
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
networkdisk

A media action string or an array of media action strings.

arrayNetwork Disk
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
disk-image

A media action string or an array of media action strings.

arrayDisk Image
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
bd

A media action string or an array of media action strings.

arrayBlu-ray
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
cd

A media action string or an array of media action strings.

arrayCD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
dvd

A media action string or an array of media action strings.

arrayDVD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
dvdram

A media action string or an array of media action strings.

arrayDVD-RAM
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
blankbd

A media action string or an array of media action strings.

arrayRecordable Blu-ray
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
blankcd

A media action string or an array of media action strings.

arrayRecordable CD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
blankdvd

A media action string or an array of media action strings.

arrayRecordable DVD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
all-media

Unused; set to an empty string.

string—
unmount-controls

The media type dictionary that controls volume unmounting.

dictVolume Unmount Controls
harddisk-external

A string or an array of media action strings. The hard disk-external category includes internally installed SD cards and USB flash drives. This key is the default for media types that don't fall into other categories.

arrayExternal Disk
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
harddisk-internal

A media action string or an array of media action strings.

arrayInternal Disk
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
networkdisk

A media action string or an array of media action strings.

arrayNetwork Disk
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
disk-image

A media action string or an array of media action strings.

arrayDisk Image
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
bd

A media action string or an array of media action strings.

arrayBlu-ray
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
cd

A media action string or an array of media action strings.

arrayCD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
dvd

A media action string or an array of media action strings.

arrayDVD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
dvdram

A media action string or an array of media action strings.

arrayDVD-RAM
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
blankbd

A media action string or an array of media action strings.

arrayRecordable Blu-ray
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
blankcd

A media action string or an array of media action strings.

arrayRecordable CD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
blankdvd

A media action string or an array of media action strings.

arrayRecordable DVD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
all-media

Unused; set to an empty string.

string—
logout-eject

The media type dictionary that defines volumes to eject when the user logs out.

dictEject on logout
harddisk-external

A string or an array of media action strings. The hard disk-external category includes internally installed SD cards and USB flash drives. This key is the default for media types that don't fall into other categories.

arrayExternal Disk
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
harddisk-internal

A media action string or an array of media action strings.

arrayInternal Disk
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
networkdisk

A media action string or an array of media action strings.

arrayNetwork Disk
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
disk-image

A media action string or an array of media action strings.

arrayDisk Image
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
bd

A media action string or an array of media action strings.

arrayBlu-ray
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
cd

A media action string or an array of media action strings.

arrayCD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
dvd

A media action string or an array of media action strings.

arrayDVD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
dvdram

A media action string or an array of media action strings.

arrayDVD-RAM
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
blankbd

A media action string or an array of media action strings.

arrayRecordable Blu-ray
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
blankcd

A media action string or an array of media action strings.

arrayRecordable CD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
blankdvd

A media action string or an array of media action strings.

arrayRecordable DVD
ActionStringItem

One of the following values: authenticate - User will be authenticated before media is mounted read-only - The media will be mounted read-only. Not valid for unmount-controls. deny - The media will not be mounted. eject - The media will not be mounted and it will be ejected if possible. Note that some volumes are not defined as ejectable, so using the deny key may be the best solution. Not valid for unmount-controls.

Range: Authenticate (authenticate), Read-Only (read-only), Deny (deny), Eject (eject), Alert (alert)

stringAction
all-media

Unused; set to an empty string.

string—
menuExtras

List of menu extras to combine with the user's menu bar

arrayMenu Extras
menuExtra

Range: /System/Library/CoreServices/Menu Extras/AirPort.menu, /System/Library/CoreServices/Menu Extras/Battery.menu, /System/Library/CoreServices/Menu Extras/Bluetooth.menu, /System/Library/CoreServices/Menu Extras/Clock.menu, /System/Library/CoreServices/Menu Extras/Displays.menu, /System/Library/CoreServices/Menu Extras/DwellControl.menu, /System/Library/CoreServices/Menu Extras/Eject.menu, /System/Library/CoreServices/Menu Extras/ExpressCard.menu, /System/Library/CoreServices/Menu Extras/Ink.menu, /System/Library/CoreServices/Menu Extras/IrDA.menu, /System/Library/CoreServices/Menu Extras/PPP.menu, /System/Library/CoreServices/Menu Extras/PPPoE.menu, /System/Library/CoreServices/Menu Extras/SafeEjectGPUExtra.menu, /System/Library/CoreServices/Menu Extras/Script, /System/Library/CoreServices/Menu Extras/Menu.menu, /System/Library/CoreServices/Menu Extras/TextInput.menu, /System/Library/CoreServices/Menu Extras/TimeMachine.menu, /System/Library/CoreServices/Menu Extras/UniversalAccess.menu, /System/Library/CoreServices/Menu Extras/User.menu, /System/Library/CoreServices/Menu Extras/VPN.menu, /System/Library/CoreServices/Menu Extras/Volume.menu, /System/Library/CoreServices/Menu Extras/WWAN.menu, /System/Library/CoreServices/Menu Extras/iChat.menu

stringMenu Extra Path