Endpoint configuration · GraphQL type

SystemSettingsMacOS type

macOS-specific system settings including power management, privacy permissions, backup configuration, and security settings. Per-user preferences (screen saver locking, Universal Control, Siri and search data sharing) live on UserSystemSettingsMacOS.

Fields

Field Name Description
powerProfile - PowerProfile Power management profile with battery and AC power source settings.
locationServiceClients - [LocationServiceClient!] Applications registered with the location services daemon.
privacyPermissions - [PrivacyPermission!] TCC (Transparency, Consent, and Control) privacy permission entries.
lockScreenSettings - LockScreenSettings Lock screen and login window settings.
backupConfiguration - BackupConfiguration Time Machine backup configuration and destination encryption state.
printerSharingEnabled - Boolean! Whether printer sharing is enabled on the system.
authorizationRights - [AuthorizationRight!] Authorization rights from the Security framework authorization database.
hotCornerSettings - HotCornerSettings Hot corner action assignments for each screen corner.
locationServicesEnabled - Boolean Whether location services are enabled system-wide.
showLocationSystemServices - Boolean Whether the location services status bar icon is shown for system services.
analyticsSharingEnabled - Boolean Whether analytics sharing with Apple is enabled.
fileVaultDisableRestricted - Boolean Whether FileVault disable is restricted by policy.
isGatekeeperEnabled - Boolean! Whether Gatekeeper is enabled, preventing unsigned or unnotarized applications from running.
isNetworkTimeEnabled - Boolean! Whether network time synchronization (NTP) is enabled.
getRemoteAppleEvents - Boolean! Whether remote Apple events are accepted from other machines.
forceInternetSharingOff - Boolean Whether Internet Sharing is forced off by policy.
bonjourAdvertisingDisabled - Boolean Whether Bonjour multicast advertising is disabled.
automaticLoginEnabled - Boolean Whether a user is automatically logged in at boot without entering a password (the autoLoginUser setting of the login window). CIS recommends automatic login be disabled.
installLogRetention - Duration How long entries in the system install log (/var/log/install.log) are retained, from the ttl setting of the asl(5) configuration at /etc/asl/com.apple.install. CIS recommends retaining install.log entries for at least 365 days.
xProtectLaunchScansEnabled - Boolean Whether XProtect malware scanning of applications at launch is enabled.
xProtectBackgroundScansEnabled - Boolean Whether XProtect background malware scanning is enabled.
csrFlags - [CSRFlag!] System Integrity Protection (SIP) bypass flags decoded from the CSR bitmask. Each entry is a protection that is currently bypassed. An empty or null list indicates SIP is fully enabled.
guestHomeFolderExists - Boolean! Whether the guest home folder (/Users/Guest) exists on the system.
isAMFIEnabled - Boolean Whether Apple Mobile File Integrity (AMFI) is enabled.
loginWindowBannerExists - Boolean! Whether a login window policy banner message file exists on the system.
sudoConfig - SudoConfig Sudo configuration parsed from sudo -V output.

Used by

Example

Example

{
  "powerProfile": PowerProfile,
  "locationServiceClients": [LocationServiceClient],
  "privacyPermissions": [PrivacyPermission],
  "lockScreenSettings": LockScreenSettings,
  "backupConfiguration": BackupConfiguration,
  "printerSharingEnabled": true,
  "authorizationRights": [AuthorizationRight],
  "hotCornerSettings": HotCornerSettings,
  "locationServicesEnabled": false,
  "showLocationSystemServices": true,
  "analyticsSharingEnabled": false,
  "fileVaultDisableRestricted": true,
  "isGatekeeperEnabled": false,
  "isNetworkTimeEnabled": true,
  "getRemoteAppleEvents": true,
  "forceInternetSharingOff": false,
  "bonjourAdvertisingDisabled": false,
  "automaticLoginEnabled": false,
  "installLogRetention": "600000000",
  "xProtectLaunchScansEnabled": true,
  "xProtectBackgroundScansEnabled": false,
  "csrFlags": ["ALLOW_APPLE_INTERNAL"],
  "guestHomeFolderExists": true,
  "isAMFIEnabled": false,
  "loginWindowBannerExists": false,
  "sudoConfig": SudoConfig
}