Skip to content
Avanet

Understanding iOS and iPadOS updates with Sophos Mobile

This overview describes documented capabilities and limitations, not results verified in our own tenant or on a device. Tenant permissions and interface, effective policies, device behavior, and recovery have not been tested in practice.

Choose an update path

1. Check the device: In the specific Sophos Mobile tenant, check permissions and available menus, management mode, supervision, and the target device’s iOS/iPadOS version. In Sophos, Apple Device Enrollment is the management mode for the entire device; Automated Device Enrollment (ADE) through Apple Business is an enrollment method that supervises iPhones and iPads. With Apple Configurator 2, supervision depends on the configuration—it cannot be inferred from the Sophos mode alone. Apple User Enrollment for personal devices manages only settings, apps, and data associated with the managed Apple Account; these devices cannot be supervised and do not meet the management-mode requirement for the declarative update configurations described here. Mobile Threat Defense alone manages the Intercept X app, not the device as an MDM-managed device.

2. Choose the objective: The three policy configurations below use Apple declarative device management (DDM), Apple’s modern protocol for Mobile Device Management (MDM). With classic MDM, Sophos Mobile controls individual settings and checks device status at regular intervals. DDM instead uses asynchronous communication between the device and Sophos Mobile: a desired state is specified, and the device is responsible for reaching and maintaining it. The device reports changes immediately, allowing Sophos Mobile to respond without waiting for the next periodic synchronization. This describes the management model, not a guarantee of an immediately updated console display or an installation; assignment alone still does not prove installation.

  • Check for/trigger the latest update once on one device: classic device action, only for supervised devices running iOS/iPadOS 26 or earlier. At 26, it overlaps with the declarative options; for 27 or later, Sophos points to declarative policies instead of this device action.
  • Control offered versions and automatic updates: Software update settings, for planning purposes iOS/iPadOS 26 or later according to the English edition, Apple Device Enrollment and supervision.
  • Require a specific OS version by a deadline: Enforced software update, for planning purposes iOS/iPadOS 26 or later according to the English edition, Apple Device Enrollment.
  • Require a supplemental security patch by a deadline: Enforced Background Security Improvement (BSI), for planning purposes iOS/iPadOS 26 or later according to the English edition, Apple Device Enrollment, and the matching base OS version already installed. A BSI does not upgrade the base version.

Unresolved version discrepancy for the three declarative update configurations: The English Sophos editions dated September 22, 2026 list iOS/iPadOS 26 or later for Software update settings, Enforced software update, and Enforced Background Security Improvement. This overview uses that as a conservative planning limit. The German editions dated August 25, 2026, by contrast, list 18 or later for Software update settings and 17 or later for Enforced software update and Enforced Background Security Improvement. These lower version requirements do not constitute approval for use. A resolution of this discrepancy by Sophos is not established; the newer page date alone does not prove which minimum version actually applies. Before using any of these configurations on lower versions, clarify its suitability for the specific tenant and device version with Sophos and verify it in a pilot.

The Sophos pages for the two Enforced configurations do not list supervision separately as a prerequisite. This does not constitute approval for unsupervised devices; establish their suitability in the pilot.

Before enforcing any update: A delivered command or a set deadline does not prove installation. Deadlines use the device’s local time; lack of network access, insufficient battery or storage, and user/passcode conditions can cause delays. An update that has started cannot reliably be canceled, and removing a policy cannot roll back an installed OS version. After the device reconnects and the deadline passes, check the OS/build version actually installed and, where applicable, the BSI status on the pilot device.

3. Safeguard the pilot: Check the existing setup, device readiness, and recovery before assignment. Change instructions that have not yet been carried out only within the approved pilot scope, and check the effective desired state after synchronization; the next section lists the checks and evidence to collect.

What the four functions do—and do not do

  • Individual device, classic action: On a supervised device running iOS/iPadOS 26 or earlier, the path described by Sophos—Devices > [arrow next to device] > Show > Actions > Show available updates—displays available updates; Install latest available update creates and sends a command. Check the exact click path in your own tenant. Critical identifies critical security updates according to Apple’s classification. Sophos mentions the Install latest iOS update task bundle for device groups, but this page does not establish whether it applies to iOS/iPadOS 27 or later. The “26 or earlier” limit explicitly applies to the Show available updates device action; it is not an established limit for the task bundle.
  • Offered versions and automation: Software update settings (iOS/iPadOS 26+ under the planning limit above, Apple Device Enrollment, supervised) determines through Update strategy which available OS versions are offered: Current version the lowest, Latest version the highest, or All versions all of them. Download updates automatically controls automatic OS download, Install updates automatically controls automatic OS installation, and Install security updates automatically controls automatic installation of Background Security Improvements (supplemental security patches, or BSI). All three fields can each be set separately to user-configurable, always enabled, or always disabled; they are distinct from the separate BSI control Install automatically. Apple requires automatic downloads to be enabled for automatic OS installation. Automatic OS updates begin only after any configured deferral has expired. Major and minor updates (days) defers major and minor OS updates by 0 to 90 days after release; this deferral does not apply directly to BSI. If the latest matching minor OS version has been deferred or is not yet installed, a BSI that depends on it may still be delayed indirectly until that base OS version is installed. This does not enforce a particular build version by a deadline.
  • OS version with a deadline: Enforced software update (iOS/iPadOS 26+ under the planning limit above, Apple Device Enrollment) specifies a selected OS version through Enforced OS version and a matching build version through Enforced build version. The build list contains only builds for the selected OS version. If no patch number is specified, the latest available patch release of the selected version is installed. This is a specific version requirement, not a general strategy for offered versions or automation. Enforced software update alone cannot enforce a specific BSI; the separate Enforced Background Security Improvement configuration is also required for that.
  • Supplemental patch with a deadline: Enforced Background Security Improvement (iOS/iPadOS 26+ under the planning limit above, Apple Device Enrollment) enforces an available BSI patch on the matching base OS version already installed, not an upgrade to another OS version. Here, Enforced OS version selects the base OS version; Enforced build version selects the BSI patch, not an OS build. The list contains only BSIs for the selected base version. Sophos recommends also adding Enforced software update to the policy so that the base version is in place; the second configuration is not an unconditional prerequisite for a device that already has the matching base. If both configurations are used, select the same base OS version; for staggered enforcement, Sophos illustrates scheduling the BSI deadline after the base-update deadline. Both deadlines use the device’s local time. A BSI can be selected only for a version with an available BSI. If Enforced software update is present and no BSI is available for the OS version it enforces, Enforced Background Security Improvement is unavailable. Even with both configurations, installation is not guaranteed.

Shared fields of the two Enforced configurations: Enforcement date and time sets the latest installation deadline in the device’s local time. Users can install the update beforehand; if it is not installed by then, the device enforces the update. This does not guarantee completion exactly at the deadline: the battery, storage, network, and user/passcode conditions mentioned above still need to be checked. Information URL points to a web page where the organization provides information about the enforced update. Users can open it when the operating system notifies them about the update. Documentation of this field does not mean that such a URL is mandatory for every enforcement.

Apple explicitly allows enforced update targets regardless of configured deferrals or disabled automatic BSI installation. These settings therefore do not prevent targeted enforcement. The separate BSI configuration and matching base version remain necessary to enforce a specific BSI.

According to Sophos, a declarative policy can coexist with a classic iOS device policy, and, with Apple User Enrollment, even with an iOS user policy. Such coexistence at the policy level does not override the prerequisites for the update configurations; interactions with existing classic restrictions must be tested.

Pilot: existing setup, readiness, evidence

  • Record the existing setup: Document the target device and group, existing classic and declarative update requirements, deferrals, automatic downloads/installations, notifications, offered OS/build versions, and available BSI. Do not infer precedence or the effects of existing restrictions merely from coexistence.
  • Prepare the device and user: Check compatibility, network, battery, free storage, backup, user/passcode availability, and the approved maintenance window. If a passcode is set, iOS and iPadOS require it to be entered at enforcement unless it has already been entered beforehand. With full enforcement notifications enabled, reminders become more frequent as the deadline approaches; during the final 24 hours, Apple ignores Do Not Disturb for these notifications. Turning down Show all enforcement notifications does not mean silence: Sophos still describes a notification one hour before the deadline and the restart countdown. If Install automatically is disabled for BSI, the device does not offer them to the user. Allow rollback controls only whether an offered BSI rollback is shown to users, not an admin downgrade of an OS version. If the option is disabled, the device does not offer users a BSI rollback.
  • Check update readiness specifically: The required Apple update hosts must be reachable for download and personalization. If HTTPS traffic passes through a web proxy, exclude the relevant hosts from HTTPS interception (SSL Inspection); Apple services reject such intercepted connections. For user-initiated OS updates and upgrades on iPhone and iPad, Apple specifies at least 20% battery. Enforced updates have the same requirements as user-initiated updates of the same type. Separately, automatic OS installation requires at least 30% battery; automatic download and preparation require a connection to power. For BSI on iPhone and iPad, Apple specifies at least 20% battery, or 5% when connected to power. These thresholds do not apply universally to all update types and ways of initiating them. Sufficient free storage must be available for download, preparation, and installation; the source does not specify a fixed storage threshold. User-initiated updates or upgrades may require acceptance of updated terms and conditions; this condition does not apply to updates enforced by device management on supervised devices.
  • Plan for cellular downloads: If an iPhone or iPad is connected only through cellular data during a declarative update, the user must confirm the download. Without confirmation, the device waits for Wi-Fi.
  • Document the result: After assignment and device reconnection, including after the deadline, compare the effective desired state, enrollment, supervision, and installed OS/build version. For each pilot device, record device, desired OS/build version, observed OS/build version, task/device status, and time; for BSI, check the base version first, then the supplemental patch/build status. According to Sophos, the warning icon next to Operating system means the latest available version is not installed; OsUpdateAvailable is the corresponding column in the Devices report. Only supervised devices report this update status. Neither the display nor successful delivery of a task proves installation. If an update does not occur, check network, battery, storage, and offered versions; completion by the deadline is not guaranteed. If the device misses the deadline, it automatically retries enforcement when it reconnects to the internet. After a further interruption, it retries once it is powered on and online.

Stop the pilot or change a requirement—no guaranteed rollback: Changing a policy cannot reliably cancel an update that has already started; removing the policy does not undo an installed OS version. Change declarative requirements or assignments that have not yet been executed only within the approved pilot scope, and check the actual effective desired state after synchronization. Sophos does not document per-device Uninstall policy as a way to remove declarative iOS policies; Update devices is likewise not a general synchronization step for them. In the event of errors, follow only approved device recovery procedures with a secured backup; wiping the device requires separate approval.

Not part of the update path: The special update workflow for Shared iPad with multiple user accounts is not covered here. DDM is not limited to updates; this overview covers only iPhone/iPad updates, not every Apple DDM feature or its availability in Sophos Mobile. Math settings is the fourth configuration in the declarative policy overview: for supervised iPhones/iPads running iOS/iPadOS 26 or later, it controls Calculator, Math Notes, and mathematical keyboard suggestions, not OS updates. The Math settings section in the iPhone/iPad device policy guide explains the individual options and the unresolved version discrepancy between the Sophos language editions. Macs have their own configurations and prerequisites; use the macOS updates with Sophos Mobile guide rather than applying the iPhone/iPad limits to them.

Before a real rollout or claims about tested outcomes: Independently validate tenant permissions and UI (including click path and assignment), effective policy interactions, update availability, actual installation/BSI after the deadline, notifications, and recovery on a supervised pilot device. Without these checks, do not present installation or BSI effects as observed.