PayloadKit

Enterprise Connect

com.apple.Enterprise-Connect

Enterprise Connect settings

macOS
exclusive

Configuration Keys (45)

KeyTypeTitle
adRealm

The host name of your organization's Active Directory domain.

stringActive Directory Realm
PFC_SegmentedControl_0required
string
launchAtLogin

Determines if Enterprise Connect should set itself as a login item.

Default: true

booleanLaunch At Login
runPeriodicStateCheck

Enable or Disable periodic state checking. Customers who expose their DNS to the public Internet will need to disable periodic state checking.

Default: true

booleanRun Periodic State Check
orgUsernameLabel

The name your organization gives usernames.

stringOrganization Username Label
prepopulatedUsername

Upon launch or sign out, Enterprise Connect will pre-populate the Username field with this username.

stringPre Populated Username
preferredDC

Preferred domain controller when doing LDAP queries and getting a Kerberos TGT. If this domain controller is unavailable, Enterprise Connect will fall back to domain controllers it discovers from DNS.

stringPreferred Domain Controller
setupReminderNagInterval

The interval, in seconds, between setup notifications.

Default: 86400

integerReminder Nag Interval
getRenewableTGT

Acquire a renewable Kerberos TGT.

Default: false

booleanGet Renewable TGT
showMenuExtra

Determines whether the Enterprise Connect menu extra is loaded.

Default: true

booleanShow Menu Extra
checkShowLegacyCertificates

Automatically check the "Show Legacy Certificates" option in the certificate chooser window.

Default: false

booleanShow Legacy Certificates
showKeychainIdentities

Automatically check the "Show Legacy Certificates" option in the certificate chooser window.

Default: false

booleanShow Keychain Identities
disableQuitMenu

Disables the Quit menu item from Enterprise Connect.

Default: false

booleanDisable Quit Menu
orgLogoPath

The path to a file containing your organization's logo, in PNG, JPG or GIF format.

stringOrganization Logo Path
debugMode

Enables debugging mode.

Default: false

booleanDebug Mode
syncLocalPassword

Enables Active Directory to local account password sync. This only works if the user is logged into their Mac with a local account.

booleanSync Local Password
pwReqComplexity

Tells Enterprise Connect that passwords should meet Active Directory's definition of complexity. Used to enable and configure live password testing.

Default: false

booleanPassword Required Complexity
pwReqComplexityDisableUnicode

Disables the "Has a Unicode character" password test from live password testing.

Default: false

booleanPassword Required Complexity Disable Unicode
pwReqLength

Require passwords to be at least as long as the specified value.

integerPassword Required Length
pwReqText

Path to a RTF file to display for the user during password changes.

stringPassword Change Message Path
pwReqHistoryCount

How many previous passwords cannot be re-used.

integerPassword History Count
pwReqMinimumPasswordAge

The minimum age of passwords before they can be changed.

integerPassword Minimum Age
disablePasswordFunctions

Disable Enterprise Connect's password management abilities, including expiration notices and the "Change Password" menu item. This is useful for customers who don't change their passwords in AD.

Default: false

booleanDisable Password Functions
disablePasswordExpirationChecking

Disable Enterprise Connect's password expiration checking, but still leave intact the ability for the user to change their password with Enterprise Connect.

booleanDisable Password Expiration Checking
runPasswordChangeScriptOnLocalPasswordSync

Determines if Enterprise Connect should run the password change script upon a local password sync.

Default: true

booleanRun Password Change Script On Local Password Sync
passwordChangeScriptPath

Path to the password change script.

stringPassword Change Script Path
passwordChangeURL

URL to open in the user's default web browser when they use Enterprise Connect to change their password. Standard password change functionality will no longer work.

stringPassword Change URL
passwordExpireOverride

Override domain password policy when calculating password expiration.

integerPassword Expire Override
passwordNotificationDays

Determines the amount of days before password expiration that the user receives expiration notifications.

Default: 15

integerPassword Expire Notification
checkForNetworkType

Check for a host in your organization's network.

Default: false

booleanCheck For Network Server
checkForNetworkServer

The host Enterprise Connect should check for when connecting.

Depends on: checkForNetworkType ∈ [true]

stringNetwork Server
connectDelay

Delay starting the connection process when your organization's network is detected. This may be useful for customers who use Cisco NAC and need to delay connection while host checks are performed.

Default: 0

integerConnect Delay
connectionCompletedScriptPath

Path to the connection completed script.

stringConnection Completed Script Path
connectReminderNagInterval

The interval, in seconds, between connection reminders.

Default: 86400

integerConnection Reminder Interval
dailyReconnectTime

The interval, in seconds, that Enterprise Connect should attempt its daily reconnect. Set this to 0 to disable the daily reconnect.

Default: 86400

integerDaily Reconnect Time
runAuditScript

Tells Enterprise Connect to execute an audit script.

booleanRun Audit Script
runAuditScriptPath

Path to the audit script.

stringAudit Script Path
mountNetworkHomeDirectory

Determines if Enterprise Connect mounts the user's network home directory.

booleanMount Network Home Directory
pfc_preventUserShares

Prevents the user from adding custom shares to Enterprise Connect.

booleanPrevent User Shares
shares

List of shares that Enterprise Connect should attempt to mount.

Depends on: pfc_preventUserShares ∈ [true]

Default: [{}]

arrayShares
managedshares

List of shares that Enterprise Connect should attempt to mount. Users will still be able to add their own shares.

arrayManaged Shares
shareMountWaitSeconds

Delay the mounting of network shares when your organization's network is detected. This may be useful for customers who use Cisco NAC and need to delay connection while host checks are performed.

Default: 0

integerShare Mount Delay
smartCardMode

Determines whether smart card mode should be enabled.

Default: false

booleanEnable Smart Card Mode
showUsernameWithSmartcard

Determines if Enterprise Connect should display the username field if smart card mode is enabled.

Default: false

booleanShow Username in Smart Card Mode
destroyKerbTicketUponCardRemoval

Default: true

booleanDestroy Kerberos Ticket on Smart Card Removal
managedshare
dictShare
path
stringPath
managedshare
dictShare
path
stringPath