Skip to main content

Apple Software Update Policy

Overview

The Apple Software Update Policy controls how managed Macs, iPhones, and iPads check for, download, defer, and install Apple software updates. You can also use it to require the newest available update by a date and time you choose.

The policy has two parts, and they behave differently depending on the OS version:

Part

Settings

Platforms

Works on OS 27

Update preferences and deferrals

Automatic checks, downloads, and installs; App Store app updates; XProtect and security updates; beta releases; admin-only installs; update deferrals

macOS only

No. Apple removed these controls in macOS 27.

Install Action (enforced updates)

Install as soon as possible, on a specific date, or on a recurring day and hour

macOS 14+, iOS 17+, iPadOS 17+

Yes. It uses Apple's declarative software update enforcement.

Important: Apple OS 27 change Apple deprecated MDM-based software update management in macOS 26, including the com.apple.SoftwareUpdate payload, software update restrictions, commands, and queries. As of the OS 27 releases (September 2026), these controls no longer work on macOS 27, iOS 27, or iPadOS 27. That includes deferrals.

On devices running OS 27 or later, only the policy's Install Action has an effect. The other settings still apply to Macs running macOS 26 and earlier.


Supported platforms

Platform

Policy minimum

Settings that apply

macOS

macOS 12.0+

macOS 12–26: all settings. Install Action requires macOS 14+. macOS 27+: Install Action only.

iOS

iOS 11.5+

Install Action only. It requires iOS 17+.

iPadOS

iPadOS 11.5+

Install Action only. It requires iPadOS 17+.

Each setting also has its own minimum OS version, listed in the tables below. A device that doesn't meet a setting's minimum ignores that setting.

Enrollment requirements

  • Install Action requires Automated Device Enrollment or Device Enrollment. It isn't available for Apple User Enrollment (BYOD).

  • Update preferences and deferrals aren't available for User Enrollment.

  • Macs running macOS 11 or later that are enrolled through Automated Device Enrollment or Device Enrollment are supervised automatically. On iPhone and iPad, Apple's deferral restrictions require supervision. See About Apple device supervision.


Before you begin

  1. Check OS versions. Review your fleet's OS versions in Swif. Macs on macOS 27 and iPhones or iPads on iOS/iPadOS 27 respond only to Install Action.

  2. Decide whether devices may move to a new major version. Install Action targets the newest update available for each device, and that includes major upgrades. See What Install Action installs.

  3. Check bootstrap tokens on Macs with Apple silicon. At an enforcement deadline, macOS uses the bootstrap token, if one is available, to authorize the update. Without one, the user is prompted for credentials.

  4. Plan a test group. Assign the policy to a small group first, then expand.


Create the policy

  1. In the Swif Console, go to Device Management > Policies.

  2. Click Create Policy and select Apple Software Update Policy.

  3. Enter a Policy Name and, optionally, a Description.

  4. Configure the settings described below.

  5. To enforce updates, leave Automatically Install Updates on and choose an Install Action.

  6. Click Continue, then assign the policy to devices or device groups.

  7. Save the policy. Swif delivers it to the assigned devices.


Settings reference

Update preferences (macOS 26 and earlier)

These settings correspond to keys in Apple's Software Update payload. They apply only to Macs running macOS 26 or earlier. macOS 27 ignores them.

Setting

Default

What it does

Minimum macOS

Automatically check for updates

On

When off, deselects Check for updates in Software Update settings and prevents the user from changing it.

10.15

Download newly available updates in the background

On

When off, turns off automatic background downloads and prevents the user from changing the setting.

10.15

Automatically Install Updates

On

When off, turns off automatic macOS update installation and prevents the user from changing it. When on, the Install Action field appears (see Install Action).

10.15

Automatically install App Store app Updates

On

When off, deselects Install app updates from the App Store and prevents the user from changing it.

10.15

Install XProtect, MRT, & Gatekeeper updates automatically

On

When off, stops automatic installation of security configuration data, such as XProtect and Gatekeeper updates.

10.15

Install security updates automatically

On

When off, disables automatic installation of critical updates and prevents the user from changing Install system data files and security updates.

10.15

Allow installation of macOS beta releases

Off

When on, allows prerelease macOS software to be installed on the Mac.

10.9

Restrict Software Update Require Admin To Install

Off

When on, only administrator accounts can install updates. Apple documents this key as equivalent to the App Store's "require admin to install" restriction.

10.14

On iPhone and iPad, Automatically Install Updates only controls whether the Install Action field is shown. The other preferences in this table don't apply to iOS or iPadOS.


Install Action (enforced updates)

Install Action appears when Automatically Install Updates is on. It uses Apple's declarative device management software update enforcement, which is still supported on OS 27.

Requirement

Value

Minimum OS

macOS 14, iOS 17, iPadOS 17

Supervision

Not required

Enrollment

Automated Device Enrollment or Device Enrollment

Default

None. With no action selected, the device follows its own software update settings.

What Install Action installs

Swif targets the newest update available for each device, including major upgrades. For example, a Mac on macOS 26 that is eligible for macOS 27 is directed to upgrade to macOS 27.

If you need devices to stay on their current major version, don't assign a policy with an Install Action to them. Apple enforces the update regardless of any deferrals you've configured. See Install and enforce software updates.

If a device is already on the newest version, Apple ignores the enforcement.

Install Action options

Option

Behavior

InstallASAP

Downloads and installs the update as soon as the device has it ready, then restarts.

InstallForceRestart

Downloads and installs the update as soon as the device has it ready, then restarts. It currently behaves the same as InstallASAP.

InstallSpecificDate

Enforces the update at a specific date and time.

InstallSpecificDayHours

Enforces the update at the next matching day and hour.

Schedule fields

Field

Shown for

Default

Values

Target Local Date Time

InstallSpecificDate

(empty)

Date and time in the format YYYY-MM-DDTHH:MM:SS, for example 2026-10-17T22:00:00

Target Local Day

InstallSpecificDayHours

ANY

ANY, Monday through Sunday

Target Local Hours

InstallSpecificDayHours

00:00

On the hour, 00:00 through 23:00

Target Local Time Zone

InstallSpecificDayHours

+00

UTC offsets from -12 to +14, including half-hour and 45-minute offsets such as +05:30 and +05:45

How time zones work

The enforcement time applies in each device's own local time zone. Apple's enforcement date and time don't include a time zone offset. A deadline of 22:00 means 22:00 wherever the device is.

Swif uses Target Local Time Zone to calculate the next matching day and hour and to reschedule if a device is offline at the scheduled time. The offset doesn't change the device's local deadline. It doesn't make a New York Mac update at 22:00 Tokyo time.

If today matches Target Local Day when you deploy, the schedule may land on the same day next week. After saving, check the effective date shown in Swif.

What users experience

The behavior below is Apple's, as described in Install and enforce software updates:

  • Before the deadline

    • The device downloads and prepares the update.

    • The user sees the deadline in Settings or System Settings and in notifications. Notifications become more frequent as the deadline approaches.

    • Users can install at any convenient time before the deadline.

    • Do Not Disturb is ignored during the final 24 hours.

    • If an iPhone or iPad is connected only to cellular, the user is asked to confirm the download. Otherwise the device waits for Wi-Fi.

  • At the deadline on macOS

    • macOS force quits all open apps, even if documents are unsaved, and restarts if needed.

    • On Apple silicon, the Mac uses the bootstrap token if one is available. Otherwise it prompts the user for credentials.

  • At the deadline on iOS and iPadOS

    • The device requires the passcode, if one is set, unless the user entered it earlier.

  • If the deadline is missed

    • A device can miss the deadline because it's offline, low on battery, or short on storage.

    • When it can proceed, it notifies the user that the update is past due and tries to install it within the next hour.

    • If that attempt is interrupted, the device tries again the next time it's powered on and connected to the internet.

Tip: On Macs, schedule enforcement outside working hours. The force quit at the deadline can cause users to lose unsaved work.


Deferrals (macOS 26 and earlier)

Deferrals hide updates from users for a set number of days after Apple releases them. These settings correspond to Apple's software update restrictions. Apple removed them in macOS 27, so they have no effect on Macs running macOS 27 or later.

A deferral delays an update. It doesn't block it:

  • When the deferral period ends, the update becomes visible to the user. If automatic installation is on, the Mac can install it.

  • Install Action ignores deferrals. Apple enforces the declared update at the scheduled time even when a deferral is in place.

Defer MacOS Updates

Option

What appears

No deferral (default)

No deferral settings

Defer all macOS updates

Managed Deferred Install Delay

Defer macOS updates by type

Separate settings for OS updates, non-OS updates, and major upgrades

Defer all macOS updates

Setting

Default

Range

Minimum macOS

Managed Deferred Install Delay

30 days

1–90 days

10.13.4

Apple's current device management reference doesn't document a deferral key with this name. On macOS 11.3 and later, use Defer macOS updates by type instead. Apple documents those restrictions.

Defer macOS updates by type

Setting

Default

Range

What it does

Minimum macOS

Force update delay

Off

—

Delays when users see OS updates. The Mac still offers seed (beta) builds without delay.

10.13

↳ Deferred Software Updates Delay

30 days

1–90

General delay used by Force update delay on older macOS versions

10.13.4

↳ Deferred Minor Software Updates Delay

30 days

1–90

Delay for minor OS updates, for example 26.4 to 26.5

11.3

Defer non-OS Software Updates

Off

—

Delays when users see non-OS updates, such as Safari, XProtect, printer drivers, and Xcode Command Line Tools

11.0

↳ Deferred non-OS Software Updates Delay

30 days

1–90

Delay for non-OS updates

11.3

Defer Major OS Software Updates

Off

—

Delays when users see major macOS upgrades

11.3

↳ Deferred Major Software Updates Delay

30 days

1–90

Delay for major upgrades

11.3

Rows marked ↳ appear when you turn on the setting above them.


Legacy settings

Setting

Default

Notes

Catalog URL

(empty)

Pointed Macs to a custom software update catalog. Not supported in macOS 11 and later. Leave it empty.

Disable Extended Validation check of TLS certificate

On

Controls an extra TLS certificate check when downloading updates. Apple's current Software Update payload reference doesn't document this key. Leave the default unless Swif Support advises otherwise.


Changes from earlier versions of this policy

  • Nudge is no longer part of this policy. The option to install Nudge has been removed. The policy no longer installs or configures Nudge.

  • Some earlier Install Action options were removed. If a policy used an option that is no longer listed, Swif clears that option when you save the policy. Devices then follow their own update settings until you choose a new Install Action.


Example configurations

Example 1: Mixed fleet on macOS 26 and macOS 27

Goal: keep recommended automatic updates on older Macs and enforce updates on all Macs overnight.

Setting

Value

Automatically check for updates

On

Download newly available updates in the background

On

Automatically Install Updates

On

Install Action

InstallSpecificDayHours

Target Local Day / Hours

Saturday / 02:00

Automatically install App Store app Updates

On

Install XProtect, MRT, & Gatekeeper updates automatically

On

Install security updates automatically

On

Allow installation of macOS beta releases

Off

Result:

  • Macs on macOS 26 and earlier get the automatic update preferences.

  • All Macs on macOS 14 or later, including macOS 27, are required to install the newest available version by 02:00 local time on the next matching Saturday.

  • Because the Install Action includes major upgrades, eligible macOS 26 Macs will be directed to macOS 27.

Example 2: Keep production Macs on macOS 26 for now (macOS 26 only)

Goal: delay the macOS 27 upgrade while still getting minor updates.

Setting

Value

Automatically Install Updates

On

Install Action

(none)

Defer MacOS Updates

Defer macOS updates by type

Defer Major OS Software Updates

On, 90 days

Force update delay

On, Deferred Minor Software Updates Delay = 7 days

Result: users don't see macOS 27 for 90 days after its release, and minor updates are offered after 7 days.

Don't set an Install Action on this group. Enforcement ignores deferrals and targets the newest version.

This approach stops working if a Mac reaches macOS 27, for example through a manual upgrade after the deferral ends.

Example 3: iPhone and iPad fleet

Goal: require devices to update on a weekday evening.

Setting

Value

Automatically Install Updates

On

Install Action

InstallSpecificDayHours

Target Local Day / Hours

Wednesday / 20:00

Result: devices on iOS/iPadOS 17 or later are required to install the newest available update by 20:00 local time on the next matching Wednesday. The macOS-only settings in the policy have no effect on these devices.

Example 4: Urgent security fix

For a single device or a few devices, use Adhoc Apple OS Updates from Device Details.

For a group, assign a policy with InstallASAP to a dedicated device group. When the fleet is up to date, change that group back to your normal schedule.


Verify the policy

In Swif

  1. Open the policy and confirm it shows as deployed to the assigned devices.

  2. Open a device's Device Details and check the Updates tab for available and pending updates.

On a Mac

  1. Open System Settings > General > Device Management and confirm the Swif profile is listed.

  2. Open System Settings > General > Software Update. When an Install Action is enforced, the pending update and its deadline appear here.

  3. On macOS 26 and earlier, you can check the managed preferences in Terminal:

    defaults read "/Library/Managed Preferences/com.apple.SoftwareUpdate" defaults read "/Library/Managed Preferences/com.apple.applicationaccess"

    The first command shows update preferences. The second shows restrictions, including deferral keys such as forceDelayedMajorSoftwareUpdates. If a file doesn't exist, those settings weren't delivered to the Mac.

On an iPhone or iPad

  1. Open Settings > General > VPN & Device Management to confirm the device is managed.

  2. Open Settings > General > Software Update. An enforced update shows its deadline.


Troubleshooting

Settings have no effect on some devices

  • The device runs OS 27 or later. This is expected. On macOS 27, iOS 27, and iPadOS 27, only Install Action works. The update preferences and deferrals no longer apply.

  • The device uses Apple User Enrollment. Apple doesn't allow these settings on User Enrollment devices.

  • The device is below a setting's minimum OS version. Check the minimums in the tables above.

The Install Action field isn't shown

Turn on Automatically Install Updates. The Install Action field appears only when that setting is on.

A device didn't update by the deadline

  • Confirm the device runs macOS 14, iOS 17, or iPadOS 17 or later.

  • Check that the device was online and had enough battery and free storage. Apple applies the same requirements as a user-initiated update.

  • A device that misses the deadline retries automatically. It tries within an hour of becoming able to install, or the next time it's powered on and connected to the internet.

  • On Apple silicon Macs without a bootstrap token, the update waits for the user to enter credentials.

  • Check the device's Updates tab in Swif for errors or status.

A Mac upgraded to a new major macOS version unexpectedly

The Install Action targets the newest update available for the device, including major upgrades. Enforcement ignores deferrals.

Remove the Install Action from devices that must stay on their current major version. On macOS 26 and earlier, use a major-version deferral instead (see Example 2).

An update installed even though a deferral was set

  • Install Action ignores deferrals.

  • When a deferral period ends, the update becomes available. It can then install automatically if Automatically Install Updates is on.

  • On macOS 27, deferrals don't apply at all.

Updates ran at an unexpected time

  • The deadline uses each device's local time zone. Check the time zone on the device itself.

  • With InstallSpecificDayHours, the next matching day may be a week out if the current day matches when you deploy. Check the effective date in Swif.

  • For InstallSpecificDate, confirm the date uses YYYY-MM-DDTHH:MM:SS and isn't already in the past.

An existing policy lost its Install Action after editing

The policy used an Install Action option that was removed. Choose one of the current options and save again.

Users lost unsaved work

At the deadline, macOS force quits open apps, including those with unsaved documents. To reduce the impact:

  • Schedule enforcement outside working hours.

  • Tell users about the deadline in advance.

  • Encourage them to install early from System Settings > General > Software Update.


Related resources

Swif

Apple

Did this answer your question?