Profile: Software Update Settings
The "Software Update Settings" profile is a declarative configuration that controls the appearance and behavior of the Software Update pane on devices, including deferral periods, notification behavior, automatic action defaults, beta program enrollment, and Rapid Security Response handling. Unlike the Managed Software Updates profile, this profile does not force devices to install a specific OS version — it configures preferences and defaults for how updates are surfaced and handled on the device.
Apple documentation for this feature is available here.
To create a Software Update Settings profile:
- Make sure the target devices are running macOS 15+ or iOS/iPadOS 18+, have DDM enabled, and are enrolled via Automated Enrollment.
- Go to Configs > Profiles and click "Create Profile".
- From the list, select "Software Update Settings".
- Configure the settings as desired.
- Assign the configuration to your devices/groups.
Software Update Settings configuration settings explained
- Allow Standard User OS Updates: When enabled, standard (non-admin) user accounts on the device are permitted to install OS updates without providing administrator credentials. Enabled by default.
- Notifications: Controls whether the device user is notified when software updates are available. Enabled by default.
- Recommended Cadence: Determines which available update version(s) are recommended to the device user in the Software Update pane. Options:
- All: All available update versions are recommended.
- Oldest: Only the lowest-versioned available update is recommended.
- Newest: Only the highest-versioned available update is recommended.
- Automatic Actions: Controls the device's default automatic behavior for downloading and installing updates. Each of the following can be set independently to Allowed (the user's own System Settings preference is respected), AlwaysOn (always enabled, regardless of the user's preference), or AlwaysOff (always disabled, regardless of the user's preference):
- Download: Whether updates are automatically downloaded when available.
- Install OS Updates: Whether OS updates are automatically installed once downloaded.
- Install Security Update: Whether security updates are automatically installed once downloaded.
Deferrals: Allows admins to delay the visibility of new update availability under System Settings for a specified number of days after release. Each deferral type can be independently enabled and set from 1–90 days.
Note: MDM-initiated OS updates (such as those pushed via the Managed Software Updates profile or a manual update command) will ignore any configured deferral periods.
- Combined Period: Deferral applied when no more specific period below is configured.
- Major Period: Deferral applied specifically to major OS version updates (ex. macOS 14 > 15).
- Minor Period: Deferral applied specifically to minor and patch updates (ex. 15.1 > 15.1.1).
- System Period: Deferral applied to system data/security updates.
- Beta – Program Enrollment: Controls whether the device user is permitted to enroll the device in Apple's public beta software program. Set to Allowed, AlwaysOn, or AlwaysOff.
- Rapid Security Response: Controls handling of Rapid Security Response updates, which deliver security fixes to devices outside of the normal OS release cycle.
- Enable: Whether Rapid Security Response updates are enabled on the device. Enabled by default.
- Enable Rollback: Whether the device user is permitted to remove an installed Rapid Security Response update. Enabled by default.
Note: To remotely force macOS 14+ and iOS/iPadOS 17+ devices to update to a specific OS version by a deadline, use the Managed Software Updates profile instead. The Software Update Settings profile configures device-side preferences and defaults only — it does not enforce a specific update.