Skip to content
rolle
Esc
↑↓navigate↵open⌘Jpreview
On this page

MDM profile

Set up rolle for your users with a Jamf or other MDM configuration profile. Preset and lock settings, add Identity Center portals and Entra ID tenants, and turn off self-updates.

A configuration profile for the com.getrolle.app preference domain sets up rolle for your users. The desktop app and the rolle command both read it. To install rolle itself, use rolle.pkg; see Managed Macs.

The profile has four keys. You can use any of them, in one profile or in several:

Key Type Effect
DisableUpdates boolean Turn off self-updates
Settings dictionary Preset settings that the user can change
LockedSettings array of strings Lock settings that the user cannot change
Integrations array of dictionaries Add portals and tenants for the user

Jamf Pro

rolle publishes a custom schema for Jamf Pro, so you fill in a form instead of a property list:

  1. In a computer configuration profile, add Application & Custom Settings → External Applications → Add.
  2. Choose Custom Schema as the source. Enter com.getrolle.app as the preference domain.
  3. Paste the schema from https://getrolle.com/mdm/com.getrolle.app.json.
  4. Fill in the keys you need. Leave the others Not Configured.

You can also use Application & Custom Settings → Upload with one of the property lists on this page.

Turn off self-updates

rolle updates itself unless you turn that off. When root owns rolle.app, as after rolle.pkg, an update asks for an administrator to approve it. Turn self-updates off when you deliver every version yourself, through your MDM or a patch tool, or when your users cannot approve that prompt.

Set DisableUpdates to true. The app then does not check for updates and hides the Update button. In Settings, the Automatic updates switch is locked and says that your organization manages updates. rolle reads the key only from a configuration profile, so defaults write has no effect.

As a property list:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>DisableUpdates</key>
  <true/>
</dict>
</plist>

For another MDM, use a .mobileconfig with a payload of type com.getrolle.app. Replace the two UUIDs with your own (uuidgen):

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>PayloadType</key>
  <string>Configuration</string>
  <key>PayloadVersion</key>
  <integer>1</integer>
  <key>PayloadIdentifier</key>
  <string>com.example.rolle</string>
  <key>PayloadUUID</key>
  <string>00000000-0000-0000-0000-000000000001</string>
  <key>PayloadDisplayName</key>
  <string>rolle</string>
  <key>PayloadScope</key>
  <string>System</string>
  <key>PayloadContent</key>
  <array>
    <dict>
      <key>PayloadType</key>
      <string>com.getrolle.app</string>
      <key>PayloadVersion</key>
      <integer>1</integer>
      <key>PayloadIdentifier</key>
      <string>com.example.rolle.updates</string>
      <key>PayloadUUID</key>
      <string>00000000-0000-0000-0000-000000000002</string>
      <key>DisableUpdates</key>
      <true/>
    </dict>
  </array>
</dict>
</plist>

Settings

Put the settings for your users in a Settings dictionary. rolle applies each value once, the next time the app or the rolle command reads its settings. The user can change it afterwards. When you change a value in the profile, rolle applies the new value again. If you remove a key and add it back later, rolle applies it again.

Key Type Setting
DefaultRegion string AWS region for new sessions, such as eu-west-1
AssumeRoleMinutes integer Duration of chained assume-role sessions, 15 to 720
ProxyURL string HTTPS proxy for every request rolle makes
CABundle string Path of a PEM file with extra root certificates, for TLS inspection
UpdateChannel string beta for pre-releases; anything else is stable
AutoUpdateOff boolean Turn off the automatic update check
HiddenSections array of strings Sidebar sections to hide: aws-sso, aws-iam, azure, gcp
HideOnClose boolean Keep the app in the tray when its window closes
NotifyOff boolean Turn off expiry notifications
NotifyLeadMinutes integer Minutes before expiry that the warning shows, up to 60
Terminal string Terminal for Open terminal: auto, terminal, iterm, ghostty, warp, or cmux

rolle ignores a key that is not in the table and a value of the wrong type. It clamps a value out of range the same way the settings screen does. Appearance stays with the user. For a login item, use your MDM’s managed login items.

Locked settings

To stop users from changing a setting, list its key in LockedSettings. A locked setting gets the profile’s value every time, the control in Settings is turned off and says that your organization manages the setting, and the CLI cannot change it either. A key in LockedSettings without a value in Settings locks nothing.

rolle checks the proxy and the CA bundle each time a user saves a setting. If a locked ProxyURL is not valid, or a locked CABundle file is missing on a Mac, every save of a setting fails on that Mac until the profile is fixed. Deploy the PEM file before you lock CABundle.

This profile turns off self-updates, sets the region and the role duration, and locks the proxy and the CA bundle:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>DisableUpdates</key>
  <true/>
  <key>Settings</key>
  <dict>
    <key>DefaultRegion</key>
    <string>eu-west-1</string>
    <key>AssumeRoleMinutes</key>
    <integer>240</integer>
    <key>ProxyURL</key>
    <string>http://proxy.example.com:3128</string>
    <key>CABundle</key>
    <string>/Library/Application Support/Example/corp-root.pem</string>
  </dict>
  <key>LockedSettings</key>
  <array>
    <string>ProxyURL</string>
    <string>CABundle</string>
  </array>
</dict>
</plist>

Integrations

Put the IAM Identity Center portals and Entra ID tenants of your organization in an Integrations array. Users then only sign in. rolle adds each one once. Users can rename it, remove it, and add their own integrations next to it. If a user removes one, rolle adds it again only when you change its entry in the profile. If the user has the same portal or tenant already, rolle keeps theirs and adds no copy. When you change the region of a portal, rolle updates the region of the user’s portal.

Key Type Value
Type string aws-sso for an Identity Center portal, azure for an Entra ID tenant
Alias string The name in rolle. If a user has this name already, rolle adds -2, -3, and so on
StartURL string aws-sso: the portal’s https start URL
Region string aws-sso: the Identity Center region
TenantID string azure: the tenant ID or domain

rolle skips an entry that misses a key that its type needs, that has a value of the wrong type, or whose start URL is not https. Google Cloud is not available: rolle uses the credentials of gcloud.

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>Integrations</key>
  <array>
    <dict>
      <key>Type</key>
      <string>aws-sso</string>
      <key>Alias</key>
      <string>example</string>
      <key>StartURL</key>
      <string>https://example.awsapps.com/start</string>
      <key>Region</key>
      <string>us-east-1</string>
    </dict>
    <dict>
      <key>Type</key>
      <string>azure</string>
      <key>Alias</key>
      <string>example-azure</string>
      <key>TenantID</key>
      <string>example.onmicrosoft.com</string>
    </dict>
  </array>
</dict>
</plist>

Where rolle reads the profile

rolle reads /Library/Managed Preferences/com.getrolle.app.plist and then the file for the current user in /Library/Managed Preferences/<user>/. The user’s file wins for each key. rolle uses a file only when root owns it and only root can write it. These are the files that macOS writes for installed profiles.

Was this page helpful?