PayloadKit

Login Window

com.apple.loginwindow

The payload that configures Login Window behavior.

macOS
macOS 10.7+combined

Configuration Keys (37)

KeyTypeTitle
PFC_SegmentedControl_0required
string
AdminHostInfo

The admin host info. If present in the payload, the system displays its value in the Login Window as additional computer information. Before macOS 10.10, this string could only contain host name, system version, or IP address. After macOS 10.10, setting this key to any value allows the user to click the time area of the menu bar to toggle through various computer information values.

Default: "HostName"

Range: HostName, SystemVersion, IPAddress

stringShow additional information in the menu bar
LoginwindowText

The text to display in the Login Window.

stringBanner
SHOWFULLNAME

If 'true', the system shows the name and password dialog. If 'false', the system displays a list of users.

Default: false

booleanDisplay login window as
HideLocalUsers

If 'true', the system shows only network and system users when showing a user list.

Default: false

booleanShow local users
HideMobileAccounts

If 'true', the system hides mobile account users in a user list. In some cases, mobile users show up as network users.

Default: false

booleanShow mobile accounts
IncludeNetworkUser

If 'true', the system shows network users when showing a user list.

Default: false

booleanShow network users
HideAdminUsers

If 'true', the system hides administrator users when showing a user list.

Default: false

booleanShow Mac computer's administrator accounts
SHOWOTHERUSERS_MANAGED

If 'true', the system displays "Other..." when it shows a list of users.

Default: false

booleanShow "Other"
SleepDisabled

If 'true', the system disables the Sleep button.

Default: false

booleanShow the Sleep button
RestartDisabled

If 'true', the system disables the Restart item.

Default: false

booleanShow the Restart button
ShutDownDisabled

If 'true', the system disables the Shut Down button.

Default: false

booleanShow the Shut Down button
RestartDisabledWhileLoggedIn

If 'true', the system disables the Restart menu item when the user is logged in.

Default: false

booleanDisable the Restart menu item while logged in
ShutDownDisabledWhileLoggedIn

If 'true', the system disables the Shut Down menu item when the user is logged in.

Default: false

booleanDisable the Shut Down menu item while logged in
PowerOffDisabledWhileLoggedIn

If 'true', the system disables the Power Off menu item when the user is logged in.

Default: false

booleanDisable the Power Off menu item while logged in
LogOutDisabledWhileLoggedIn

If 'true', the system disables the Log Out menu item when the user is logged in. Available in macOS 10.13 and later.

Default: false

booleanDisable the Log Out menu item while logged in
DisableScreenLockImmediate

If 'true', the system disables the immediate Screen Lock functions. Available in macOS 10.13 and later.

Default: false

booleanDisable the immediate Screen Lock function
com.apple.login.mcx.DisableAutoLoginClient

A loginwindow password will be required to login.

Default: true

booleanDisable automatic login if FileVault is disabled
AutologinUsername

The user short name for an existing user to set up auto login.

string
AutologinPassword

An optional user password to set up auto login. This must match the 'AutologinUsername' user's current password.

string
DisableFDEAutoLogin

If 'true', the system disables the automatic login option when using FileVault.

Default: false

booleanDisable automatic login if FileVault is enabled
DisableConsoleAccess

If 'true', the system disregards the '>console' special user name, which provides a command line UI.

Default: false

booleanEnable >console login
EnableExternalAccounts

Allows external accounts to log in.

Default: true

booleanEnable external accounts
AdminMayDisableMCX

Allows Mac administrators on the computer to refresh or disable the management features.

Default: true

booleanMac computer administrators may refresh content or disable management
TALLogoutSavesState

Reopens windows that were open at time of logout

Default: true

booleanReopen windows when logging back in
UseComputerNameForComputerRecordName

Forces the name of the Mac to be set as the computer record name.

Default: true

booleanSet Mac computer name to computer record name
AllowList

The list of user GUIDs or group GUIDs of users that the system allows to log in. An asterisk ('*') string specifies all users or groups. This only applies to network accounts and mobile accounts.

arrayAllowed Users or Groups
DenyList

The list of user GUIDs or group GUIDs of users that the system disallows to log in. This list takes priority over the list in the 'AllowList' key. This only applies to network accounts and mobile accounts.

arrayDenied Users or Groups
LocalUserLoginEnabled

Permit only local users to log in. Network users won't be allowed to log in.

booleanLocal-only users may log in
LocalUsersHaveWorkgroups

Local users are forced to use any available workgroup settings.

booleanLocal-only users use available workgroup settings
FlattenUserWorkgroups

If users are part of a nested workgroup, only the settings of the user's workgroup are enforced.

booleanIgnore workgroup nesting
CombineUserWorkgroups

If users are part of a nested workgroup, all nested workgroup settings are enforced.

booleanCombine available workgroup settings
AlwaysShowWorkgroupDialog

If the workgroup has a specific dialog, that dialog is shown when users log in.

booleanAlways show workgroup dialog during log in
ChangePasswordDisabled

Enable or disable the "Change Password…" button in the Users & Groups preference pane.

booleanAllow user to change password
RetriesUntilHint

Number of tries until password hint is shown (0 = disable password hints).

integerShow password hints after failed attempts
showInputMenu

If 'true', the system shows the Input Menu in the Login Window.

Default: false

booleanShow input menu in login window
HiddenUsersList

Hides users defined in the list from the login window under the Other button

arrayHidden Users List
AllowListItemrequired

A user or group GUID.

stringUser or Group GUID
DenyListItemrequired

A user or group GUID.

stringUser or Group GUID
username
stringUsername