This guide applies to Mac computers, iOS devices, iPadOS devices, and Apple TV
About Managed OS
Managed OS deploys and enforces OS updates across your fleet of Apple devices. Updates are delivered via Declarative Device Management (DDM) on supported versions. Which OS version a device receives when it updates depends on Version Enforcement: Rolling enforcement and Manually enforce a minimum version install the latest Iru-approved update; Enforce a specific version enforces the OS version you select. For configuration steps, see Configuring Managed OS for macOS or Configuring Managed OS for iOS, iPadOS, and tvOS.Version Enforcement
Under Updates, choose how OS updates are enforced. Rolling enforcement and Manually enforce a minimum version set a minimum version floor; Enforce a specific version targets an exact OS version by a deadline.Shared enforcement behavior
- When DDM is in use, enforcement uses the device’s local time zone.
- When a new update is available in Iru Endpoint, it is cached on devices as soon as possible. After the update is cached, users are notified leading up to enforcement. On macOS, the Iru menu app displays rounded days (for example, if an update will be enforced in 7.6 days, 8 days is displayed).
- Rolling enforcement and Manually enforce a minimum version install the latest Iru-approved OS version (shown in the upper-right corner of the Library Item). Enforce a specific version enforces the OS version you selected.
Do not manage updates
Iru Endpoint does not enforce an OS version. On macOS, this option cannot be used with Upgrade automatically under Upgrades, since Upgrades sets the major-version upgrade schedule and conditions separately from Updates.Rolling enforcement
New OS updates are enforced automatically after release. You configure:- Within: How long after release (1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, or 3 months) of release
- at: The time of day the update is enforced
- Delay enforcement by (optional): How many days (up to 90) to delay sending the target-version declaration. This does not change the enforcement date calculated from Within and at. Use it to temporarily hold back the newest available version while still using Rolling enforcement.
If Delay enforcement by is shorter than your Software Update Library Item deferral, Managed OS still sends its declaration before the deferral ends and overrides the deferral for that update.
Manually enforce a minimum version
You set the minimum OS version and an Enforcement Deadline (plus Enforcement Time). No update is enforced if a device is already above the minimum. Use this for critical security updates or to align the fleet to a version by a date. Devices below the minimum receive the latest Iru-approved OS version when they update.Enforce a specific version
Uses the same version selection dropdown and enforcement scheduling fields as Manually enforce a minimum version: select a Specific version, an Enforcement Deadline, and an Enforcement Time. Unlike Manually enforce a minimum version, this option enforces that exact OS version on your deadline rather than treating it as a minimum floor. Use this when you need all devices on a particular version by a fixed date. To enforce an Apple beta build, select This is a beta version and choose a Seed Token synced from Apple to Iru. Iru applies Software Update Settings (beta enrollment) and then Software Update Enforcement (to the specified version) as separate declarations. For example, to test a beta upgrade to the next major macOS release, use a macOS Tahoe Managed OS Library Item, select a macOS Golden Gate seed token, and enter the target major version (such as27.0) and the current AppleSeed beta build.
Managed OS is for beta program enrollment and a specific beta version together. To offer opt-in programs, enforce enrollment without a version, or enroll at ADE before management, see Testing Apple Beta Releases.
The Seed Token list can be long and difficult to navigate.
Phased rollout
Select the Enable phased rollout checkbox under Updates, then enter the number of hours in the Rollout window field (24–168). Iru gradually rolls out the enforced update by staggering when each device receives its enforcement declaration across that window. Enforcement deadlines are unchanged, and OS upgrades and initial installs are unaffected. When each device becomes eligible (the reveal time), that timing appears on the Library Item Status tab, similar to phased rollout for Mac Auto Apps. See Library Item Status Activity Timeline. How declarations are staggered depends on the Version Enforcement option:- Enforce a specific version: When you create the Library Item, or when you change OS version settings or the enforcement date or time and save, declaration issuance is spread across the Rollout window starting from Library Item save.
- Rolling enforcement: When Apple releases a new version, if Delay enforcement by is set, the update remains hidden until that delay ends. After the delay expires (or immediately if delay is not set), declaration issuance is spread across the additional Rollout window hours.
- Manually enforce a minimum version: When you first create the Library Item, or when you change OS version settings or the enforcement date or time and save, distribution is spread across the Rollout window from Library Item save. When Apple releases a new version, new declaration issuance is spread across the Rollout window for the fleet.
Background Security Improvements
In the same Library Item you can configure Background Security Improvements (lightweight security updates from Apple). Automatically enforce under Background Security Improvements is separate from Rolling enforcement under Updates → Version Enforcement. For configuration steps, see Configuring Managed OS for macOS or Configuring Managed OS for iOS, iPadOS, and tvOS.macOS: Installation Options
macOS Managed OS also lets you choose how major macOS upgrades are offered under Upgrades:- Upgrade automatically: Iru Endpoint forces the device to the latest version of this OS either immediately upon Library Item assignment, or on a specified date and time. Optionally make it Available in Self Service so users can install before the deadline.
- Upgrade on demand from Self Service: Users upgrade through Self Service or Software Update with no enforced deadline. Use different copies of the same Managed OS Library Item with different labels to offer this in some Blueprints and automatic upgrades in others.
- Managed OS does not support downgrading macOS.
- Do not block the Software Update System Settings pane; doing so is not compatible with Managed OS and can produce unexpected behavior.
iOS, iPadOS, and tvOS: Supervision
Managed OS for iOS, iPadOS, and tvOS requires supervision.
Recommendations
- First time enforcing an OS version on your fleet: Use Manually enforce a minimum version and set the Enforcement Deadline at least 5 days later so users get advance notifications. For UI steps, see Configuring Managed OS for macOS or Configuring Managed OS for iOS, iPadOS, and tvOS.
- Rolling enforcement and immediate update requirements: If Apple has not released an update within your selected window (e.g. Within 2 weeks of release), all out-of-date devices may immediately be required to update and restart.
- Delay enforcement by and Software Update deferrals: Use Delay enforcement by with a matching Software Update Library Item deferral when you want to hold back the newest version under Rolling enforcement and keep it hidden from users. Set both to the same number of days so Managed OS does not override the deferral early. See OS Update Strategies: OS Deferral Restriction and Managed OS.
- Phased rollout: Select the Enable phased rollout checkbox and enter hours in Rollout window when you want declaration issuance staggered across the fleet instead of all at once. Pair it with Delay enforcement by under Rolling enforcement when a new Apple release should stay hidden until the delay ends, then spread over the Rollout window.
- Software Update Library Items: If you use Managed OS, turn off automatic download of updates in any Software Update Library Items used in the same Blueprint to avoid conflicts with caching. On macOS, see also Deployment Considerations in Managed OS for macOS Compatibility and Installation Mechanisms.
Labels
Use labels to tell copies of the same Managed OS apart when you add it to your Library more than once. See Library Item Labels in Library Overview.Related Articles
Configure Managed OS for macOS
Configure Managed OS updates for Mac computers
Configure Managed OS for iOS, iPadOS and tvOS
Configure Managed OS updates for iOS, iPadOS, and tvOS devices
Managed OS for macOS Compatibility and Installation Mechanisms
Understand compatibility and installation mechanisms for Managed OS on macOS
Understanding Issues with Managed OS for macOS
Understand how Managed OS works with DDM and macOS when troubleshooting updates
Declarative Device Management and Managed OS
About Apple DDM and Managed OS in Iru Endpoint
macOS Managed OS User Experience
What to expect when Managed OS updates run on your Mac
User Experience with Managed OS for iOS, iPadOS and tvOS
What to expect when Managed OS updates run on iOS, iPadOS, and tvOS devices