Endpoint configuration · GraphQL type

UserSystemSettingsMacOS type

macOS-specific per-user system settings read from the user's own preference domains (~/Library/Preferences) and local account record, covering screen saver locking, Universal Control, Siri and search data sharing, Bluetooth sharing, the user's location daemon preference, and password hint presence.

Fields

Field Name Description
idleTime - Duration Idle time (in minutes) before this user's screen saver activates or the screen locks.
askForPassword - Boolean Whether this user requires a password after sleep or screen saver begins.
universalControlEnabled - Boolean Whether Universal Control is enabled for cross-device input sharing for this user.
searchDataSharingEnabled - Boolean Whether search data sharing with Apple is enabled for this user.
siriDataSharingOptIn - SiriDataSharingOptInStatus Siri data sharing opt-in status for this user. See SiriDataSharingOptInStatus.
siriVoiceTriggerEnabled - Boolean Whether the Siri voice trigger ("Hey Siri") is enabled for this user.
siriVoiceFeaturesEnabled - Boolean Whether Siri voice features are enabled for this user.
bluetoothSharingEnabled - Boolean Whether Bluetooth Sharing is enabled for this user (ByHost com.apple.Bluetooth preference). CIS recommends Bluetooth Sharing be disabled.
locationDaemonEnabled - Boolean Whether the location daemon (locationd) is enabled in this user's global preferences.
hasPasswordHint - Boolean Whether this user's local account has a password hint set (a non-empty hint attribute in the user's directory services record). CIS recommends that user accounts do not have a password hint.

Used by

  • UserSystemSettings type: The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.
  • UserSystemSettingsOsSpecific union: OS-specific per-user system settings union type.

Example

Example

{
  "idleTime": "600000000",
  "askForPassword": true,
  "universalControlEnabled": true,
  "searchDataSharingEnabled": true,
  "siriDataSharingOptIn": "OPTED_IN",
  "siriVoiceTriggerEnabled": true,
  "siriVoiceFeaturesEnabled": false,
  "bluetoothSharingEnabled": false,
  "locationDaemonEnabled": false,
  "hasPasswordHint": true
}