Jamf Pro / Intune: enterprise managed policy for the Bolt desktop app
The Bolt desktop app (distinct from the browser extension, which has its own policy files in the browser-extension kit) reads MDM policy directly from the app’s own managed preference domain. No native-messaging bridge is involved, which is why this is a standard MDM “Custom Settings” payload and not a special case.
- Preference domain (bundle id):
app.sparcle.bolt.enterprise - Template:
bolt-desktop.mobileconfig - Windows: same key catalogue, read from the registry instead. See the Windows guide and its ADMX/ADML template.
This profile carries app SETTINGS only. A second profile covers privacy permissions, and neither implies the other, so deploy both:
| Profile | What it does | Without it |
|---|---|---|
bolt-pppc.mobileconfig |
Grants the privacy (TCC) permissions Bolt needs. The macOS guide explains every entry | Prompts the user cannot satisfy on a managed Mac (no admin password) |
bolt-desktop.mobileconfig (this one) |
DLP mode, guarded sites, vault policy, sign-in target | The user’s own choices apply |
A third, bolt-nativemessaging.mobileconfig, matters only if your
browsers restrict native messaging. The macOS guide says when.
There is no system-extension profile. The current release does not ship a network filter or any other system extension, so there is nothing to pre-approve.
Which keys exist
Bolt reads a closed catalogue of keys. A key outside this list is silently ignored, not an error you would see. These are the same key names the browser extension’s managed schema publishes, so admins have one vocabulary across both surfaces.
| Key (write this) | Type | Merge kind | Notes |
|---|---|---|---|
dlpMode |
string | Level | off | warn | redact | block. Most-restrictive wins across sources, even over a forced value. |
dlpEnabled |
bool | Switch | Forced wins outright; else off beats on. Accepts <integer>0/1</integer> too (MDM tooling habit). |
inputGuardEnabled |
bool | Switch | Same switch semantics as above. |
pageCaptureEnabled |
bool | Switch | Same switch semantics as above. |
vaultRequirePin |
bool | Switch | Force the vault to require a PIN to unlock, instead of leaving it to the user’s own vault setting. Same switch semantics as above. |
vaultRequireMasterPassword |
bool | Switch | Require a master password for Bolt’s own vault. Forced true: the vault stays shut until the user sets one (with a recovery kit), and it cannot be turned off. Gates access in the running app; stored records are not yet re-encrypted under it. Only the recovery kit resets it; no admin reset exists. |
riskySites |
array<string> | Coverage | Hostnames the AI-DLP guard covers. Union: every entry ADDS coverage. |
riskyAppBundleIds |
array<string> | Coverage | Native-only (no browser equivalent): other apps’ bundle ids to treat as risky AI destinations. |
inputGuardHosts |
array<string> | Coverage | Extra hosts the on-type guard covers beyond riskySites. |
allowedCorpDomains |
array<string> | Exemption | Intersection: every entry is a HOLE in the policy. An explicit empty array is a real value (closes every hole), not “unset”. |
inputGuardExcludeHosts |
array<string> | Exemption | Same exemption semantics as above. |
pageCaptureExcludeHosts |
array<string> | Exemption | Same exemption semantics as above. |
boltUrl |
string | Config | The org’s Bolt deployment URL. |
launchMode |
string | Config | Free-form config value (not validated by the merge); use the same values as the extension’s launchMode (native, popup, sidebar) unless the app documents otherwise. |
inputGuardMode |
string | Config | Free-form config value; extension convention is ai-sites | all-sites. |
vaultAutoLockMinutes |
string | Config | Force the vault auto-lock timeout. Matches the app’s own picker: 1 | 5 | 15 | 30 | 0 (Never). |
vaultMasterPasswordSessionHours |
string | Config | Hours a master password unlock lasts before it is asked again; the PIN only re-unlocks within it. 4 | 12 | 24 | 0 (until Bolt restarts). |
vaultPendingMaxHours |
string | Config | Hours a pending vault action (a login, password change, passkey or authenticator code not yet saved or dismissed) is kept, sealed under the user’s vault key on this device only. 1 (default) | 4 | 24 | 0 (memory only, never written to disk). |
appUpdatesEnabled |
bool | Switch | May Bolt check for, download and install its own updates? <false/> unregisters the updater entirely: no request is made to the release manifest, so there is nothing for an egress proxy to see. A value of the wrong type is treated as <false/>, never as “allowed”. Omitting the key leaves updating exactly as it ships. This key is the sole authority: the app’s in-app update preference and an air-gapped build flag can only make it update less. |
appUpdatePinnedVersion |
string | Config | Hold the fleet at ONE version, e.g. 0.1.159. Exact version, not a maximum: Bolt moves to that version and no other, in either direction; a re-published build of the pinned version is still accepted. A string that is not valid semver is treated as “updates off”, not as “no pin”. appUpdatesEnabled <false/> wins over this. |
Known gap, not in scope here: pageCaptureAllowHosts exists on the
browser-extension side but is deliberately not yet read by the
desktop app, because what an empty list means there has to be settled before it can be
added safely. Setting it in a profile today
does nothing on the desktop app.
Only keys you set are treated as forced; anything you omit falls through to the
device-default tier (/Library/Preferences/…, root-writable: e.g. a
provisioning script’s sudo defaults write) and then to the app’s own
built-in default. There is no per-key opt-out beyond simply not setting it.
Deploy via Jamf Pro
- Computers → Configuration Profiles → New.
- General payload: give it a name, and set Level to Computer Level (this policy is device/machine-wide, not per-user. Bolt deliberately does not read the user preference domain).
- Add the Custom Settings payload (this is the same payload type as
PayloadType: com.apple.ManagedClient.preferencesin the template). - Set the Preference Domain to
app.sparcle.bolt.enterprise. - Either upload
bolt-desktop.mobileconfigdirectly (“Upload File”) or paste itsmcx_preference_settings<dict>into the property-list editor: both produce the same forced keys. - Scope to the target smart group and deploy.
Deploy via Microsoft Intune
Intune’s macOS support for arbitrary managed-preferences domains is via a custom configuration profile (it has no first-class UI for third-party app preferences the way Jamf does):
- Devices → macOS → Configuration profiles → Create → Templates → Custom.
- Upload
bolt-desktop.mobileconfigas-is (replace the placeholders first: organization name,boltUrl, and bothPayloadUUIDvalues; generate fresh UUIDs withuuidgen, one per occurrence). - Assign to the target device group. Intune installs it as a standard
.mobileconfig; no additional Intune-side schema/OMA-URI mapping is needed since the payload is already a complete Apple configuration profile.
Verify
-
Install Bolt. Its bundle id is
app.sparcle.bolt.enterprise. -
Install the profile for local testing.
profiles installno longer exists: the command-line tool has been unable to install configuration profiles since macOS 11 (profiles install …answers “profiles tool no longer supports installs. Use System Settings Profiles to add configuration profiles.”; verified on macOS 26, profiles tool 8.51). Double-click the.mobileconfigand approve it in System Settings → General → Device Management.This works for
bolt-desktop.mobileconfig, whose keys land in/Library/Managed Preferences/either way. It does not work forbolt-pppc.mobileconfig: its privacy grants are honoured only when the profile is delivered by an MDM enrollment. A hand-installed copy is accepted by macOS and then ignored. Test that one on an enrolled Mac or not at all. -
Confirm it landed:
sudo defaults read /Library/Managed\ Preferences/app.sparcle.bolt.enterprise.plistshould show the keys you set. -
Launch (or restart) Bolt and confirm the pushed policy is honored: e.g. set
dlpModetoblockand confirm a risky paste is blocked rather than just warned, or add a host toriskySitesand confirm it’s now covered. Since Bolt treats an unmanaged machine as “zero keys, no error,” an absent effect first means: check the profile actually installed (step 3) before assuming the app ignored it. -
Remove the profile (
sudo profiles remove -identifier app.sparcle.bolt.enterprise.mdm-policy-profile) to confirm behavior reverts to the device-default / built-in floor. Removing the profile un-forces the keys immediately.