PayloadKit

Support Companion

com.github.macadmins.SupportCompanion

Support Companion settings

macOS
macOS 14.0+

Configuration Keys (80)

KeyTypeTitle
PFC_SegmentedControl_0required
string—
KnowledgeBaseUrl

If configured, a menu item "Knowledge base" will show up where the user can browse the page from the UI.

stringKnowledge Base Url
MenuShowIdentity

Configures whether to show the Identity menu item. Defaults to true

Default: true

booleanShow Identity Menu Item
MenuShowApps

Configures whether to show the Apps menu item. Defaults to true

Default: true

booleanShow Apps Menu Item
MenuShowSelfService

Configures whether to show the Self Service menu item. Defaults to true

Default: true

booleanShow Self Service Menu Item
MenuShowCompanyPortal

Configures whether to show the Company Portal menu item. Defaults to true

Default: true

booleanShow Company Portal Menu Item
MenuShowKnowledgeBase

Configures whether to show the Knowledge Base menu item. Defaults to true

Default: true

booleanShow Knowledge Base Menu Item
BrandName

Configures the name shown in the navigation menu.

stringBrand Name
AccentColor

Configures the brand color shown in the app, specify in hex format.

stringAccent Color
BrandLogo

Configures the brand logo shown in the apps side menu. Specify a Base64 string.

stringBrand Logo
BrandLogoLight

Configures the brand logo shown in the apps side menu when light theme is used. Specify a base64 string

stringBrand Logo Light
SupportPageUrl

Configures the URL to open when the user clicks on the Get Support button.

stringSupport Page URL
ChangePasswordUrl

Configures the URL to open when the user clicks on the Change Password button.

stringChange Password URL
ChangePasswordMode

Configures the mode for the Change Password button, available modes are: local, SSOExtension, url. Defaults to local if not configured.

Range: Local (local), SSO Extension (SSOExtension), URL (url)

stringChange Password Mode
SupportEmail

Configures the email address shown when the user clicks on the Support Info button.

stringSupport Email
SupportPhone

Configures the phone number shown when the user clicks on the Support Info button.

stringSupport Phone
HiddenCards

Configures which cards to hide, available cards are: DeviceInformation, Evergreen, Battery, Actions, ApplicationInstallProgress, Storage, DeviceManagement, PendingAppUpdates, Jamf, Fleet, FleetPolicies.

arrayHidden Cards

Range: Device Information (DeviceInformation), Evergreen (Evergreen), Battery (Battery), Actions (Actions), Application Install Progress (ApplicationInstallProgress), Storage (Storage), Device Management (DeviceManagement), Pending App Updates (PendingAppUpdates), Jamf (Jamf), Fleet (Fleet), Fleet Policies (FleetPolicies)

string—
HiddenActions

Configures which actions to hide, available actions are: ChangePassword, Reboot, OpenManagementApp, GetSupport, GatherLogs, SoftwareUpdates, RestartIntuneAgent.

arrayHidden Actions

Range: Change Password (ChangePassword), Reboot (Reboot), Open Management App (OpenManagementApp), Get Support (GetSupport), Gather Logs (GatherLogs), Software Updates (SoftwareUpdates), Restart Intune Agent (RestartIntuneAgent)

string—
NotificationInterval

Configures the interval for notifications in hours for Application Updates and Software Updates notifications.

Range: 1 – 24

integerNotification Interval
NotificationTitle

Configures the title for notifications for notifications. Defaults to Support Companion if not configured.

stringNotification Title
NotificationImage

Configures an image to add to notifications. Local path should be specified.

stringNotification Image
SoftwareUpdateNotificationMessage

Configures the message for notifications for Software Updates notifications. Defaults to "Software Updates Available. Please update your device to the latest version." if not configured.

Default: "Software Updates Available. Please update your device to the latest version."

stringSoftware Update Notification Message
SoftwareUpdateNotificationButtonText

Configures the button text for notifications for Software Updates notifications. Defaults to "Update Now 🚀" if not configured.

Default: "Update Now 🚀"

stringSoftware Update Notification Button Text
AppUpdateNotificationMessage

Configures the message for notifications for App Updates notifications. Defaults to "App Updates Available. Please update your apps to the latest version." if not configured.

Default: "App Updates Available. Please update your apps to the latest version."

stringApp Update Notification Message
AppUpdateNotificationButtonText

Configures the button text for notifications for App Updates notifications. Defaults to "Update Now 🚀" if not configured.

Default: "Update Now 🚀"

stringApp Update Notification Button Text
RebootReminderDays

Configures the number of days after which the user will be reminded to reboot. Defaults to 0 days if not configured (no reminder).

Default: 0

integerReboot Reminder Days
Mode

Configures which source the app reads application information from. Detection runs only when this is empty: Fleet is chosen on Macs running Fleet's agent (orbit) when no other mode matches.

Range: Munki, Intune, Jamf, Fleet, SystemProfiler

stringMode
RefreshSelfService

Configures whether to refresh the Self Service+ app data in the background when in Jamf mode. Defaults to true

Default: true

booleanRefresh Self Service
JamfLogPollHours

Configures how often to poll Jamf logs in hours. Only used when in Jamf mode. Defaults to 36 if not configured.

Default: 36

Range: 0 – —

integerJamf Log Poll Hours
LogFolders

Configures the log folders to gather logs from. Only used when gathering logs. Defaults to "/Library/Logs/Microsoft" if not configured.

arrayLog Folders
string—
ExcludedLogFolders

Configures the log folders to exclude when gathering logs. Only used when gathering logs.

arrayExcluded Log Folders
string—
Actions

Configures custom actions to add to the tray menu. Actions defined in the user's own preferences still run, but IsPrivileged is honored only when the action comes from a configuration profile. From 3.0 the app sends only the action's name and the helper looks the command up itself, so a privileged action must be defined in a profile to run at all.

arrayActions
dict—
Name

Name of the action to show in the menu.

stringName
Command

Command to run when to item is clicked.

stringCommand
Icon

SF Symbol to show in the Self Service page in the UI.

stringIcon
IsPrivileged

SF Symbol to show in the Self Service page in the UI.

booleanIs Privileged
Description

Description to show in the Self Service page in the UI.

stringDescription
ButtonLabel

Configures the button label for the action.

stringButton Label
ShowLogoInTrayMenu

Configures whether to show the branding logo in the tray menu. Defaults to true.

Default: true

booleanShow Logo In Tray Menu
TrayMenuBrandingIcon

Configures the icon to show in the tray menu. Specify a Base64 string.

stringTray Menu Branding Icon
TrayMenuShowIcon

Configures whether to show the tray menu icon. Useful if you only want to show desktop information for example. Defaults to true.

Default: true

booleanShow Tray Menu Icon
ShowDesktopInfo

Configures the desktop info widget.

Default: false

booleanShow Desktop Info
DesktopInfoWindowPosition

Configures the position of the desktop info. Defaults to Lower Right.

Default: "LowerRight"

Range: Upper Left (UpperLeft), Upper Right (UpperRight), Lower Left (LowerLeft), Lower Right (LowerRight)

stringDesktop Position
DesktopInfoLevel

Configures the level of information to show on the desktop. Defaults to 4.

Range: 1, 2, 3, 4, 5

integerDesktop Info Level
DesktopInfoHideItems

Use this array to determine which information to hide. Available items are: HostName, Model, SerialNumber, Processor, IPAddress, Memory, OSBuild, OSVersion, LastRestart, FileVault, StorageName, SupportPhone, SupportEmail. It is also possible to hide entire sections: Hardware Specifications, System Information, Network Information, Storage, Support.

arrayDesktop Info Hide Items

Range: Host Name (HostName), Model (Model), Serial Number (SerialNumber), Processor (Processor), IP Address (IPAddress), Memory (Memory), OS Build (OSBuild), OS Version (OSVersion), Last Restart (LastRestart), FileVault (FileVault), Storage Name (StorageName), Support Phone (SupportPhone), Support Email (SupportEmail), Hardware Specifications (Hardware Specifications), System Information (System Information), Network Information (Network Information), Storage (Storage), Support (Support), Category (Category), Divider (Divider)

string—
DesktopInfoBackgroundOpacity

Configures the opacity of the desktop info. Defaults to 0%.

Default: 1

Range: 10% (0.1), 20% (0.2), 30% (0.3), 40% (0.4), 50% (0.5), 60% (0.6), 70% (0.7), 80% (0.8), 90% (0.9), 100% (1)

realDesktop Info Background Opacity
DesktopInfoBackgroundFrosted

Enables a frosted glass look on the desktop info when set to true.

booleanDesktop Info Background Frosted
DesktopInfoFontSize

Configures the font size for the desktop info. Defaults to 14.

Default: 14

Range: 8 – 24

integerDesktop Info Font Size
CustomCardPath

Configures a path to a JSON file containing custom widgets to show on the Home view.

stringCustom Card Path
DebugLogging

Configures whether debug logging is enabled. Defaults to false.

Default: false

booleanDebug Logging
EnableElevation

When set to true allows the user to elevate to admin during a set time frame. Defaults to false. From 3.0 this is only honored when it comes from a configuration profile.

Default: false

booleanEnable Elevation
RequireResonForElevation

Requires the user to enter a reason for the elevation. Defaults to false. From 3.0 this is only honored when it comes from a configuration profile.

Default: false

booleanRequire Reason For Elevation
ReasonMinLength

Set a minimum amount of characters the user must enter as the reason. Defaults to 10. From 3.0 this is only honored when it comes from a configuration profile.

Default: 10

integerReason Min Length
MaxElevationTime

The amount of time (in minutes) the user is elevated. Defaults to 5. From 3.0 this is only honored when it comes from a configuration profile.

Default: 5

integerMax Elevation Time
ElevationWebhookUrl

When configured, sends the entered elevation reason to a webhook instead of saving to disk. From 3.0 this is only honored when it comes from a configuration profile.

stringElevation Webhook Url
ShowElevateTrayCard

Configure wether to show the elevate button in the tray menu or not. Defaults to false.

Default: false

booleanShow Elevate Tray Card
ElevationSeverity

Configure the elevation severity. Defaults to 6 (Informational). From 3.0 this is only honored when it comes from a configuration profile.

Default: 6

integerElevation Severity
MarkdownFilePath

Configure a path to a Markdown file to show in the menu.

stringMarkdown File Path
MarkdownMenuLabel

Configure the menu label for the custom Markdown view.

stringMarkdown Menu Label
MarkdownMenuIcon

Configure the icon for the custom Markdown menu item.

stringMarkdown Menu Icon
CustomCardsMenuLabel

Configure the menu label for the custom cards view.

stringCustom Cards Menu Label
CustomCardsMenuIcon

Configure the icon for the custom cards menu item.

stringCustom Cards Menu Icon
RequirePrivilegedActionAuthentication

Requires the user to authenticate before a privileged action runs. From 3.0 this defaults to true unless an administrator sets it, and is honored only from a configuration profile.

Default: true

booleanRequire Privileged Action Authentication
EnforceAdminAllowlist

When true, the helper reconciles the admin group at startup and every five minutes: any account holding administrator rights that is neither listed in PermanentAdmins nor inside a live elevation window is demoted. Set PermanentAdmins before enabling this, or those accounts are demoted within five minutes. Defaults to false. Must be delivered in a device-scoped configuration profile; it is ignored anywhere else.

Default: false

booleanEnforce Admin Allowlist
PermanentAdmins

Accounts that may hold administrator rights permanently when EnforceAdminAllowlist is enabled. List every such account: management accounts, break-glass accounts, permanently administrative staff, and anything granted rights by another system such as Platform SSO's AdministratorGroups. An explicitly empty array is honored and means no account is a permanent administrator; a missing list is refused with an error rather than acted on. root is always permitted. Must be delivered in a device-scoped configuration profile; it is ignored anywhere else.

arrayPermanent Admins
string—
ElevationAllowedAdmins

Accounts the elevation watchdog ignores, for management accounts an MDM may legitimately add while somebody is elevated. Defaults to an empty list. Must be delivered in a device-scoped configuration profile; it is ignored anywhere else.

Default: []

arrayElevation Allowed Admins
string—
EnableUserInstalls

When true, a standard user can install a .pkg or .dmg listed in AllowedInstallers without holding administrator rights. Both the app and the helper read this: the app decides whether to stage a file at all, the helper decides whether to install it. Defaults to false. Read only from a configuration profile, device-scoped or scoped to the user being served.

Default: false

booleanEnable User Installs
ShowInstallerServiceMenuItem

Whether Finder's context menu offers "Install with Support Companion". Follows EnableUserInstalls unless set explicitly; set it to false to keep user installs but route everyone through the in-app catalog. Applied on every launch.

booleanShow Installer Service Menu Item
RequireAuthenticationForInstalls

Whether the user authenticates before a user install proceeds. They authenticate as themselves, not as an administrator. Turning this off means an unlocked unattended Mac is enough to install an allowlisted item. Defaults to true.

Default: true

booleanRequire Authentication For Installs
UserInstallFallback

What to offer when an installer is not on the allowlist. "installer" opens it in Apple's Installer, "elevate" offers the normal time-limited elevation instead, "none" offers nothing. Defaults to "installer".

Default: "installer"

Range: Open in Installer (installer), Offer Elevation (elevate), None (none)

stringUser Install Fallback
SkipHelperInstall

When true, the package does not install or load its own copy of the privileged helper, and removes any it finds. Set this only where the helper is deployed declaratively with com.apple.configuration.services.background-tasks, otherwise two daemons claim the same Mach service. Defaults to false. Must be delivered in a device-scoped configuration profile; it is ignored anywhere else.

Default: false

booleanSkip Helper Install
FleetUrl

Overrides the Fleet server URL otherwise discovered from fleetd or orbit. Read only from a configuration profile, because the device's token is sent to whatever server this names.

stringFleet URL
FleetRecommendedApps

Fleet software keys pinned to the top of the self-service catalog, whether or not they are already installed.

arrayFleet Recommended Apps
string—
FleetRecommendedTitle

Renames the recommended section of the Fleet catalog.

stringFleet Recommended Title
FleetIconsFromGitHub

Whether to fetch application icons from Fleet's public catalog on GitHub. Defaults to true.

Default: true

booleanFleet Icons From GitHub
FleetAppOpenMessages

Replaces the built-in wording shown when an install is waiting for the user to quit the application first.

arrayFleet App Open Messages
string—
FleetButtonLabels

Custom button text in the Fleet catalog, keyed by software title and optionally nested by action.

dictFleet Button Labels
Title

Software title, or an action name nested under one.

string—
FleetNotifyUpdates

Notify when Fleet reports available application updates. Defaults to true.

Default: true

booleanFleet Notify Updates
FleetNotifyInstallResults

Notify when a Fleet install, update or uninstall finishes. Defaults to true.

Default: true

booleanFleet Notify Install Results
FleetNotifyPolicies

Notify when Fleet policies are failing on the Mac. Defaults to true.

Default: true

booleanFleet Notify Policies
FleetNotifySignIn

Remind the user to sign in to Fleet Desktop SSO while signed out, at most once a day. Defaults to false, unlike the other Fleet notifications.

Default: false

booleanFleet Notify Sign In
CompanyPortalUrl

Overrides the Company Portal URL, for sovereign cloud endpoints such as GCC High.

stringCompany Portal URL
SoftwareUpdateNotificationCommand

Command run when the software update notification's button is clicked. Defaults to opening the Software Update pane.

stringSoftware Update Notification Command
AppUpdateNotificationCommand

Command run when the application update notification's button is clicked. Set at every launch to open the management application for the detected mode; a value forced by profile still wins.

stringApp Update Notification Command
FileDebugLogging

Write debug logging to disk as well as to the unified log. Defaults to false.

Default: false

booleanFile Debug Logging
AllowedInstallers

Installers a standard user may install without administrator rights when EnableUserInstalls is true. The helper re-reads this and re-derives the installer's facts before it acts, so the confirmation sheet the user sees is presentation only. Entries that cannot decide anything are dropped and logged. Read only from a configuration profile, device-scoped or scoped to the user being served.

arrayAllowed Installers
Installer
dict—
Name

Display name for this entry. Required.

stringName
SHA256

64 hex characters. When present the entry is strict: it pins one exact build and stops matching as soon as the vendor ships an update.

stringSHA256
TeamID

The signing team. Required whenever SHA256 is absent.

stringTeam ID
LeafCertificateSHA256

Pins the signing certificate itself. Stricter than TeamID, and needs updating when the vendor renews.

stringLeaf Certificate SHA256
PackageIdentifier

Package identifiers this entry allows, for a .pkg. A distribution package needs every component listed. A single string is also accepted.

arrayPackage Identifier
string—
BundleIdentifier

Bundle identifiers this entry allows, for the application inside a .dmg. A single string is also accepted.

arrayBundle Identifier
string—
AllowAnyIdentifier

Accept anything the named team signs. This is a vendor allowlist rather than an application allowlist. Defaults to false.

Default: false

booleanAllow Any Identifier
MinimumVersion

Refuse builds older than this, so a signed but vulnerable version cannot be installed instead.

stringMinimum Version
RequireNotarized

Require the installer to be notarized. Defaults to true.

Default: true

booleanRequire Notarized
AllowScripts

Whether the package may carry install scripts. A scriptless package landing in /Applications is a file copy; one with a postinstall is arbitrary root code on every future build the vendor signs. Defaults to false.

Default: false

booleanAllow Scripts
AllowedPayloadPrefixes

Absolute path prefixes this installer may write to. Unrestricted when unset, though some destinations always need naming explicitly.

arrayAllowed Payload Prefixes
string—
AllowUnrestrictedPayload

Lets this installer write anywhere, including the destinations that otherwise always need naming. Its own key, so the most dangerous setting has to be meant. Defaults to false.

Default: false

booleanAllow Unrestricted Payload