Wi-Fi
com.apple.wifi.managed
The payload that configures Wi-Fi settings.
Configuration Keys (30)
| Key | Type | Title |
|---|---|---|
PFC_InterfaceSelectorrequiredType of network interface on the device. Range: Wi-Fi (BuiltInWireless), Legacy Hotspot (Hotspot), Passpoint (Hotspot2) | string | Network Interface |
IsHotspotiOS 7.0+ · macOS 10.9+ If 'true', the device treats the network as a hotspot. Depends on: PFC_InterfaceSelector Default: false | boolean | Is hotspot |
SSID_STRiOS 7.0+ The SSID of the Wi-Fi network to use. In iOS 7.0 and later, the SSID is optional if a value exists for 'DomainName' value. Depends on: PFC_InterfaceSelector; DomainName not set | string | Service Set Identifier (SSID) |
HIDDEN_NETWORKIf 'true', defines this network as hidden. Default: false | boolean | Hidden Network |
AutoJoiniOS 5.0+ If 'true', the device joins the network automatically. If 'false', the user must tap the network name to join it. Default: true | boolean | Auto join |
CaptiveBypassiOS 10.0+ · not on macOS If 'true', the system bypasses Captive Network detection when the device connects to the network. Default: false | boolean | Disable captive network detection |
DisableAssociationMACRandomizationiOS 14.0+ · macOS 15.0+ · watchOS 7.0+ · visionOS · not on tvOS If 'true,' disables MAC address randomization for a Wi-Fi network while associated with that network. This feature also shows a privacy warning in Settings indicating that the network has reduced privacy protections. If 'false', then the system enables MAC address randomization on iOS, watchOS, and visionOS. This value is only locked when MDM installs the profile. If the profile is manually installed, the system sets the value but the user can change it. Default: false | boolean | Disable MAC address randomization during association |
EnableIPv6If 'true', enables IPv6 on this interface. Default: true | boolean | Enable IPv6 |
ProxyTypeiOS · visionOS The proxy type, if any, to use. If you choose the manual proxy type, you need the proxy server address, including its port and optionally a user name and password into the proxy server. If you choose the auto proxy type, you can enter a proxy autoconfiguration (PAC) URL. Default: "None" Range: None, Manual, Auto | string | Proxy type |
ProxyServeriOS · macOS · visionOS The proxy server's network address. Depends on: ProxyType ∈ [Manual]; ProxyType | string | Proxy server |
ProxyServerPortiOS · macOS · visionOS The proxy server's port number. Depends on: ProxyType ∈ [Manual]; ProxyType Range: 0 – 65535 | integer | Proxy server port |
ProxyUsernameiOS · macOS · visionOS The user name used to authenticate to the proxy server. | string | Proxy username |
ProxyPasswordiOS · visionOS The password used to authenticate to the proxy server. | string | Proxy password |
ProxyPACURLiOS · macOS · visionOS The URL of the PAC file that defines the proxy configuration. | string | Proxy PAC URL |
ProxyPACFallbackAllowediOS · macOS · visionOS If 'true', allows connecting directly to the destination if the PAC file is unreachable. Default: false | boolean | Proxy PAC fallback allowed |
EncryptionTypeThe encryption type for the network. If set to anything except 'None', the payload may contain the following three keys: 'Password', 'PayloadCertificateUUID', or 'EAPClientConfiguration'. As of iOS 16, tvOS 16, watchOS 9, and macOS 13: 'WPA' allows joining WPA or WPA2 networks 'WPA2' allows joining WPA2 or WPA3 networks 'WPA3' allows joining WPA3 networks only 'Any' allows joining WPA, WPA2, WPA3, and WEP networks Prior to iOS 16, tvOS 16, and watchOS 9, specifying 'WPA', 'WPA2', and 'WPA3' were equivalent and would allow joining any WPA network. Prior to macOS 13, the encryption type, if specified explicitly, needed to match the encryption type of the network exactly. Default: "Any" Range: WEP (WEP), WPA and WPA2 (WPA), WPA2 and WPA3 (WPA2), WPA3 (WPA3), Any (Any), None (None) | string | Encryption type |
PasswordThe password for the access point. | string | Password |
DisplayedOperatorNameiOS 7.0+ · macOS 10.9+ The operator name to display when connected to this network. Used only with Wi-Fi Hotspot 2.0 access points. Depends on: PFC_InterfaceSelector ∈ [Hotspot2] | string | Displayed operator name |
DomainNameiOS 7.0+ · macOS 10.9+ The primary domain of the tunnel. Depends on: PFC_InterfaceSelector ∈ [Hotspot2] | string | Domain name |
ServiceProviderRoamingEnablediOS 7.0+ · macOS 10.9+ If 'true', allows connection to roaming service providers. Default: false | boolean | Roaming enable |
RoamingConsortiumOIsiOS 7.0+ · macOS 10.9+ An array of Roaming Consortium Organization Identifiers used for Wi-Fi Hotspot 2.0 negotiation. | array | Roaming OIs |
RoamingConsortiumOI | string | — |
NAIRealmNamesiOS 7.0+ · macOS 10.9+ An array of Network Access Identifier Realm names used for Wi-Fi Hotspot 2.0 negotiation. | array | Realm names |
NAIRealmName | string | — |
MCCAndMNCsiOS 7.0+ · not on macOS An array of Mobile Country Code/Mobile Network Code (MCC/MNC) pairs used for Wi-Fi Hotspot 2.0 negotiation. Each string must contain exactly six digits. | array | MCC/MNCs |
MCCAndMNC | string | — |
HESSIDiOS 7.0+ The HESSID used for Wi-Fi Hotspot 2.0 negotiation. | string | Homogenous Extended Service Set Identifier (HESSID) |
SetupModesmacOS 10.7+ · not on iOS, tvOS, watchOS, visionOS An array of strings that contain the type of connection mode to attach. | array | EAP Setup Modes |
SetupModesItemrequiredA type of connection mode. Range: System (System), Login Window (Loginwindow) | string | Setup Mode |
EAPClientConfigurationThe enterprise network configuration. | dict | EAP client configuration |
AcceptEAPTypesrequiredThe EAP types that the system accepts. Allowed values: '13': EAP-TLS '17': LEAP '18': EAP-SIM '21': EAP-TTLS '23': EAP-AKA '25': PEAPv0/v1 '43': EAP-FAST For EAP-TLS authentication without a network payload, install the necessary identity certificates and have your users select EAP-TLS mode in the 802.1X credentials dialog that appears when they connect to the network. For other EAP types, a network payload is necessary and must specify the correct settings for the network. | array | Accept EAP types |
EAPTypeAn integer representing an EAP type, inside of the Accept EAP Types array. Range: TLS (13), LEAP (17), EAP-SIM (18), TTLS (21), EAP-AKA (23), PEAP (25), EAP-FAST (43) | integer | EAP type |
UserNameThe user name for the account. If you don't specify a value, the system prompts the user during login. | string | Username |
UserPasswordThe user's password. If you don't specify a value, the system prompts the user during login. Depends on: EAPClientConfiguration.AcceptEAPTypes; EAPClientConfiguration.OneTimeUserPassword | string | Password |
OneTimeUserPasswordiOS 8.0+ · macOS 10.8+ · tvOS 9.0+ If 'true', the user receives a prompt for a password each time they connect to the network. Default: false | boolean | Per-connection password |
PayloadCertificateAnchorUUIDAn array of the UUID of each certificate payload in the same profile to trust for authentication. Use this key to prevent the device from asking the user whether to trust the listed certificates. The device disables dynamic trust (the certificate dialogue) if you specify this property without also enabling 'TLSAllowTrustExceptions'. | array | Certificate anchor UUID |
CertificateAnchorUUIDA UUID for a trusted certificate | string | Individual certificate anchor UUID |
TLSTrustedServerNamesThe list of accepted server certificate common names. If a server presents a certificate that isn't in this list, the system doesn't trust it. If you specify this property, the system disables dynamic trust (the certificate dialog) unless you also specify 'TLSAllowTrustExceptions' with the value 'true'. If necessary, use a single "*" character to specify a wildcard for an individual component of the name, such as 'wpa.*.example.com'. | array | TLS trusted server names |
TLSTrustedServerNameAn item in the TLS Trusted Server Names array representing a Common Name of a server certificate. | string | Individual trusted TLS server name |
TLSAllowTrustExceptionsdeprecatediOS · removed 8.0 · not on visionOS If 'true', allows a dynamic trust decision by the user. The dynamic trust is the certificate dialogue that appears when the system doesn't trust a certificate. If 'false', the authentication fails if the system doesn't already trust the certificate. As of iOS 8, Apple no longer supports this key. Default: true | boolean | Allow trust exceptions |
TTLSInnerAuthenticationThe inner authentication that the TTLS module uses. Depends on: EAPClientConfiguration.AcceptEAPTypes Default: "MSCHAPv2" Range: PAP, EAP, CHAP, MSCHAP, MSCHAPv2 | string | TTLS inner authentication |
OuterIdentityA name that hides the user's true name. The user's actual name appears only inside the encrypted tunnel. For example, you might set this to anonymous or anon, or anon@mycompany.net. It can increase security because an attacker can't see the authenticating user's name in the clear. This key is only relevant to TTLS, PEAP, and EAP-FAST. This field is required if 'TLSMinimumVersion' is '1.3'. Depends on: EAPClientConfiguration.TLSMinimumVersion ∈ [1.3] | string | Outer identity |
TLSMinimumVersioniOS 11.0+ · macOS 10.13+ · tvOS 11.0+ The minimum TLS version for EAP authentication. Default: "1.0" Range: 1.0, 1.1, 1.2, 1.3 | string | TLS Minimum Version |
TLSMaximumVersioniOS 11.0+ · macOS 10.13+ · tvOS 11.0+ The maximum TLS version for EAP authentication. Default: "1.2" Range: 1.0, 1.1, 1.2, 1.3 | string | TLS Maximum Version |
EAPFASTUsePACIf 'true', the device uses an existing PAC if it's present. Otherwise, the server must present its identity using a certificate. Default: false | boolean | Use PAC |
EAPFASTProvisionPACIf 'true', allows PAC provisioning. This value is only applicable if 'EAPFASTUsePAC' is 'true'. This value must be 'true' for EAP-FAST PAC usage to succeed because there's no other way to provision a PAC. Depends on: EAPClientConfiguration.AcceptEAPTypes; EAPClientConfiguration.EAPFASTUsePAC ∈ [true] Default: false | boolean | Provision PAC |
EAPFASTProvisionPACAnonymouslyIf 'true', provisions the device anonymously. Note that there are known machine-in-the-middle attacks for anonymous provisioning. Default: false | boolean | Provision PAC anonymously |
EAPSIMNumberOfRANDsiOS 8.0+ The minimum number of RAND values to accept from the server. For use with EAP-SIM only. Default: 3 Range: 2, 3 | integer | Allow two RANDs |
SystemModeCredentialsSourceSet this string to 'ActiveDirectory' to use the AD computer name and password credentials. If using this property, you can't use 'SystemModeUseOpenDirectoryCredentials'. Range: Active Directory (ActiveDirectory) | string | System Profile Credentials Source |
SystemModeUseOpenDirectoryCredentialsIf 'true', the system mode connection tries to use the Open Directory credentials. If using this property, you can't use 'SystemModeCredentialsSource'. Default: false | boolean | Use OpenDirectory System Profile Credentials |
TLSTrustedCertificatesAn array of trusted certificates. Each entry in the array must contain certificate data that represents an anchor certificate used for verifying the server certificate. | array | TLS trusted certificates |
TLSTrustedCertificatesItemrequiredA certificate identifier. | string | — |
TLSCertificateIsRequirediOS 7.0+ If 'true', allows for two-factor authentication for EAP-TTLS, PEAP, or EAP-FAST. If 'false', allows for zero-factor authentication for EAP-TLS. If you don't specify a value, the default is 'true' for EAP-TLS, and 'false' for other EAP types. Default: false | boolean | — |
QoSMarkingPolicyiOS 10.0+ · macOS 10.13+ A dictionary that contains the list of apps that the system allows to benefit from L2 and L3 marking. When this dictionary isn't present, the system allows all apps to use L2 and L3 marking when the Wi-Fi network supports Cisco QoS fast lane. | dict | QoS marking policy |
QoSMarkingEnabledIf 'true', disables L3 marking and only uses L2 marking for traffic that goes to the Wi-Fi network. If 'false', the system behaves as if Wi-Fi doesn't have an association with a Cisco QoS fast lane network. Default: true | boolean | Allow QoS marking |
QoSMarkingAppleAudioVideoCallsIf 'true', adds audio and video traffic of built-in audio or video services, such as FaceTime and Wi-Fi Calling, to the allow list for L2 and L3 marking for traffic that goes to the Wi-Fi network. Default: true | boolean | QoS marking for audio or video calls |
QoSMarkingAllowListAppIdentifiersiOS 14.5+ · macOS 14.0+ An array of app bundle identifiers that defines the allow list for L2 and L3 marking for traffic that goes to the Wi-Fi network. If the array isn't present, but the 'QoSMarkingPolicy' key is present — even empty — no apps can use L2 and L3 marking. | array | Allowlisted app identifiers |
appBundleID | string | Allowlisted app |
QoSMarkingWhitelistedAppIdentifiersdeprecatediOS · deprecated 14.5 · macOS · deprecated 14.0 · not on visionOS Use 'QoSMarkingAllowListAppIdentifiers' instead. | array | Whitelisted app identifiers |
appBundleID | string | Allowlisted app |
PayloadCertificateUUIDThe UUID of the certificate payload within the same profile to use for the client credential. Depends on: EAPClientConfiguration.AcceptEAPTypes | string | Certificate UUID |
TLSCertificateRequiredIf 'true', allows for two-factor authentication for EAP-TTLS, PEAP, or EAP-FAST. If 'false', allows for zero-factor authentication for EAP-TLS. Default: false | boolean | Certificate required |
AllowJoinBeforeFirstUnlockvisionOS 26.0+ · not on iOS, macOS, tvOS, watchOS If `true`, the device makes this network available for joining before the device is unlocked for the first time following a reboot, on a device configured for return to service. The device places any network credentials into Class D storage within the keychain and stores information about the network on disk in Class D. There are several restrictions on the use of this flag: - This property is only available in the return to service mode. - You can designate only one network as available before first unlock. - `EAPClientConfiguration` must not be present. - If `IsHotspot` is present, it must be set to `false`. - `QoSMarkingPolicy` must not be present. - If `ProxyType` is present, it must be set to `None`. The device fails to install the profile payload if any of these conditions aren't met. Default: false | boolean | Allow join before first unlock |