# Add a new Extensible SSO payload configuration to an existing profile To create Mac Extensible SSO policy ## Endpoints **POST** `/api/v1/mdm/profiles/{profile_id}/payloads/macextensiblessopolicy` ## Request URL `https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/macextensiblessopolicy` ## Scope `MDMDeviceMgmt.CREATE` ## Header `Authorization: d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers - **Content-Type** (string, Mandatory): `application/json` - **Accept** (string, Mandatory): `application/json` ### Path Parameters - **profile_id** (string, Mandatory): Unique identifier of the profile. Obtain from the [Create Profile](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mdm-profiles-create-profile.html) or [Get Profiles](https://www.manageengine.com/products/desktop-central/help/api/onpremise/mdm-profiles-get-profile.html) response. ### Request Body `application/json` - **extension_identifier** (string, Mandatory): Bundle identifier of the app extension that provides Single Sign-On (e.g., `com.apple.AppSSOKerberos.KerberosExtension`) - **team_identifier** (string, Mandatory): Apple Developer Team identifier of the app extension - **type** (integer, Mandatory): SSO extension type. Allowed values: `0=Credential (Kerberos)`, `1=Redirect` - **realm** (string, Mandatory): Kerberos realm name (e.g., `ZYLKER.COM`). Required when type is `0` (Credential), must be empty when type is `1` (Redirect) - **authentication_method** (integer, Mandatory): Authentication method for Platform SSO. Allowed values: `-1=Not Configured`, `0=Password`, `1=User Secure Enclave Key` - **screen_locked_behavior** (integer, Mandatory): Behavior when SSO is requested while the screen is locked. Allowed values: `-1=Not Configured`, `0=Cancel`, `1=Do Not Handle` - **extension_data** (string, Mandatory): Custom configuration data for the SSO extension in Apple property list XML format - **registration_token** (string, Mandatory): Token used for Platform SSO registration. When provided, authentication_method must also be configured - **hosts_and_urls** (array, Mandatory): List of identity provider URL prefixes that the SSO extension handles (at least one required) - **denied_apps_details** (JSON Array, Mandatory): List of apps excluded from using this SSO extension. Each item requires an app_group_id. ## Sample Request ```curl curl --request POST \ --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/macextensiblessopolicy \ --header 'Accept: application/json' \ --header 'Authorization: d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/json' \ --data '{"authentication_method":-1,"hosts_and_urls":["https://login.zylker.com"],"extension_identifier":"com.apple.AppSSOKerberos.KerberosExtension","screen_locked_behavior":-1,"extension_data":"helpURLhttps://zylker.com/help","team_identifier":"apple","realm":"ZYLKER.COM","registration_token":"","type":0,"denied_apps_details":[{"app_group_id":9007199254741072}]}' ``` ### Sample Request Body Add Extensible SSO payload to the profile ```json { "authentication_method": -1, "hosts_and_urls": [ "https://login.zylker.com" ], "extension_identifier": "com.apple.AppSSOKerberos.KerberosExtension", "screen_locked_behavior": -1, "extension_data": "helpURLhttps://zylker.com/help", "team_identifier": "apple", "realm": "ZYLKER.COM", "registration_token": "", "type": 0, "denied_apps_details": [ { "app_group_id": 9007199254741072 } ] } ``` ## Response Parameters ### HTTP Code 200 Response Body: `application/json` - **payload_id** (long): Unique identifier for the created payload item - **extension_identifier** (string): Bundle identifier of the app extension that provides Single Sign-On - **team_identifier** (string): Apple Developer Team identifier of the app extension - **type** (integer): SSO extension type. Allowed values: `0=Credential (Kerberos)`, `1=Redirect` - **realm** (string): Kerberos realm name. Empty when type is `1` (Redirect) - **authentication_method** (integer): Authentication method for Platform SSO. Allowed values: `-1=Not Configured`, `0=Password`, `1=User Secure Enclave Key` - **screen_locked_behavior** (integer): Behavior when SSO is requested while the screen is locked. Allowed values: `-1=Not Configured`, `0=Cancel`, `1=Do Not Handle` - **extension_data** (string): Custom configuration data for the SSO extension in Apple property list XML format - **registration_token** (string): Token used for Platform SSO registration - **hosts_and_urls** (array): List of identity provider URL prefixes that the SSO extension handles - **denied_apps_details** (JSON Array): List of apps excluded from using this SSO extension, with resolved app details ## Possible Response Codes - **200** (HTTP code) ## Sample Response: HTTP 200 Extensible SSO payload successfully added ```json { "authentication_method": -1, "hosts_and_urls": [ "https://login.zylker.com" ], "extension_identifier": "com.apple.AppSSOKerberos.KerberosExtension", "payload_id": 9007199254741000, "screen_locked_behavior": -1, "extension_data": "helpURLhttps://zylker.com/help", "team_identifier": "apple", "realm": "ZYLKER.COM", "registration_token": "", "type": 0, "denied_apps_details": [ { "identifier": "com.zylker.deniedapp", "group_display_name": "Denied App", "app_group_id": 9007199254741072 } ] } ``` ## Rate Limits **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.