Apple’s OS 27 release changes the operating model for organizations that manage iPhone, iPad, Mac, Apple TV, or Apple Vision Pro with Microsoft Intune. Microsoft has expanded day-zero support in the settings catalog, but Apple is also retiring legacy mobile device management (MDM) workloads in favor of declarative device management (DDM).
The deadline that deserves a place on every Apple fleet owner’s calendar is the October 2610 Intune service release. Microsoft says the Intune admin center will remove several legacy software-update policies and reports then. Existing profiles may not stop working on the same day, but the management surface and reporting path your team relies on will change.
What Microsoft changed for Apple OS 27
| Microsoft’s update | Why it matters | Admin decision |
|---|---|---|
| New DDM and MDM settings are available through the Intune settings catalog. | Teams can manage OS 27 capabilities such as app allow/deny rules, Apple Intelligence, accessibility, Safari, Siri, content caching, DNS proxy, and web-content filtering from a current policy surface. | Create a small set of named DDM policies with clear owners instead of adding one-off profiles as new settings appear. |
| Apple has deprecated several legacy MDM payloads and commands. | Content caching, DNS settings, DNS proxy, parental controls, application restrictions, privacy preferences, passcode, and parts of Restrictions are moving to DDM equivalents. | Export or document the current payloads, identify their business purpose, and map each to the equivalent settings-catalog location. |
| Intune will remove five legacy update/reporting workloads in October 2610. | The admin center will no longer expose iOS/iPadOS update policies, macOS update policies, the per-device macOS software-updates report, or iOS and macOS installation-failure views. | Move update management to DDM and document the replacement reports before the service release reaches production. |
| The supported-versus-allowed model remains different for userless Apple devices. | Shared iPads and other userless devices have a distinct compatibility boundary from user-affinity enrollments and sign-in-dependent apps. | Separate userless device groups, OS requirements, and Conditional Access assumptions from employee-owned or user-affinity scenarios. |
DDM is now the center of gravity
DDM lets the device manage a declared state and report status back to Intune, rather than waiting for an administrator to send every individual command through the older MDM model. That matters most for software updates: Apple has deprecated the MDM-based update workloads, and Microsoft recommends DDM through the settings catalog for current Apple update management.
Do not read the change as a requirement to rewrite every Apple policy immediately. Start with the policies that control software updates and the deprecated payloads called out in Microsoft’s OS 27 guidance. Keep a simple mapping record: the old profile or payload, its intended outcome, the new DDM setting, the target device group, and the validation evidence.
That record becomes valuable during troubleshooting. If a device is not receiving an update, the team should be able to tell whether the problem is the device’s OS, the DDM declaration, an assignment or filter, a conflict, or a userless-device limitation.
Before October 2610: run a six-step migration
- Inventory: export Apple configuration profiles, update policies, compliance rules, app protection policies, enrollment profiles, and reports used by the help desk. Include iOS/iPadOS, macOS, tvOS, and visionOS where they are in scope.
- Classify: mark each item as current DDM, legacy MDM, enrollment-only, reporting-only, or no longer needed. Pay special attention to update policies and Restrictions payloads.
- Map: use the OS 27 settings catalog and Microsoft’s DDM guidance to choose the replacement. Record the exact category and setting name, not just a screenshot.
- Pilot: assign DDM policies to a representative ring: one supervised iPhone, one shared iPad, one Mac with user affinity, and one userless Mac where those scenarios exist. Confirm policy status, update behavior, and end-user messaging.
- Cut over: move production groups in waves. Avoid assigning old and new controls with conflicting intent, and keep the old profile available only long enough to support rollback and evidence collection.
- Verify: update the runbook, screenshots, monitoring queries, help-desk article, and compliance evidence. Confirm that the replacement reports answer the questions your team used the removed views to answer.
For a smaller business, the inventory can be a spreadsheet with one row per profile and one accountable owner. The important part is making the dependency visible before a technician discovers it during an enrollment or update incident.
Separate supported and allowed Apple versions
Microsoft’s OS 27 post calls out a separate support statement for devices enrolled without user affinity. The current model lists iOS/iPadOS 18.x and later and macOS 15.x and later as supported for userless devices. Older ranges can be allowed to enroll, but Microsoft does not provide the same guarantee that every eligible feature will behave correctly when Apple changes the OS.
That distinction should appear in your policy design. A shared iPad or kiosk Mac may need a managed grace period while a new OS is validated; a user-affinity device accessing Microsoft 365 data may need a stricter minimum version. Use Intune enrollment restrictions, compliance policies, app protection policies, and Conditional Access together so that the policy matches the device scenario.
| Scenario | What to test | Evidence to retain |
|---|---|---|
| Userless shared device | Enrollment, DDM status, shared-use apps, update deadline, and recovery after a failed update. | Device group, OS version, policy status, update result, and help-desk runbook. |
| User-affinity iPhone or iPad | Company data access, app protection, Conditional Access, and the user experience when the minimum OS is not met. | Compliance state, app protection action, user communication, and exception approval. |
| Managed Mac | DDM software updates, FileVault and security settings, login-window behavior, and network or content-caching dependencies. | DDM declaration, device check-in, update status, and rollback or recovery steps. |
Use the new settings without creating policy sprawl
OS 27 adds useful controls for Apple Intelligence, privacy prompts, Safari, Siri, accessibility, content caching, DNS proxy, and web-content filtering. The settings are valuable only when they are tied to a business decision.
- Apple Intelligence: decide which capabilities are appropriate for managed data and whether the setting should be allowed, limited, or tested by a ring.
- Privacy and app controls: define organization defaults for camera, microphone, Bluetooth, location, local network, dictation, and accessibility without making the help desk the approval queue for every prompt.
- Safari and Siri: test privacy, summaries, on-device behavior, and lock-screen access against the data-handling policy.
- Content caching and DNS proxy: document the network owner, provider app, storage, and failure behavior before assigning the policy broadly.
- Accessibility and login window: treat these as user-experience and support controls, not only security settings; validate them with the people who rely on them.
Remember the app-protection layer
Microsoft also highlights Intune App SDK for iOS version 21.8.0 or later for the new iOS MAM experiences. The refreshed prompts and account-removal experience are mostly user-experience changes, but the Screen capture app-protection setting now controls whether Siri onscreen awareness can access organizational data. If Screen capture remains allowed, users can share organizational data through Siri onscreen awareness; if the organization needs to block that path, test the policy with apps that use the supported SDK.
This is a useful reminder that Apple readiness is not only an MDM project. Include app owners, the help desk, and whoever manages third-party iOS apps in the pilot. A device can be on a supported OS while an application still needs an updated Intune SDK or a new app-protection policy decision.
Use enhanced logging when AppleCare needs evidence
For supported supervised devices running a compatible OS 27 release, Intune can trigger Apple’s Enhanced Logging device action with an AppleCare-provided token. The administrator can monitor the request status through Intune while the device uploads the diagnostic bundle directly to the AppleCare case.
Add this to the support runbook now. Define who can trigger the action, where the AppleCare token is stored, which permissions are required, and how the team records the device, case number, status, and approval. It gives the help desk a cleaner escalation path when an MDM or DDM issue needs Apple engineering rather than another round of local troubleshooting.
A practical 30-day readiness plan
| Window | Work | Exit evidence |
|---|---|---|
| Days 1–5 | Inventory Apple profiles, update policies, device groups, userless scenarios, app-protection rules, and the reports the team uses today. | Signed inventory with owner, platform, scope, and legacy/current classification. |
| Days 6–12 | Map deprecated MDM payloads and software-update workloads to DDM settings catalog controls. Identify conflicts and unsupported assumptions. | Migration matrix, exception list, and a short rollback plan. |
| Days 13–20 | Pilot with supervised userless and user-affinity devices, verify OS gates, test app protection, and exercise an update failure. | Device status, screenshots, user feedback, support notes, and resolved conflicts. |
| Days 21–30 | Roll out in rings, update documentation, and brief help-desk and security owners on the October admin-center changes. | Production assignments, monitoring checklist, communications, and a post-2610 review date. |
Frequently asked questions
Does OS 27 mean every Apple policy must be rebuilt? No. Prioritize the software-update workloads and the MDM payloads Apple has deprecated. Then migrate other policies when the DDM equivalent is validated for your scenario.
Which workloads disappear in October 2610? Microsoft says Intune will remove iOS/iPadOS update policies, macOS update policies, the per-device macOS software-updates report, and iOS and macOS update installation-failure views from the admin center.
Can older userless devices still enroll? Microsoft describes older versions as allowed within a broader range, but they are not the same as supported versions and may be affected by OS changes or bugs. Keep exceptions explicit and time-bound.
Is enhanced logging available on every Apple device? No. Microsoft Learn lists it for supervised macOS 27 and iOS/iPadOS 27 devices, with the required remote-task permissions and an AppleCare token.
Need an Apple fleet readiness review?
Accred Consulting can inventory Intune Apple policies, map deprecated MDM workloads to DDM, and build a staged OS and support plan before the October 2610 change.
Plan an Intune Readiness Review