# DDM Software Update Not Installing

> A device with a DDM Software Update Enforcement Specific configuration doesn't update by the deadline, or shows a software update failure. Causes and fixes.

Source: https://docs.capaone.com/capaone/troubleshooting/ddm-software-update-not-installing/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

## Problem

A **Software Update Enforcement Specific** configuration is assigned to an Apple device, but one of the following happens:

- The deadline passes and the device is still on the old version.
- The device reports the install state **failed**, or a failure count above 0.
- The update never appears on the device.
- The configuration itself shows an error.

## Cause

With DDM, the device — not CapaOne — downloads, prepares and installs the update. It only installs when **all** of these are true:

- The device runs DDM, and its OS supports the configuration (iOS or iPadOS 17 or later, macOS 14 or later).
- Apple currently offers the target version to that device model.
- The device can install the target version from the version it runs now — for example, a supplemental update needs its base version.
- The device meets the install conditions: enough battery or connected to power, enough free storage, and network access to Apple's update servers.
- On Mac, the update can be authorized — with a bootstrap token, or by the user.

If any of these isn't met, the configuration stays active and the device waits. It doesn't produce an error in every case.

## Solution

Work through the checks in order.

### 1. Check the configuration status

1. Open the device in **Apple → Endpoints** and select the **Configurations** tab.
2. Check that the enforcement is listed under **Assigned** with the **DDM** label.
3. If it shows an error icon, look up the code in [DDM Status Reason Codes](/capaone/troubleshooting/ddm-status-reason-codes/).

If the configuration isn't listed at all, check that it's assigned to a group the device is a member of, and that the device runs DDM — its badge shows **Supervised DDM**, **Unsupervised DDM**, or **Kiosk Mode DDM**. See [Enable Apple DDM](/capaone/mobile-manager/apple-ddm/enable-apple-ddm/).

### 2. Check that Apple offers the target version

1. Open [gdmf.apple.com/v2/pmv](https://gdmf.apple.com/v2/pmv). This is Apple's public list of the OS versions it currently offers, per device model.
2. Under the platform (`iOS` for iPhone and iPad, `macOS` for Mac), find the **Target OS Version** from your configuration.
3. Check that the device is listed under **SupportedDevices** for that version. iPhone and iPad are listed by model identifier, for example `iPhone17,1`. Macs are listed by board ID, for example `J414cAP` or `Mac-…`.

If the version isn't listed, or the device's model isn't listed for it, the device can't install it. The configuration stays active without effect. Create a new enforcement for a version Apple offers, and remove the old one.

:::caution[Exact version only]
The device installs exactly the **Target OS Version**. An enforcement for `27.0` doesn't install `27.0.1`, and once Apple stops offering `27.0`, the enforcement can't complete. Target the latest version Apple offers.
:::

### 3. Check the path from the current version

- **Supplemental updates** — an update such as `27.0.1 (a)` only installs on a device that runs exactly `27.0.1`. Use two enforcements: one for the base version with an earlier deadline, then one for the supplemental version, with the build version and its letter suffix in **Target Build Version**. See [Enforce a Specific OS Update](/capaone/mobile-manager/apple-ddm/enforce-a-specific-os-update/#supplemental-and-background-security-improvement-updates).
- **Already newer** — a device that already runs a newer version than the target doesn't downgrade. The enforcement has no effect on it.
- **Major versions** — check that the device model supports the target major version at all. Devices Apple dropped from a release are not listed for it in step 2.

### 4. Check what the device reports

DDM devices report their software update state on their own, but CapaOne doesn't show these values as separate fields today. Check the device's OS version on its page, the configuration's **Endpoints** tab for the endpoint's **Status**, and **Settings → General → Software Update** on the device. The values the device reports are:

| What the device reports | What to look for |
|---|---|
| Install state | `downloading` or `prepared` — the update is on its way; wait. `failed` — continue below. `none` with the old OS version — the device isn't processing the update; recheck steps 1–3. |
| Pending version | Should show your target version and, for an enforced update, the enforcement date and time. If it shows another version, a different enforcement or the user started another update. |
| Install reason | `declaration` means your enforcement is driving the update. |
| Failure reason | Count, last reason, and time. The reason text usually points to the cause — for example, insufficient storage or battery. |

### 5. Check the device's conditions

| Condition | What to check |
|---|---|
| Battery | The device needs enough charge, or to be connected to power. Ask the user to connect the device to power. |
| Storage | Major updates need several GB of free space. Check free storage on the device page. |
| Network | The device must reach Apple's update servers. Check that your firewall or proxy allows Apple's software update hosts. See Apple's [Use Apple products on enterprise networks](https://support.apple.com/101555). |
| Device off or offline at the deadline | Expected. When the device is back on and connected, it shows a past-due notification and tries to install within about an hour. |
| Content caching | If you use a content cache, check that it's healthy — a broken cache can slow downloads. |

### 6. Mac only: authorization

On Apple silicon Macs, the installation must be authorized. If the update can't be authorized automatically, the user is asked for their credentials at the deadline — and if nobody is there, the update waits. Ask a user to be at the Mac at the deadline, or choose a deadline when someone is.

### 7. Check for conflicting policy

- **Deferrals** — a long deferral in **Software Update Settings** hides new updates from the user, but doesn't stop an enforcement for a version Apple offers.
- **Automatic actions** — **Install OS Updates** set to **Always Off** stops automatic installs, but not an enforced deadline.
- **Legacy software update settings** — on OS 27, they're ignored. On older versions, DDM software update configurations take precedence over the equivalent Legacy MDM commands.
- **Several enforcements** — if a device has enforcements for two different versions, it processes the ones Apple offers. Remove enforcements for old versions.

If the device still doesn't update, contact CapaOne support. Include:

- The configuration's name, **Target OS Version**, and **Target Local Date/Time**.
- The device's model, OS version, and whether it's Supervised.
- What the device shows in **Settings → General → Software Update**, and the configuration's status on its **Endpoints** tab.

## Good to know

- **No error doesn't mean no problem** — an enforcement for a version the device can't install stays active without an error. Always check step 2.
- **The deadline is device-local time** — devices in different time zones install at the same local hour, not at the same moment.
- **The device keeps trying** — DDM devices retry on their own after a failure or a missed deadline. You don't need to resend anything.
- **Unsupervised iPhone and iPad are supported** — enforcement works on unsupervised devices, even though deferrals and automatic actions don't.
- **Source:** Apple's [Software Update Enforcement Specific declaration](https://github.com/apple/device-management/blob/release/declarative/declarations/configurations/softwareupdate.enforcement.specific.yaml) and software update status items (Release v27.0), and Apple Platform Deployment: [Install and enforce software updates](https://support.apple.com/guide/deployment/install-and-enforce-software-updates-depd30715cbb/web).
