<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content
All posts

iOS 27 for Enterprise: What Changes for Software Updates and Device Management

Apple released iOS 27 on 14 September 2026, and legacy MDM software update management stopped working with it. According to Apple's notes on what's new for enterprise in iOS 27, software update commands, software update queries, recommended cadence settings and software update restrictions such as deferrals no longer function in any 27.0 operating system. For iOS 27 in the enterprise, update control now has to run through declarative device management.

The same change applies to iPadOS 27. When we covered the enterprise features of iOS 18 in 2024, the declarative software update settings were one new item on a long list. With iOS 27 they are the route that remains.

Oliver Schiemann and Magnus Wonschik walked through what this means for administrators in our webcast “Apple und iOS 27: was für Unternehmen wichtig ist” (in German) on 14 July 2026. The recording is free after registration, like the others in our webcast overview.

iOS 27 in the enterprise: what stops working

Apple's wording is short: "Legacy software update management no longer functions in all 27.0 operating systems." The list that follows names software update commands, software update queries, recommended cadence settings, and software update restrictions, like deferrals and Background Security Improvements. Apple's instruction to IT teams is to use declarative software update management to configure and enforce updates.

This did not come out of nowhere. Apple's developer documentation lists the MDM commands ScheduleOSUpdate, AvailableOSUpdates and OSUpdateStatus as deprecated from iOS 26.0 and points to the declarative configuration and status items instead. Oliver Schiemann and Magnus Wonschik flagged it back in September 2025 in our webcast on iOS 26 (in German): the legacy MDM mechanism for updates was on its way out, and update management would then run through declarative device management only.

For planning, this means update control moves from commands the server sends to a state the server declares. If your UEM still manages updates the old way, those settings have no effect on devices running iOS 27.

Do software update deferrals still work on iOS 27?

Deferrals still exist on iOS 27, but not as an MDM restriction. They now live in the declarative Software Update settings configuration, which Apple describes for supervised iPhone and iPad from iOS 18: a deferral of 1 to 90 days (CombinedPeriodInDays), and a recommended cadence that shows all updates, only updates for the oldest version, or only the upgrade to the newest (RecommendedCadence).

For organisations that hold back updates until their specialist apps are tested, this is the practical question. It came first in the recommendations of our iOS 27 webcast: if you hold back updates for up to 90 days with an MDM restriction today, that route is gone, so check your UEM policies for legacy mechanisms now. The test-group-first approach keeps working, provided your UEM sends these declarations. The same configuration also decides whether Background Security Improvements install automatically and whether users may remove them afterwards.

What is declarative software update management, and what does your UEM need?

With declarative device management, the server declares the target state and the device works towards it on its own. Apple gives an example in its guide to installing and enforcing software updates: if a device misses an enforcement date because it doesn't meet the requirements, it detects this and resumes the process when it connects to the internet again.

Two declarations carry the work:

  • Software Update (com.apple.configuration.softwareupdate.enforcement.specific) enforces a specific version by a set time. Its keys include TargetOSVersion, TargetBuildVersion, TargetLocalDateTime and DetailsURL, a link to your own notes about the release. It is available from iOS 17 and does not require supervision. The enforcement time applies in the device's local time zone, so one declaration works across regions.
  • Software Update settings governs deferrals, recommended cadence, automatic downloads and installs, Background Security Improvements, notification behaviour and beta programmes. It requires supervised devices, except for its enforcement keys and the beta OfferPrograms key.

Your UEM has to support these declarations and their keys. Apple says so itself: not all configurations and settings are available in all device management services, and each developer implements them differently. Which keys your platform exposes is a question for your UEM vendor, and one to settle before iOS 27 goes out to the wider fleet. The same caveat appeared in the webcast on the slide about moving to DDM: DDM features have to be supported by the MDM vendor. So find out what your platform covers today and what is on its roadmap.

How do you prove which device ran which iOS version, and when?

The evidence comes from declarative status reports. The device management service subscribes to status items, and the device then reports when the subscription becomes active, whenever a subscribed item changes, and every 24 hours (Apple Developer).

The items that matter for updates cover the operating system version and build, the Background Security Improvement version, any pending update, the install state (none, waiting, downloading, prepared, installing or failed), what started the install, and failure details including the number of failures and the time of the last one.

A device reports its current state. A history of which device ran which version, and since when, exists only if something records these reports over time. For approval and audit processes, that is the part to plan for. ISEC7 SPHERE, our platform for central monitoring of devices and systems, checks operating system and patch level per device as a compliance rule, based on the data from the connected UEM systems.

Other device management changes in iOS 27

The rest of Apple's list is shorter, but several items affect day-to-day management:

  • Device management can restrict Siri AI, Visual Intelligence and Natural Language Calendar Event Editing.
  • New status items report the enrollment type, Lockdown Mode status, and when a device is waiting in Setup Assistant for the device management service.
  • VPN, DNS and relay configurations are now available in declarative device management, and legacy MDM profiles can be delivered as declarative assets.
  • Software updates can be enforced on a supervised device when it receives a Return to Service erase command.
  • On supervised devices, log collection for an AppleCare ticket can be started remotely.
  • A consolidated consent prompt lets users grant an app or website its default privacy permissions, and the new Liquid Glass setup pane can be skipped.

Oliver Schiemann and Magnus Wonschik made two of these items tangible in the webcast. In DDM, different network configurations, such as VPN, reference the same certificate as an asset instead of each carrying their own copy, and a renewal then applies to all of them at once (Apple, WWDC26 device management updates). And on iPhone and iPad with iOS 27, Return to Service can take language and region from the Automated Device Enrollment profile and can be set to retry a failed enrollment by itself (Apple, Return to Service). That helps wherever devices change hands between shifts.

One more change is missing from that list but affects every UEM environment. From version 27.0, Apple operating systems may refuse connections to servers with outdated TLS configurations for MDM, DDM, Automated Device Enrollment, profile and app installation, and software updates. Servers need TLS 1.2 or later, ATS-compliant cipher suites and valid certificates (Apple, KB 126655). The webcast speakers pointed out that MDM vendors have to catch up here too.

The Siri restrictions are ordinary management controls. They belong in the same policy review as any other restriction, together with the question of who in your organisation decides what is allowed. That was one of the four recommendations in the webcast: decide which Apple Intelligence and Siri features are allowed, bearing in mind that not all of them are available in the EU.

Where to start

  1. List what your UEM sends today. Which update policies still rely on commands, queries or restrictions? On iOS 27 devices they do nothing.
  2. Ask your UEM vendor which declarative keys it supports, from which release, and whether its servers meet the stricter TLS requirements.
  3. Rebuild the approval flow declaratively: deferral and cadence for the test phase, then an enforcement declaration with a date for everyone else.
  4. Subscribe to the software update status items and decide where the reports are kept.
  5. Review Return to Service workflows, because an update can now be enforced as part of the erase.

Who does what

Apple defines the declarations and status items. Your UEM vendor decides which of them the platform exposes, and when. ISEC7 advises on, integrates and operates UEM platforms from several vendors as part of our endpoint management services. For Apple in the enterprise, we work as a member of the Apple Consultants Network and with Apple-certified employees. If a platform change is on the cards anyway, the recording of our webcast on MDM migration (in German) from 14 October 2025 shows how to plan and monitor a migration in waves. If your team wants to build up Apple know-how first, our Apple Enterprise Mobility Fundamentals training runs virtually and in Hamburg, with current dates on the course page.

Frequently asked questions

Do MDM software update deferrals still work on iOS 27?

Not as a legacy MDM restriction. Apple states that software update restrictions such as deferrals no longer function in 27.0 operating systems. Deferrals of 1 to 90 days remain available through the declarative Software Update settings configuration on supervised devices, provided your UEM supports it.

What stops working in iOS 27 for software update management?

Software update commands, software update queries, recommended cadence settings and software update restrictions, including deferrals and Background Security Improvements. Apple asks IT teams to use declarative software update management instead. Its developer documentation had already listed the commands ScheduleOSUpdate, AvailableOSUpdates and OSUpdateStatus as deprecated from iOS 26.0.

Does declarative update enforcement require supervised devices?

The Software Update declaration, which enforces a specific version by a set date and time, works from iOS 17 without supervision. The Software Update settings configuration for deferrals, cadence and automatic updates requires supervision, apart from its enforcement keys and beta programme offers.

How can IT see whether an iOS 27 device has installed an update?

Through declarative status reports. After subscribing, the device reports its OS version and build, any pending update, the install state and failure details. It sends a report when the subscription becomes active, when a subscribed item changes, and every 24 hours.

Sources

ISEC7 resources