Apple released iOS 27 on 14 September 2026, and legacy MDM software update management stopped working with it. According to Apple's notes on what's new for enterprise in iOS 27, software update commands, software update queries, recommended cadence settings and software update restrictions such as deferrals no longer function in any 27.0 operating system. For iOS 27 in the enterprise, update control now has to run through declarative device management.
The same change applies to iPadOS 27. When we covered the enterprise features of iOS 18 in 2024, the declarative software update settings were one new item on a long list. With iOS 27 they are the route that remains.
Oliver Schiemann and Magnus Wonschik walked through what this means for administrators in our webcast “Apple und iOS 27: was für Unternehmen wichtig ist” (in German) on 14 July 2026. The recording is free after registration, like the others in our webcast overview.
Apple's wording is short: "Legacy software update management no longer functions in all 27.0 operating systems." The list that follows names software update commands, software update queries, recommended cadence settings, and software update restrictions, like deferrals and Background Security Improvements. Apple's instruction to IT teams is to use declarative software update management to configure and enforce updates.
This did not come out of nowhere. Apple's developer documentation lists the MDM commands ScheduleOSUpdate, AvailableOSUpdates and OSUpdateStatus as deprecated from iOS 26.0 and points to the declarative configuration and status items instead. Oliver Schiemann and Magnus Wonschik flagged it back in September 2025 in our webcast on iOS 26 (in German): the legacy MDM mechanism for updates was on its way out, and update management would then run through declarative device management only.
For planning, this means update control moves from commands the server sends to a state the server declares. If your UEM still manages updates the old way, those settings have no effect on devices running iOS 27.
Deferrals still exist on iOS 27, but not as an MDM restriction. They now live in the declarative Software Update settings configuration, which Apple describes for supervised iPhone and iPad from iOS 18: a deferral of 1 to 90 days (CombinedPeriodInDays), and a recommended cadence that shows all updates, only updates for the oldest version, or only the upgrade to the newest (RecommendedCadence).
For organisations that hold back updates until their specialist apps are tested, this is the practical question. It came first in the recommendations of our iOS 27 webcast: if you hold back updates for up to 90 days with an MDM restriction today, that route is gone, so check your UEM policies for legacy mechanisms now. The test-group-first approach keeps working, provided your UEM sends these declarations. The same configuration also decides whether Background Security Improvements install automatically and whether users may remove them afterwards.
With declarative device management, the server declares the target state and the device works towards it on its own. Apple gives an example in its guide to installing and enforcing software updates: if a device misses an enforcement date because it doesn't meet the requirements, it detects this and resumes the process when it connects to the internet again.
Two declarations carry the work:
Your UEM has to support these declarations and their keys. Apple says so itself: not all configurations and settings are available in all device management services, and each developer implements them differently. Which keys your platform exposes is a question for your UEM vendor, and one to settle before iOS 27 goes out to the wider fleet. The same caveat appeared in the webcast on the slide about moving to DDM: DDM features have to be supported by the MDM vendor. So find out what your platform covers today and what is on its roadmap.
The evidence comes from declarative status reports. The device management service subscribes to status items, and the device then reports when the subscription becomes active, whenever a subscribed item changes, and every 24 hours (Apple Developer).
The items that matter for updates cover the operating system version and build, the Background Security Improvement version, any pending update, the install state (none, waiting, downloading, prepared, installing or failed), what started the install, and failure details including the number of failures and the time of the last one.
A device reports its current state. A history of which device ran which version, and since when, exists only if something records these reports over time. For approval and audit processes, that is the part to plan for. ISEC7 SPHERE, our platform for central monitoring of devices and systems, checks operating system and patch level per device as a compliance rule, based on the data from the connected UEM systems.
The rest of Apple's list is shorter, but several items affect day-to-day management:
Oliver Schiemann and Magnus Wonschik made two of these items tangible in the webcast. In DDM, different network configurations, such as VPN, reference the same certificate as an asset instead of each carrying their own copy, and a renewal then applies to all of them at once (Apple, WWDC26 device management updates). And on iPhone and iPad with iOS 27, Return to Service can take language and region from the Automated Device Enrollment profile and can be set to retry a failed enrollment by itself (Apple, Return to Service). That helps wherever devices change hands between shifts.
One more change is missing from that list but affects every UEM environment. From version 27.0, Apple operating systems may refuse connections to servers with outdated TLS configurations for MDM, DDM, Automated Device Enrollment, profile and app installation, and software updates. Servers need TLS 1.2 or later, ATS-compliant cipher suites and valid certificates (Apple, KB 126655). The webcast speakers pointed out that MDM vendors have to catch up here too.
The Siri restrictions are ordinary management controls. They belong in the same policy review as any other restriction, together with the question of who in your organisation decides what is allowed. That was one of the four recommendations in the webcast: decide which Apple Intelligence and Siri features are allowed, bearing in mind that not all of them are available in the EU.
Apple defines the declarations and status items. Your UEM vendor decides which of them the platform exposes, and when. ISEC7 advises on, integrates and operates UEM platforms from several vendors as part of our endpoint management services. For Apple in the enterprise, we work as a member of the Apple Consultants Network and with Apple-certified employees. If a platform change is on the cards anyway, the recording of our webcast on MDM migration (in German) from 14 October 2025 shows how to plan and monitor a migration in waves. If your team wants to build up Apple know-how first, our Apple Enterprise Mobility Fundamentals training runs virtually and in Hamburg, with current dates on the course page.
Not as a legacy MDM restriction. Apple states that software update restrictions such as deferrals no longer function in 27.0 operating systems. Deferrals of 1 to 90 days remain available through the declarative Software Update settings configuration on supervised devices, provided your UEM supports it.
Software update commands, software update queries, recommended cadence settings and software update restrictions, including deferrals and Background Security Improvements. Apple asks IT teams to use declarative software update management instead. Its developer documentation had already listed the commands ScheduleOSUpdate, AvailableOSUpdates and OSUpdateStatus as deprecated from iOS 26.0.
The Software Update declaration, which enforces a specific version by a set date and time, works from iOS 17 without supervision. The Software Update settings configuration for deferrals, cadence and automatic updates requires supervision, apart from its enforcement keys and beta programme offers.
Through declarative status reports. After subscribing, the device reports its OS version and build, any pending update, the install state and failure details. It sends a report when the subscription becomes active, when a subscribed item changes, and every 24 hours.