Privacy Preferences Policy Control
com.apple.TCC.configuration-profile-policy
The payload that configures privacy preferences.
Configuration Keys (1)
| Key | Type | Title |
|---|---|---|
ServicesrequiredA dictionary whose keys are limited to the privacy policy control services. In the case of conflicting specifications, the most restrictive setting (deny) is used. | dict | Services |
AccessibilitySpecifies the policies for the app via the Accessibility subsystem. The ability to grant access by this profile is deprecated as of macOS 26.2, and will be removed in macOS 27.0. | array | Accessibility |
AppleEvents | array | AppleEvents |
BluetoothAlwaysSpecifies the policies for the app to access Bluetooth devices. | array | Bluetooth Always |
Calendar | array | Calendar |
Camera | array | Camera |
AddressBook | array | Contacts |
FileProviderPresence | array | — |
ListenEvent | array | — |
MediaLibrary | array | — |
Microphone | array | Microphone |
Photos | array | Photos |
PostEventSpecifies the policies for the application to use CoreGraphics APIs to send CGEvents to the system event stream. | array | PostEvent |
Reminders | array | Reminders |
SystemPolicyAllFiles | array | SystemPolicyAllFiles |
ScreenCapture | array | — |
SpeechRecognition | array | — |
SystemPolicyDesktopFolder | array | — |
SystemPolicyDocumentsFolder | array | — |
SystemPolicyDownloadsFolder | array | — |
SystemPolicyNetworkVolumes | array | — |
SystemPolicyRemovableVolumes | array | — |
SystemPolicySysAdminFiles | array | System Policy Sys Admin Files |
SystemPolicyAppDataAllows the application to access data of other apps. | array | — |
SystemPolicyAppBundles | array | App Management |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
AEReceiverIdentifierrequiredThe identifier of the process receiving an ApplEvent sent by the Identifier process. | string | AEReceiverIdentifier |
AEReceiverIdentifierTyperequiredThe type of AEReceiverIdentifier value. Range: Bundle ID (bundleID), Path (path) | string | AEReceiverIdentifierType |
AEReceiverCodeRequirementrequiredCode requirement for the receiving binary. | string | AEReceiverCodeRequirement |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AuthorizationThe 'Authorization' key is an optional replacement for the 'Allowed' key. Every payload must specify either 'Authorization' or 'Allowed', but not both. 'Allow': Equivalent to a 'true' value for the 'Allowed' key. 'Deny': Equivalent to a 'false' value for the 'Allowed' key. Range: Allow, Deny | string | — |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |
IdentityDict | dict | — |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | — |
IdentifierTyperequiredThe type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle. Range: bundleID, path | string | — |
CodeRequirementrequiredObtained via the command ''codesign -display -r -''. | string | — |
StaticCodeIf 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | — |
AllowedrequiredIf 'true', access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value. | boolean | — |
AuthorizationThe 'Authorization' key is an optional replacement for the 'Allowed' key. Every payload must specify either 'Authorization' or 'Allowed', but not both. 'Allow': Equivalent to a 'true' value for the 'Allowed' key. 'Deny': Equivalent to a 'false' value for the 'Allowed' key. 'AllowStandardUserToSetSystemService:' allows a standard (non-admin) user to configure the permissions for the specified app in the Privacy preferences for services that otherwise require admin authorization. 'AllowStandardUserToSetSystemService' is only valid for the 'ListenEvent' and 'ScreenCapture' services. Available in macOS 11 and later. Range: Allow, Deny, AllowStandardUserToSetSystemService | string | — |
CommentNot used. | string | — |
AEReceiverIdentifierThe identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services. | string | — |
AEReceiverIdentifierTypeThe type of AEReceiverIdentifier value, either 'bundleID' or 'path'. This setting is required for AppleEvents service; not valid for other services. Range: bundleID, path | string | — |
AEReceiverCodeRequirementThe code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services. | string | — |
ServicesrequiredKeys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used. | dict | Services |
IdentifierrequiredThe bundle ID or installation path of the binary. | string | Identifier |
IdentifierTyperequiredThe type of Identifier value. Range: Bundle ID (bundleID), Path (path) | string | Identifier Type |
CodeRequirementrequiredThe designated requirement describing the code signature of this executable. | string | Code Requirement |
StaticCodeIf set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature. | boolean | StaticCode |
AllowedIf set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value. Range: Deny (false), Allow (true) | boolean | Allowed |
CommentNot Used | string | Comment |