Software Update:Settings ()

The declaration to configure software updates.

iOS(18.0)macOS(15.0)tvOS(18.4)visionOS(26.0)
Branch: release

Settings (24)

SettingTypeRequiredDefaultManual InstallSupported OS
Software update notifications
Notifications
If set to `true`, the device shows all software update enforcement notifications. If set to `false`, the device only shows notifications triggered one hour before the enforcement deadline, and the restart countdown notification.
booleanoptionaltrue
✓Yes
iOS (18.0+)macOS (15.0+)tvOS (18.4+)visionOS (26.0+)
Software update deferrals
Deferrals
This object configures the deferral of software updates. Background Security Improvements aren't considered in `Major`, `Minor`, or `System` deferral mechanism.
4 subkeys
dictionaryoptional—
✗No
└─
Combined major/minor update deferral period
CombinedPeriodInDays
Specifies the number of days to defer a major or minor OS software update on the device. When set, software updates only appear after the specified delay, following the release of the software update.
Range: 1 - 90
integeroptional—
✗No
└─
Major update deferral period
MajorPeriodInDays
Specifies the number of days to defer a major OS software update on the device. When set, software updates only appear after the specified delay, following the release of the software update.
Range: 1 - 90
integeroptional—
✗No
└─
Minor update deferral period
MinorPeriodInDays
Specifies the number of days to defer a minor OS software update on the device. It also defers major updates for iOS. When set, software updates only appear after the specified delay, following the release of the software update.
Range: 1 - 90
integeroptional—
✗No
└─
System update deferral period
SystemPeriodInDays
Specifies the number of days to defer system or non-OS updates. When set, updates only appear after the specified delay, following the release of the update.
Range: 1 - 90
integeroptional—
✗No
Software update recommended cadence
RecommendedCadence
This string specifies how the device shows software updates to the user. When more than one update is available update, the device behaves as follows: - `All` - Shows all software update versions. - `Oldest` - Shows only the oldest (lower numbered) software update version. - `Newest` - Shows only the newest (highest numbered) software update version.
stringoptional—
✗No
Automatic software update settings
AutomaticActions
This object configures various automatic Software Update functionality.
3 subkeys
dictionaryoptional—
✗No
└─
Automatic downloads of available updates.
Download
Specifies whether the user can control automatic downloads of available updates: - `Allowed` - the user can enable or disable automatic downloads. - `AlwaysOn` - automatic downloads are always enabled. - `AlwaysOff` - automatic downloads are always disabled.
stringoptionalAllowed
✗No
└─
Automatic installs of OS updates.
InstallOSUpdates
Specifies whether the user can control automatic installation of available updates: - `Allowed` - the user can enable or disable automatic installation. - `AlwaysOn` - automatic installations are always enabled. - `AlwaysOff` - automatic installations are always disabled. > Note: > The device uses this only with automatic downloads enabled.
stringoptionalAllowed
✓Yes
iOS (18.0+)macOS (15.0+)tvOS (18.4+)visionOS (26.0+)
└─
Automatic installs of available security updates.
InstallSecurityUpdate
Specifies whether the user can control automatic installation of available security updates: - `Allowed` - the user can enable or disable automatic installation. - `AlwaysOn` - automatic installations are always enabled. - `AlwaysOff` - automatic installations are always disabled. > Note: > The device uses this only with automatic downloads enabled.
stringoptionalAllowed
✗No
Background Security Improvements settings
RapidSecurityResponse
These configurations set user access to interacting with Background Security Improvement.
2 subkeys
dictionaryoptional—
✗No
└─
Enable Background Security Improvements installation
Enable
If set to `false`, Background Security Improvements aren't offered for user installation. The system can still install Background Security Improvements with `com.apple.configuration.softwareupdate.enforcement.specific` configurations. If set to `true`, the system offers Background Security Improvements to the user.
booleanoptionaltrue
✓Yes
iOS (18.0+)macOS (15.0+)tvOS (18.4+)visionOS (26.0+)
└─
Enable Background Security Improvements rollbacks
EnableRollback
If set to `false`, the system doesn't offer Background Security Improvement rollbacks to the user. If set to `true`, the system offers Background Security Improvement rollbacks to the user.
booleanoptionaltrue
✓Yes
iOS (18.0+)macOS (15.0+)tvOS (18.4+)visionOS (26.0+)
Allow standard user OS updates
AllowStandardUserOSUpdates
If set to `true`, a standard user can perform Major and Minor Software Updates. If set to `false`, only administrators can perform Major and Minor Software Updates.
booleanoptionaltrue
✗No
Beta
Beta
This object configures the beta program settings for a device.
3 subkeys
dictionaryoptional—
✓Yes
macOS (15.4+)
└─
Program enrollment
ProgramEnrollment
Specifies whether the user can control beta program enrollment in the software update settings UI: - `Allowed` - the user can enroll in any applicable beta programs associated with their logged in Apple Account. If the `OfferPrograms` key is present, then the programs listed in that key are also presented to the user. - `AlwaysOn` - the device uses the beta programs the organization specifies, and the user isn't able to enroll in a beta program using their logged in Apple Account. The device is automatically enrolled into the beta program specified by the `RequireProgram` key if it's present. Otherwise, the system presents the programs listed in the `OfferPrograms` key to the user to choose which to enroll with. - `AlwaysOff` - The device isn't allowed to enroll in any beta programs. The system removes the device from any beta programs, if already enrolled.
stringoptionalAllowed
✗No
└─
Offer programs
OfferPrograms
An array of beta programs allowed on the device. This key must only be present if the `ProgramEnrollment` key is set to `Allowed` or `AlwaysOn`. This key must not be present if the `RequireProgram` key is present. This key can be present on unsupervised devices where the `ProgramEnrollment` key isn't supported but is implicitly set to `Allowed`.
1 subkey
arrayoptional—
✓Yes
iOS (18.0+)macOS (15.0+)tvOS (18.4+)visionOS (26.0+)
└─ └─
Program
Program
The name and token associated with a specific beta program to be allowed.
2 subkeys
dictionaryrequired—
✓Yes
iOS (18.0+)macOS (15.0+)tvOS (18.4+)visionOS (26.0+)
└─ └─ └─
Description
Description
A human readable description of the beta program.
stringrequired—
✓Yes
iOS (18.0+)macOS (15.0+)tvOS (18.4+)visionOS (26.0+)
└─ └─ └─
Token
Token
The Apple School Manager or Apple Business seeding service token for the organization the MDM server is part of. The system uses this token to enroll the device in the corresponding beta program.
stringrequired—
✓Yes
iOS (18.0+)macOS (15.0+)tvOS (18.4+)visionOS (26.0+)
└─
Require program
RequireProgram
The device automatically enrolls in this beta program. This key must only be present if the `ProgramEnrollment` key is set to `AlwaysOn`. The `OfferPrograms` key must not be present if this key is present.
2 subkeys
dictionaryoptional—
✗No
└─ └─
Description
Description
A human readable description of the beta program.
stringrequired—
✓Yes
iOS (18.0+)macOS (15.0+)tvOS (18.4+)visionOS (26.0+)
└─ └─
Token
Token
The Apple School Manager or Apple Business seeding service token for the organization the MDM server is part of. The system uses this token to enroll the device in the corresponding beta program.
stringrequired—
✓Yes
iOS (18.0+)macOS (15.0+)tvOS (18.4+)visionOS (26.0+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information