Overview: Declarative OS Updates in Addigy (DDM)
Overview: OS Updates in Addigy (DDM)
As Apple continues to phase out support for OS updates via MDM, it is becoming more important than ever to understand and leverage settings via Declarative management (aka DDM).
Declarative OS Updates let you choose how updates reach your fleet: enforced by a deadline that you set, installed automatically by on-device AI without disturbing end users, or held back entirely while you manage update behavior through settings alone.
In this article, we will detail everything you need to know about OS Updates so that you can confidently and effectively keep your fleet up to date.
For more information on the general concept of Declarative management, please follow this link.
Note on enablement: If DDM OS Updates are enabled (via Account > Account Integrations > Addigy Add-Ons > DDM OS Updates), macOS 14+ and iOS/iPadOS 17+ will use Scheduled Update Declarations by default, and macOS 15+ and iOS/iPadOS 18+ will use Updates via Device AI if optionally enabled in the policy. If overall DDM integration is not enabled at the organization level, MDM will cover all OS types listed in these requirements and up.
Enabling the Integration
To begin using Declarative Updates in your environment, you must enable the DDM OS Updates integration from within your Addigy portal's Account > Integrations page. Enabling the integration will not automatically start sending updates to your devices; you must configure the updates in the policy.
Where are OS Updates Configured?
To begin configuring updates, navigate to any policy and select the Updates tab in the left-hand menu. By default, everything in the policy will be disabled, and no updates will be sent to devices.
These settings will be inherited by any child policies, so be aware of where you are configuring Declarative Updates to avoid conflicts.
Choosing OS Update Behavior
There are two dropdowns at the top of the page that control which settings will be displayed for configuration.
The "Keep devices" setting sets the version target, and it determines which delivery methods are available.
"How do you want updates delivered?" sets the cadence, and it determines which settings appear further down the page.
Keep devices updated to the latest OS
Addigy will automatically send the latest OS version to all applicable devices. This includes major versions (upgrades). This is the only version setting that allows updates to be delivered via On-Device AI.
Keep devices updated to a maximum version
This setting lets you define the maximum version that Addigy can deploy. This does not serve as a device-wide version restriction and it will not block users from updating beyond the defined version. It only controls what version Addigy will send as a managed update. If you would like to restrict users from updating or upgrading to certain versions, please reference this article.
Setting the maximum version number to 26.99.99 allows devices in this policy to get all of the minor and patch versions of macOS Tahoe (26) while not deploying a future version of macOS past 26. This field follows the major.minor.patch versioning standard. These same rules apply to iOS, iPadOS, and tvOS.
The On-Device AI option will not be available because it requires you to send the latest.
Deferred with settings
Addigy will not send any update declarations to devices in this policy. Instead, you can deploy update-related settings such as deferrals, notification preferences, and automatic action controls, then let users and the OS handle the rest within those boundaries.
This is the right choice when you want to delay what users see and control how the OS behaves, while not wanting to push a specific version or enforce a due date.
Version vs. Settings Summary
| Keep devices | Delivery options available | What Addigy sends |
|---|---|---|
| Updated to the latest OS | Deadline or On-Device AI | The latest OS version, including major upgrades |
| Updated to a maximum version | Deadline only | Any version up to the maximum you define |
| Deferred with settings | None | Settings only, no updates sent via Addigy |
Updates Delivered via Deadline (Scheduled OS Updates)
Scheduled OS Updates set a "deadline" for the maximum OS version you allow. The due date will vary based on the settings you configure in Addigy. In a general sense, it's like telling the device, "you have to install x version by y date". If it misses the deadline, the enforcement behavior will change based on what settings you configure.
This is the most predictable option. You know when the update will happen, users get warned in advance, and devices that miss the window can be forced to comply.
What it can do:
- Set a due date based on how many days an OS version has been publicly released
- Restrict enforcement to specific days of the week
- Block managed update enforcement across a fixed date range, such as a holiday freeze or an audit period
- If the 'Force past due updates' setting is enabled, devices will restart to apply the update within one hour of missing the deadline
- Surface a custom support link in Software Update on the device
Requirements:
- Device is Supervised via ADE or MDM Manual Device Enrollment
- macOS 14 and newer
- iOS 17 and newer
- iPadOS 17 and newer
Updates Delivered via On-Device AI
When configured to do so, the device will use locally run machine learning to determine a suitable installation time. The device's AI will identify the best time to apply the update based on when the user will not be disturbed, while also considering factors such as battery percentage, network usage, free space requirements, and when the device is asleep. Once it has determined a good time to apply the update and knows the user will not be disturbed, it will perform the update at the predicted time unless the end user interrupts the process.
This is the least disruptive option and the best fit for fleets where user experience matters more than a guaranteed completion date.
Note: Updates via On-Device AI will not force install at any scheduled time. The OS will determine when it is best to install the update without disturbing the end user. At the time of writing, it is not possible to know exactly when the device plans to do the update once it decides.
Requirements:
- Device is Supervised via ADE or MDM Manual Device Enrollment
- macOS 15 and newer
- iOS 18 and newer
- iPadOS 18 and newer
- Keep devices updated to the latest OS selected
- Configure Automatic Actions enabled and set to Always On
Power requirements:
Depending on the type of update and how it is initiated, devices must be connected to power or have the following minimum battery charging level to download, prepare, and install a software update with automatic install.
| Device | Minimum charge |
|---|---|
| iPhone | 30% |
| iPad | 30% |
| Mac with Apple silicon | 50% |
| Intel-based Mac | 50% |
Deferred with Settings
No automatic updates or scheduled OS updates are sent. Addigy manages the device's update experience instead of the update itself. Use this when you need to configure certain update cadences, like deferred updates, but do not want to enforce an update version.
What it can do:
- Hide major, minor, and non-OS updates from users for a set number of days
- Control whether standard users can perform updates
- Control notification behavior
- Turn off automatic downloads and installs while updates are deferred
- Control user interaction with Background Security Improvements
What it cannot do:
- Enforce a version
- Enforce a due date
Requirements:
- Device is Supervised via ADE or MDM Manual Device Enrollment
- macOS 15 and newer
- iOS 18 and newer
- iPadOS 18 and newer
Settings Overview
Each setting below lists the delivery options it appears under, along with any OS restrictions.
Force install (x) days after release, at (y)
Deadline | macOS 14+, iOS/iPadOS 17+
This setting is your due date for the OS version, which is based on when the particular version was released by Apple. OS updates will be enforced at this local 24-hour device time.
As an example, let's say I have a maximum version of 26.99.99 and a force install of 14 days at 0:00. The due date for 26.6.2 will be August 30th, 2026 at 12 AM device local time, given the update was released on August 16th, 2026.
Force past due updates
Deadline | macOS 14+, iOS/iPadOS 17+
If an update deadline is missed by a device, this setting will dictate what happens next.
If disabled, Addigy will only ever schedule the update declaration to install at the configured time. For example, if the "Force install (x) days after release, at (y)" setting is configured to force 30 days after release at 11 AM, when the update goes past due, Addigy will reschedule the update for 11 AM on the next allowed day.
If enabled, when a scheduled update declaration is past its due date, Addigy will allow the update to follow the past due update workflow:
- The device misses the due date for the update.
- When the device is available and communicating with Apple servers, it will schedule the update to install within 1 hour.
- Users can prematurely install the update to avoid a forceful restart.
- Once the 1 hour passes, the device will automatically restart to apply the update.
- Any open apps that require additional interaction to be closed will halt the restart, which can cause an unexpected restart if the user is away, comes back, and interacts with the prompt to close the app.
- If the device was not able to update during the past due timeframe, it will automatically reschedule the update for the next hour.
This setting is disabled by default, and we recommend keeping it disabled if you want to avoid updates being force-installed outside of the defined install time.
Note: Addigy will always obey allowed days, even with this setting enabled. For example, if you only allow updates on Saturdays, the update will not try to install on any other day of the week.
Enforcement Days
Deadline | macOS 14+, iOS/iPadOS 17+
This setting designates which days of the week declarations can and cannot take place, including past due updates. Selecting only Monday will allow OS update declarations to be scheduled on Mondays alone.
Avoid updates from (x) to (y)
Deadline | macOS 14+, iOS/iPadOS 17+
This setting allows you to set a static range of dates to avoid applying a declaration, including past due updates. For example, if we enforce 15.3.1 to install 1 day after release, a range of 2/19 to 2/26 will not allow that update to install during that window.
Include a support article link with each update
Deadline | macOS 14+, iOS/iPadOS 17+
This setting will add your custom link to System Settings (macOS) or Settings (iOS/iPadOS) > Software Update. On macOS, it appears as the Organization Help URL.
macOS:
iOS/iPadOS:
Set Deferrals for Software Updates
Deadline, On-Device AI, Deferred with settings | macOS 15+, iOS/iPadOS 18+
macOS:
iOS/iPadOS:
Sets how long software updates can be delayed before installation. Note: Deferrals will not apply to Scheduled Update Declarations. For example, if you force install 10 days after release and deferrals are set to 90 days, the scheduled update will still go through 10 days after release.
- Major Updates (range: 1 to 90 days) Specifies the number of days to defer visibility and autorun of a software upgrade on the device. When set, software upgrades appear only after the specified delay, following the release of the software upgrade.
- Minor Updates Specifies the number of days to defer a software update only (not a software upgrade or Rapid Security Response) on the device. When set, software updates appear only after the specified delay, following the release of the software update.
- System (Non-OS) Updates Specifies the number of days to defer non-operating system updates, such as XProtect and Safari. When set, updates appear only after the specified delay, following the release of the update.
Set Notification Preferences for Updates
Deadline, On-Device AI, Deferred with settings | macOS 15+, iOS/iPadOS 18+
Devices will show all update notifications, or only urgent ones an hour before the deadline with a restart countdown.
- Show all notifications If selected, users will see all notifications related to updating the device.
- Show notifications one hour before If selected, devices will only show notifications triggered one hour before the enforcement deadline and the restart countdown notification.
Users performing major/minor updates
Deadline, On-Device AI, Deferred with settings | macOS only, 15+
Controls whether a Standard User can perform updates.
- Enabled Standard users (non-admins) can perform updates and upgrades on the device.
- Disabled Only administrators can perform updates and upgrades on the device.
Recommended Cadence
Deadline, On-Device AI, Deferred with settings | iOS/iPadOS only, 18+
Specifies how the device shows software upgrades to the user. When multiple OS versions are available, the device behaves as follows.
- All Shows all software updates and upgrades.
- Oldest Shows only updates for the oldest (lower numbered) software version allowed by your maximum allowed OS version. For example, if my maximum version is set to 18.3, an iPad on 18.0 will only see 18.3 in Settings > Software Update. If you leverage the "keep latest update" setting, it will still show the latest OS version.
Newest Shows only a software upgrade to the newest (highest numbered) software version.
Manage Background Security Improvement Settings
Deadline, On-Device AI, Deferred with settings | macOS 15+, iOS/iPadOS 18+
Controls the user's ability to interact with Background Security Improvement (BSI), formerly Rapid Security Response (RSR).
Enable installation
- If enabled, the system offers Background Security Improvement (BSI) to the user. If the BSI requires a reboot (most do), user interaction will be required or it will try to install when the device is not in use.
- If disabled, Background Security Improvements aren't offered for user installation. The system can still install Rapid Security Responses with Scheduled Update Declarations. More on BSIs can be found here.
Enable rollback
- If enabled, the system offers Background Security Improvement rollbacks to the user.
- If disabled, the system doesn't offer them.
Configure Automatic Actions
On-Device AI, Deferred with settings | macOS 15+, iOS/iPadOS 18+
Sets preferences for automatic Software Update functions.
Under On-Device AI, this setting is what enables machine learning to download, prepare, and install updates on its own. It must be enabled and set to Always On for AI-driven updates to work.
Under Deferred with settings, this setting turns off automatic downloads and installs while updates are deferred.
Downloads
- Allowed: The user can turn on or turn off automatic downloads.
- AlwaysOn: Automatic downloads are always turned on.
- AlwaysOff: Automatic downloads are always turned off.
Install OS Updates
- Allowed: The user can turn on or turn off automatic installations.
- AlwaysOn: Automatic installations are always turned on.
- AlwaysOff: Automatic installations are always turned off.
Install Security Updates (macOS only)
- Allowed: The user can turn on or turn off automatic installations.
- AlwaysOn: Automatic installations are always turned on.
- AlwaysOff: Automatic installations are always turned off.
General Configuration Recommendations
Updates via Deadline
If you'd like to leverage scheduled OS updates but are not sure what to configure, we recommend configuring it like so:
- A managed update will not be forced outside of Friday-Sunday, meaning end-users will not be disturbed during the common working hours
- The update will be scheduled for the closest Friday on or after your designated OS version has been out for 15+ days
- For example, 26.4.1 was released on Wednesday, April 8th. 15 days after that is Thursday, April 23rd. Since Thursday isn't an allowed day, but Friday is, Addigy will schedule it for Friday, April 24
- Once within 24 hours of the install time (beginning Thursday at 5pm), users will receive this notification every hour. This helps encourage them to install the update themselves before the forced update at 5pm
- If you do not want to force an update at 5pm on a business day, consider pushing the install time up to something later, like 6pm or 7pm
- So long as devices are reachable and have sufficient battery, they should be able to update over the weekend if the update doesn't go on Friday
Updates via On-Device AI
If you would like to leverage on-device AI auto-update settings, we recommend configuring it like so:
End User Experience
Updates via Deadline
Apple has this diagram that shows the cadence and frequency of notifications that are sent to devices. These notifications are controlled by Apple and cannot be modified except for the ability to hide notifications until the 1-hour enforcement countdown begins.
Source from Apple
Standard Declaration Prompt (macOS)
Users will see the following prompt when the declaration is successfully sent to the device. Additionally, this prompt will show every hour when the device is within 24 hours of the enforced due date.
Past Due (macOS)
When an update is past the enforced due date, it will enter the "past due" phase, which gives the user 1 hour to install it manually, or it will force reboot at the end of the hour.
Standard Declaration Prompt With Passcode Set (iOS/iPadOS)
If no passcode is configured on the device, it will automatically restart with no prompt once the update is downloaded and prepared.
Past Due (iOS/iPadOS)
For the first prompt pictured below, users can select "Emergency" to hide the prompt and temporarily skip the update. If they select Emergency, the same past due prompt will reappear a few minutes later.
If the 1-hour time limit expires, users will see the following prompt.
Updates via On-Device AI
AI-based updates utilize much of the same prompting process that the consumer Apple OS Updates use. The main idea behind machine learning updates is to keep devices updated without user interaction, so users may not encounter as many prompts as they would with Scheduled OS Update Declarations.
Note: The device will try to fetch the password used to most recently unlock the device. If it cannot fetch this, the user will be prompted to enter their credentials.
macOS
When the Automatic Actions setting is in use and set to "Always On", once the device decides when to do the update, the end user will see a prompt stating that an update is available for installation.
If the user clicks on this notification or navigates into System Settings to view the details of the update, they will see the available version of the update that is cached and booked to install when the device is in an applicable state (e.g. PowerNap). More simply, this green checkmark signifies that machine learning has prepared the update and will try to install it when the device is in a good state to apply it.
Once the device has figured out a good time to update, users will be warned to close any apps that may block a restart.
If any apps prevent the device from rebooting to apply the update, users will see this warning the next time they log in:
iOS/iPadOS
Similar to the above, when the Automatic Actions setting is in use and set to "Always On" and Addigy sends the settings, the end user will see a prompt stating that an update is available for installation.
If the user clicks on this notification or navigates into Settings to view the details of the update, they will see the available version of the update that is cached and booked to install when the device is in an applicable state. More simply, this green checkmark signifies that machine learning has prepared the update and will try to install it when the device is in a good state to apply it.
Viewing Update Statuses in Addigy
To review pending updates, enforcement dates, and update events for a device, see this article: Viewing OS Update Statuses in Addigy
Additional Settings
The Additional Settings button at the bottom of the Updates page holds configuration for beta OS updates and legacy MDM OS updates.
MDM Updates
macOS 12 to 13 | Legacy
MDM OS updates are deprecated on OS 26 and removed entirely on OS 27. They are not recommended and only apply to devices that cannot use Declarative Updates.
- Update method Determines how the update command is delivered. The Default option downloads and installs depending on the current device state.
- Re-send the update command if status is older than Sets how long Addigy waits before re-issuing the update command when it has not received a fresh status from the device.
Beta Settings
- Beta Updates (macOS 15+) To access Beta features, you need to add Beta programs for your organization in AppleSeed for IT. Once added, Addigy will automatically retrieve them from your ADE Token and display them here for you.
- Push Beta OS Updates (macOS 14 only, Legacy) Applies to devices enrolled in the Beta Program with beta builds available on device.
For full details on beta configuration, review Managing Beta OS Updates via Addigy.
Important Notes for Managed OS Updates
General Notes
- If you have parent and child policies with differing update settings, Addigy will send the most restrictive settings.
- For enforcement dates, if you have a 90-day enforcement time configured in the child policy but 14 days configured in the parent policy, the device will try to update 14 days after the release of the OS version you are sending.
- For version, Addigy will send the lowest OS version, and if the device exceeds the lowest version, it will not receive updates from Addigy. For example, if you enforce 15.3.2 in the parent and 15.5 in the child, a 15.4 device will not receive the updates for 15.5.
- Enforcement Declarations can only enforce OS updates, not application updates for things like Safari and XProtect.
- Addigy will automatically deploy updates for software like XProtect and Safari via MDM for devices running OS 26 or lower.
- For devices on OS 27+, application updates can only be deployed by configuring Automatic Actions and setting Always On for Install Security Updates and Downloads. This will ensure Safari and XProtect are automatically updated via on-device AI.
- On a Mac with Apple silicon, the Mac uses a bootstrap token to authorize the update. If that cannot be done, the Mac will prompt the user for their credentials.
- In GoLive, Addigy will show all pending OS updates, including those not initiated by Addigy. For example, if you see a pending update in GoLive with no method or enforcement date and a "Prepared" status, it may have been automatically downloaded and prepared by the OS. If you are unsure whether an unwanted update was initiated by Addigy, please reach out to our support team for further insight.
- If the device does not support the maximum version enforced in the policy, it will go to the next applicable version. For example, when using the "keep latest version" setting, Addigy will only send applicable Sonoma (14) versions to a macOS 14 device that does not support macOS 15+.
Updates via Deadline
- For iOS/iPadOS, if a passcode has been configured, users will be prompted to enter their passcode to authorize the update. If no passcode is configured, the device will automatically restart with no prompt once the update is downloaded and prepared. This may cause unexpected or unwanted downtime.
- Devices will directly update or upgrade to the maximum version you have configured. They will not need to install different OS versions to reach the enforced max version. For example, a device on 15.2 can upgrade directly to 26.0.1.
- Per Apple, if a patch version is available for a minor version, the device may require an update to the latest applicable patch version, according to what is available on the Apple CDN. For example, if the maximum version is set to 15.7.0, the device may install 15.7.3, given that it is the current latest patch version related to that minor version, because the .1 and .2 patch versions are not available in the update catalog.
- Addigy will shift the active declaration due date if a new, applicable OS version comes out. For example, if you have 15.99.99 as the max version and a 60-day enforcement period, a device on 15.3 will declare 15.3.1 for 60 days after its release date. If 15.3.2 comes out within the designated 60 days for 15.3.1, Addigy will change the due date to 60 days after the release of 15.3.2.
- Deferrals will not apply to Scheduled Update Declarations. For example, if you force install 10 days after release and deferrals are set to 90 days, the scheduled update will still go through 10 days after release.
Updates via On-Device AI
- AI-controlled updates will only install when the device is not actively being used.
- Updates controlled via On-Device AI do not have a due date like scheduled updates. In the "Pending Update" modal in GoLive, no enforcement date will be posted, given that these do not send traditional due dates.
- You can confirm Addigy is applying the settings by navigating to GoLive > Events for a device and searching for "Any = Addigy DDM". More info here: Viewing OS Update Statuses in Addigy
- Per Apple, devices using automatic updates (excluding Scheduled OS Updates) may prompt the user for their password. This happens if the OS is unable to automatically fetch the current user credentials, which is needed to authorize the update.
- If devices are not updating even after weeks of having these AI settings correctly configured, please reach out to our support team for assistance with troubleshooting.