Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Property List checks in Trust Profile

In this document
  • General Notes
    • Writing the Domain
    • Key Names
  • Preference domain exists
  • Preference key exists
  • Preference key

Property List checks read macOS preferences, the settings that the defaults command and MDM configuration profiles work with. They are the macOS equivalent of the Windows registry checks and work the same way.

Supported platforms: [macOS]

General Notes

Writing the Domain

The Domain field accepts the same forms as the defaults command:

  • a preference domain name, for example com.microsoft.wdav

  • the path of a .plist file, with or without the .plist extension, for example /Library/Preferences/com.apple.loginwindow. Anything containing / is treated as a path.

  • NSGlobalDomain for the global domain

A domain name is looked up first in /Library/Managed Preferences and then in /Library/Preferences, and the first location that has it is used. Managed Preferences come first because that is where MDM configuration profiles are installed. A check that asks whether a policy is in force therefore sees the policy.

Important
Only machine-wide preferences are read. Preferences stored in a single user’s ~/Library/Preferences are not visible to these checks.

Key Names

The Key field accepts:

  • an exact key name

  • a glob pattern, for example Allow*

  • __ANY__ to look at every key in the domain

With a pattern or __ANY__, the check passes when at least one matching key satisfies it. Only top-level keys are looked at. A key that holds a dictionary is not searched inside.

trust profile mac property check

Preference domain exists

Platforms

[macOS]

Comparison

None

Fields

Domain (required)

Passes when the preference domain exists. This is a quick way to confirm that an MDM configuration profile for a product has been installed.

Example
  • com.microsoft.wdav

Preference key exists

Platforms

[macOS]

Comparison

None

Fields

Domain (required), Key (required)

Passes when the key exists in the domain. The value is not read.

Preference key

Platforms

[macOS]

Comparison

equals, does not equal, is less than, is less than or equal, is greater than, is greater or equal, starts with, ends with, contains, matches (glob)

Fields

Domain (required), Key (required), Compared with (required)

Reads a preference and compares it with the text in Compared with.

Table 1. How the value type affects the comparison
Preference type Comparison

String

Compared as text. The ordering comparisons are version-aware, so 1.9 is less than 1.10.

Number

Compared as a number. Comparing a number with text that is not a number reports an error.

Boolean

Matches true, yes or 1, and false, no or 0.

Array

The check passes when at least one element satisfies it. NOT equals X means the list does not contain X.

Date, Data

Cannot be compared. The check reports an error.

Table 2. Examples
Domain Key Comparison Compared with

com.microsoft.wdav

userInterface

equals

true

com.apple.loginwindow

DisableGuestAccount

equals

true

com.apple.SoftwareUpdate

AutomaticallyInstallMacOSUpdates

equals

true

When the key is missing

If the domain or key does not exist, Preference key fails for every comparison, including does not equal. Add Preference key exists when you need to decide what happens to a missing key. The Registry article describes the same pattern for Windows.

Tip
To see a domain’s current values, run defaults read <domain> in Terminal. For managed preferences, run sudo defaults read "/Library/Managed Preferences/<domain>".
www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013