> ## Documentation Index
> Fetch the complete documentation index at: https://iru-kbee-63-enhance-rts-documentation.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Understanding Managed OS for Apple Platforms

> How Managed OS enforcement works in Iru Endpoint across macOS, iOS, iPadOS, and tvOS, including rolling enforcement, phased rollout, and version options.

<Callout icon="apple" color="#B84A7A" iconType="regular">This guide applies to Mac computers, iOS devices, iPadOS devices, and Apple TV</Callout>

### About Managed OS

Managed OS deploys and enforces OS updates across your fleet of Apple devices. Updates are delivered via [Declarative Device Management (DDM)](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) on supported versions.

Which OS version a device receives when it updates depends on [Version Enforcement](#version-enforcement): **Rolling enforcement** and **Manually enforce a minimum version** install the latest Iru-approved update; **Enforce a specific version** enforces the OS version you select.

For configuration steps, see [Configuring Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos) or [Configuring Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos).

### Version Enforcement

Under **Updates**, choose how OS updates are enforced. **Rolling enforcement** and **Manually enforce a minimum version** set a minimum version floor; **Enforce a specific version** targets an exact OS version by a deadline.

| Option                                 | Sets a floor?                   | OS version installed          | Key configuration fields                                                                                                                                                                                                  |
| -------------------------------------- | ------------------------------- | ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Do not manage updates**              | No                              | No Managed OS enforcement     | N/A                                                                                                                                                                                                                       |
| **Rolling enforcement**                | Yes (from Apple's release date) | Latest Iru-approved version   | **Within** (1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, or 3 months) **of release**, **at**, optional **Delay enforcement by** (up to 90 days), optional **Enable phased rollout** and **Rollout window** |
| **Manually enforce a minimum version** | Yes (admin-set minimum)         | Latest Iru-approved version   | Minimum version, **Enforcement Deadline**, **Enforcement Time**, optional **Enable phased rollout** and **Rollout window**                                                                                                |
| **Enforce a specific version**         | No (exact target)               | Selected **Specific version** | **Specific version**, **Enforcement Deadline**, **Enforcement Time**, optional **Enable phased rollout** and **Rollout window**                                                                                           |

#### Shared enforcement behavior

* When [DDM](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) is in use, enforcement uses the device's local time zone.
* When a new update is available in Iru Endpoint, it is cached on devices as soon as possible. After the update is cached, users are notified leading up to enforcement. On macOS, the Iru menu app displays rounded days (for example, if an update will be enforced in 7.6 days, 8 days is displayed).
* **Rolling enforcement** and **Manually enforce a minimum version** install the latest Iru-approved OS version (shown in the upper-right corner of the Library Item). **Enforce a specific version** enforces the OS version you selected.

#### Do not manage updates

Iru Endpoint does not enforce an OS version. On macOS, this option cannot be used with **Upgrade automatically** under **Upgrades**, since **Upgrades** sets the major-version upgrade schedule and conditions separately from **Updates**.

#### Rolling enforcement

New OS updates are enforced automatically after release. You configure:

* **Within**: How long after release (1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, or 3 months) **of release**
* **at**: The time of day the update is enforced
* **Delay enforcement by** (optional): How many days (up to 90) to delay sending the target-version declaration. This does not change the enforcement date calculated from **Within** and **at**. Use it to temporarily hold back the newest available version while still using **Rolling enforcement**.

The floor is calculated from Apple's release date. Devices receive the latest Iru-approved OS version when they update.

To hide a new OS version from users for the same period, set a matching deferral in a [Software Update Library Item](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates#configure-the-software-update-library-item). For example, if an OS update is released on July 22 and you set **Delay enforcement by** to 5 days and a 5-day Software Update deferral, users do not see that update until July 27.

<Note>
  If **Delay enforcement by** is shorter than your Software Update Library Item deferral, Managed OS still sends its declaration before the deferral ends and overrides the deferral for that update.
</Note>

#### Manually enforce a minimum version

You set the minimum OS version and an **Enforcement Deadline** (plus **Enforcement Time**). No update is enforced if a device is already above the minimum. Use this for critical security updates or to align the fleet to a version by a date. Devices below the minimum receive the latest Iru-approved OS version when they update.

#### Enforce a specific version

Uses the same version selection dropdown and enforcement scheduling fields as **Manually enforce a minimum version**: select a **Specific version**, an **Enforcement Deadline**, and an **Enforcement Time**. Unlike **Manually enforce a minimum version**, this option enforces that exact OS version on your deadline rather than treating it as a minimum floor. Use this when you need all devices on a particular version by a fixed date.

To enforce an Apple beta build, select **This is a beta version** and choose a **Seed Token** synced from Apple to Iru. Iru applies **Software Update Settings** (beta enrollment) and then **Software Update Enforcement** (to the specified version) as separate declarations. For example, to test a beta upgrade to the next major macOS release, use a macOS Tahoe Managed OS Library Item, select a macOS Golden Gate seed token, and enter the target major version (such as `27.0`) and the current AppleSeed beta build.

Managed OS is for beta program enrollment and a specific beta version together. To offer opt-in programs, enforce enrollment without a version, or enroll at ADE before management, see [Testing Apple Beta Releases](/en/endpoint/devices/device-configurations/apple/testing-apple-beta-releases#ways-to-manage-apple-beta-program-enrollment).

<Note>
  The **Seed Token** list can be long and difficult to navigate.
</Note>

Iru checks hardware compatibility before enforcing **Enforce a specific version**, **Manually enforce a minimum version**, and **Rolling enforcement** targets. Devices that cannot run the required version are not forced to install an incompatible update.

#### Phased rollout

Select the **Enable phased rollout** checkbox under **Updates**, then enter the number of hours in the **Rollout window** field (24–168). Iru gradually rolls out the enforced update by staggering when each device receives its enforcement declaration across that window. Enforcement deadlines are unchanged, and OS upgrades and initial installs are unaffected.

When each device becomes eligible (the reveal time), that timing appears on the Library Item **Status** tab, similar to [phased rollout for Mac Auto Apps](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos#phased-rollout). See [Library Item Status Activity Timeline](/en/endpoint/library/library-items-profiles/library-item-status-activity-timeline).

How declarations are staggered depends on the Version Enforcement option:

* **Enforce a specific version**: When you create the Library Item, or when you change OS version settings or the enforcement date or time and save, declaration issuance is spread across the **Rollout window** starting from Library Item save.
* **Rolling enforcement**: When Apple releases a new version, if **Delay enforcement by** is set, the update remains hidden until that delay ends. After the delay expires (or immediately if delay is not set), declaration issuance is spread across the additional **Rollout window** hours.
* **Manually enforce a minimum version**: When you first create the Library Item, or when you change OS version settings or the enforcement date or time and save, distribution is spread across the **Rollout window** from Library Item save. When Apple releases a new version, new declaration issuance is spread across the **Rollout window** for the fleet.

#### Background Security Improvements

In the same Library Item you can configure **Background Security Improvements** (lightweight security updates from Apple). **Automatically enforce** under Background Security Improvements is separate from **Rolling enforcement** under **Updates** → Version Enforcement. For configuration steps, see [Configuring Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos) or [Configuring Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos).

### macOS: Installation Options

macOS Managed OS also lets you choose how major macOS upgrades are offered under **Upgrades**:

* **Upgrade automatically**: Iru Endpoint forces the device to the latest version of this OS either immediately upon Library Item assignment, or on a specified date and time. Optionally make it **Available in Self Service** so users can install before the deadline.
* **Upgrade on demand from Self Service**: Users upgrade through Self Service or Software Update with no enforced deadline. Use different copies of the same Managed OS Library Item with different [labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) to offer this in some Blueprints and automatic upgrades in others.

**Updates** and **Upgrades** use separate enforcement schedules in the same Library Item. You can enforce minor macOS updates on one timeline and major upgrades on another. This avoids devices on an older major version appearing out of date and being forced to upgrade as soon as the Library Item is scoped.

For UI steps, see [Configure Installation Method](/en/endpoint/library/managed-os/configure-managed-os-for-macos#configuring-managed-os-for-macos) in **Configuring Managed OS for macOS**.

Additional macOS considerations:

* Managed OS does not support downgrading macOS.
* Do not block the Software Update System Settings pane; doing so is not compatible with Managed OS and can produce unexpected behavior.

### iOS, iPadOS, and tvOS: Supervision

<Note>
  Managed OS for iOS, iPadOS, and tvOS requires supervision.
</Note>

At the enforcement deadline, on iOS and iPadOS devices with a passcode, users must be prompted for the update and enter their passcode. On tvOS, and on iOS and iPadOS devices without passcodes, updates apply without user intervention at the deadline. For details, see [User Experience with Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/devices/user-experience-with-managed-os-for-ios-ipados-and-tvos).

### Recommendations

* **First time enforcing an OS version on your fleet:** Use **Manually enforce a minimum version** and set the **Enforcement Deadline** at least 5 days later so users get advance notifications. For UI steps, see [Configuring Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos) or [Configuring Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos).
* **Rolling enforcement and immediate update requirements:** If Apple has not released an update within your selected window (e.g. **Within 2 weeks of release**), all out-of-date devices may immediately be required to update and restart.
* **Delay enforcement by and Software Update deferrals:** Use **Delay enforcement by** with a matching Software Update Library Item deferral when you want to hold back the newest version under **Rolling enforcement** and keep it hidden from users. Set both to the same number of days so Managed OS does not override the deferral early. See [OS Update Strategies: OS Deferral Restriction and Managed OS](/en/endpoint/devices/device-configurations/apple/os-update-strategies-os-deferral-restriction-and-managed-os).
* **Phased rollout:** Select the **Enable phased rollout** checkbox and enter hours in **Rollout window** when you want declaration issuance staggered across the fleet instead of all at once. Pair it with **Delay enforcement by** under **Rolling enforcement** when a new Apple release should stay hidden until the delay ends, then spread over the **Rollout window**.
* **Software Update Library Items:** If you use Managed OS, turn off automatic download of updates in any Software Update Library Items used in the same Blueprint to avoid conflicts with caching. On macOS, see also [Deployment Considerations](/en/endpoint/library/managed-os/managed-os-for-macos-compatibility-and-installation-mechanisms#deployment-considerations) in **Managed OS for macOS Compatibility and Installation Mechanisms**.

### Labels

Use **labels** to tell copies of the same Managed OS apart when you add it to your Library more than once. See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview.

### Related Articles

<CardGroup cols={2}>
  <Card title="Configure Managed OS for macOS" icon="apple" href="/en/endpoint/library/managed-os/configure-managed-os-for-macos">
    Configure Managed OS updates for Mac computers
  </Card>

  <Card title="Configure Managed OS for iOS, iPadOS and tvOS" icon="mobile" href="/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos">
    Configure Managed OS updates for iOS, iPadOS, and tvOS devices
  </Card>

  <Card title="Managed OS for macOS Compatibility and Installation Mechanisms" icon="cog" href="/en/endpoint/library/managed-os/managed-os-for-macos-compatibility-and-installation-mechanisms">
    Understand compatibility and installation mechanisms for Managed OS on macOS
  </Card>

  <Card title="Understanding Issues with Managed OS for macOS" icon="triangle-exclamation" href="/en/endpoint/library/managed-os/understanding-issues-with-managed-os-for-macos">
    Understand how Managed OS works with DDM and macOS when troubleshooting updates
  </Card>

  <Card title="Declarative Device Management and Managed OS" icon="apple" href="/en/endpoint/library/managed-os/declarative-device-management-and-managed-os">
    About Apple DDM and Managed OS in Iru Endpoint
  </Card>

  <Card title="macOS Managed OS User Experience" icon="user" href="/en/endpoint/devices/macos-managed-os-user-experience">
    What to expect when Managed OS updates run on your Mac
  </Card>

  <Card title="User Experience with Managed OS for iOS, iPadOS and tvOS" icon="user" href="/en/endpoint/devices/user-experience-with-managed-os-for-ios-ipados-and-tvos">
    What to expect when Managed OS updates run on iOS, iPadOS, and tvOS devices
  </Card>
</CardGroup>
