Skip to main content
Add optional settings only inside the completed universal profile from required configuration. Silmaril checks forced organization policy first, then a saved local value, then the application default. If a managed key is later removed, the setting falls back to any saved local value. Use these statuses to check policy application. Confirm active protection separately with endpoint verification.

Optional settings

Add the settings required for your deployment inside the existing mcx_preference_settings dictionary, and add each key only once. Use the Dashboard URL or Firewall ID supplied by Silmaril when provided. To remove an optional setting, delete its complete key element and the following value element. To force Launch at Login Off, remove the complete com.apple.loginitems.managed payload before adding silmaril.launchAtLoginEnabled set to false. Duplicate keys, a display name used where an ID is required, or Launch at Login forced off while the template login-items payload remains, leave the profile invalid or still forcing launch. Fix the XML, validate again, and replace the profile while preserving its identity. See troubleshooting.

Dashboard URL

Sets the supplied dashboard origin used by Fleet and Playground links.

Firewall ID

Routes audit records to the supplied Firewall.

Protection mode

Makes Shadow the required mode for all protected agents.

Request timeout

Wait up to 2500 milliseconds for a Firewall response.

Audit Off

Stops new audit collection and uploads. Existing records remain.

Agent exclusions

Excludes Codex and Cursor from endpoint protection.

Connection

Protection and audit

Discovery and startup

Updates

For current release and Nightly availability, see Install.