# Software Update Settings

> Every setting in the DDM Software Update Settings configuration — what it does, which devices it works on, and recommended baselines for supervised, unsupervised and kiosk devices.

Source: https://docs.capaone.com/capaone/mobile-manager/apple-ddm/software-update-settings/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

**Software Update Settings** is the DDM configuration type that controls how a device handles software updates on its own: whether updates download and install automatically, how long new updates are hidden from users, whether users get notifications, and whether Background Security Improvements are offered.

It replaces the Legacy MDM software update restrictions (deferrals, recommended cadence, Background Security Improvements) that no longer function on iOS 27 and later. See [iOS 27 and Software Update Management](/capaone/mobile-manager/apple-ddm/ios-27-and-software-update-management/).

:::note[Before you start]
- **Software Update Settings** requires **iOS or iPadOS 18 or later**, or **macOS 15 or later**. Devices on older versions reject the configuration.
- Several settings only work on **Supervised** devices. On Unsupervised devices, the device applies the settings it supports and ignores the rest. The tables below show which settings need supervision.
- To *force* a specific version by a deadline, use **Software Update Enforcement Specific** instead. The two types work together. See [Enforce a Specific OS Update](/capaone/mobile-manager/apple-ddm/enforce-a-specific-os-update/).
:::

## Settings vs. enforcement

| | Software Update Settings | Software Update Enforcement Specific |
|---|---|---|
| Purpose | General behavior: automatic actions, deferrals, notifications, BSI, beta. | Install one specific OS version by a specific date and time. |
| How many per device | One effective policy — several configurations are merged. | Several can be active at once. |
| Minimum version | iOS 18 / macOS 15 | iOS 17 / macOS 14 |
| Typical use | One baseline for all devices of a kind. | One per OS release you want to enforce. |

## Create a Software Update Settings configuration

1. Navigate to **Apple → Configurations → DDM**.
2. Click **New**.
3. On the **Configurations** tab, select **Software Update Settings**.
4. Give the configuration a descriptive name, for example `DDM - SU Settings - Supervised iPhone`.
5. Configure the settings described below. Leave a setting on **Not configured** to keep Apple's default.
6. Save the configuration.
7. Select the **Assignment** tab, and then **Group**. Click **Assign** and move the group to **Assigned**.

![New DDM Software Update Settings configuration with Allow Standard User OS Updates, Automatic Actions, Beta and Deferrals](/attachments/capaone/software-update-settings--editor.png)

The editor groups the settings under **Automatic Actions**, **Beta**, **Deferrals**, **Notifications**, **Rapid Security Response**, and **Recommended Cadence**. **Allow Standard User OS Updates** is a single setting outside these groups.

The settings use three kinds of input:

- **Yes / No settings** have the options **Not configured**, **No**, and **Yes**. **Not configured** leaves the setting out of the configuration, so the device keeps its default.
- **Automatic Actions** and **Program Enrollment** are lists with the options **Allowed**, **Always On**, and **Always Off**. Each option has a short explanation in the list, for example *Allowed - user can enable or disable*. **Deselect** clears the setting.
- **Deferrals** are numbers of days that you enter yourself.

## Settings reference

### Notifications

| Setting | Values | Default | Platforms | Supervision |
|---|---|---|---|---|
| **Notifications** | Not configured / No / Yes | Device default: Yes | iOS, macOS | Not required |

- **Yes** — the device shows all software update enforcement notifications leading up to a deadline.
- **No** — the device only shows the notification one hour before an enforcement deadline, and the restart countdown. Use this on shared or kiosk devices where nobody can act on earlier notifications.

This setting only affects notifications for updates enforced with **Software Update Enforcement Specific**.

### Deferrals

Deferrals hide a new update from the user for a number of days after Apple releases it. The update isn't offered — in **Settings** or through automatic updates — until the period has passed.

| Setting | Values | Platforms | Supervision |
|---|---|---|---|
| **Combined Period (Days)** | 1–90 days | iOS, iPadOS | **Supervised only** |
| **Major Period (Days)** | 1–90 days | macOS | Supervised (all macOS DDM is supervised) |
| **Minor Period (Days)** | 1–90 days | macOS | Supervised |
| **System Period (Days)** | 1–90 days | macOS — non-OS updates such as Safari, XProtect, and printer drivers | Supervised |

:::caution
- Deferrals don't apply to **Background Security Improvements**. However, a BSI only applies to the latest minor OS version, so deferring that minor update effectively defers its BSI as well.
- A deferral doesn't stop an enforcement. If you enforce a version with **Software Update Enforcement Specific**, the device installs it by the deadline even if a deferral would otherwise hide it — as long as Apple has the version available.
:::

### Recommended Cadence (iOS and iPadOS)

| Setting | Values | Platforms | Supervision |
|---|---|---|---|
| **Recommended Cadence** | All / Oldest / Newest | iOS, iPadOS | Not required |

When more than one update is available — for example, a minor update for the current major version and a new major version — this decides what the user sees:

- **All** — the user sees every available update and chooses.
- **Oldest** — only the lowest version is shown. Use this to keep users on the current major version, for example iOS 26.x, while still getting its security updates.
- **Newest** — only the highest version is shown, typically the new major version.

### Automatic Actions

| Setting | Values | Default | Platforms | Supervision |
|---|---|---|---|---|
| **Download** | Allowed / Always On / Always Off | Allowed | iOS, macOS | **Supervised only** on iOS |
| **Install OS Updates** | Allowed / Always On / Always Off | Allowed | iOS, macOS | **Supervised only** on iOS |
| **Install Security Update** | Allowed / Always On / Always Off | Allowed | macOS | Supervised |

- **Allowed** — the user can turn the setting on or off in **Settings**.
- **Always On** — the setting is on and locked.
- **Always Off** — the setting is off and locked.

Automatic installs only work when automatic downloads are on. Setting **Install OS Updates** to **Always On** while **Download** is **Always Off** has no effect.

### Rapid Security Response

The editor calls this group **Rapid Security Response**. Apple now calls the feature Background Security Improvements (BSI): small security fixes Apple delivers between regular updates.

| Setting | Values | Default | Platforms | Supervision |
|---|---|---|---|---|
| **Enable** | Not configured / No / Yes | Device default: Yes | iOS, macOS | **Supervised only** on iOS |
| **Enable Rollback** | Not configured / No / Yes | Device default: Yes | iOS, macOS | **Supervised only** on iOS |

- Setting **Enable** to **No** stops the device from *offering* BSIs to the user. You can still install a specific BSI with **Software Update Enforcement Specific** by entering its build version with the letter suffix in **Target Build Version** (for example `24A341a`).
- Setting **Enable Rollback** to **No** stops the user from removing an installed BSI.

### Allow Standard User OS Updates (macOS)

| Setting | Values | Default | Platforms |
|---|---|---|---|
| **Allow Standard User OS Updates** | Not configured / No / Yes | Device default: Yes | macOS |

When **No**, only administrators can install major and minor macOS updates.

### Beta

| Setting | Values | Platforms | Supervision |
|---|---|---|---|
| **Program Enrollment** | Allowed / Always On / Always Off | iOS 18+, macOS 15.4+ | **Supervised only** on iOS |

- **Always Off** removes the device from any beta program and blocks enrollment. This is the recommended value for production devices.

## Recommended baselines

Use these as starting points. Combine each with a **Software Update Enforcement Specific** configuration per release when you need a deadline.

| Setting | Supervised company iPhone/iPad | Unsupervised device | Kiosk / shared iPad | Managed Mac |
|---|---|---|---|---|
| Notifications | Yes | Yes | **No** | Yes |
| Deferrals | 7–14 days (Combined) | *Not supported* | 7 days (Combined) | Major 30–90, Minor 7–14, System 0–3 |
| Recommended Cadence | Oldest (stay on current major) or All | Oldest | Oldest | — |
| Download | Always On | *Not supported* | Always On | Always On |
| Install OS Updates | Allowed or Always On | *Not supported* | Always On | Allowed |
| Install Security Update | — | — | — | Always On |
| Rapid Security Response: Enable / Enable Rollback | Yes / No | *Not supported* | Yes / No | Yes / No |
| Allow Standard User OS Updates | — | — | — | Yes |
| Beta: Program Enrollment | Always Off | — | Always Off | Always Off |

:::tip[Why a short deferral?]
A deferral of 7–14 days gives you time to test a new release on a pilot group before the rest of the fleet is offered it — without leaving devices unpatched for long. Pair it with an enforcement deadline for security releases, so devices don't wait for users to act.
:::

## Check that the settings applied

1. Open the device in **Apple → Endpoints**.
2. Select the **Configurations** tab, and check that **Software Update Settings** is listed under **Assigned** with the **DDM** label and no error icon.
3. Select **Applied** and check the settings the device received.
4. On the device, open **Settings → General → Software Update → Automatic Updates**. Locked settings are dimmed.

If the configuration shows an error, see [DDM Status Reason Codes](/capaone/troubleshooting/ddm-status-reason-codes/). A device on iOS 17 rejects the configuration — it requires iOS 18.

## Good to know

- **Keep one Software Update Settings per device** — several configurations are merged with the most restrictive value winning, for example the longest deferral and **Always Off** over **Always On**. See [How Multiple DDM Configurations Combine](/capaone/mobile-manager/apple-ddm/how-ddm-configurations-combine/).
- **Unsupervised devices get a reduced feature set** — on Unsupervised iPhone and iPad, only **Notifications** and **Recommended Cadence** apply. Use enforcement to keep these devices current.
- **Legacy equivalents stop working on iOS 27** — the Legacy restrictions `forceDelayedSoftwareUpdates`, `enforcedSoftwareUpdateDelay`, the macOS major/minor/non-OS delay restrictions, and the BSI restrictions were deprecated in OS 26 and removed in OS 27. Recreate them here before devices update.
- **DDM takes precedence** — if both a Legacy software update policy and a DDM configuration exist on a device, the DDM configuration wins.
- **Source:** Apple's [Software Update Settings declaration](https://github.com/apple/device-management/blob/release/declarative/declarations/configurations/softwareupdate.settings.yaml) (Release v27.0) and Apple Platform Deployment: [Software Update settings declarative configuration](https://support.apple.com/guide/deployment/software-update-settings-declarative-dep0578d8b8a/web).
