ONC variables and examples
Use variables to reuse one network policy across users or devices. Expansion depends on whether the ONC is applied to a signed-in user or device scope.
Supported variables
| Variable | Expands to | Typical use |
|---|---|---|
${LOGIN_ID} | Signed-in email before @ | RADIUS or VPN short username |
${LOGIN_EMAIL} | Full signed-in email | RADIUS or VPN identity |
${DEVICE_SERIAL_NUMBER} | Device serial number | Device-wide identity |
${DEVICE_ASSET_ID} | Administrator-set asset ID | Device-wide identity |
${CERT_SAN_EMAIL} | First certificate RFC822 SAN | Certificate-backed identity |
${CERT_SAN_UPN} | Certificate UPN SAN | Active Directory-style identity |
${CERT_SUBJECT_COMMON_NAME} | Certificate common name | Certificate-backed identity |
${PASSWORD} | Signed-in user's password | Exact Wi-Fi EAP password or L2TP password field |
${PASSWORD} is a substitution, not a general template. The field must equal
${PASSWORD} exactly. A value such as ${PASSWORD}-suffix is not replaced.
Reusable PEAP example
{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-peap-corporate}",
"Name": "Corporate Wi-Fi",
"Type": "WiFi",
"WiFi": {
"AutoConnect": true,
"SSID": "Corporate",
"Security": "WPA2-Enterprise",
"EAP": {
"Outer": "PEAP",
"Inner": "MSCHAPv2",
"Identity": "${LOGIN_EMAIL}",
"Password": "${PASSWORD}",
"SaveCredentials": true,
"UseSystemCAs": true
}
}
}
]
}
Multiple networks in one document
NetworkConfigurations is an array. Add each complete network object as a
separate array item with a unique GUID:
{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-primary}",
"Name": "Primary Wi-Fi",
"Type": "WiFi",
"WiFi": {
"AutoConnect": true,
"SSID": "Primary",
"Security": "WPA-PSK",
"Passphrase": "replace-with-managed-secret"
}
},
{
"GUID": "{ethernet-dhcp}",
"Name": "Ethernet",
"Type": "Ethernet",
"Ethernet": {
"Authentication": "None"
}
}
]
}
Remove a managed object
Use the same GUID that identified the existing object:
{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-old-network}",
"Remove": true
}
]
}
Do not reuse that GUID for a different network.
Validation checklist
- The document parses as JSON; it contains no comments or trailing commas.
- The top-level
TypeisUnencryptedConfiguration. - Every network and certificate GUID is non-empty and unique.
- Every referenced certificate GUID is defined in the same document.
- The network
Typematches its object, such asWiFiwith aWiFiobject. - Required fields for the selected security, EAP, IP, VPN, and proxy modes are present.
- Booleans and numbers are not quoted.
- Example addresses, secrets, hosts, and certificate data have been replaced.
Keep a reviewed copy of the last working document. The ONC reference is the source for complete field definitions.
What's next
- Configure network policies, validate and publish ONC safely.
- Manage certificates, prepare trust anchors and client certificates.
- Troubleshoot managed networks, diagnose policy and connection failures.
- ONC reference, look up schema fields and accepted values.