Skip to main content

Create a User Level macOS App Settings Privacy Policy

The App Settings Privacy policy lets you recommend privacy permission defaults for one or more applications on managed Mac computers. When a matching application launches, macOS can show a consent prompt that includes your organization justification and the defaults you configured. The User can allow those defaults or continue with the standard macOS permission prompts.

note

This is a user-level policy. It applies to an eligible Mobile Device Management (MDM)-enabled User on a supervised Mac. You can bind this policy to individual users or user groups.

Prerequisites​

  • Apple MDM must be configured for your organization, and Mac computers must be enrolled in JumpCloud MDM. See Set up Apple MDM.
  • Target Mac computers must use supervised enrollment.
  • Target Mac computers must run macOS 27 or later.
  • Assign the policy to an eligible JumpCloud User or user group so the MDM-enabled User on the Mac receives the policy.

Considerations​

  • Policy settings apply automatically. No restart is required.
  • If the User has already seen all configured permission requests for an application, macOS does not show the App Settings consent prompt again for those permissions.
  • On macOS, While using for Location is equivalent to Always.

Creating the Policy​

Configure the policy below, then select target groups or users to apply it.

Selecting the Policy Template​

  1. Log in to the JumpCloud Admin Portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Device Management > Policy Management. The Policy Management page is displayed.
  2. On the Policy Management page, click (+) Add New.
  3. Select User Policy.
  4. Select the macOS tab.
  5. Search for and select App Settings Privacy, then click Configure.
  6. On the Details tab, review the policy summary and configure the settings described below.
  7. (Optional) In the Policy name field, enter a unique name for the policy, or keep the default App Settings Privacy.
  8. (Optional) In the Policy notes field, enter details such as the creation date and deployment notes.

The Details tab also includes Policy groups, User groups, and Users tabs for assignment.

note

The right-hand panel lists Supported operating system as macOS 27 or later, Policy scope as User, and Supported enrollment as Supervised enrollment.

Reviewing the Policy Summary​

On the Details tab, JumpCloud shows:

SectionWhat it explains
Policy descriptionRecommends privacy permission defaults for matching applications on macOS 27 or later.
Policy behaviorWhen a matching application launches, macOS shows a consent prompt with the organization justification and configured defaults. The User can allow the defaults or continue with the standard permission prompts.
Policy activationApplies when assigned to an eligible MDM-enabled User on a supervised Mac. No restart is required.

Configuring Applications​

Under Applications, set the privacy permission defaults macOS recommends when each application launches.

Adding an Application​

  1. Click Add application.
  2. A new application configuration appears (for example, Application 1).
  3. Configure the fields and privacy permissions for that application.
  4. (Optional) Click Add application again to add another independent application configuration.

Each application has its own App bundle ID, Organization justification, and permission selections. Removing one application does not change the settings of another application.

Configuring Application Fields​

FieldRequiredDescription
App bundle IDYesThe reverse-DNS identifier for the application. Placeholder example: com.example.application.
Organization justificationYesThe organization's explanation for requesting the selected permission defaults. The Mac includes this text in Apple's consent prompt when the application launches.
note

You cannot save the policy when Organization justification is empty or contains only whitespace.

App Bundle ID Validation​

JumpCloud validates each App bundle ID before you can save the policy:

  • The value cannot be empty.
  • Leading and trailing whitespace is removed.
  • Spaces are not permitted within the value.
  • Only letters A-Z and a-z, numbers 0-9, hyphens (-), and periods (.) are permitted.
  • The value must use reverse-DNS format with dot-separated components, such as com.example.application.
  • The value cannot begin or end with a period.
  • The value cannot contain consecutive periods.
  • Empty components are not permitted.
  • Bundle ID comparisons are case-insensitive.
  • The same bundle ID cannot be added more than once in the policy.

If the value is invalid, JumpCloud displays:

Enter a valid App Bundle ID using reverse-DNS format, such as com.example.application. Use only letters, numbers, hyphens, and periods.

You cannot save the policy while an application contains an invalid or duplicate App bundle ID.

Configuring Privacy Permissions​

Under Privacy permissions, select the privacy permissions this policy should recommend. For each permission, choose a value from the drop-down list. Free-form values are not accepted.

PermissionAvailable values
AccessibilityNone, Allow
BluetoothNone, Allow
CameraNone, Allow
DictationNone, Allow
Local networkNone, Allow
LocationNone, While using, Always
MicrophoneNone, Allow

At least one permission must be set to a value other than None. If every permission remains None, JumpCloud displays:

Select at least one privacy permission for this application.

Important

Location Accuracy is not shown on the macOS policy. Apple supports that setting only on iOS and iPadOS.

Removing an Application​

  1. Open the application configuration you want to remove.
  2. Click Remove application.

Settings for other applications in the policy remain unchanged.

Applying the Policy​

  1. (Optional) Select the Policy groups tab and select one or more policy groups.
  2. Select the User groups tab and select the user groups that should receive this configuration. For user groups with multiple OS member types, the policy applies only when a User signs in on a supported, supervised Mac that is enrolled in Apple MDM.
  3. Or select the Users tab and select one or more Users.
  4. Click Create policy. A success message is displayed when policy creation completes.
note

Assigning this policy only to a device or device group, without an eligible user-level assignment, does not cause the policy to be reported as successfully applied.

Viewing Policy Status​

  1. Open the saved policy.
  2. Select the Status tab.
  3. Review results for assigned Users or devices through the existing policy results workflow.

JumpCloud distinguishes unsuccessful outcomes such as unsupported OS, enrollment issues, missing user binding, schema problems, and delivery errors from successful activation.

note

A successful activation result means the configuration was delivered. It is not proof that the User selected Allow on the consent prompt.

Was this information helpful?