PayloadKit

Network Share Mounter

de.fau.rrze.NetworkShareMounter

Network Share Mounter settings

macOS

Configuration Keys (33)

KeyTypeTitle
managedNetworkShares

Array with managed network shares that are centrally deployed to users.

arrayManaged network shares
managedNetworkShares
dict—
networkSharerequired

The share URL, e.g. smb://fileserver.example.com/share. Note: %USERNAME% is replaced at runtime with the user's macOS login name.

stringServer and share
authTyperequired

Authentication method: krb (Kerberos/SSO), pwd (username + password), or guest. Default: krb.

Default: "krb"

Range: Kerberos (krb), Password (pwd), Guest (guest)

stringAuthentication type
username

Pre-defines a username for pwd-type shares. If omitted, the user is prompted.

stringUsername (Optional)
mountPoint

Overrides the local directory name used as the mount point. Only relevant when the mount location is not /Volumes. Leave blank to use the share name (recommended).

stringMount point name (Optional)
externalKerberosManagement

Set to true if Kerberos tickets for this share are managed externally (AD binding, Jamf Connect, Apple SSO Extension). NSM will mount the share without interfering with ticket management and will not prompt for a Kerberos profile. Only relevant for authType: krb.

Default: "false"

Range: Yes (true), No (false)

stringExternally managed Kerberos tickets
kerberosRealm

Per-share Kerberos realm override. Used together with externalKerberosManagement to identify which external profile to assign. Defaults to the global kerberosRealm setting.

stringPer-share Kerberos realm (Optional)
autoMount

true (default): the share is mounted automatically at startup and on network changes. false: the share appears in the menu but is never mounted automatically - the user can mount it on demand.

Default: "true"

Range: Yes (true), No (false)

stringAutomatically mount
kerberosRealm

Kerberos/AD domain for user authentication (e.g. EXAMPLE.COM). When set, NSM manages Kerberos ticket acquisition and renewal automatically. Required for app-managed Kerberos SSO.

Default: ""

stringKerberos Realm
kerberosProfileDisplayName

Friendly display name for the Kerberos authentication profile shown in the app's Settings. If not set, the realm name (e.g. EXAMPLE.COM) is used as-is.

stringKerberos Profile Display Name
usernameOverride

Overrides the %USERNAME% variable used in share paths. Use this when the local macOS login name differs from the AD or network username.

stringUsername Override
singleUserMode

If true, automatic Kerberos sign-in and ticket renewal only process the default account. If false, all configured accounts are processed.

Default: false

booleanSingle User Mode
ExpirationCountdownStartDay

Passive warning. Days before password expiry when a silent countdown item first appears in the menu bar. The user only sees it when they open the menu. Set to 0 to disable all password expiration features entirely. Mirrors the Apple Kerberos SSO Extension key of the same name.

Default: 14

integerPassword Expiration Countdown Start Day
ExpirationNotificationStartDay

Active warning. Days before password expiry when an alert dialog is shown automatically, once per calendar day. Set this lower than ExpirationCountdownStartDay so the dialog only interrupts when expiry is genuinely imminent. Mirrors the Jamf Connect / Apple Kerberos SSO Extension key of the same name.

Default: 14

integerPassword Expiration Notification Start Day
passwordChangeURL

URL of a web-based password self-service portal (SSPR). If set, a Change Password button in the expiration dialog opens this URL in the default browser. If not set, the user can change their password directly within NSM (requires kerberosRealm).

stringPassword Change URL
allowPasswordChange

When true, a permanent Change Password... item is shown in the menu bar at all times, even before the expiry threshold is reached. It automatically transforms into the expiry countdown when the threshold is reached. If passwordChangeURL is also set, clicking the item opens that URL instead of the in-app dialog. Mirrors the Apple Kerberos SSO Extension key of the same name.

Default: false

booleanAllow Password Change
autostart

When deployed as a locked MDM key, the value is enforced on every app launch. When deployed as an unlocked default, it is applied once on the first launch only - after that, the user retains control.

Default: false

booleanEnable Autostart
canChangeAutostart

Controls only the autostart toggle in the app's Settings UI. Set to false to grey it out. Does not affect MDM enforcement. To enforce the autostart state on every launch, deploy autostart as a locked key instead.

Default: true

booleanCan Change Autostart
canQuit

When true, the user can quit the app via the menu bar. Set to false to remove the Quit item entirely.

Default: true

booleanAllow to Quit App
unmountOnExit

When true, all managed shares are automatically unmounted when the app quits.

Default: true

booleanUnmount Shares on Exit
location

Path where network shares are mounted. The default is a localized folder in the user's home directory (e.g. ~/Network Shares). It is strongly recommended to leave this empty and use the default - changing it can break Finder integration.

Default: ""

stringMount path
useNewDefaultLocation

If true, shares are mounted under /Volumes by default instead of the legacy per-user location. Ignored if 'location' is set.

Default: false

booleanUse the new default mount location
useLocalizedMountDirectories

If false, always uses the English folder name 'Networkshares' for the legacy default mount path instead of a name localized to the user's language. Only relevant when 'useNewDefaultLocation' is false.

Default: true

booleanUse Localized Mount Folder Name
cleanupLocationDirectory

When true, NSM removes files and empty directories from the mount location that would prevent a share from mounting. Read the documentation carefully before enabling - this modifies the user's file system.

Default: false

booleanClean up obstructing files and directories
helpURL

URL to your organization's internal helpdesk or IT documentation. When set, an About Network Share Mounter item appears in the menu bar, opening this URL in the default browser.

Default: ""

stringHelp URL
menuConnectShares

Controls the "Mount shares" action. Set to hidden to remove the item completely, or disabled to grey it out without removing it. Leave unconfigured to show it normally.

Range: Hidden (hidden), Disabled (disabled)

stringMenu Item: Connect Shares
menuDisconnectShares

Controls the "Unmount shares" action. Set to hidden to remove the item completely, or disabled to grey it out without removing it. Leave unconfigured to show it normally.

Range: Hidden (hidden), Disabled (disabled)

stringMenu Item: Disconnect Shares
menuShowSharesMountDir

Controls "Show mounted shares" (opens the mount folder in Finder). Set to hidden to remove the item completely, or disabled to grey it out without removing it. Leave unconfigured to show it normally.

Range: Hidden (hidden), Disabled (disabled)

stringMenu Item: Show Shares Mount Directory
menuShowShares

Controls the individual share items listed in the menu. Set to hidden to remove them completely, or disabled to grey them out without removing them. Leave unconfigured to show them normally.

Range: Hidden (hidden), Disabled (disabled)

stringMenu Item: Show Shares List
menuSettings

Controls the "Preferences..." item. Set to hidden to remove the item completely, or disabled to grey it out without removing it. Leave unconfigured to show it normally.

Range: Hidden (hidden), Disabled (disabled)

stringMenu Item: Settings
menuCheckUpdates

Controls the "Check for Updates..." item. Set to hidden to remove the item completely, or disabled to grey it out without removing it. Leave unconfigured to show it normally.

Range: Hidden (hidden), Disabled (disabled)

stringMenu Item: Check for Updates
menuAbout

Controls the "About Network Share Mounter" item (only visible when helpURL is set). Set to hidden to remove the item completely, or disabled to grey it out without removing it. Leave unconfigured to show it normally.

Range: Hidden (hidden), Disabled (disabled)

stringMenu Item: About
menuQuit

Controls the "Quit Network Share Mounter" item. Set to hidden to remove the item completely, or disabled to grey it out without removing it. Leave unconfigured to show it normally.

Range: Hidden (hidden), Disabled (disabled)

stringMenu Item: Quit
disableAutoUpdateFramework

Master switch. Set to true to completely disable the Sparkle update framework. When disabled, no update checks occur and the Check for Updates menu item is removed.

Default: false

booleanDisable Auto Update Framework
SUEnableAutomaticChecks

When the framework is enabled, controls whether NSM actively checks for new versions in the background. Set to false to suppress checks while keeping the framework loaded.

Default: true

booleanEnable Automatic Update Checks
SUAutomaticallyUpdate

When true, updates are downloaded and installed automatically without asking the user for confirmation. Only takes effect when SUEnableAutomaticChecks is also true.

Default: true

booleanAutomatically Install Updates
sendDiagnostics

If true, diagnostic and crash data is sent to help improve the app. Independent of 'disableDiagnostics', which only hides the section in Settings.

Default: true

booleanSend Diagnostic Data
disableDiagnostics

When true, hides the hidden "Diagnostics" trigger in Settings and General (five consecutive clicks) that lets users send NSM's unified-log activity to the developers for troubleshooting. Use this to prevent users from sending diagnostic data off-device, e.g. for data-privacy reasons.

Default: false

booleanDisable Diagnostics
enableAutoUpdater

Deprecated since version 4. Use 'disableAutoUpdateFramework' instead (inverted logic: enableAutoUpdater = true equals disableAutoUpdateFramework = false).

Default: true

booleanEnable AutoUpdater Framework
networkShares

Legacy array with all network shares. Example: smb://filer.your.domain/share. Note: %USERNAME% will be replaced with the login name of the current user. Still accepted for backward compatibility but should not be used in new profiles - use managedNetworkShares instead.

arrayNetwork shares (deprecated, legacy)
string—