managed.json overrides user configuration and CLI or SDK options; omitted settings remain under employee control.
Define managed settings
Save the settings you want to enforce asmanaged.json:
versionidentifies the managed file format and defaults to1when omitted. It is independent of the user config version.overridesaccepts the fields in Global config, including registries, paths, runtime settings, and outbound proxies.- Omitted settings remain under employee control. Managed values are never written into the user’s
config.json. - Unrecognized keys are ignored with a warning listing their paths. Check warnings during rollout to catch misspelled settings.
How overrides are merged
How overrides are merged
Precedence, from lowest to highest: built-in defaults → user config → CLI/SDK options → managed overrides.
Tagged values need their discriminator, such as
kind, mode, or protocol. See registry rules and backend selection for their specific behavior.Understand policy coverage
Supported CLI and SDK backends apply managed settings on the employee device. The file does not configure the cloud service or its hosted SSH gateway.
An enforced
multi-tenant deployment profile restricts several network settings together. Snapshot restores reject policy that conflicts with the captured root-disk layout or full-checkpoint CPU and memory geometry.
Keep credentials separate
Employees can readmanaged.json. Distribute credential references rather than passwords or tokens, and provision the credentials separately. For registries, omit auth to preserve employee credentials, supply it to enforce an authentication configuration, or set it to null to require anonymous access. See the registry example.
Protect the policy file
Your deployment tool must install the policy at the system location below and prevent employees from modifying or replacing it.File location
MSB_HOME and MSB_CONFIG_PATH do not change this location. microsandbox needs no additional enrollment, daemon, plist, or mobileconfig.
File protection
On macOS and Linux, backend construction fails if the file or its immediate parent directory is not root-owned or is group- or world-writable, or if their permissions cannot be checked. An administrator must correct the reported ownership or permissions before retrying. These checks do not inspect ACLs or other ancestor directories; Windows permissions are not checked. Protect the complete path.
Older CLI and SDK releases do not enforce managed settings. Include supported versions in your rollout. Local administrators can remove policy or replace the runtime.