> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure Managed OS for macOS

> Configure the macOS Managed OS Library Item in Iru Endpoint with rolling enforcement, minimum version, specific version, installation method, and updates.

<Callout icon="apple" color="#B84A7A" iconType="regular">This guide applies to Mac computers</Callout>

Deploying and enforcing a macOS version is as easy as adding Managed OS for macOS to your Library and assigning it to an Assignment Map. To configure it, follow the steps below.

### About Managed OS for macOS

Managed OS for macOS deploys and enforces macOS updates across your fleet of Mac computers via [Declarative Device Management (DDM)](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os). You can offer major macOS upgrades **on-demand from Self Service** or have them enforced automatically. When you configure Managed OS, Iru declares the required macOS version and deadline; macOS handles download, caching, notifications, and installation. Iru handles:

* **Update detection**: Iru monitors for available macOS updates from Apple
* **Download and caching**: Updates are automatically downloaded and cached on devices
* **User notification**: Users are notified of pending updates with enforcement deadlines
* **Automatic installation**: Updates are installed according to your configured schedule
* **Compliance monitoring**: Iru tracks which devices have successfully updated

For how **Rolling enforcement** calculates the floor, how **Enforce a Specific Version** differs from **Manually Enforce Minimum Version**, notifications, and [first-time fleet enforcement recommendations](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#recommendations), see [Understanding Managed OS for Apple Platforms](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms).

### Enabling Managed OS for macOS in your Library

To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article.

#### Enabling Multiple Managed OS Library Items

When using Iru Endpoint, you can add the same Managed OS version to your Library multiple times. This is helpful when configuring different settings for various Blueprints or creating distinct update settings for nodes in an Assignment Map. To differentiate between these copies, you can use labels. See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview for steps.

### Configuring Managed OS for macOS

<Warning>
  Managed OS for macOS is not compatible with blocking the Software Update System Settings pane via any method, and doing so can produce unexpected behavior.
</Warning>

<Steps>
  <Step title="Add Label">
    Add a **Label** to easily identify this instance of Managed OS for macOS in your Library. While these labels won't be visible to end users, they will appear throughout the Iru Endpoint Web App. See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview for steps.
  </Step>

  <Step title="Assign to Blueprints">
    Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints).
  </Step>

  <Step title="Configure Installation Method">
    Under **Upgrades**, configure the way upgrade installations of this major version of macOS should be enforced:

    * **Continuously Enforce** will automatically initiate an upgrade on older versions of macOS, or users can upgrade on their own if they choose to
    * **Install on-demand from Self Service**. This option can easily be differentiated between Blueprints by making additional copies of the same Managed OS for macOS

    When **Continuously Enforce** is selected, set a separate **Enforcement Deadline** and **Enforcement Time** for upgrades under **Upgrades**. Update enforcement under **Updates** uses its own schedule, so the same Library Item can enforce minor updates and major upgrades on different timelines. Devices on an older major macOS version are no longer treated as out of date for updates and forced to upgrade as soon as the Library Item is scoped.

    Which macOS version a Mac receives when it updates depends on your Version Enforcement option under **Updates** (see **Configure Version Enforcement** below). **Rolling enforcement** and **Manually Enforce Minimum Version** install the latest Iru-approved update for the selected major version; **Enforce a Specific Version** enforces the macOS version you select.
  </Step>
</Steps>

<Steps>
  <Step title="Configure Version Enforcement">
    Under **Updates**, select an option for Version Enforcement. Available options include the following:

    <Frame>
      <img src="https://mintcdn.com/iru/R2ZpjRI3I6iEPdWV/assets/media/images/iru-managed-os-macos-version-enforcement-options.png?fit=max&auto=format&n=R2ZpjRI3I6iEPdWV&q=85&s=c81345a592154436ed1064de6bd94050" alt="Managed OS for macOS Version Enforcement options" width="974" height="538" data-path="assets/media/images/iru-managed-os-macos-version-enforcement-options.png" />
    </Frame>

    #### Do Not Manage

    This option will not manage macOS updates. It cannot be selected if you've chosen to **Continuously Enforce** upgrades, as **Upgrades** also determines the schedule and conditions for upgrading.

    #### Rolling enforcement

    Select **Within** (1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, or 3 months) **of release** and **at** a time for enforcement.

    <Frame>
      <img src="https://mintcdn.com/iru/R2ZpjRI3I6iEPdWV/assets/media/images/iru-managed-os-macos-rolling-enforcement.png?fit=max&auto=format&n=R2ZpjRI3I6iEPdWV&q=85&s=42c5b1951278e08a065008a342f31b29" alt="Managed OS for macOS Rolling enforcement Within and at settings" width="1928" height="584" data-path="assets/media/images/iru-managed-os-macos-rolling-enforcement.png" />
    </Frame>

    #### Manually Enforce Minimum Version

    Specify the minimum macOS version a Mac should be running and the **Enforcement Deadline** date by which users must update. No updates will be enforced if a Mac is already running a macOS version greater than the specified minimum. You will also select an **Enforcement Time**.

    <Frame>
      <img src="https://mintcdn.com/iru/R2ZpjRI3I6iEPdWV/assets/media/images/iru-managed-os-macos-manually-enforce-minimum-version.png?fit=max&auto=format&n=R2ZpjRI3I6iEPdWV&q=85&s=08cbc2b084f92f515734081eb5eba891" alt="Managed OS for macOS Manually Enforce Minimum Version settings" width="1932" height="866" data-path="assets/media/images/iru-managed-os-macos-manually-enforce-minimum-version.png" />
    </Frame>

    #### Enforce a Specific Version

    Uses the same version selection dropdown and enforcement scheduling fields as **Manually Enforce Minimum Version**—select a **Specific version**, an **Enforcement Deadline** (**on**), and an **Enforcement Time** (**at**). Unlike **Manually Enforce Minimum Version**, this option enforces that exact macOS version rather than a minimum floor.

    To enforce an Apple beta build, select **This is a beta version**, choose a **Seed Token** synced from Apple to Iru, then enter the beta version and build. Iru applies two declarations to the device in order: **Software Update Settings** (to enroll the device in the beta program), then **Software Update Enforcement** (to the specified version). For example, to test a beta upgrade to the next major macOS release, use a macOS Tahoe Managed OS Library Item, select a macOS Golden Gate seed token, and enter the target major version (such as `27.0`) and the current AppleSeed beta build.

    <Note>
      The **Seed Token** list can be long and difficult to navigate.
    </Note>

    <Frame>
      <img src="https://mintcdn.com/iru/R2ZpjRI3I6iEPdWV/assets/media/images/iru-managed-os-macos-enforce-specific-version.png?fit=max&auto=format&n=R2ZpjRI3I6iEPdWV&q=85&s=f8a4984f579dfd093ff5908872cb3039" alt="Managed OS for macOS Enforce a Specific Version settings" width="1900" height="554" data-path="assets/media/images/iru-managed-os-macos-enforce-specific-version.png" />
    </Frame>
  </Step>
</Steps>

For how each Version Enforcement option behaves after you save—including floors and user notifications—see [Version Enforcement option behavior](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#version-enforcement) in **Understanding Managed OS for Apple Platforms**.

<Steps>
  <Step title="Configure Background Security Improvements Enforcement">
    Under **Background Security Improvements Enforcement**, choose whether to automatically enforce these updates when Apple makes them available. Options:

    * **None**: Background Security Improvements will not be enforced.
    * **Automatically enforce**: Choose the enforcement timeframe and local time for enforcement.
  </Step>

  <Step title="Set Background Security Improvements Enforcement Timeframe">
    Select an **Enforcement timeframe for Background Security Improvements.**
  </Step>

  <Step title="Configure Background Security Improvements Enforcement Time">
    Select an **Enforcement Time**, the time of day Background Security Improvements are enforced in the device's local time zone.
  </Step>

  <Step title="Save the configuration">
    Click **Save** in the bottom right corner.
  </Step>
</Steps>

<Note>
  Background Security Improvements apply only to Mac computers on the latest macOS version; users must be on the latest macOS before these updates can be enforced. Background Security Improvements use [Declarative Device Management](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) for enforcement.
</Note>

### Related Articles

<CardGroup cols={2}>
  <Card title="Understanding Issues with Managed OS for macOS" icon="circle-exclamation" href="/en/endpoint/library/managed-os/understanding-issues-with-managed-os-for-macos">
    Understand how Managed OS works with DDM and macOS when troubleshooting updates
  </Card>

  <Card title="Understanding Managed OS for Apple Platforms" icon="book" href="/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms">
    Understand how Managed OS enforcement works on Apple devices
  </Card>

  <Card title="Managed OS for macOS Compatibility and Installation Mechanisms" icon="cog" href="/en/endpoint/library/managed-os/managed-os-for-macos-compatibility-and-installation-mechanisms">
    Understand compatibility and installation mechanisms for Managed OS on macOS
  </Card>

  <Card title="Declarative Device Management and Managed OS" icon="diagram-project" href="/en/endpoint/library/managed-os/declarative-device-management-and-managed-os">
    About Apple DDM and Managed OS in Iru Endpoint
  </Card>

  <Card title="macOS Managed OS User Experience" icon="user" href="/en/endpoint/devices/macos-managed-os-user-experience">
    What to expect when using Managed OS on Mac computers
  </Card>

  <Card title="OS Update Strategies: OS Deferral Restriction and Managed OS" icon="clock" href="/en/endpoint/devices/device-configurations/apple/os-update-strategies-os-deferral-restriction-and-managed-os">
    Compare different OS update management strategies
  </Card>

  <Card title="Delay and Enforce OS Updates" icon="calendar" href="/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates">
    Configure OS update delays and enforcement policies
  </Card>

  <Card title="Configure the Windows Update Library Item" icon="microsoft" iconType="brands" href="/en/endpoint/library/library-items-profiles/configure-the-windows-update-library-item">
    Manage Windows Update settings and the end-user update experience on Windows devices
  </Card>
</CardGroup>
