Skip to content

Kernel Extension Policy macOS

This payload sets the kernel extension policy on a macOS device. Use it to allow kernel extensions from specific developers (team identifiers) or with specific bundle identifiers to load without the user having to approve them. In the Profile Editor it’s listed as Kernel Extension, and it can only be added once in a profile.

Separate multiple values with semicolons (;).

Setting Description Example
Users can approve additional kernel extensions Lets users approve kernel extensions that aren’t explicitly allowed by configuration profiles.
Allowed team identifiers The team identifiers of the developers whose validly signed kernel extensions are allowed to load. VB5E2TV963 ; EG7KH642X6
Allowed Kernel Extensions Specific kernel extensions that are allowed to load. Write each team identifier followed by a colon (:) and its bundle identifiers separated by commas (,). End each team identifier entry with a semicolon (;). EG7KH642X6 : com.vmware.kext.vmnet, com.vmware.kext.vmx86 ;
Allowed unsigned bundle identifiers The bundle identifiers of unsigned kernel extensions that are allowed to load. com.ATTO.driver.ATTOCelerityFC8 ; com.malwarebytes.mbam.rtprotection