Confusion over DDM-enforced iOS updates on unsupervised devices in Intune + Apple Business Manager

How come, that in the Intune + Apple Business Manager setup, the policies that enforce device system update using Declarative Device Management, apply also to non-supervised devices? This is the side result of our pilot deployment of ABM. We can see that on unsupervised devices, that are covered by the policy, the behavior is identical in terms of enforcing iOS 18.5 to iOS 18.6 version (prompts, update download, increased frequency of prompts, finally the prompt where it's possible to only install or choose "Emergency call").

At WWDC 2024 (see What’s new in device management - WWDC24 - Videos - Apple Developer) DDM was explained as allowing pushing updates to supervised devices only. Since when it is available to enforce updates on unsupervised devices?

And it clearly is available: for example About software updates for Apple devices - Apple Support (IL) states

"Users may also need to agree to updated terms and conditions to initiate a software update or upgrade on their devices. This doesn’t apply to updates device management enforces on supervised devices." - which implies it affects unsupervised devices.

I was not able to find any clear Apple documentation explaining then as of August 2025, pushing iOS system updates to devices using DDM, should be possible. If so, ability to enforce iOS updates installation on unsupervised devices would be a great news for our Security team, but this is so opposite direction from what Apple has been doing with shifting more and more capabilities under supervision, that I don't dare to jump in joy yet.



[Re-Titled by Moderator]


iPhone 13

Posted on Aug 11, 2025 09:32 AM

Reply
1 reply

Aug 12, 2025 09:25 AM in response to Adam_Lew1337

So... as of today, it seems that Apple made some basic keys in DDM - system updates available for unsupervised devices: TargetOSVersion, TargetBuildVersion, TargetLocalDateTime + OfferPrograms (for Beta updates). See: Software Update declarative configuration for Apple devices - Apple Support


Use the Software Update configuration to enforce software updates at a certain time. The Software Update configuration supports the following:

Minimum supported operating system versions and channels: iOS 17, iPadOS 17, Shared iPad device, macOS 14 device.

Requires supervision: No.

Supported enrollment methods: Device Enrollment, Automated Device Enrollment.


This ain't much, but still a game changer for our first line support teams.


Looking at it in Intune - Devices - Config - DDM - Software Updates Settings: the three keys are there, the Beta keys seem not available yet (there was somewhere info about updates coming in 'new August 2025 release of Intune'), but also the keys available in DDM - Software Updates are present and seem working for unsupervised devices:


Software Update Enforce Latest

Enforce Latest Software Update Version True

Delay In Days x

Install Time xx:xx


This looks like a little transitional mess and it can change either way, but the point here is: it is finally possible to force latest iOS updates on unsupervised devices!

Confusion over DDM-enforced iOS updates on unsupervised devices in Intune + Apple Business Manager

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.