Written for Synergy 1 (v1.21.4), checked 3 October 2026.
Note - locked settings are part of the Synergy Business Advanced plan (previously called Business Team).
How locked settings work
To enforce a fixed value for certain settings so that the people using a computer cannot change them, place a file named Synergy.locked.ini in the system-wide settings folder. On every launch, Synergy 1 reads that file, applies each setting it contains, and grays out the matching control in the settings windows. If a user changes the setting in their own profile, the locked value is applied again the next time Synergy 1 starts.
Two things to keep in mind:
- A setting is locked because its key is present in the file, whatever the value. Only include the keys you want to enforce.
- The locked file is a policy control for standard users. A local administrator can still edit or delete it.
The locked file is not the text-based server configuration file (the .conf file that describes your screen layout). That file is covered in: Creating and using text config files
Where the file goes
- Windows:
C:\ProgramData\Synergy\Synergy.locked.ini - macOS:
/Library/Synergy/Synergy.locked.ini, or/etc/xdg/Synergy/Synergy.locked.ini - Linux:
/etc/Synergy/Synergy.locked.ini, or/etc/xdg/Synergy/Synergy.locked.ini
Create the folder if it does not exist. On Linux the file name is case-sensitive.
Either path works on macOS and Linux, and /etc/xdg takes precedence if a file exists in both. An /etc/xdg path looks out of place on macOS, and it is there because Synergy 1 keeps its settings in INI files, which the settings library places in Unix locations on every platform. Deployments already using it keep working. A new macOS deployment reads more clearly using /Library/Synergy.
Settings that are grayed out when locked
| Setting in the app | Section | Key | Value |
|---|---|---|---|
| Enable TLS Encryption (Preferences, Network tab) | [security] |
tlsEnabled |
true or false
|
| Certificate (Preferences, Network tab) | [security] |
certificate |
As written in Synergy.conf |
| Key length (Preferences, Network tab) | [security] |
keySize |
As written in Synergy.conf |
| Require client certificates (Preferences, Network tab) | [security] |
checkPeerFingerprints |
true or false
|
| Enable clipboard sharing (Server Configuration, Advanced tab) | [internalConfig] |
clipboardSharing |
true or false
|
| Clipboard size limit, in MB (Server Configuration, Advanced tab) | [internalConfig] |
clipboardSharingSize |
As written in Synergy.conf |
Files written for Synergy 1.20 and earlier keep working: the locked file also accepts the old names, such as cryptoEnabled, tlsCertPath and tlsKeyLength under [General], and reads them as the settings above.
Any other setting from the settings file can be locked the same way, and its value is applied on every launch, but its control stays editable: a change the user makes lasts until Synergy 1 next starts.
The locked file uses the same keys and values as the settings file Synergy 1 saves to, Synergy.conf. To find the right value for any key, set it in the app on a reference machine and copy the line from that machine's Synergy.conf: %APPDATA%\Synergy\Synergy.conf on Windows, ~/Library/Synergy/Synergy.conf on macOS and ~/.config/Synergy/Synergy.conf on Linux.
Example file
This file requires TLS and turns clipboard sharing off:
[security] tlsEnabled=true [internalConfig] clipboardSharing=false
File format rules
- The
[security]header is required for the TLS keys, and the[internalConfig]header for the clipboard keys. The old 1.20 names are read from[General], or from before any header. - For on/off settings use
trueorfalse(1and0also work). Do not useno,off, ordisabled: Synergy 1 reads these as true, which leaves the setting enabled without any warning. - Save the file as UTF-8. A byte order mark and Windows line endings are both fine, so Notepad's defaults work.
Two-machine setups
Clipboard sharing is a server setting: Synergy 1 writes it into the server configuration it generates at startup, and the client follows the server. Deploy the same locked file to every machine so the lock applies whichever computer is acting as the server.
Deploying the file
Windows
Create the folder and the file from your deployment tool (Intune, SCCM, and GPO startup scripts all run as SYSTEM) or from an administrator account, before Synergy 1 is installed or first launched. Windows lets any standard user create files and folders under C:\ProgramData, and whoever creates something there becomes its owner with full control. So if a standard user launches Synergy 1 before C:\ProgramData\Synergy exists, that user owns the folder and can edit or delete the locked file.
Then lock the file itself down, so that only SYSTEM and Administrators can change it and standard users can only read it. In your deployment step, after writing the file:
icacls "C:\ProgramData\Synergy\Synergy.locked.ini" /inheritance:r /grant:r "SYSTEM:F" "Administrators:F" "Users:RX"
Leave the folder's own permissions as Windows sets them. On Windows, Synergy 1 keeps more than the locked file in C:\ProgramData\Synergy, whichever settings profile is in use: it rewrites the server configuration (synergy-server.conf) there every time the server starts, and keeps its TLS certificate and fingerprints in the tls folder inside it. Standard users need to be able to create files there, so read-only access on the folder stops the server from starting. With the "All users" settings profile, the shared Synergy.conf lives there too. The profiles are described in: Configure Synergy for multi-user support
On a machine where the folder already exists, check who owns it and what standard users can do with the locked file:
icacls "C:\ProgramData\Synergy" icacls "C:\ProgramData\Synergy\Synergy.locked.ini"
On the locked file, Users should show (RX) or (R) only, with (F) for SYSTEM and Administrators. If a user account shows (F) on the folder, that user created it. Take ownership as an administrator, then run the command above on the locked file:
takeown /f "C:\ProgramData\Synergy" /r /d y
Fleet-wide deployment steps are in: Synergy Business Silent & Automated Deployment (Windows)
macOS and Linux
The locked file on macOS and Linux has been verified by our developers but has not yet been used in a customer deployment. It is expected to work exactly as on Windows; if it does not, please contact our business support team
/etc/xdg is owned by root, so a standard user cannot change files in it. Create the folder and file as root:
sudo mkdir -p /etc/xdg/Synergy sudo tee /etc/xdg/Synergy/Synergy.locked.ini > /dev/null <<'EOF' [security] tlsEnabled=true [internalConfig] clipboardSharing=false EOF sudo chmod 644 /etc/xdg/Synergy/Synergy.locked.ini
Checking that the lock is applied
Start Synergy 1 and open the settings windows. A locked setting is grayed out: the TLS settings on the Network tab of Preferences (Edit, then Preferences), and clipboard sharing on the Advanced tab of Server Configuration (Configure Server in the main window).
- If the control is still editable, Synergy 1 did not read the file. Check that it is at the path above, named exactly
Synergy.locked.ini, and that each key sits under the right header ([security]for the TLS keys,[internalConfig]for the clipboard keys). - If the control is grayed out but shows the wrong value, check the value. Anything other than
true,false,1, or0is read as true.