Support Companion
com.github.macadmins.SupportCompanion
Support Companion settings
Configuration Keys (80)
| Key | Type | Title |
|---|---|---|
PFC_SegmentedControl_0required | string | — |
KnowledgeBaseUrlIf configured, a menu item "Knowledge base" will show up where the user can browse the page from the UI. | string | Knowledge Base Url |
MenuShowIdentityConfigures whether to show the Identity menu item. Defaults to true Default: true | boolean | Show Identity Menu Item |
MenuShowAppsConfigures whether to show the Apps menu item. Defaults to true Default: true | boolean | Show Apps Menu Item |
MenuShowSelfServiceConfigures whether to show the Self Service menu item. Defaults to true Default: true | boolean | Show Self Service Menu Item |
MenuShowCompanyPortalConfigures whether to show the Company Portal menu item. Defaults to true Default: true | boolean | Show Company Portal Menu Item |
MenuShowKnowledgeBaseConfigures whether to show the Knowledge Base menu item. Defaults to true Default: true | boolean | Show Knowledge Base Menu Item |
BrandNameConfigures the name shown in the navigation menu. | string | Brand Name |
AccentColorConfigures the brand color shown in the app, specify in hex format. | string | Accent Color |
BrandLogoConfigures the brand logo shown in the apps side menu. Specify a Base64 string. | string | Brand Logo |
BrandLogoLightConfigures the brand logo shown in the apps side menu when light theme is used. Specify a base64 string | string | Brand Logo Light |
SupportPageUrlConfigures the URL to open when the user clicks on the Get Support button. | string | Support Page URL |
ChangePasswordUrlConfigures the URL to open when the user clicks on the Change Password button. | string | Change Password URL |
ChangePasswordModeConfigures the mode for the Change Password button, available modes are: local, SSOExtension, url. Defaults to local if not configured. Range: Local (local), SSO Extension (SSOExtension), URL (url) | string | Change Password Mode |
SupportEmailConfigures the email address shown when the user clicks on the Support Info button. | string | Support Email |
SupportPhoneConfigures the phone number shown when the user clicks on the Support Info button. | string | Support Phone |
HiddenCardsConfigures which cards to hide, available cards are: DeviceInformation, Evergreen, Battery, Actions, ApplicationInstallProgress, Storage, DeviceManagement, PendingAppUpdates, Jamf, Fleet, FleetPolicies. | array | Hidden Cards |
Range: Device Information (DeviceInformation), Evergreen (Evergreen), Battery (Battery), Actions (Actions), Application Install Progress (ApplicationInstallProgress), Storage (Storage), Device Management (DeviceManagement), Pending App Updates (PendingAppUpdates), Jamf (Jamf), Fleet (Fleet), Fleet Policies (FleetPolicies) | string | — |
HiddenActionsConfigures which actions to hide, available actions are: ChangePassword, Reboot, OpenManagementApp, GetSupport, GatherLogs, SoftwareUpdates, RestartIntuneAgent. | array | Hidden Actions |
Range: Change Password (ChangePassword), Reboot (Reboot), Open Management App (OpenManagementApp), Get Support (GetSupport), Gather Logs (GatherLogs), Software Updates (SoftwareUpdates), Restart Intune Agent (RestartIntuneAgent) | string | — |
NotificationIntervalConfigures the interval for notifications in hours for Application Updates and Software Updates notifications. Range: 1 – 24 | integer | Notification Interval |
NotificationTitleConfigures the title for notifications for notifications. Defaults to Support Companion if not configured. | string | Notification Title |
NotificationImageConfigures an image to add to notifications. Local path should be specified. | string | Notification Image |
SoftwareUpdateNotificationMessageConfigures the message for notifications for Software Updates notifications. Defaults to "Software Updates Available. Please update your device to the latest version." if not configured. Default: "Software Updates Available. Please update your device to the latest version." | string | Software Update Notification Message |
SoftwareUpdateNotificationButtonTextConfigures the button text for notifications for Software Updates notifications. Defaults to "Update Now 🚀" if not configured. Default: "Update Now 🚀" | string | Software Update Notification Button Text |
AppUpdateNotificationMessageConfigures the message for notifications for App Updates notifications. Defaults to "App Updates Available. Please update your apps to the latest version." if not configured. Default: "App Updates Available. Please update your apps to the latest version." | string | App Update Notification Message |
AppUpdateNotificationButtonTextConfigures the button text for notifications for App Updates notifications. Defaults to "Update Now 🚀" if not configured. Default: "Update Now 🚀" | string | App Update Notification Button Text |
RebootReminderDaysConfigures the number of days after which the user will be reminded to reboot. Defaults to 0 days if not configured (no reminder). Default: 0 | integer | Reboot Reminder Days |
ModeConfigures which source the app reads application information from. Detection runs only when this is empty: Fleet is chosen on Macs running Fleet's agent (orbit) when no other mode matches. Range: Munki, Intune, Jamf, Fleet, SystemProfiler | string | Mode |
RefreshSelfServiceConfigures whether to refresh the Self Service+ app data in the background when in Jamf mode. Defaults to true Default: true | boolean | Refresh Self Service |
JamfLogPollHoursConfigures how often to poll Jamf logs in hours. Only used when in Jamf mode. Defaults to 36 if not configured. Default: 36 Range: 0 – — | integer | Jamf Log Poll Hours |
LogFoldersConfigures the log folders to gather logs from. Only used when gathering logs. Defaults to "/Library/Logs/Microsoft" if not configured. | array | Log Folders |
| string | — |
ExcludedLogFoldersConfigures the log folders to exclude when gathering logs. Only used when gathering logs. | array | Excluded Log Folders |
| string | — |
ActionsConfigures custom actions to add to the tray menu. Actions defined in the user's own preferences still run, but IsPrivileged is honored only when the action comes from a configuration profile. From 3.0 the app sends only the action's name and the helper looks the command up itself, so a privileged action must be defined in a profile to run at all. | array | Actions |
| dict | — |
NameName of the action to show in the menu. | string | Name |
CommandCommand to run when to item is clicked. | string | Command |
IconSF Symbol to show in the Self Service page in the UI. | string | Icon |
IsPrivilegedSF Symbol to show in the Self Service page in the UI. | boolean | Is Privileged |
DescriptionDescription to show in the Self Service page in the UI. | string | Description |
ButtonLabelConfigures the button label for the action. | string | Button Label |
ShowLogoInTrayMenuConfigures whether to show the branding logo in the tray menu. Defaults to true. Default: true | boolean | Show Logo In Tray Menu |
TrayMenuBrandingIconConfigures the icon to show in the tray menu. Specify a Base64 string. | string | Tray Menu Branding Icon |
TrayMenuShowIconConfigures whether to show the tray menu icon. Useful if you only want to show desktop information for example. Defaults to true. Default: true | boolean | Show Tray Menu Icon |
ShowDesktopInfoConfigures the desktop info widget. Default: false | boolean | Show Desktop Info |
DesktopInfoWindowPositionConfigures the position of the desktop info. Defaults to Lower Right. Default: "LowerRight" Range: Upper Left (UpperLeft), Upper Right (UpperRight), Lower Left (LowerLeft), Lower Right (LowerRight) | string | Desktop Position |
DesktopInfoLevelConfigures the level of information to show on the desktop. Defaults to 4. Range: 1, 2, 3, 4, 5 | integer | Desktop Info Level |
DesktopInfoHideItemsUse this array to determine which information to hide. Available items are: HostName, Model, SerialNumber, Processor, IPAddress, Memory, OSBuild, OSVersion, LastRestart, FileVault, StorageName, SupportPhone, SupportEmail. It is also possible to hide entire sections: Hardware Specifications, System Information, Network Information, Storage, Support. | array | Desktop Info Hide Items |
Range: Host Name (HostName), Model (Model), Serial Number (SerialNumber), Processor (Processor), IP Address (IPAddress), Memory (Memory), OS Build (OSBuild), OS Version (OSVersion), Last Restart (LastRestart), FileVault (FileVault), Storage Name (StorageName), Support Phone (SupportPhone), Support Email (SupportEmail), Hardware Specifications (Hardware Specifications), System Information (System Information), Network Information (Network Information), Storage (Storage), Support (Support), Category (Category), Divider (Divider) | string | — |
DesktopInfoBackgroundOpacityConfigures the opacity of the desktop info. Defaults to 0%. Default: 1 Range: 10% (0.1), 20% (0.2), 30% (0.3), 40% (0.4), 50% (0.5), 60% (0.6), 70% (0.7), 80% (0.8), 90% (0.9), 100% (1) | real | Desktop Info Background Opacity |
DesktopInfoBackgroundFrostedEnables a frosted glass look on the desktop info when set to true. | boolean | Desktop Info Background Frosted |
DesktopInfoFontSizeConfigures the font size for the desktop info. Defaults to 14. Default: 14 Range: 8 – 24 | integer | Desktop Info Font Size |
CustomCardPathConfigures a path to a JSON file containing custom widgets to show on the Home view. | string | Custom Card Path |
DebugLoggingConfigures whether debug logging is enabled. Defaults to false. Default: false | boolean | Debug Logging |
EnableElevationWhen set to true allows the user to elevate to admin during a set time frame. Defaults to false. From 3.0 this is only honored when it comes from a configuration profile. Default: false | boolean | Enable Elevation |
RequireResonForElevationRequires the user to enter a reason for the elevation. Defaults to false. From 3.0 this is only honored when it comes from a configuration profile. Default: false | boolean | Require Reason For Elevation |
ReasonMinLengthSet a minimum amount of characters the user must enter as the reason. Defaults to 10. From 3.0 this is only honored when it comes from a configuration profile. Default: 10 | integer | Reason Min Length |
MaxElevationTimeThe amount of time (in minutes) the user is elevated. Defaults to 5. From 3.0 this is only honored when it comes from a configuration profile. Default: 5 | integer | Max Elevation Time |
ElevationWebhookUrlWhen configured, sends the entered elevation reason to a webhook instead of saving to disk. From 3.0 this is only honored when it comes from a configuration profile. | string | Elevation Webhook Url |
ShowElevateTrayCardConfigure wether to show the elevate button in the tray menu or not. Defaults to false. Default: false | boolean | Show Elevate Tray Card |
ElevationSeverityConfigure the elevation severity. Defaults to 6 (Informational). From 3.0 this is only honored when it comes from a configuration profile. Default: 6 | integer | Elevation Severity |
MarkdownFilePathConfigure a path to a Markdown file to show in the menu. | string | Markdown File Path |
MarkdownMenuLabelConfigure the menu label for the custom Markdown view. | string | Markdown Menu Label |
MarkdownMenuIconConfigure the icon for the custom Markdown menu item. | string | Markdown Menu Icon |
CustomCardsMenuLabelConfigure the menu label for the custom cards view. | string | Custom Cards Menu Label |
CustomCardsMenuIconConfigure the icon for the custom cards menu item. | string | Custom Cards Menu Icon |
RequirePrivilegedActionAuthenticationRequires the user to authenticate before a privileged action runs. From 3.0 this defaults to true unless an administrator sets it, and is honored only from a configuration profile. Default: true | boolean | Require Privileged Action Authentication |
EnforceAdminAllowlistWhen true, the helper reconciles the admin group at startup and every five minutes: any account holding administrator rights that is neither listed in PermanentAdmins nor inside a live elevation window is demoted. Set PermanentAdmins before enabling this, or those accounts are demoted within five minutes. Defaults to false. Must be delivered in a device-scoped configuration profile; it is ignored anywhere else. Default: false | boolean | Enforce Admin Allowlist |
PermanentAdminsAccounts that may hold administrator rights permanently when EnforceAdminAllowlist is enabled. List every such account: management accounts, break-glass accounts, permanently administrative staff, and anything granted rights by another system such as Platform SSO's AdministratorGroups. An explicitly empty array is honored and means no account is a permanent administrator; a missing list is refused with an error rather than acted on. root is always permitted. Must be delivered in a device-scoped configuration profile; it is ignored anywhere else. | array | Permanent Admins |
| string | — |
ElevationAllowedAdminsAccounts the elevation watchdog ignores, for management accounts an MDM may legitimately add while somebody is elevated. Defaults to an empty list. Must be delivered in a device-scoped configuration profile; it is ignored anywhere else. Default: [] | array | Elevation Allowed Admins |
| string | — |
EnableUserInstallsWhen true, a standard user can install a .pkg or .dmg listed in AllowedInstallers without holding administrator rights. Both the app and the helper read this: the app decides whether to stage a file at all, the helper decides whether to install it. Defaults to false. Read only from a configuration profile, device-scoped or scoped to the user being served. Default: false | boolean | Enable User Installs |
ShowInstallerServiceMenuItemWhether Finder's context menu offers "Install with Support Companion". Follows EnableUserInstalls unless set explicitly; set it to false to keep user installs but route everyone through the in-app catalog. Applied on every launch. | boolean | Show Installer Service Menu Item |
RequireAuthenticationForInstallsWhether the user authenticates before a user install proceeds. They authenticate as themselves, not as an administrator. Turning this off means an unlocked unattended Mac is enough to install an allowlisted item. Defaults to true. Default: true | boolean | Require Authentication For Installs |
UserInstallFallbackWhat to offer when an installer is not on the allowlist. "installer" opens it in Apple's Installer, "elevate" offers the normal time-limited elevation instead, "none" offers nothing. Defaults to "installer". Default: "installer" Range: Open in Installer (installer), Offer Elevation (elevate), None (none) | string | User Install Fallback |
SkipHelperInstallWhen true, the package does not install or load its own copy of the privileged helper, and removes any it finds. Set this only where the helper is deployed declaratively with com.apple.configuration.services.background-tasks, otherwise two daemons claim the same Mach service. Defaults to false. Must be delivered in a device-scoped configuration profile; it is ignored anywhere else. Default: false | boolean | Skip Helper Install |
FleetUrlOverrides the Fleet server URL otherwise discovered from fleetd or orbit. Read only from a configuration profile, because the device's token is sent to whatever server this names. | string | Fleet URL |
FleetRecommendedAppsFleet software keys pinned to the top of the self-service catalog, whether or not they are already installed. | array | Fleet Recommended Apps |
| string | — |
FleetRecommendedTitleRenames the recommended section of the Fleet catalog. | string | Fleet Recommended Title |
FleetIconsFromGitHubWhether to fetch application icons from Fleet's public catalog on GitHub. Defaults to true. Default: true | boolean | Fleet Icons From GitHub |
FleetAppOpenMessagesReplaces the built-in wording shown when an install is waiting for the user to quit the application first. | array | Fleet App Open Messages |
| string | — |
FleetButtonLabelsCustom button text in the Fleet catalog, keyed by software title and optionally nested by action. | dict | Fleet Button Labels |
TitleSoftware title, or an action name nested under one. | string | — |
FleetNotifyUpdatesNotify when Fleet reports available application updates. Defaults to true. Default: true | boolean | Fleet Notify Updates |
FleetNotifyInstallResultsNotify when a Fleet install, update or uninstall finishes. Defaults to true. Default: true | boolean | Fleet Notify Install Results |
FleetNotifyPoliciesNotify when Fleet policies are failing on the Mac. Defaults to true. Default: true | boolean | Fleet Notify Policies |
FleetNotifySignInRemind the user to sign in to Fleet Desktop SSO while signed out, at most once a day. Defaults to false, unlike the other Fleet notifications. Default: false | boolean | Fleet Notify Sign In |
CompanyPortalUrlOverrides the Company Portal URL, for sovereign cloud endpoints such as GCC High. | string | Company Portal URL |
SoftwareUpdateNotificationCommandCommand run when the software update notification's button is clicked. Defaults to opening the Software Update pane. | string | Software Update Notification Command |
AppUpdateNotificationCommandCommand run when the application update notification's button is clicked. Set at every launch to open the management application for the detected mode; a value forced by profile still wins. | string | App Update Notification Command |
FileDebugLoggingWrite debug logging to disk as well as to the unified log. Defaults to false. Default: false | boolean | File Debug Logging |
AllowedInstallersInstallers a standard user may install without administrator rights when EnableUserInstalls is true. The helper re-reads this and re-derives the installer's facts before it acts, so the confirmation sheet the user sees is presentation only. Entries that cannot decide anything are dropped and logged. Read only from a configuration profile, device-scoped or scoped to the user being served. | array | Allowed Installers |
Installer | dict | — |
NameDisplay name for this entry. Required. | string | Name |
SHA25664 hex characters. When present the entry is strict: it pins one exact build and stops matching as soon as the vendor ships an update. | string | SHA256 |
TeamIDThe signing team. Required whenever SHA256 is absent. | string | Team ID |
LeafCertificateSHA256Pins the signing certificate itself. Stricter than TeamID, and needs updating when the vendor renews. | string | Leaf Certificate SHA256 |
PackageIdentifierPackage identifiers this entry allows, for a .pkg. A distribution package needs every component listed. A single string is also accepted. | array | Package Identifier |
| string | — |
BundleIdentifierBundle identifiers this entry allows, for the application inside a .dmg. A single string is also accepted. | array | Bundle Identifier |
| string | — |
AllowAnyIdentifierAccept anything the named team signs. This is a vendor allowlist rather than an application allowlist. Defaults to false. Default: false | boolean | Allow Any Identifier |
MinimumVersionRefuse builds older than this, so a signed but vulnerable version cannot be installed instead. | string | Minimum Version |
RequireNotarizedRequire the installer to be notarized. Defaults to true. Default: true | boolean | Require Notarized |
AllowScriptsWhether the package may carry install scripts. A scriptless package landing in /Applications is a file copy; one with a postinstall is arbitrary root code on every future build the vendor signs. Defaults to false. Default: false | boolean | Allow Scripts |
AllowedPayloadPrefixesAbsolute path prefixes this installer may write to. Unrestricted when unset, though some destinations always need naming explicitly. | array | Allowed Payload Prefixes |
| string | — |
AllowUnrestrictedPayloadLets this installer write anywhere, including the destinations that otherwise always need naming. Its own key, so the most dangerous setting has to be meant. Defaults to false. Default: false | boolean | Allow Unrestricted Payload |