To modify Mac Firewall policy payload item
https://{server-hostname}:8383/api/v1/mdm/profiles/{profile_id}/payloads/macfirewallpolicy/payloaditems/{payload_id}
MDMDeviceMgmt.UPDATECopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
Unique identifier of the profile. Obtain from the Create Profile or Get Profiles response
Unique identifier of the payload item. Obtain from the Get Payload Item IDs response
Enable or disable the macOS application firewall. Allowed values: 0=Disable, 1=Enable
Block all incoming connections except those required for basic internet services (DHCP, Bonjour, IPSec). Allowed values: 0=Disable, 1=Enable, 2=User Controlled
Enable stealth mode to prevent the Mac from responding to probing requests (ICMP ping). Allowed values: 0=Disable, 1=Enable, 2=User Controlled
Automatically allow downloaded signed software to receive incoming connections. Requires macOS 12.3+. Allowed values: 0=Block, 1=Allow, 2=User Controlled
Automatically allow built-in signed software to receive incoming connections. Requires macOS 12.3+. Allowed values: 0=Block, 1=Allow, 2=User Controlled
Enable firewall logging. Allowed values: 0=Disable, 1=Enable
Firewall logging detail level. Allowed values: 0=Throttled, 1=Brief, 2=Detail
List of app-specific firewall rules controlling incoming connections for individual applications
App group ID of the application. Obtain from the Apps API response
Whether to allow incoming connections for this app. Allowed values: 0=Block, 1=Allow
curl --request PUT \
--url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/macfirewallpolicy/payloaditems/{payload_id} \
--header 'Accept: application/json' \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52' \
--header 'Content-Type: application/json' \
--data '{"enable_stealth_mode":1,"allow_signed_app":1,"block_all_incoming":2,"allow_signed":1,"enable_firewall":1,"restricted_apps":[{"allow_incoming_connection":0,"app_group_id":6967000000047041}]}'Modify Firewall payload — change stealth mode and update blocked apps
{
"enable_stealth_mode": 1,
"allow_signed_app": 1,
"block_all_incoming": 2,
"allow_signed": 1,
"enable_firewall": 1,
"restricted_apps": [
{
"allow_incoming_connection": 0,
"app_group_id": 6967000000047041
}
]
}
Unique identifier of the payload item
Whether the macOS application firewall is enabled. Values: 0=Disabled, 1=Enabled
Whether all incoming connections are blocked. Values: 0=Disabled, 1=Enabled, 2=User Controlled
Whether stealth mode is enabled. Values: 0=Disabled, 1=Enabled, 2=User Controlled
Whether downloaded signed software is allowed incoming connections. Values: 0=Block, 1=Allow, 2=User Controlled
Whether built-in signed software is allowed incoming connections. Values: 0=Block, 1=Allow, 2=User Controlled
Whether firewall logging is enabled. Values: 0=Disabled, 1=Enabled
Firewall logging detail level. Values: 0=Throttled, 1=Brief, 2=Detail
List of app-specific firewall rules with resolved app details
App group ID of the application
Display name of the application
Bundle identifier of the application
Whether incoming connections are allowed. Values: 0=Blocked, 1=Allowed
Firewall payload item successfully modified
{
"enable_stealth_mode": "1",
"payload_id": 6967000001030034,
"allow_signed_app": "1",
"block_all_incoming": "2",
"allow_signed": "1",
"enable_firewall": "1",
"restricted_apps": [
{
"app_name": "Calculator",
"allow_incoming_connection": "0",
"bundle_id": "com.apple.calculator",
"app_group_id": 6967000000047041
}
]
}
![]()
Duration: 1 minute | Threshold: 60 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.