Overview
The Apple Software Update Policy controls how managed Macs, iPhones, and iPads check for, download, defer, and install Apple software updates. You can also use it to require the newest available update by a date and time you choose.
The policy has two parts, and they behave differently depending on the OS version:
Part | Settings | Platforms | Works on OS 27 |
Update preferences and deferrals | Automatic checks, downloads, and installs; App Store app updates; XProtect and security updates; beta releases; admin-only installs; update deferrals | macOS only | No. Apple removed these controls in macOS 27. |
Install Action (enforced updates) | Install as soon as possible, on a specific date, or on a recurring day and hour | macOS 14+, iOS 17+, iPadOS 17+ | Yes. It uses Apple's declarative software update enforcement. |
Important: Apple OS 27 change Apple deprecated MDM-based software update management in macOS 26, including the com.apple.SoftwareUpdate payload, software update restrictions, commands, and queries. As of the OS 27 releases (September 2026), these controls no longer work on macOS 27, iOS 27, or iPadOS 27. That includes deferrals.
On devices running OS 27 or later, only the policy's Install Action has an effect. The other settings still apply to Macs running macOS 26 and earlier.
Supported platforms
Platform | Policy minimum | Settings that apply |
macOS | macOS 12.0+ | macOS 12–26: all settings. Install Action requires macOS 14+. macOS 27+: Install Action only. |
iOS | iOS 11.5+ | Install Action only. It requires iOS 17+. |
iPadOS | iPadOS 11.5+ | Install Action only. It requires iPadOS 17+. |
Each setting also has its own minimum OS version, listed in the tables below. A device that doesn't meet a setting's minimum ignores that setting.
Enrollment requirements
Install Action requires Automated Device Enrollment or Device Enrollment. It isn't available for Apple User Enrollment (BYOD).
Update preferences and deferrals aren't available for User Enrollment.
Macs running macOS 11 or later that are enrolled through Automated Device Enrollment or Device Enrollment are supervised automatically. On iPhone and iPad, Apple's deferral restrictions require supervision. See About Apple device supervision.
Before you begin
Check OS versions. Review your fleet's OS versions in Swif. Macs on macOS 27 and iPhones or iPads on iOS/iPadOS 27 respond only to Install Action.
Decide whether devices may move to a new major version. Install Action targets the newest update available for each device, and that includes major upgrades. See What Install Action installs.
Check bootstrap tokens on Macs with Apple silicon. At an enforcement deadline, macOS uses the bootstrap token, if one is available, to authorize the update. Without one, the user is prompted for credentials.
Plan a test group. Assign the policy to a small group first, then expand.
Create the policy
In the Swif Console, go to Device Management > Policies.
Click Create Policy and select Apple Software Update Policy.
Enter a Policy Name and, optionally, a Description.
Configure the settings described below.
To enforce updates, leave Automatically Install Updates on and choose an Install Action.
Click Continue, then assign the policy to devices or device groups.
Save the policy. Swif delivers it to the assigned devices.
Settings reference
Update preferences (macOS 26 and earlier)
These settings correspond to keys in Apple's Software Update payload. They apply only to Macs running macOS 26 or earlier. macOS 27 ignores them.
Setting | Default | What it does | Minimum macOS |
Automatically check for updates | On | When off, deselects Check for updates in Software Update settings and prevents the user from changing it. | 10.15 |
Download newly available updates in the background | On | When off, turns off automatic background downloads and prevents the user from changing the setting. | 10.15 |
Automatically Install Updates | On | When off, turns off automatic macOS update installation and prevents the user from changing it. When on, the Install Action field appears (see Install Action). | 10.15 |
Automatically install App Store app Updates | On | When off, deselects Install app updates from the App Store and prevents the user from changing it. | 10.15 |
Install XProtect, MRT, & Gatekeeper updates automatically | On | When off, stops automatic installation of security configuration data, such as XProtect and Gatekeeper updates. | 10.15 |
Install security updates automatically | On | When off, disables automatic installation of critical updates and prevents the user from changing Install system data files and security updates. | 10.15 |
Allow installation of macOS beta releases | Off | When on, allows prerelease macOS software to be installed on the Mac. | 10.9 |
Restrict Software Update Require Admin To Install | Off | When on, only administrator accounts can install updates. Apple documents this key as equivalent to the App Store's "require admin to install" restriction. | 10.14 |
On iPhone and iPad, Automatically Install Updates only controls whether the Install Action field is shown. The other preferences in this table don't apply to iOS or iPadOS.
Install Action (enforced updates)
Install Action appears when Automatically Install Updates is on. It uses Apple's declarative device management software update enforcement, which is still supported on OS 27.
Requirement | Value |
Minimum OS | macOS 14, iOS 17, iPadOS 17 |
Supervision | Not required |
Enrollment | Automated Device Enrollment or Device Enrollment |
Default | None. With no action selected, the device follows its own software update settings. |
What Install Action installs
Swif targets the newest update available for each device, including major upgrades. For example, a Mac on macOS 26 that is eligible for macOS 27 is directed to upgrade to macOS 27.
If you need devices to stay on their current major version, don't assign a policy with an Install Action to them. Apple enforces the update regardless of any deferrals you've configured. See Install and enforce software updates.
If a device is already on the newest version, Apple ignores the enforcement.
Install Action options
Option | Behavior |
InstallASAP | Downloads and installs the update as soon as the device has it ready, then restarts. |
InstallForceRestart | Downloads and installs the update as soon as the device has it ready, then restarts. It currently behaves the same as InstallASAP. |
InstallSpecificDate | Enforces the update at a specific date and time. |
InstallSpecificDayHours | Enforces the update at the next matching day and hour. |
Schedule fields
Field | Shown for | Default | Values |
Target Local Date Time | InstallSpecificDate | (empty) | Date and time in the format |
Target Local Day | InstallSpecificDayHours |
|
|
Target Local Hours | InstallSpecificDayHours |
| On the hour, |
Target Local Time Zone | InstallSpecificDayHours |
| UTC offsets from |
How time zones work
The enforcement time applies in each device's own local time zone. Apple's enforcement date and time don't include a time zone offset. A deadline of 22:00 means 22:00 wherever the device is.
Swif uses Target Local Time Zone to calculate the next matching day and hour and to reschedule if a device is offline at the scheduled time. The offset doesn't change the device's local deadline. It doesn't make a New York Mac update at 22:00 Tokyo time.
If today matches Target Local Day when you deploy, the schedule may land on the same day next week. After saving, check the effective date shown in Swif.
What users experience
The behavior below is Apple's, as described in Install and enforce software updates:
Before the deadline
The device downloads and prepares the update.
The user sees the deadline in Settings or System Settings and in notifications. Notifications become more frequent as the deadline approaches.
Users can install at any convenient time before the deadline.
Do Not Disturb is ignored during the final 24 hours.
If an iPhone or iPad is connected only to cellular, the user is asked to confirm the download. Otherwise the device waits for Wi-Fi.
At the deadline on macOS
macOS force quits all open apps, even if documents are unsaved, and restarts if needed.
On Apple silicon, the Mac uses the bootstrap token if one is available. Otherwise it prompts the user for credentials.
At the deadline on iOS and iPadOS
The device requires the passcode, if one is set, unless the user entered it earlier.
If the deadline is missed
A device can miss the deadline because it's offline, low on battery, or short on storage.
When it can proceed, it notifies the user that the update is past due and tries to install it within the next hour.
If that attempt is interrupted, the device tries again the next time it's powered on and connected to the internet.
Tip: On Macs, schedule enforcement outside working hours. The force quit at the deadline can cause users to lose unsaved work.
Deferrals (macOS 26 and earlier)
Deferrals hide updates from users for a set number of days after Apple releases them. These settings correspond to Apple's software update restrictions. Apple removed them in macOS 27, so they have no effect on Macs running macOS 27 or later.
A deferral delays an update. It doesn't block it:
When the deferral period ends, the update becomes visible to the user. If automatic installation is on, the Mac can install it.
Install Action ignores deferrals. Apple enforces the declared update at the scheduled time even when a deferral is in place.
Defer MacOS Updates
Option | What appears |
No deferral (default) | No deferral settings |
Defer all macOS updates | Managed Deferred Install Delay |
Defer macOS updates by type | Separate settings for OS updates, non-OS updates, and major upgrades |
Defer all macOS updates
Setting | Default | Range | Minimum macOS |
Managed Deferred Install Delay | 30 days | 1–90 days | 10.13.4 |
Apple's current device management reference doesn't document a deferral key with this name. On macOS 11.3 and later, use Defer macOS updates by type instead. Apple documents those restrictions.
Defer macOS updates by type
Setting | Default | Range | What it does | Minimum macOS |
Force update delay | Off | — | Delays when users see OS updates. The Mac still offers seed (beta) builds without delay. | 10.13 |
↳ Deferred Software Updates Delay | 30 days | 1–90 | General delay used by Force update delay on older macOS versions | 10.13.4 |
↳ Deferred Minor Software Updates Delay | 30 days | 1–90 | Delay for minor OS updates, for example 26.4 to 26.5 | 11.3 |
Defer non-OS Software Updates | Off | — | Delays when users see non-OS updates, such as Safari, XProtect, printer drivers, and Xcode Command Line Tools | 11.0 |
↳ Deferred non-OS Software Updates Delay | 30 days | 1–90 | Delay for non-OS updates | 11.3 |
Defer Major OS Software Updates | Off | — | Delays when users see major macOS upgrades | 11.3 |
↳ Deferred Major Software Updates Delay | 30 days | 1–90 | Delay for major upgrades | 11.3 |
Rows marked ↳ appear when you turn on the setting above them.
Legacy settings
Setting | Default | Notes |
Catalog URL | (empty) | Pointed Macs to a custom software update catalog. Not supported in macOS 11 and later. Leave it empty. |
Disable Extended Validation check of TLS certificate | On | Controls an extra TLS certificate check when downloading updates. Apple's current Software Update payload reference doesn't document this key. Leave the default unless Swif Support advises otherwise. |
Changes from earlier versions of this policy
Nudge is no longer part of this policy. The option to install Nudge has been removed. The policy no longer installs or configures Nudge.
Some earlier Install Action options were removed. If a policy used an option that is no longer listed, Swif clears that option when you save the policy. Devices then follow their own update settings until you choose a new Install Action.
Example configurations
Example 1: Mixed fleet on macOS 26 and macOS 27
Goal: keep recommended automatic updates on older Macs and enforce updates on all Macs overnight.
Setting | Value |
Automatically check for updates | On |
Download newly available updates in the background | On |
Automatically Install Updates | On |
Install Action | InstallSpecificDayHours |
Target Local Day / Hours | Saturday / 02:00 |
Automatically install App Store app Updates | On |
Install XProtect, MRT, & Gatekeeper updates automatically | On |
Install security updates automatically | On |
Allow installation of macOS beta releases | Off |
Result:
Macs on macOS 26 and earlier get the automatic update preferences.
All Macs on macOS 14 or later, including macOS 27, are required to install the newest available version by 02:00 local time on the next matching Saturday.
Because the Install Action includes major upgrades, eligible macOS 26 Macs will be directed to macOS 27.
Example 2: Keep production Macs on macOS 26 for now (macOS 26 only)
Goal: delay the macOS 27 upgrade while still getting minor updates.
Setting | Value |
Automatically Install Updates | On |
Install Action | (none) |
Defer MacOS Updates | Defer macOS updates by type |
Defer Major OS Software Updates | On, 90 days |
Force update delay | On, Deferred Minor Software Updates Delay = 7 days |
Result: users don't see macOS 27 for 90 days after its release, and minor updates are offered after 7 days.
Don't set an Install Action on this group. Enforcement ignores deferrals and targets the newest version.
This approach stops working if a Mac reaches macOS 27, for example through a manual upgrade after the deferral ends.
Example 3: iPhone and iPad fleet
Goal: require devices to update on a weekday evening.
Setting | Value |
Automatically Install Updates | On |
Install Action | InstallSpecificDayHours |
Target Local Day / Hours | Wednesday / 20:00 |
Result: devices on iOS/iPadOS 17 or later are required to install the newest available update by 20:00 local time on the next matching Wednesday. The macOS-only settings in the policy have no effect on these devices.
Example 4: Urgent security fix
For a single device or a few devices, use Adhoc Apple OS Updates from Device Details.
For a group, assign a policy with InstallASAP to a dedicated device group. When the fleet is up to date, change that group back to your normal schedule.
Verify the policy
In Swif
Open the policy and confirm it shows as deployed to the assigned devices.
Open a device's Device Details and check the Updates tab for available and pending updates.
On a Mac
Open System Settings > General > Device Management and confirm the Swif profile is listed.
Open System Settings > General > Software Update. When an Install Action is enforced, the pending update and its deadline appear here.
On macOS 26 and earlier, you can check the managed preferences in Terminal:
defaults read "/Library/Managed Preferences/com.apple.SoftwareUpdate" defaults read "/Library/Managed Preferences/com.apple.applicationaccess"
The first command shows update preferences. The second shows restrictions, including deferral keys such as
forceDelayedMajorSoftwareUpdates. If a file doesn't exist, those settings weren't delivered to the Mac.
On an iPhone or iPad
Open Settings > General > VPN & Device Management to confirm the device is managed.
Open Settings > General > Software Update. An enforced update shows its deadline.
Troubleshooting
Settings have no effect on some devices
The device runs OS 27 or later. This is expected. On macOS 27, iOS 27, and iPadOS 27, only Install Action works. The update preferences and deferrals no longer apply.
The device uses Apple User Enrollment. Apple doesn't allow these settings on User Enrollment devices.
The device is below a setting's minimum OS version. Check the minimums in the tables above.
The Install Action field isn't shown
Turn on Automatically Install Updates. The Install Action field appears only when that setting is on.
A device didn't update by the deadline
Confirm the device runs macOS 14, iOS 17, or iPadOS 17 or later.
Check that the device was online and had enough battery and free storage. Apple applies the same requirements as a user-initiated update.
A device that misses the deadline retries automatically. It tries within an hour of becoming able to install, or the next time it's powered on and connected to the internet.
On Apple silicon Macs without a bootstrap token, the update waits for the user to enter credentials.
Check the device's Updates tab in Swif for errors or status.
A Mac upgraded to a new major macOS version unexpectedly
The Install Action targets the newest update available for the device, including major upgrades. Enforcement ignores deferrals.
Remove the Install Action from devices that must stay on their current major version. On macOS 26 and earlier, use a major-version deferral instead (see Example 2).
An update installed even though a deferral was set
Install Action ignores deferrals.
When a deferral period ends, the update becomes available. It can then install automatically if Automatically Install Updates is on.
On macOS 27, deferrals don't apply at all.
Updates ran at an unexpected time
The deadline uses each device's local time zone. Check the time zone on the device itself.
With InstallSpecificDayHours, the next matching day may be a week out if the current day matches when you deploy. Check the effective date in Swif.
For InstallSpecificDate, confirm the date uses
YYYY-MM-DDTHH:MM:SSand isn't already in the past.
An existing policy lost its Install Action after editing
The policy used an Install Action option that was removed. Choose one of the current options and save again.
Users lost unsaved work
At the deadline, macOS force quits open apps, including those with unsaved documents. To reduce the impact:
Schedule enforcement outside working hours.
Tell users about the deadline in advance.
Encourage them to install early from System Settings > General > Software Update.
Related resources
Swif
Apple
