Overview
Starting with macOS 11 Big Sur, Apple has deprecated the ability to block and ignore system updates via the softwareupdate utility. This means that updates and upgrades can only be hidden from end-users (deferred) for up to 90 days by using deferrals, and that upgrades via the .app installers can only be blocked via our blocker. These two avenues to update and upgrade mean you must take a layered approach to fully hide and block updates and upgrades.
Along with the OS 27 release comes the removal of deferrals via the Restrictions MDM profile and instead offering deferrals via Declarative. On OS 26, Apple has announced that these same deferrals via the Restrictions MDM profile to be deprecated, but from our assessment, it still works. Your experience may differ, and because it is deprecated, we ultimately suggest using deferrals via Declarative for OS 26+.
Please be sure to review the "Important Things to Account For" section at the bottom to familiarize yourself with specific behavior and expectations with deferring and blocking updates and upgrades.
Deferring updates for devices on macOS 15/iOS 18
The Restrictions MDM profile allows you to defer major and minor updates in a range of 1-90 days. When enabled, updates/upgrades within the deferral period will be hidden in System Settings > General > Software Updates. This deferral does not serve as a blocker; it will only hide the update from users.
This payload can be found in Catalog > Device Settings > New > Restrictions > Software Updates. (Reference this article if you are unfamiliar with Device Settings.)
The screenshot below is an example of setting up a major OS deferral for 90 days. When configured this way, the end user will not see any major OS upgrades that are less than 90 days old. For example, macOS Tahoe (26) was released on September 15th 2025, which means this MDM payload will hide the upgrade from the user until December 14th 2025.
Note: Selecting "How many days to delay a minor macOS software update on the device" will accomplish the same behavior as defined above, but for minor OS updates. (ie. macOS 15.1 to macOS 15.2)
If you would like to hide these updates for iPhones, iPads, and tvOS devices, you will want to leverage the two settings below. Please note that this will hide all updates that are within the deferral criteria, not just OS upgrades. This also applies to macOS, so if you want your Mac users to be able to manually update to minor macOS versions, consider deploying this to just iPhones/iPads via a Flex Policy.
Deferring updates for devices on OS 26+
As the transition from MDM to Declarative Management ramps up, Apple continues to alter how current deployments can be accomplished through Declarative. In this instance, OS update deferrals were possible via the Restrictions MDM profile, but that has since been removed for OS 27+ and deprecated on OS 26. Now, deferrals must be configured via Apple's Global Settings, also known as "Auto Install Updates via Device AI" in Addigy.
Before continuing further, it's worth noting that for OS 26, Apple has deprecated deferrals via the previously discussed Restrictions profile. In many instances of deprecation, this means it is no longer supported, but can still work. In our tests, deferrals through the Restrictions profile do hide the applicable versions, but they may be unreliable given the deprecation status from Apple. Thus, the ultimate suggestion is to leverage deferrals via Declarative for OS 26+.
To configure these deferrals:
- Navigate to the policy that handles OS updates.
- Click the Updates tab and check the device types you wish to configure deferrals for.
- For the version, you must select Keep devices updated to the latest OS. This is a requirement for sending deferrals via Declarative and is controlled by Apple.
- Scroll down and check Set Deferrals for Software Updates. Then, configure the deferrals to your preference.
Major Updates - This will hide major OS versions, for example, OS 26 -> 27.
Minor Updates - This will hide minor versions, for example, OS 26.5 -> 26.6.
System (Non-OS) Updates - This will hide updates for software, for example, Safari and XProtect.
While deferrals can hide the newest release, they cannot hold devices on an older version indefinitely, which can be problematic if a specific version is older than 90 days. For example, say you want to keep your fleet on macOS 26.3 because 26.4 introduced an issue with your VPN client and persists through later OS 26 versions. A 90-day deferral will hide 26.4+ at first, but once the version passes the 90-day mark, it can no longer be hidden. At that point, the device will either update on its own via Configure Automatic Actions, or, if Automatic Actions is not configured, receive a Scheduled OS Update declaration in accordance with your schedule.
If your goal is to prevent updates entirely rather than delay them, configure Automatic Actions so the device never downloads or installs updates on its own:
- In your policy's Updates tab, check Configure Automatic Actions.
- Check Downloads and set it to Always Off.
- Check Install OS Updates and set it to Always Off.
With this in place, the device will not automatically download or install OS updates, and no Scheduled OS Update declarations will be sent.
Note: Updates outside the deferral window are still visible in System Settings > General > Software Update, and users can install them manually. If the end-users of your fleet are standard users (not admins), set Users performing major/minor updates to Disabled. This will restrict OS updates to administrators only, and further restrict the possibility of an unwanted version being installed.
Blocking .app Upgrades using Prebuilt Apps (deprecated for upgrades macOS 27+)
The second layer of suggested workflows to avoid unwanted upgrades is to leverage our macOS blocker for the specific version of macOS you would like to block. For more information and instructions on how to deploy this, please follow this article.
Important Things to Account For
- Deferrals do not prevent Scheduled OS Updates, given deferrals only hide updates. If you have deferrals configured and do not use the Configure Automatic Actions setting, an update declaration will be sent in accordance with your schedule.
For example, if I have a policy with the settings below, the latest applicable OS version will be sent 15 days after the release of said version. - The Addigy macOS blocker is only capable of blocking the macOS installer .app files. As of now, macOS devices can upgrade to a major version via System Settings without the use of the macOS installer .app files. This is why it's important to deploy deferrals to hide the upgrade from your users in System Settings.
- The "Set maximum version" setting when configuring managed System Updates does not serve as a deferral/blocker. It simply determines the OS version Addigy will send to devices. For example, if you have the maximum version set to "26.99.99", that alone will not prevent OS 27 from being offered to the user (assuming no deferrals are configured).
If you see that devices have been upgraded unintentionally, please account for the 3 points above and review your policy settings. If you have verified that all possible preventative measures are in place, yet a device was upgraded within the deferral window, please do not hesitate to submit a support ticket.