> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Understanding Managed OS for Apple Platforms

> How Managed OS enforcement works in Iru Endpoint across macOS, iOS, iPadOS, and tvOS, including rolling enforcement, minimum and specific version options.

<Callout icon="apple" color="#B84A7A" iconType="regular">This guide applies to Mac computers, iOS devices, iPadOS devices, and Apple TV</Callout>

### About Managed OS

Managed OS deploys and enforces OS updates across your fleet of Apple devices. Updates are delivered via [Declarative Device Management (DDM)](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) on supported versions.

Which OS version a device receives when it updates depends on [Version Enforcement](#version-enforcement): **Rolling enforcement** and **Manually Enforce Minimum Version** install the latest Iru-approved update; **Enforce a Specific Version** enforces the OS version you select.

For configuration steps, see [Configuring Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos) or [Configuring Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos).

### Version Enforcement

Under **Updates**, choose how OS updates are enforced. **Rolling enforcement** and **Manually Enforce Minimum Version** set a minimum version floor; **Enforce a Specific Version** targets an exact OS version by a deadline.

| Option                               | Sets a floor?                   | OS version installed          | Key configuration fields                                                                                    |
| ------------------------------------ | ------------------------------- | ----------------------------- | ----------------------------------------------------------------------------------------------------------- |
| **Do Not Manage**                    | No                              | No Managed OS enforcement     | —                                                                                                           |
| **Rolling enforcement**              | Yes (from Apple's release date) | Latest Iru-approved version   | **Within** (1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, or 3 months) **of release**, **at** |
| **Manually Enforce Minimum Version** | Yes (admin-set minimum)         | Latest Iru-approved version   | Minimum version, **Enforcement Deadline**, **Enforcement Time**                                             |
| **Enforce a Specific Version**       | No (exact target)               | Selected **Specific version** | **Specific version**, **Enforcement Deadline**, **Enforcement Time**                                        |

#### Shared enforcement behavior

* When [DDM](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) is in use, enforcement uses the device's local time zone.
* When a new update is available in Iru Endpoint, it is cached on devices as soon as possible. After the update is cached, users are notified leading up to enforcement. On macOS, the Iru menu app displays rounded days (for example, if an update will be enforced in 7.6 days, 8 days is displayed).
* **Rolling enforcement** and **Manually Enforce Minimum Version** install the latest Iru-approved OS version (shown in the upper-right corner of the Library Item). **Enforce a Specific Version** enforces the OS version you selected.

#### Do Not Manage

Iru Endpoint does not enforce an OS version. On macOS, this option cannot be used with **Continuously Enforce** under **Upgrades**, since **Upgrades** sets the major-version upgrade schedule and conditions separately from **Updates**.

#### Rolling enforcement

New OS updates are enforced automatically after release. You configure:

* **Within**: How long after release (1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, or 3 months) **of release**
* **at**: The time of day the update is enforced

The floor is calculated from Apple's release date. Devices receive the latest Iru-approved OS version when they update.

#### Manually Enforce Minimum Version

You set the minimum OS version and an **Enforcement Deadline** (plus **Enforcement Time**). No update is enforced if a device is already above the minimum. Use this for critical security updates or to align the fleet to a version by a date. Devices below the minimum receive the latest Iru-approved OS version when they update.

#### Enforce a Specific Version

Uses the same version selection dropdown and enforcement scheduling fields as **Manually Enforce Minimum Version**: select a **Specific version**, an **Enforcement Deadline**, and an **Enforcement Time**. Unlike **Manually Enforce Minimum Version**, this option enforces that exact OS version on your deadline rather than treating it as a minimum floor. Use this when you need all devices on a particular version by a fixed date.

To enforce an Apple beta build, select **This is a beta version** and choose a **Seed Token** synced from Apple to Iru. Iru applies **Software Update Settings** (beta enrollment) and then **Software Update Enforcement** (to the specified version) as separate declarations. For example, to test a beta upgrade to the next major macOS release, use a macOS Tahoe Managed OS Library Item, select a macOS Golden Gate seed token, and enter the target major version (such as `27.0`) and the current AppleSeed beta build.

<Note>
  The **Seed Token** list can be long and difficult to navigate.
</Note>

Iru checks hardware compatibility before enforcing **Enforce a Specific Version**, **Manually Enforce Minimum Version**, and **Rolling enforcement** targets. Devices that cannot run the required version are not forced to install an incompatible update.

#### Background Security Improvements

In the same Library Item you can configure **Background Security Improvements** (lightweight security updates from Apple). **Automatically enforce** under Background Security Improvements is separate from **Rolling enforcement** under **Updates** → Version Enforcement. For configuration steps, see [Configuring Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos) or [Configuring Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos).

### macOS: Installation Options

macOS Managed OS also lets you choose how major macOS upgrades are offered under **Upgrades**:

* **Continuously Enforce**: Iru Endpoint initiates an upgrade on Mac computers running older versions, or users can upgrade on their own.
* **Install on-demand from Self Service**: The upgrade is not pushed; users install it from Self Service when ready. Use different copies of the same Managed OS Library Item with different [labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) to offer this in some Blueprints and continuous enforcement in others.

**Updates** and **Upgrades** use separate enforcement schedules in the same Library Item. You can enforce minor macOS updates on one timeline and major upgrades on another. This avoids devices on an older major version appearing out of date and being forced to upgrade as soon as the Library Item is scoped.

For UI steps, see [Configure Installation Method](/en/endpoint/library/managed-os/configure-managed-os-for-macos#configuring-managed-os-for-macos) in **Configuring Managed OS for macOS**.

Additional macOS considerations:

* Managed OS does not support downgrading macOS.
* Do not block the Software Update System Settings pane; doing so is not compatible with Managed OS and can produce unexpected behavior.

### iOS, iPadOS, and tvOS: Supervision

<Note>
  Managed OS for iOS, iPadOS, and tvOS requires supervision.
</Note>

At the enforcement deadline, on iOS and iPadOS devices with a passcode, users must be prompted for the update and enter their passcode. On tvOS, and on iOS and iPadOS devices without passcodes, updates apply without user intervention at the deadline. For details, see [User Experience with Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/devices/user-experience-with-managed-os-for-ios-ipados-and-tvos).

### Recommendations

* **First time enforcing an OS version on your fleet:** Use **Manually Enforce Minimum Version** and set the **Enforcement Deadline** at least 5 days later so users get advance notifications. For UI steps, see [Configuring Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos) or [Configuring Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos).
* **Rolling enforcement and immediate update requirements:** If Apple has not released an update within your selected window (e.g. **Within 2 weeks of release**), all out-of-date devices may immediately be required to update and restart.
* **Software Update Library Items:** If you use Managed OS, turn off automatic download of updates in any Software Update Library Items used in the same Blueprint to avoid conflicts with caching. On macOS, see also [Deployment Considerations](/en/endpoint/library/managed-os/managed-os-for-macos-compatibility-and-installation-mechanisms#deployment-considerations) in **Managed OS for macOS Compatibility and Installation Mechanisms**.

### Labels

Use **labels** to tell copies of the same Managed OS apart when you add it to your Library more than once. See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview.

### Related Articles

<CardGroup cols={2}>
  <Card title="Configure Managed OS for macOS" icon="apple" href="/en/endpoint/library/managed-os/configure-managed-os-for-macos">
    Configure Managed OS updates for Mac computers
  </Card>

  <Card title="Configure Managed OS for iOS, iPadOS and tvOS" icon="mobile" href="/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos">
    Configure Managed OS updates for iOS, iPadOS, and tvOS devices
  </Card>

  <Card title="Managed OS for macOS Compatibility and Installation Mechanisms" icon="cog" href="/en/endpoint/library/managed-os/managed-os-for-macos-compatibility-and-installation-mechanisms">
    Understand compatibility and installation mechanisms for Managed OS on macOS
  </Card>

  <Card title="Understanding Issues with Managed OS for macOS" icon="triangle-exclamation" href="/en/endpoint/library/managed-os/understanding-issues-with-managed-os-for-macos">
    Understand how Managed OS works with DDM and macOS when troubleshooting updates
  </Card>

  <Card title="Declarative Device Management and Managed OS" icon="apple" href="/en/endpoint/library/managed-os/declarative-device-management-and-managed-os">
    About Apple DDM and Managed OS in Iru Endpoint
  </Card>

  <Card title="macOS Managed OS User Experience" icon="user" href="/en/endpoint/devices/macos-managed-os-user-experience">
    What to expect when Managed OS updates run on your Mac
  </Card>

  <Card title="User Experience with Managed OS for iOS, iPadOS and tvOS" icon="user" href="/en/endpoint/devices/user-experience-with-managed-os-for-ios-ipados-and-tvos">
    What to expect when Managed OS updates run on iOS, iPadOS, and tvOS devices
  </Card>
</CardGroup>
