> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Declarative Device Management and Managed OS

> Learn how Apple Declarative Device Management (DDM) works with Managed OS in Iru Endpoint. Understand status reports, declarations, and update behavior.

<Callout icon="apple" color="#B84A7A" iconType="regular">This guide applies to Apple devices</Callout>

### About Declarative Device Management

Declarative Device Management (DDM) is Apple's next-generation device management framework that provides a more efficient and reliable way to manage devices. Unlike traditional MDM, which uses a push-based approach, DDM allows devices to pull their configuration from the MDM server, making them more autonomous and self-managing.
Iru Endpoint was [first to market](https://the-sequence.com/kandji-support-declarative-device-management) to support actively managing supervised devices with DDM in 2022, and since that launch, has continued to expand the usage of DDM throughout the product.

### How It Works

DDM enhances Managed OS functionality by providing more reliable update delivery and enforcement. When DDM is enabled, devices can:

* **Pull updates autonomously** - Devices check for updates independently
* **Handle offline scenarios** - Updates can be cached and applied when connectivity is restored
* **Provide better reliability** - Reduced dependency on constant server communication
* **Improve user experience** - More seamless update processes with fewer interruptions

### DDM and Managed OS

<Note>
  Iru Endpoint uses DDM for Managed OS for macOS, iOS 17, iPadOS 17, and tvOS 17 and later.
</Note>

DDM is used to manage software updates automatically; there is no additional configuration needed in Managed OS Library Items. When DDM is used, Iru Endpoint applies declarations to scoped devices that specify the required OS version and enforcement deadline. For beta enforcement, Iru applies **Software Update Settings** (beta enrollment) and then **Software Update Enforcement** (to the specified version). From that point forward, the respective operating system handles all end user notifications and the actual enforcement process.

### Admin Experience

#### Library Item Configuration

Managed OS Library Items for macOS Sonoma, iOS 17, and iPadOS 17 separate the enforcement time zone option into its own section. This option now applies only to *upgrades* from older operating systems.

<Note>
  When DDM is in use, update enforcement always uses the device's local time zone. Iru Endpoint cannot change this behavior as it is set by the operating systems.
</Note>

#### MDM Commands

Only a single MDM command for **DeclarativeManagement** is visible in the device's activity stream when new OS versions are released or enforcement timelines are changed. Individual AvailableOSUpdates and OSUpdateStatus commands are no longer run throughout the update lifecycle as they don't provide any information to Iru Endpoint when DDM is in use.

#### Library Item Status

macOS, iOS, iPadOS, and tvOS send updates proactively to Iru Endpoint about the status of OS updates. The operating systems, not Iru Endpoint, control the contents and granularity of these status updates. Iru Endpoint simply displays the updates as they are received. Iru Endpoint then maps various reported statuses to standard Library Item statuses, such as Downloading, Cached, Installing, Pass, and Error.

### User Experience

Please visit the [User Experience with Managed OS for macOS](/en/endpoint/devices/macos-managed-os-user-experience) and [User Experience with Managed OS for iOS, iPadOS and tvOS](/en/endpoint/devices/user-experience-with-managed-os-for-ios-ipados-and-tvos) articles for more information.

### Deferrals

Users cannot defer enforced updates beyond their enforcement deadline an hour at a time; this is because the operating systems do not allow it. This means updates could happen during critical business tasks if users continuously ignore notifications and don't update their devices (though all notifications in the last 24hrs of enforcement ignore Do Not Disturb). Iru Endpoint cannot control this, but does recommend considering this important change when setting enforcement times in Managed OS. Also be sure to consider that all updates are enforced in device local time.

### Troubleshooting

<Accordion title="Who should I contact for help with Managed OS?">
  Check System Settings on macOS or Settings on iOS or iPadOS for the applied declaration. If it has the correct enforcement settings but users are not being notified properly, or updates are failing to install, please contact [Apple support](https://support.apple.com/guide/deployment/applecare-support-dep6971a1932/web) or send feedback to Apple through [AppleSeed for IT](https://support.apple.com/guide/deployment/join-appleseed-for-it-depe9ec59a81/web). If devices are not receiving the correct declarations at all, or you have a general question about Managed OS, including how to configure it, please [contact Iru support](/en/iru/iru-support/access-to-iru-support).
</Accordion>

### Frequently Asked Questions

<AccordionGroup>
  <Accordion title="Why is Iru Endpoint using DDM to manage software updates?">
    Using DDM to manage software updates on [Iru-supported Apple devices](/en/iru/requirements/device-requirements) is the most reliable way to do so. It also brings a number of benefits like enforcement of updates in a device's local time zone, and notifications that are able to bypass Do Not Disturb in the last 24hrs leading up to enforcement.
  </Accordion>

  <Accordion title="How can I verify that Iru Endpoint has applied the correct declaration for Managed OS?">
    macOS: Open System Settings > General > Device Management > Double click on "MDM Profile" > Scroll down to "Device Declarations".

    <Note>
      Once a declaration hits a device, users will be notified immediately that an update is scheduled. Depending on your configuration, this notification could happen weeks or months ahead of the enforcement date.
    </Note>

    iOS: Open **Settings > General > VPN & Device Management > MDM Profile > Configurations**
  </Accordion>

  <Accordion title="Is Managed OS still supported on older operating systems where DDM is not used?">
    Yes. Iru Endpoint supports Managed OS for [all supported operating systems](/en/iru/requirements/device-requirements).
  </Accordion>

  <Accordion title="What happens if the update is already cached and I would like to change the enforcement date/time?">
    When an update is already cached, and you want to push back the enforcement date, the enforcement date and time will be re-evaluated as soon as possible with the next MDM check-in.
  </Accordion>

  <Accordion title="Where can I send feedback about the end user experience when DDM is in use?">
    Feedback about the end user experience when updates are managed with DDM, including the contents of notifications, their frequency, deferrals, or any other customizations should be sent to Apple through [AppleSeed for IT](https://support.apple.com/guide/deployment/join-appleseed-for-it-depe9ec59a81/web).
  </Accordion>

  <Accordion title="Who should I contact for help with Managed OS?">
    Check System Settings on macOS or Settings on iOS or iPadOS for the applied declaration. If it has the correct enforcement settings but users are not being notified properly, or updates are failing to install, please contact [Apple support](https://support.apple.com/guide/deployment/applecare-support-dep6971a1932/web) or send feedback to Apple through [AppleSeed for IT](https://support.apple.com/guide/deployment/join-appleseed-for-it-depe9ec59a81/web). If devices are not receiving the correct declarations at all, or you have a general question about Managed OS, including how to configure it, please [contact Iru support](/en/iru/iru-support/access-to-iru-support).
  </Accordion>
</AccordionGroup>

### Related Articles

<CardGroup cols={2}>
  <Card title="Configure Managed OS for macOS" icon="apple" href="/en/endpoint/library/managed-os/configure-managed-os-for-macos">
    Configure managed OS updates for Mac computers
  </Card>

  <Card title="Understanding Managed OS for Apple Platforms" icon="book" href="/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms">
    Understand how Managed OS enforcement works on Apple devices
  </Card>

  <Card title="Configure Managed OS for iOS, iPadOS and tvOS" icon="mobile" href="/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos">
    Configure managed OS updates for iOS, iPadOS, and tvOS devices
  </Card>

  <Card title="OS Update Strategies: OS Deferral Restriction and Managed OS" icon="clock" href="/en/endpoint/devices/device-configurations/apple/os-update-strategies-os-deferral-restriction-and-managed-os">
    Compare different OS update management strategies
  </Card>
</CardGroup>
