Nothing on the device announces it. No prompt, no re-enrollment, no ticket. But iOS 27 software update management no longer runs on the commands behind most existing policies, and the fleet that followed your rules last week may not follow them this week.
Apple released iOS 27 on September 14, 2026, and removed the legacy MDM commands that management platforms used to discover, schedule, and track OS updates. The device stays enrolled and stays managed. What stops is the part that tells it when to update — and because nothing fails loudly, the gap shows up weeks later, when someone notices a fleet that has quietly been updating on its users’ schedule instead of yours.
What iOS 27 Software Update Management Changes
Traditional MDM works as an exchange. The management service sends a command, the device acknowledges it, and the service polls to confirm the setting took effect. Every setting costs a round trip, and a device that sits offline drifts until it checks in again.
Declarative device management works alongside that rather than replacing it. Apple added it to the existing MDM architecture: the service sends the intended state as a set of declarations, the device evaluates them locally, and it reports status changes back as they happen. Both models run on the same enrollment, and a fleet can use each where it fits.
What iOS 27 removes is narrower than a protocol change. The commands and queries that platforms used to schedule updates, read available versions, and delay releases no longer answer. Where a declarative configuration and a legacy policy target the same setting, the declarative configuration takes effect. Apple sets this out in its deployment documentation, which now treats declarative software update management as the way to configure and enforce updates.
What to Verify Before More Devices Update
Your Update Policies
Open the software update policies covering your Apple devices and confirm they use the declarative type. Check the target versions, the deferral windows, and whether your console still reports installed and available versions. A policy built on the old command model does not error — it simply stops governing anything, and the device reports healthy while running whatever version its user accepted.
Your Existing Devices
The devices move themselves. A device that updates to iOS 27 lands on the declarative model, and so does a device you enroll on iOS 27. Below that version, you move a device across from its endpoint page in CapaOne when you are ready.
Your configurations do not follow. The policies you built under the legacy model stay where they are, and the declarative side starts empty until you recreate them. That is the gap: the device arrives on the new model and finds nothing governing it.
A Small Group First
Put a handful of devices on iOS 27 and confirm your policies behave the way you expect before the rest of the fleet follows. A small pilot shows you whether update discovery, deferral, and enforcement still work the way your reporting claims they do.
Neither of these is reason to hold devices back. The declarative model enforces more consistently than the commands it replaces. The risk sits in the policies, not in the devices.
How CapaOne Manages Apple Devices Through the Change
For IT teams, the goal is not to run two update architectures in two workflows. It is to keep visibility over OS versions, update policy, and compliance while the fleet moves.
Mobile Manager, part of the CapaOne Endpoint Management Platform, manages iOS, iPadOS, and Android devices from one console, across both the legacy and declarative models. Devices you have moved to DDM keep their update control on iOS 27, and newly enrolled devices run under DDM from the start.
For teams running a mixed fleet, that means the change happens per device rather than as a migration project. Some devices sit on iOS 26 and earlier, some move to 27, and both keep reporting into the same mobile device management console with the same compliance view.
The work that remains is the work that was always there: knowing which policies govern which devices, and confirming that they still do.
Book a demo to see how Mobile Manager handles Apple devices across both models, or start a trial and check your own fleet.