Blueprints Components Reference - Jamf Pro Blueprints Configuration Guide

Jamf Pro Blueprints Configuration Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
ComponentDescriptionRequirementsNotes
AI Governance

AI Governance policy components are organized by product in the Components library, meaning that multiple policies exist inside of a single component. For example, if you created two separate policies for Claude Code, only one Claude Code component will appear in the Components library.

For more information on creating AI Governance policies to deploy via blueprints, see AI Policies in the AI Governance Configuration Guide.

App SettingsControl which apps and binaries can run, and set app privacy permission defaults

macOS 27* or later, supervised

iOS 27* or later, supervised

iPadOS 27* or later, supervised

tvOS 27* or later, supervised

visionOS 27* or later, supervised

*Feature support is based on testing with the latest Apple beta releases.

Configure app settings such as:

  • Allowed and denied mobile device apps, identified by bundle ID
  • Allowed and denied binaries for macOS applications, identified by code signature
  • App privacy permission defaults for camera, microphone, location, and other subsystems
Note:

On macOS, app privacy permission defaults in the App Settings component are installed via the declarative device management user channel and require a macOS user that is MDM-enabled. Allowed and denied binaries are installed via the system channel and do not have the same requirement.

For more information, see MDM-Enabled Local User Accounts in the Jamf Pro Documentation.

Audio accessory settings

Configure settings for temporarily pairing audio accessories

  • iOS 26 or later, supervised

  • iPadOS 26 or later, supervised

Temporarily pair audio accessories without syncing pairing information with iCloud and automatically unpair audio accessories at a set time each day.

Configuration profile payloads

In the component library list, configuration profile payloads are identified by the label "Legacy payload".

If you previously deployed a configuration profile to a device and then deploy a blueprint that contains conflicting keys, unexpected behavior may occur. For example, if keys within the Restrictions payload conflict, the most restrictive setting will take precedence.

The configuration profiles delivered through the blueprints service are not signed by the Jamf Pro built-in certificate authority (CA). This is by design, as the declarative device management protocol prevents declarative payload tampering within the network and on the device.

To mitigate end user concerns that may be caused by the red "Unsigned" label, these payloads are now labeled as "Not signed" in gray text beginning with macOS 26, iOS 26, iPadOS 26, watchOS 26, visionOS 26, and tvOS 26.

Content Cache Settings

Configure the content caching service on Mac computers

macOS 27* or later

*Feature support is based on testing with the latest Apple beta releases.

Manage the content caching service declaratively to reduce the bandwidth consumed by Apple software updates, apps, and iCloud data. Configure Content Caching settings such as:

  • Automatic activation of the service
  • Personal and shared content caching
  • Cache size limits and the storage location
  • Client and peer IP address ranges
  • Parent content caches and the parent selection policy
  • Status reporting to a management server

Only one Content Cache Settings configuration applies to a computer. If more than one blueprint containing this component is scoped to the same computer, the settings do not combine.

Important:

Some settings suppress others. For example, if Local subnets only is set to True, the computer ignores Listen ranges. If Peer local subnets only is set to True, it overrides both Peer filter ranges and Peer listen ranges. Both settings default to True, so review them before you configure IP address ranges.

Note:

Removing a blueprint that set Auto activation to True does not deactivate Content Caching on the computer.

Custom Declarations

Custom declarative device management configurations allow you to define advanced settings tailored to specific needs, offering unmatched flexibility and control. With these custom configurations, you can configure options beyond the standard blueprint capabilities, enabling advanced functionality that supports unique use cases. For more information, see Creating a Custom Declaration Blueprint.

Important:

Misconfigurations can lead to unintended behavior, affecting device performance and security. Jamf recommends only using custom declarations if you have an advanced understanding of Apple's declarative device management protocol and testing custom declarations in a sandbox environment before deploying to a production environment. For more information, see Use declarative device management to manage Apple devices in Apple Platform Deployment.

Disk management policy

Configure restriction levels for external storage and network storage

macOS 15 or later, supervised

Permit or deny the device to mount external USB or network drives

External Intelligence Settings

Configure interaction with external intelligence integrations

  • macOS 26.4 or later, supervised

  • iOS 26.4 or later, supervised

  • iPadOS 26.4 or later, supervised

  • visionOS 26.4 or later, supervised

Disable external integrations entirely, prevent users from signing in to external intelligence services, or restrict usage to a specific approved workspace by specifying an allowed workspace ID. When a workspace ID is specified, users are required to sign in before making requests to that integration.

Note:

On macOS, the Allow External Intelligence Integrations and Allow External Intelligence Integrations Sign In settings are not applied in External Intelligence Settings declarations when using the default values. Other settings in the declaration are enforced as expected. This is a known Apple issue.

Intelligence Settings

Configure Apple Intelligence settings

  • macOS 26.4 or later, supervised

  • iOS 26.4 or later, supervised

  • iPadOS 26.4 or later, supervised

  • visionOS 26.4 or later, supervised

Disable system-wide features individually, such as Writing Tools, Genmoji, Image Playground, Image Wand, and Visual Intelligence Summary. You can also restrict AI-powered features within specific apps, including Mail Smart Replies, Mail Summary, Notes Transcription, Notes Transcription Summary, and Safari Summary. Additionally, you can require that dictation and translation are processed on-device only, preventing data from being sent to external servers.

Keyboard Settings

Configure keyboard settings

  • macOS 26.4 or later, supervised

  • iOS 26.4 or later, supervised

  • iPadOS 26.4 or later, supervised

Disable features individually, including auto-correction, predictive text, spell check, text replacement, slide to type, definition lookup, dictation, and math keyboard suggestions.

Math settings

Configure settings for the calculator app and system behavior

  • macOS 15 or later, supervised

  • iOS 18 or later, supervised

  • iPadOS 18 or later, supervised

Configure calculator settings such as:
  • Scientific mode

  • Unit conversion

  • Math Notes

Package

Configure a package

macOS 26 or later

Installs a signed package on Mac computers using a manifest URL that points to the package file. Supports optional installation or required installation.

For more information, see Configuring the Package Component.

Passcode policy

Configure passcode policy settings

  • macOS 13 or later

  • iOS 15 or later

  • iPadOS 15 or later

  • visionOS 2.0 or later

Configure password settings such as:
  • Passcode complexity
  • Passcode length
  • Login attempts If you have an existing profile with a Passcode payload and scope this component to the same devices, the most restrictive settings will apply.
  • Custom regex
Safari bookmarks

Configure managed bookmarks for Safari

  • macOS 26 or later, supervised

  • iOS 26 or later, supervised

  • iPadOS 26 or later, supervised

  • visionOS 26 or later, supervised

Configure managed bookmarks for Safari by creating a bookmark folder containing a list of bookmarks that cannot be edited or deleted by users.

Safari extensions

Configure the extensions end users can use with Safari

  • macOS 15 or later, supervised

  • iOS 18 or later, supervised

  • iPadOS 18 or later, supervised

Manage which Safari extensions are allowed, always on, or always off. Managed extensions can also be allowed or denied access to specific domains.

Safari settings

Configure Safari settings on mobile devices

  • macOS 26 or later, supervised

  • iOS 26 or later, supervised

  • iPadOS 26 or later, supervised

  • visionOS 26 or later, supervised

Configure Safari settings such as:
  • Cookie management policy
  • Fraud warnings
  • History clearing
  • JavaScript
  • Pop-ups
  • Private browsing
  • Content summarization
  • Start page for new tabs
Screen Sharing: Connection

Configure screen sharing connections on macOS

macOS 14 or later, supervised

Configure screen sharing connections on macOS by defining the remote host, connection details, credentials, and display behavior. This declarative configuration ensures secure and consistent screen sharing access across managed Mac computers.

Screen Sharing: Connection Group

Bundle multiple Screen Sharing: Connection configurations

macOS 14 or later, supervised

Bundle multiple Screen Sharing: Connection configurations into a single, named group that appears in the Screen Sharing app.

Screen Sharing: Host Settings

Configure screen sharing host behavior and restrictions

macOS 14 or later, supervised

Configure screen sharing host behavior and restrictions on managed Mac computers. You can limit the maximum number of virtual displays available to connecting clients, define the base UDP port for screen sharing connections, and restrict file transfer capabilities by preventing users from copying files to or from the host. You can also prevent clients from establishing high-performance connections to the host.

Seamless Learning Access

iPadOS 18.0 or later

Seamless Learning Access is a single sign-on capability that silently authenticates students and educators into learning apps on managed iPad devices. The capability is delivered through a Seamless Learning Access single sign-on extension which integrates with RapidIdentity, a cloud-based Identity and Access Management (IAM) platform built specifically for Ed Tech ecosystems. For more information, see Seamless Learning Access in the RapidIdentity Platform Documentation.

Self Service+

Configure administrator controls for Self Service+

macOS 15.0 or later

Administrator controls in the Self Service+ component let you manage the app across three areas:
  • Home screen content
  • Side navigation content
  • Configuration content

For more information on the available administrator controls, see Self Service+ for macOS Settings Reference in the Self Service+ for macOS Deployment Guide.

Service background tasks

Configure background task management on devices

macOS 15 or later, supervised

Control managed settings for background tasks and launch items in a tamper-resistant way.

This configuration requires a ZIP archive file that exactly matches the target service's file structure. This file must be hosted on your trusted HTTPS delivery URL and the configuration must also include a SHA-256 hash of the file.

Service configuration files

Configure Apple built-in services on devices

macOS 14 or later, supervised

Control managed settings for system services in a tamper-resistant way.

This configuration requires a ZIP archive file that exactly matches the target service's file structure. This file must be hosted on your trusted HTTPS delivery URL and the configuration must also include a SHA-256 hash of the file.

Managed services are:

  • sshd
  • sudo
  • PAM
  • CUPS
  • Apache httpd
  • bash
  • zsh
  • CryptoTokenKit
  • Authorization
Note:

CryptoTokenKit and Authorization require macOS 26.1 or later.

Siri Settings

Configure Siri settings

  • macOS 26.4 or later, supervised

  • iOS 26.4 or later, supervised

  • iPadOS 26.4 or later, supervised

  • visionOS 26.4 or later, supervised

  • watchOS 26.4 or later, supervised

Disable Siri entirely, prevent Siri from being used while a device is locked, disable user-generated content in Siri responses, and enforce a profanity filter for Siri output.

Note:

On macOS and iOS, Siri Settings declarations that include the Force Profanity Filter setting fail to apply. This is a known Apple issue.

Software Update Settings

Configure aspects of the software update process

  • macOS 15 or later, supervised

  • iOS 18 or later, supervised

  • iPadOS 18 or later, supervised

  • tvOS 18.4 or later, supervised

Enable comprehensive software update management by allowing administrators to control user permissions, customize update presentations, manage beta program enrollment, configure deferral periods, and manage Background Security Improvements. For more information, see Configuring the Software Update Settings Component.

Settings configured in this component will override equivalent settings in existing configuration profiles rather than merging with them. For example:
  • The Allow standard users to install software updates setting overrides the existing setting in the Software update payload.

  • The Recommended cadence setting overrides any existing settings that were previously defined by the Recommend Software Update Version MDM command.

  • All install actions override any update deferral setting in the Software Update payload.

  • All deferrals override any update deferral setting in the Restrictions payload.

  • Background Security Improvements setting (previously the Rapid Security Response setting) overrides the existing settings in the Restrictions payload. Additionally, specifying an OS version in the Software Update Settings component automatically installs any Background Security Improvements for that version.

  • The Beta updates setting overrides the existing settings in the Software Update payload.
    Note:

    To configure beta updates, you need the beta enrollment tokens that are available for your organization from Apple Business or Apple School Manager. For more information on retrieving a token from Apple, see Testing software updates with the AppleSeed for IT beta program in Apple Platform Deployment.

Software Updates

Configure software update enforcement

  • macOS 14 or later, supervised

  • iOS 17 or later, supervised

  • iPadOS 17 or later, supervised

  • tvOS 18.4 or later

  • visionOS 26 or later

Configure software update settings such as:
  • Set the date and time of the update
  • Specify the target OS version
  • Provide a webpage URL that provides details about the software update
  • Schedule updates up to 30 days after Apple releases a new OS at any local time
Note:

When the enforcement type is set to Latest OS version, declarations for every available minor OS version are sent and the device incrementally upgrades through each version before it upgrades to the latest minor version it is eligible for. For more infomation, see Configuring the Software Updates Component.

Note:

Blueprints that include the Math settings, Safari bookmarks, Safari extensions, or Safari settings components are installed on macOS devices via the declarative device management user channel and require a macOS user that is MDM-enabled. For more information, see MDM-Enabled Local User Accounts in the Jamf Pro Documentation.