# Enforce a Specific OS Update

> Use the DDM Software Update Enforcement Specific configuration to install a specific iOS, iPadOS or macOS version by a deadline — fields, user experience, rollout rings and cleanup.

Source: https://docs.capaone.com/capaone/mobile-manager/apple-ddm/enforce-a-specific-os-update/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

**Software Update Enforcement Specific** tells a device to install one specific OS version by a date and time you choose. Until the deadline, the user can install the update when it suits them. At the deadline, the device installs it on its own.

This is the DDM replacement for Legacy MDM's **Schedule OS update** command, which no longer functions on iOS 27 and macOS 27.

:::note[Before you start]
- **Software Update Enforcement Specific** requires **iOS or iPadOS 17 or later**, or **macOS 14 or later**, and the device must run DDM. See [Enable Apple DDM](/capaone/mobile-manager/apple-ddm/enable-apple-ddm/).
- It works on **Supervised** and **Unsupervised** iPhone and iPad. On Mac, the device must be supervised.
- The version you target must be an update Apple currently offers to that device. You can check Apple's list of available versions at [gdmf.apple.com/v2/pmv](https://gdmf.apple.com/v2/pmv).
:::

## Fields

| Field | Required | Format | Example | What it does |
|---|---|---|---|---|
| **Target OS Version** | Yes | OS version number | `27.0.1` | The version to install. The device installs exactly this version — it doesn't install a later patch if you only set the minor version. |
| **Target Build Version** | No | Build number, optionally with a supplemental letter suffix | `24A341` or `24A341a` | Pins an exact build. Use it for testing during beta seeding, or to target a supplemental update. Leave it empty otherwise. |
| **Target Local Date/Time** | Yes | `yyyy-mm-ddThh:mm:ss`, no time zone | `2026-10-15T20:00:00` | When the device force-installs the update if the user hasn't already. The time is the **device's local time**, so a fleet across time zones installs at the same local hour. |
| **Details URL** | No | `https://…` | `https://intranet.example.com/ios-update` | A **More information** link shown to the user with the update — use it to explain why and when. |

![New DDM Software Update Enforcement Specific configuration with Details URL, Target Build Version, Target Local Date/Time and Target OS Version](/attachments/capaone/enforce-a-specific-os-update--editor.png)

You type every field as text. There's no date picker, so enter **Target Local Date/Time** in the format `yyyy-mm-ddThh:mm:ss`, for example `2026-10-15T20:00:00`.

## Create an enforcement

1. Check that the target version is available. Look it up at [gdmf.apple.com/v2/pmv](https://gdmf.apple.com/v2/pmv) under the platform (`iOS` or `macOS`) and confirm that the version lists your device models.
2. Navigate to **Apple → Configurations → DDM** and click **New**.
3. On the **Configurations** tab, select **Software Update Enforcement Specific**.
4. Name the configuration after the version and ring, for example `DDM - SU Enforce - iOS 27.0.1 - Pilot`.
5. Enter the **Target OS Version** and the **Target Local Date/Time**.
6. Optionally, enter a **Details URL**.
7. Save the configuration.
8. Select the **Assignment** tab, and then **Group**. Click **Assign** and move the target group to **Assigned**.

## What the user sees

The device handles the whole process itself, and notifications become more frequent as the deadline gets closer:

1. **When the configuration arrives** — the update appears in **Settings → General → Software Update** (or **System Settings** on Mac) with the deadline, and the device downloads and prepares it in the background.
2. **Leading up to the deadline** — the device shows notifications that let the user install now or later. During the last **24 hours**, notifications show even when **Do Not Disturb** is on.
3. **One hour before the deadline** — a final notification, followed by a restart countdown.
4. **At the deadline**:
   - **iPhone and iPad** — the device asks for the passcode, if one is set and hasn't already been entered, and installs the update.
   - **Mac** — the system force-quits all open apps, *including apps with unsaved documents*, and restarts if needed. On Apple silicon Macs, it uses the bootstrap token to authorize the update if one is available — otherwise it asks the user for credentials.

If **Notifications** is set to **No** in [Software Update Settings](/capaone/mobile-manager/apple-ddm/software-update-settings/), the user only sees the one-hour notification and the restart countdown.

:::caution
On Mac, enforcement closes apps without saving. Tell users about the deadline in advance — the **Details URL** is a good place to do it — and avoid deadlines during working hours.
:::

### If the device misses the deadline

If the device is off, offline, low on battery, or low on storage at the deadline, it doesn't give up. When the device is back on and connected, it downloads and prepares the update if needed, shows a notification that the update is past due, and tries to install it within about an hour — once it meets the requirements, such as minimum battery level.

## Supplemental and Background Security Improvement updates

A supplemental update — for example `27.0.1 (a)` — can only be installed on a device that already runs its base version (`27.0.1`). A device on an older version can't jump straight to it. To target a supplemental update, enter the build version with its letter suffix in **Target Build Version**, for example `24A341a`.

To bring older devices to a supplemental version, use **two** enforcements:

1. An enforcement for the base version, for example `27.0.1`, with the first deadline.
2. An enforcement for the supplemental version, with a later deadline. Use the same **Target OS Version**, and enter the build version with its letter suffix, for example `24A341a`, in **Target Build Version**.

The device processes the first, then the second once the base version is installed.

## Roll out in rings

Enforcement is the most reliable way to keep a fleet current, so treat it like any other change: test first.

| Ring | Group example | Deadline after Apple's release | Purpose |
|---|---|---|---|
| Pilot | `DDM - Pilot` — IT and a few volunteers | 1–3 days | Catch blocking problems with your apps and VPN. |
| Early | `DDM - Early` — ~10% of users across departments | 7 days | Validate at scale. |
| Broad | All remaining devices | 14 days | Bring the fleet current. |
| Critical security release | All devices | 2–5 days | Close actively exploited vulnerabilities fast. |

Create one enforcement per ring with the same **Target OS Version** and different deadlines, and assign each to its ring's group.

## After the update: clean up

An enforcement stays active after devices have installed the version. Remove it when it's no longer needed:

1. When all devices in the ring run the target version or later, unassign the enforcement from the group.
2. Delete enforcements for versions Apple no longer offers. If a version disappears from Apple's available list, devices that haven't installed it can't install it, and the configuration just stays active without effect.
3. Create a new enforcement for the next release.

## Check the progress

Open the configuration and select its **Endpoints** tab to see each endpoint's **Status** and assignment. On the device, **Configurations → Applied** shows the enforcement settings it received. To see where the update is on a device, check its OS version on the device page, or look at **Settings → General → Software Update** on the device.

![DDM configuration Endpoints tab with the endpoint, its status and assignment](/attachments/capaone/enforce-a-specific-os-update--configuration-endpoints.png)

In the background, DDM devices report software update progress to CapaOne on their own:

| What the device reports | Values | What it means |
|---|---|---|
| Install state | `none`, `downloading`, `prepared`, `installing`, `failed` | Where the update is right now. `none` also means the last update succeeded. |
| Pending version | OS version, build, and the enforcement date and time | Which update is pending, and whether it's being enforced. |
| Install reason | for example `declaration`, `system-settings`, `auto-update` | Why the update is pending — `declaration` means your enforcement. |
| Failure reason | count, reason, timestamp | How many times the update failed, and the last reason. |

CapaOne doesn't show these values as separate fields today.

If a device doesn't update, see [DDM Software Update Not Installing](/capaone/troubleshooting/ddm-software-update-not-installing/).

## Good to know

- **The deadline is local time** — `2026-10-15T20:00:00` means 20:00 wherever the device is.
- **Exact version only** — targeting `27.0` doesn't install `27.0.1`. Enter the version you want in **Target OS Version**.
- **Several enforcements can coexist** — Software Update Enforcement Specific is a multiple type, so a device can hold one per release. Remove old ones to keep the list readable.
- **Works on Unsupervised iPhone and iPad** — unlike deferrals and automatic actions in Software Update Settings, enforcement doesn't require supervision on iOS.
- **Source:** Apple's [Software Update Enforcement Specific declaration](https://github.com/apple/device-management/blob/release/declarative/declarations/configurations/softwareupdate.enforcement.specific.yaml) (Release v27.0), Apple Platform Deployment: [Install and enforce software updates](https://support.apple.com/guide/deployment/install-and-enforce-software-updates-depd30715cbb/web), and [Apple's iOS 27 enterprise release notes](https://support.apple.com/en-us/148828).
