ProfileForge
Back to browser

Extensible Single Sign-On

com.apple.extensiblesso

The payload that configures an app extension that performs single sign-on (SSO).

iOSmacOS
macOS 10.15+iOS 13.0+combined

Configuration Keys (12)

KeyTypeTitle
ExtensionIdentifierrequired
stringExtension Identifier
Typerequired
string
TeamIdentifier
stringTeam Identifier
Hosts
array
hostnamerequired
stringHostname / Domain name
Realm
string
URLs
arrayURLs
URLrequired
stringURL
DeniedBundleIdentifiers
arrayDenied Bundle Identifiers
bundleIdentifierrequired
stringBundle Identifier
ScreenLockedBehavior
stringScreen Locked Behavior
ExtensionData
dictKerberos Extension Data
allowAutomaticLogin
booleanAllow Automatic Login
allowPasswordChange
booleanAllow Password Change
usePlatformSSOTGT
booleanUse Platform SSO TGT
allowPlatformSSOAuthFallback
booleanAllow Platform SSO Authentication Fallback
performKerberosOnly
booleanPerform Kerberos Requests Only
cacheName
stringCache Name
certificateUUID
stringCertificate UUID
credentialBundleIdACL
arrayCredential Bundle ID ACL
credentialBundleIdACLItem
stringBundle ID
credentialUseMode
stringCredential Use Mode
customUsernameLabel
stringCustom Username Label
delayUserSetup
booleanDelay User Setup
helpText
stringHelp Text
isDefaultRealm
booleanIs Default Realm
includeManagedAppsInBundleIdACL
booleanInclude Managed Apps in Bundle ID ACL
includeKerberosAppsInBundleIdACL
booleanInclude Kerberos Apps in Bundle ID ACL
monitorCredentialsCache
booleanMonitor Credential Cache
principalName
stringPrincipal Name
preferredKDCs
arrayPreferred KDCs
preferredKDCrequired
stringKey Distribution Center
pwChangeURL
stringPassword Change URL
pwNotificationDays
integerPassword Notification Days
pwExpireOverride
integerPassword Expiration Override
pwReqComplexity
booleanPassword Requirement Complexity
pwReqHistory
integerPassword Requirement History
pwReqLength
integerPassword Requirement Length
pwReqMinAge
integerPassword Requirement Minimum Age
pwReqText
stringPassword Requirement Text
pwReqRTFData
data
replicationTime
integerReplication Time
requireTLSForLDAP
booleanRequire TLS for LDAP
requireUserPresence
booleanRequire User Presence
siteCode
stringSite Code
syncLocalPassword
booleanSync Local Password
useSiteAutoDiscovery
booleanUse Site Auto Discovery
domainRealmMapping
dict
Realm
array
RealmItem
string
RealmItem
string
Enable_SSO_On_All_ManagedApps
integerEnable SSO on All Managed Apps
AppAllowList
stringApp Allow List
AppPrefixAllowList
stringApp Prefix Allow List
AppBlockList
stringApp Block List
AppCookieSSOAllowList
stringApp Cookie SSO Allow List
browser_sso_interaction_enabled
integerAllow Users to Sign in from Unknown Applications using the Safari Browser
browser_sso_disable_mfa
integerDisable Asking for MFA During Initial Bootstrapping
disable_explicit_app_prompt
integerDisable OAuth2 Application Prompts
disable_explicit_app_prompt_and_autologin
integerDisable OAuth2 Application Prompts and Autologin
identityIssuerAutoSelectFilter
string
allowSmartCard
boolean
allowPassword
boolean
startInSmartCardMode
boolean
credentialBundleIdACLItem
stringBundle ID
preferredKDCrequired
stringKey Distribution Center
Realm
array
RealmItem
string
RealmItem
string
AuthenticationMethod
stringAuthentication Method
PlatformSSO
dict
AuthenticationMethod
string
UseSharedDeviceKeys
boolean
AccountDisplayName
string
LoginFrequency
integer
EnableCreateUserAtLogin
boolean
EnableAuthorization
boolean
TokenToUserMapping
dict
AccountName
string
FullName
string
NewUserAuthorizationMode
string
UserAuthorizationMode
string
AdministratorGroups
array
Group
string
AdditionalGroups
array
Group
string
AuthorizationGroups
dict
{{key}}required
string
{{value}}required
string
FileVaultPolicy
array
policyrequired
string
LoginPolicy
array
policyrequired
string
UnlockPolicy
array
policyrequired
string
OfflineGracePeriod
integer
AuthenticationGracePeriod
integer
NonPlatformSSOAccounts
array
usernamerequired
string
AllowDeviceIdentifiersInAttestation
boolean
EnableCreateFirstUserDuringSetup
boolean
NewUserAuthenticationMethods
array
NewUserAuthenticationMethod
string
AccessKeyReaderGroupIdentifier
data
AccessKeyTerminalIdentityUUID
string
AccessKeyReaderIssuerCertificateUUID
stringAccess Key Reader Issuer Certificate UUID
AllowAccessKeyExpressMode
boolean
SynchronizeProfilePicture
boolean
TemporarySessionQuickLogin
boolean
EnableRegistrationDuringSetup
boolean
AccountName
string
FullName
string
Group
string
Group
string
{{key}}required
string
{{value}}required
string
policyrequired
string
policyrequired
string
policyrequired
string
usernamerequired
string
NewUserAuthenticationMethod
string
RegistrationToken
stringRegistration Token
hostnamerequired
stringHostname / Domain name
URLrequired
stringURL
bundleIdentifierrequired
stringBundle Identifier
allowAutomaticLogin
booleanAllow Automatic Login
allowPasswordChange
booleanAllow Password Change
usePlatformSSOTGT
booleanUse Platform SSO TGT
allowPlatformSSOAuthFallback
booleanAllow Platform SSO Authentication Fallback
performKerberosOnly
booleanPerform Kerberos Requests Only
cacheName
stringCache Name
certificateUUID
stringCertificate UUID
credentialBundleIdACL
arrayCredential Bundle ID ACL
credentialBundleIdACLItem
stringBundle ID
credentialUseMode
stringCredential Use Mode
customUsernameLabel
stringCustom Username Label
delayUserSetup
booleanDelay User Setup
helpText
stringHelp Text
isDefaultRealm
booleanIs Default Realm
includeManagedAppsInBundleIdACL
booleanInclude Managed Apps in Bundle ID ACL
includeKerberosAppsInBundleIdACL
booleanInclude Kerberos Apps in Bundle ID ACL
monitorCredentialsCache
booleanMonitor Credential Cache
principalName
stringPrincipal Name
preferredKDCs
arrayPreferred KDCs
preferredKDCrequired
stringKey Distribution Center
pwChangeURL
stringPassword Change URL
pwNotificationDays
integerPassword Notification Days
pwExpireOverride
integerPassword Expiration Override
pwReqComplexity
booleanPassword Requirement Complexity
pwReqHistory
integerPassword Requirement History
pwReqLength
integerPassword Requirement Length
pwReqMinAge
integerPassword Requirement Minimum Age
pwReqText
stringPassword Requirement Text
pwReqRTFData
data
replicationTime
integerReplication Time
requireTLSForLDAP
booleanRequire TLS for LDAP
requireUserPresence
booleanRequire User Presence
siteCode
stringSite Code
syncLocalPassword
booleanSync Local Password
useSiteAutoDiscovery
booleanUse Site Auto Discovery
domainRealmMapping
dict
Realm
array
RealmItem
string
RealmItem
string
Enable_SSO_On_All_ManagedApps
integerEnable SSO on All Managed Apps
AppAllowList
stringApp Allow List
AppPrefixAllowList
stringApp Prefix Allow List
AppBlockList
stringApp Block List
AppCookieSSOAllowList
stringApp Cookie SSO Allow List
browser_sso_interaction_enabled
integerAllow Users to Sign in from Unknown Applications using the Safari Browser
browser_sso_disable_mfa
integerDisable Asking for MFA During Initial Bootstrapping
disable_explicit_app_prompt
integerDisable OAuth2 Application Prompts
disable_explicit_app_prompt_and_autologin
integerDisable OAuth2 Application Prompts and Autologin
identityIssuerAutoSelectFilter
string
allowSmartCard
boolean
allowPassword
boolean
startInSmartCardMode
boolean
credentialBundleIdACLItem
stringBundle ID
preferredKDCrequired
stringKey Distribution Center
Realm
array
RealmItem
string
RealmItem
string
AuthenticationMethod
string
UseSharedDeviceKeys
boolean
AccountDisplayName
string
LoginFrequency
integer
EnableCreateUserAtLogin
boolean
EnableAuthorization
boolean
TokenToUserMapping
dict
AccountName
string
FullName
string
NewUserAuthorizationMode
string
UserAuthorizationMode
string
AdministratorGroups
array
Group
string
AdditionalGroups
array
Group
string
AuthorizationGroups
dict
{{key}}required
string
{{value}}required
string
FileVaultPolicy
array
policyrequired
string
LoginPolicy
array
policyrequired
string
UnlockPolicy
array
policyrequired
string
OfflineGracePeriod
integer
AuthenticationGracePeriod
integer
NonPlatformSSOAccounts
array
usernamerequired
string
AllowDeviceIdentifiersInAttestation
boolean
EnableCreateFirstUserDuringSetup
boolean
NewUserAuthenticationMethods
array
NewUserAuthenticationMethod
string
AccessKeyReaderGroupIdentifier
data
AccessKeyTerminalIdentityUUID
string
AccessKeyReaderIssuerCertificateUUID
stringAccess Key Reader Issuer Certificate UUID
AllowAccessKeyExpressMode
boolean
SynchronizeProfilePicture
boolean
TemporarySessionQuickLogin
boolean
EnableRegistrationDuringSetup
boolean
AccountName
string
FullName
string
Group
string
Group
string
{{key}}required
string
{{value}}required
string
policyrequired
string
policyrequired
string
policyrequired
string
usernamerequired
string
NewUserAuthenticationMethod
string