| Argument | Type | Description |
|---|
| mode | enum | Device mode to apply: basic, home, advanced, or ros. |
| flagged | bool | Set to no to exit the flagged state. Requires physical confirmation. |
| flagging-enabled | bool | Enable or disable configuration analysis for suspicious code. Default: yes. |
| scheduler | bool | Allow or block /system/scheduler. |
| socks | bool | Allow or block /ip/socks. |
| fetch | bool | Allow or block /tool/fetch. |
| pptp | bool | Allow or block PPTP client and server interfaces. |
| l2tp | bool | Allow or block L2TP client and server interfaces. |
| bandwidth-test | bool | Allow or block /tool/bandwidth-test and /tool/bandwidth-server. |
| traffic-gen | bool | Allow or block /tool/traffic-generator, /tool/flood-ping, and /tool/ping-speed. |
| sniffer | bool | Allow or block /tool/sniffer. |
| ipsec | bool | Allow or block /ip/ipsec. |
| romon | bool | Allow or block /tool/romon. |
| proxy | bool | Allow or block /ip/proxy. |
| hotspot | bool | Allow or block /ip/hotspot. |
| smb | bool | Allow or block /ip/smb. |
| email | bool | Allow or block /tool/e-mail. |
| zerotier | bool | Allow or block /zerotier. |
| container | bool | Allow or block container functionality. |
| install-any-version | bool | Allow or block downgrading to RouterOS versions outside the allowed-versions list. |
| partitions | bool | Allow or block changing partition count. |
| routerboard | bool | Allow or block /system/routerboard/settings (except auto-upgrade) and SwOS/RouterOS transition on dual-boot devices. |
| activation-timeout | time | Time to wait for physical confirmation (reset button press or power cycle) before canceling the update. Range: 00:00:10 to 1d00:00:00. Default: 5m. |