PayloadKit

App Store

com.apple.appstore

The payload that configures macOS App Store restrictions.

macOS
macOS 10.9+exclusive
3 of 5 settings are available in the Intune Settings Catalog. Remaining settings require a custom .mobileconfig profile.

DDM recommended — 3 of 5 settings support Declarative Device Management

Apple recommends DDM over legacy profiles. DDM declarations are autonomous — the device enforces them without server round-trips. In Intune, use Settings Catalog → Declarative Device Management to configure these settings.

Configuration Keys (5)

KeyTypeTitleDDM
restrict-store-require-admin-to-install

If 'true', the system restricts app installations to admin users only. Deprecated in macOS 10.14. Use the 'com.apple.SoftwareUpdate' payload key 'restrict-software-update-require-admin-to-install' instead.

Default: false

booleanRequire Admin To Install
restrict-store-softwareupdate-only

If 'true', the system prevents App Store from launching. Available in macOS 10.14 and later. Restricts installations to software updates only in macOS 10.10 through 10.13.

Default: false

booleanRestrict app installations to software updates only
restrict-store-disable-app-adoption

If 'true', the system disables app adoption by users. Available in macOS 10.10 and later.

Default: false

booleanDisable App Adoption by users
DisableSoftwareUpdateNotifications

If 'true', the system disables software update notifications. Available in macOS 10.10 and later.

Default: false

booleanDisable software update notifications
restrict-store-mdm-install-softwareupdate-only

Restrict app installations to MDM-installed apps and software updates

booleanRestrict app installations to MDM-installed apps and software updates