Kernel Extension Policy macOS
Description
Section titled “Description”This payload sets the kernel extension policy on a macOS device. Use it to allow kernel extensions from specific developers (team identifiers) or with specific bundle identifiers to load without the user having to approve them. In the Profile Editor it’s listed as Kernel Extension, and it can only be added once in a profile.
Configuration
Section titled “Configuration”Separate multiple values with semicolons (;).
| Setting | Description | Example |
|---|---|---|
| Users can approve additional kernel extensions | Lets users approve kernel extensions that aren’t explicitly allowed by configuration profiles. | |
| Allowed team identifiers | The team identifiers of the developers whose validly signed kernel extensions are allowed to load. | VB5E2TV963 ; EG7KH642X6 |
| Allowed Kernel Extensions | Specific kernel extensions that are allowed to load. Write each team identifier followed by a colon (:) and its bundle identifiers separated by commas (,). End each team identifier entry with a semicolon (;). |
EG7KH642X6 : com.vmware.kext.vmnet, com.vmware.kext.vmx86 ; |
| Allowed unsigned bundle identifiers | The bundle identifiers of unsigned kernel extensions that are allowed to load. | com.ATTO.driver.ATTOCelerityFC8 ; com.malwarebytes.mbam.rtprotection |