Skip to main content

ONC variables and examples

Use variables to reuse one network policy across users or devices. Expansion depends on whether the ONC is applied to a signed-in user or device scope.

Supported variables​

VariableExpands toTypical use
${LOGIN_ID}Signed-in email before @RADIUS or VPN short username
${LOGIN_EMAIL}Full signed-in emailRADIUS or VPN identity
${DEVICE_SERIAL_NUMBER}Device serial numberDevice-wide identity
${DEVICE_ASSET_ID}Administrator-set asset IDDevice-wide identity
${CERT_SAN_EMAIL}First certificate RFC822 SANCertificate-backed identity
${CERT_SAN_UPN}Certificate UPN SANActive Directory-style identity
${CERT_SUBJECT_COMMON_NAME}Certificate common nameCertificate-backed identity
${PASSWORD}Signed-in user's passwordExact Wi-Fi EAP password or L2TP password field

${PASSWORD} is a substitution, not a general template. The field must equal ${PASSWORD} exactly. A value such as ${PASSWORD}-suffix is not replaced.

Reusable PEAP example​

{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-peap-corporate}",
"Name": "Corporate Wi-Fi",
"Type": "WiFi",
"WiFi": {
"AutoConnect": true,
"SSID": "Corporate",
"Security": "WPA2-Enterprise",
"EAP": {
"Outer": "PEAP",
"Inner": "MSCHAPv2",
"Identity": "${LOGIN_EMAIL}",
"Password": "${PASSWORD}",
"SaveCredentials": true,
"UseSystemCAs": true
}
}
}
]
}

Multiple networks in one document​

NetworkConfigurations is an array. Add each complete network object as a separate array item with a unique GUID:

{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-primary}",
"Name": "Primary Wi-Fi",
"Type": "WiFi",
"WiFi": {
"AutoConnect": true,
"SSID": "Primary",
"Security": "WPA-PSK",
"Passphrase": "replace-with-managed-secret"
}
},
{
"GUID": "{ethernet-dhcp}",
"Name": "Ethernet",
"Type": "Ethernet",
"Ethernet": {
"Authentication": "None"
}
}
]
}

Remove a managed object​

Use the same GUID that identified the existing object:

{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{wifi-old-network}",
"Remove": true
}
]
}

Do not reuse that GUID for a different network.

Validation checklist​

  • The document parses as JSON; it contains no comments or trailing commas.
  • The top-level Type is UnencryptedConfiguration.
  • Every network and certificate GUID is non-empty and unique.
  • Every referenced certificate GUID is defined in the same document.
  • The network Type matches its object, such as WiFi with a WiFi object.
  • Required fields for the selected security, EAP, IP, VPN, and proxy modes are present.
  • Booleans and numbers are not quoted.
  • Example addresses, secrets, hosts, and certificate data have been replaced.

Keep a reviewed copy of the last working document. The ONC reference is the source for complete field definitions.

What's next​