---
title: MDM profile
description: Set up rolle for your users with a Jamf or other MDM configuration profile. Preset and lock settings, add Identity Center portals and Entra ID tenants, and turn off self-updates.
---

A configuration profile for the `com.getrolle.app` preference domain sets up rolle for your users. The desktop app and the `rolle` command both read it. To install rolle itself, use `rolle.pkg`; see [Managed Macs](/docs/install#managed-macs).

The profile has four keys. You can use any of them, in one profile or in several:

| Key | Type | Effect |
|---|---|---|
| `DisableUpdates` | boolean | [Turn off self-updates](#turn-off-self-updates) |
| `Settings` | dictionary | [Preset settings](#settings) that the user can change |
| `LockedSettings` | array of strings | [Lock settings](#locked-settings) that the user cannot change |
| `Integrations` | array of dictionaries | [Add portals and tenants](#integrations) for the user |

## Jamf Pro

rolle publishes a [custom schema](/mdm/com.getrolle.app.json) for Jamf Pro, so you fill in a form instead of a property list:

1. In a computer configuration profile, add **Application & Custom Settings → External Applications → Add**.
2. Choose **Custom Schema** as the source. Enter `com.getrolle.app` as the preference domain.
3. Paste the schema from `https://getrolle.com/mdm/com.getrolle.app.json`.
4. Fill in the keys you need. Leave the others **Not Configured**.

You can also use **Application & Custom Settings → Upload** with one of the property lists on this page.

## Turn off self-updates

rolle updates itself unless you turn that off. When root owns `rolle.app`, as after `rolle.pkg`, an update asks for an administrator to approve it. Turn self-updates off when you deliver every version yourself, through your MDM or a patch tool, or when your users cannot approve that prompt.

Set `DisableUpdates` to `true`. The app then does not check for updates and hides the Update button. In **Settings**, the **Automatic updates** switch is locked and says that your organization manages updates. rolle reads the key only from a configuration profile, so `defaults write` has no effect.

As a property list:

```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>DisableUpdates</key>
  <true/>
</dict>
</plist>
```

For another MDM, use a `.mobileconfig` with a payload of type `com.getrolle.app`. Replace the two UUIDs with your own (`uuidgen`):

```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>PayloadType</key>
  <string>Configuration</string>
  <key>PayloadVersion</key>
  <integer>1</integer>
  <key>PayloadIdentifier</key>
  <string>com.example.rolle</string>
  <key>PayloadUUID</key>
  <string>00000000-0000-0000-0000-000000000001</string>
  <key>PayloadDisplayName</key>
  <string>rolle</string>
  <key>PayloadScope</key>
  <string>System</string>
  <key>PayloadContent</key>
  <array>
    <dict>
      <key>PayloadType</key>
      <string>com.getrolle.app</string>
      <key>PayloadVersion</key>
      <integer>1</integer>
      <key>PayloadIdentifier</key>
      <string>com.example.rolle.updates</string>
      <key>PayloadUUID</key>
      <string>00000000-0000-0000-0000-000000000002</string>
      <key>DisableUpdates</key>
      <true/>
    </dict>
  </array>
</dict>
</plist>
```

## Settings

Put the settings for your users in a `Settings` dictionary. rolle applies each value once, the next time the app or the `rolle` command reads its settings. The user can change it afterwards. When you change a value in the profile, rolle applies the new value again. If you remove a key and add it back later, rolle applies it again.

| Key | Type | Setting |
|---|---|---|
| `DefaultRegion` | string | AWS region for new sessions, such as `eu-west-1` |
| `AssumeRoleMinutes` | integer | Duration of chained assume-role sessions, 15 to 720 |
| `ProxyURL` | string | HTTPS proxy for every request rolle makes |
| `CABundle` | string | Path of a PEM file with extra root certificates, for TLS inspection |
| `UpdateChannel` | string | `beta` for pre-releases; anything else is stable |
| `AutoUpdateOff` | boolean | Turn off the automatic update check |
| `HiddenSections` | array of strings | Sidebar sections to hide: `aws-sso`, `aws-iam`, `azure`, `gcp` |
| `HideOnClose` | boolean | Keep the app in the tray when its window closes |
| `NotifyOff` | boolean | Turn off expiry notifications |
| `NotifyLeadMinutes` | integer | Minutes before expiry that the warning shows, up to 60 |
| `Terminal` | string | Terminal for **Open terminal**: `auto`, `terminal`, `iterm`, `ghostty`, `warp`, or `cmux` |

rolle ignores a key that is not in the table and a value of the wrong type. It clamps a value out of range the same way the settings screen does. Appearance stays with the user. For a login item, use your MDM's managed login items.

### Locked settings

To stop users from changing a setting, list its key in `LockedSettings`. A locked setting gets the profile's value every time, the control in **Settings** is turned off and says that your organization manages the setting, and the CLI cannot change it either. A key in `LockedSettings` without a value in `Settings` locks nothing.

rolle checks the proxy and the CA bundle each time a user saves a setting. If a locked `ProxyURL` is not valid, or a locked `CABundle` file is missing on a Mac, every save of a setting fails on that Mac until the profile is fixed. Deploy the PEM file before you lock `CABundle`.

This profile turns off self-updates, sets the region and the role duration, and locks the proxy and the CA bundle:

```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>DisableUpdates</key>
  <true/>
  <key>Settings</key>
  <dict>
    <key>DefaultRegion</key>
    <string>eu-west-1</string>
    <key>AssumeRoleMinutes</key>
    <integer>240</integer>
    <key>ProxyURL</key>
    <string>http://proxy.example.com:3128</string>
    <key>CABundle</key>
    <string>/Library/Application Support/Example/corp-root.pem</string>
  </dict>
  <key>LockedSettings</key>
  <array>
    <string>ProxyURL</string>
    <string>CABundle</string>
  </array>
</dict>
</plist>
```

## Integrations

Put the IAM Identity Center portals and Entra ID tenants of your organization in an `Integrations` array. Users then only sign in. rolle adds each one once. Users can rename it, remove it, and add their own integrations next to it. If a user removes one, rolle adds it again only when you change its entry in the profile. If the user has the same portal or tenant already, rolle keeps theirs and adds no copy. When you change the region of a portal, rolle updates the region of the user's portal.

| Key | Type | Value |
|---|---|---|
| `Type` | string | `aws-sso` for an Identity Center portal, `azure` for an Entra ID tenant |
| `Alias` | string | The name in rolle. If a user has this name already, rolle adds `-2`, `-3`, and so on |
| `StartURL` | string | `aws-sso`: the portal's https start URL |
| `Region` | string | `aws-sso`: the Identity Center region |
| `TenantID` | string | `azure`: the tenant ID or domain |

rolle skips an entry that misses a key that its type needs, that has a value of the wrong type, or whose start URL is not https. Google Cloud is not available: rolle uses the credentials of `gcloud`.

```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>Integrations</key>
  <array>
    <dict>
      <key>Type</key>
      <string>aws-sso</string>
      <key>Alias</key>
      <string>example</string>
      <key>StartURL</key>
      <string>https://example.awsapps.com/start</string>
      <key>Region</key>
      <string>us-east-1</string>
    </dict>
    <dict>
      <key>Type</key>
      <string>azure</string>
      <key>Alias</key>
      <string>example-azure</string>
      <key>TenantID</key>
      <string>example.onmicrosoft.com</string>
    </dict>
  </array>
</dict>
</plist>
```

## Where rolle reads the profile

rolle reads `/Library/Managed Preferences/com.getrolle.app.plist` and then the file for the current user in `/Library/Managed Preferences/<user>/`. The user's file wins for each key. rolle uses a file only when root owns it and only root can write it. These are the files that macOS writes for installed profiles.
