Skip to content
Tobias Almén edited this page Sep 28, 2026 · 1 revision

Customization

Everything on this page is in the Defaults tier unless noted, so deploy it however you like. Keys and defaults are in Preference reference.

Branding

<key>BrandName</key>
<string>Contoso IT</string>
<key>AccentColor</key>
<string>#7A5AF8</string>
<key>BrandLogo</key>
<string>BASE64…</string>
<key>BrandLogoLight</key>
<string>BASE64…</string>

BrandLogo is used in dark mode and in both if BrandLogoLight is not set. BrandName also replaces "Device Information" as the heading of the desktop info window.

For the menu bar, TrayMenuBrandingIcon takes a base64 image, TrayMenuShowIcon removes the menu bar item entirely, and ShowLogoInTrayMenu controls the logo inside the popover.

Actions

Buttons that run a command. They appear on the home page, in the menu bar popover (the first six) and can be triggered from the CLI.

<key>Actions</key>
<array>
    <dict>
        <key>Name</key>
        <string>Run Munki Check</string>
        <key>Command</key>
        <string>/usr/local/munki/managedsoftwareupdate --auto</string>
        <key>Icon</key>
        <string>arrow.triangle.2.circlepath</string>
        <key>Description</key>
        <string>Check for and install available updates.</string>
        <key>ButtonLabel</key>
        <string>Check</string>
        <key>IsPrivileged</key>
        <true/>
    </dict>
</array>

Icon is an SF Symbol name.

IsPrivileged is only honoured when Actions comes from a configuration profile. Actions defined in the user's own preferences still run, but never as root, and the app logs which action it refused to privilege. When it is honoured, the app sends only the action's name to the helper, which looks the command up in the administrator-managed preferences itself — so what runs as root always comes from you, never from the app process.

RequirePrivilegedActionAuthentication (profile-only, default true) asks the user to authenticate before a privileged action runs.

Built-in actions

Hide any of them with HiddenActions:

Value Button
ChangePassword Change Password
GatherLogs Gather Logs
RestartIntuneAgent Restart Intune Agent
OpenManagementApp Open Management App
SoftwareUpdates Software Update
GetSupport Get Support
Reboot Reboot

Hiding SoftwareUpdates also suppresses its notifications. Hidden buttons are left out of the Dock badge count.

Change Password needs a mode:

<key>ChangePasswordMode</key>
<string>url</string>
<key>ChangePasswordUrl</key>
<string>https://passwordreset.microsoftonline.com</string>

SSOExtension triggers the Kerberos SSO extension's password change instead.

Get Support appears only when SupportPageUrl is set.

Cards

Hide any card with HiddenCards:

Value Card
DeviceInformation Model, OS, serial, uptime
Storage Disk usage and FileVault
Battery Health, cycles, temperature
DeviceManagement Enrollment details
ApplicationInstallProgress Patching progress
PendingAppUpdates Updates waiting
Actions The actions card
Evergreen Munki catalogs from the local manifests
Jamf Jamf device details
FleetPolicies Compliance checks
Fleet Fleet device details

Custom cards

Point CustomCardPath at a JSON file and its contents become cards. The file is watched, so a script that rewrites it updates the app without a restart.

[
    {
        "icon": "briefcase.fill",
        "Header": "Contoso Info",
        "data": {
            "Wifi": "Contoso-Corp",
            "Asset tag": "IT-4417"
        }
    }
]

icon is an SF Symbol, Header is the card title, and data is a flat map of label to value. A worked example that gathers Wi-Fi, battery, USB devices and displays is in ExampleScripts/custom_cards.py.

By default custom cards join the home grid. Set CustomCardsMenuLabel and they move to their own sidebar page with that name, with CustomCardsMenuIcon as its icon.

A Markdown page

<key>MarkdownFilePath</key>
<string>/Library/Application Support/SupportCompanion/welcome.md</string>
<key>MarkdownMenuLabel</key>
<string>Getting started</string>
<key>MarkdownMenuIcon</key>
<string>book</string>

All three are needed, and the file must exist, or no page appears.

Web pages

KnowledgeBaseUrl and CompanyPortalUrl each add a sidebar page with an embedded web view, shown unless MenuShowKnowledgeBase or MenuShowCompanyPortal is false. CompanyPortalUrl accepts sovereign cloud endpoints.

Desktop info

An information panel drawn on the desktop.

<key>ShowDesktopInfo</key>
<true/>
<key>DesktopInfoWindowPosition</key>
<string>UpperRight</string>
<key>DesktopInfoLevel</key>
<integer>3</integer>
<key>DesktopInfoFontSize</key>
<integer>13</integer>
<key>DesktopInfoHideItems</key>
<array>
    <string>FileVault</string>
    <string>Divider</string>
</array>

DesktopInfoLevel is cumulative: 1 hardware, 2 adds system, 3 adds network, 4 adds storage, 5 adds support info. DesktopInfoHideItems drops individual items or whole categories, and also takes Category and Divider to strip the headings and rules.

DesktopInfoBackgroundOpacity and DesktopInfoBackgroundFrosted control the backdrop. Position changes apply immediately; ShowDesktopInfo is only read at launch, so turning the panel on or off needs the app restarted.

Notifications

NotificationInterval is the number of hours before the same kind of notification repeats, and 0 turns all notifications off. NotificationTitle and NotificationImage apply to all of them.

The software update and app update notifications each take their own message, button text and command. RebootReminderDays adds a reminder after that many days of uptime, and is off at 0.

Fleet's three notification switches are on Fleet mode.

Clone this wiki locally