Skip to content
Avanet

Manage macOS updates with Sophos Mobile: declarative and classic policies

Start with the goal: Does a Mac need to reach a specific macOS version by a deadline, receive a specific Background Security Improvement on a compatible base version, or have automatic updates and deferrals controlled? Sophos Mobile offers different configurations for these purposes. The classic macOS device policy > Software update, by contrast, controls system update options; it sets neither an exact target version nor a deadline.

Version boundary and conflicting vendor guidance: The newer English Sophos Mobile help dated September 22, 2026 lists macOS 26 or later for all three macOS declarative policy configurations described here. The German Sophos Mobile help dated August 25, 2026, by contrast, lists macOS 14 or later for Enforced software update and Enforced Background Security Improvement, and macOS 15 or later for Software update settings. These official language versions conflict; the macOS 26 threshold here is the statement in the later-dated English documentation, not a reconciled, cross-language confirmed product minimum. In particular, the older German figures do not guarantee that these configurations are available or effective for Macs running macOS 14 or 15 in your Sophos tenant. Before planning for older devices, confirm actual applicability with Sophos or the responsible technical owner. macOS 26 is also not the latest macOS version: Apple released macOS 27 on September 14, 2026; Sophos lists macOS 27 as a supported platform starting with service release 2026.38 on September 21, 2026. Whether a Mac can install macOS 27 depends on its specific Apple model; running macOS 26 alone does not establish eligibility. This does not mean that these configurations can upgrade an older Mac to macOS 26, or that every classic option works on every older version. Support for an Apple feature at the operating-system level does not mean Sophos offers it for older Macs.

What declarative means: With Apple’s Declarative Device Management (DDM), the administrator specifies the desired state of the Mac. Once the policy is assigned, the device is responsible for reaching and maintaining that state. With classic MDM, Sophos Mobile controls individual settings and periodically queries the status; DDM reports changes immediately and asynchronously, without waiting for the next periodic status check. This is distinct from delivering a changed policy and is not proof that installation has already completed.

Choose the right policy

  • Enforced software update (declarative): Specify an Enforced OS version, optionally a matching Enforced build version to select the OS build, and an Enforcement date and time. If the chosen OS version omits the patch component, the system installs the latest available patch of that version—not necessarily the patch an administrator implicitly expects. Enforcement date and time is the latest installation time for the OS update: users can install it earlier; if they have not installed it by then, the device enforces installation at the deadline. The deadline uses the Mac’s local time zone and therefore does not reserve an exclusive installation time. Use this for an explicit version deadline, not as a general switch for automatic updates.
  • Enforced Background Security Improvement (declarative): Require a specific security improvement in addition to its matching base version. Here, Enforced OS version selects the base version, while Enforced build version selects the improvement and lists only improvements for that base version. In Enforced software update, by contrast, the same field selects an OS build. 26.3.1(a) is an illustrative example from Sophos’s documentation of an improvement for 26.3.1, not a promise that this update is currently offered; it is not a standalone OS upgrade. The Mac must already have the base version; for a coordinated rollout, specify the base version with Enforced software update and set a later deadline for the improvement. Sophos specifies a precise availability condition: if an Enforced software update configuration exists and no Background Security Improvement is available for its enforced OS version, the BSI configuration is unavailable. Enforcement date and time is the latest installation time: users can install the improvement earlier; otherwise, the device enforces installation at the deadline. This deadline also uses the device’s local time and does not guarantee success.
  • Software update settings (declarative): Set general behavior: allow users to install updates or reserve installation for admins, control notifications and automatic downloads/installation of minor updates and Background Security Improvements, and set separate deferrals for major, minor, and non-OS updates. Each category allows 0 (offer immediately) or 1–90 days from release. This configuration selects neither an exact OS build nor an installation deadline. Turning off Show all enforcement notifications does not suppress every notification: the message one hour before the deadline and the restart countdown remain. Under Background Security Improvements, Sophos says turning off Install automatically means users will no longer be offered these improvements. Allow rollback here refers only to offering a rollback of a Background Security Improvement, not to downgrading macOS.
  • Software update in the classic macOS device policy: Control system options including automatic macOS updates, checks and downloads, App Store app updates, beta updates, configuration data, and Security Responses and system files. According to Sophos, Require admin password for app installations requires users to enter an administrator password to install or update apps. For the relevant Allow automatic … checkboxes, disabling one removes the corresponding update option from the macOS interface; Automatic installation of configuration data, by contrast, specifically prevents configuration data from being installed automatically. On macOS 12 Monterey and earlier, the setting for Security Responses/system files has a different name (Install system data files and security updates). Do not extrapolate to macOS 27: Sophos release 2026.26 explicitly says the macOS software update delay under Restrictions in classic device and user policies does not apply to macOS 27. That is not the same configuration as the classic Software update page described here; the release note does not establish whether its individual checkboxes work on macOS 27. Check current Sophos documentation and a pilot device before relying on any such checkbox; do not assume that all work or that every one has been retired.

Three states for automatic updates: Download minor updates automatically, Install minor updates automatically, and Install security updates automatically are three separate controls. Each offers User-defined (users can turn the respective automatic action on or off), Always on (automatic downloading or installation is enforced), and Always off (the respective automatic action is disabled). The first two concern OS updates; for the third, Sophos describes the automatic installation of Background Security Improvements. Always off is therefore not a blanket prohibition on manual installation and is not equivalent to the separate BSI offer control Install automatically. The documentation establishes neither initial values nor the precedence of every combination of these BSI controls; do not infer defaults or combined effects.

Apple platform rules for how the settings interact: Automatic OS installation requires automatic downloads to be enabled; this does not guarantee that Sophos automatically corrects contradictory selections. Automatic OS updates respect the configured deferral. Background Security Improvements are not directly subject to that deferral, but require the latest compatible minor OS version: if that base version is deferred, the improvement effectively waits too. An explicitly enforced target version or improvement, by contrast, can be specified independently of deferrals and disabled automatic BSI installation. These rules describe Apple’s update mechanism, not an effect tested in your own Sophos tenant or a guarantee of successful installation.

Do not conflate them: In the declarative configuration, Sophos uses Install security updates automatically to describe Background Security Improvements. Apple’s broader category of automatic security updates also includes XProtect, Gatekeeper, and system data. Apple’s non-OS updates category also includes Safari and XProtect, for example. Deferring this category can therefore delay security-relevant packages and is not merely a matter of convenience. Check which category a particular device receives on its intended macOS version; a general deferral rule does not replace enforcing a specific improvement.

How policies interact and how to pilot safely

A macOS device policy applies to all users of a Mac; a macOS user policy has a different user scope. A declarative policy is a separate type of device policy and can be assigned alongside the classic one. In addition to the enrollment policy, Sophos allows one device policy, one declarative policy, and one user policy per Mac. In a conflict, the stricter setting does not always win: declarative software update and app settings take precedence over corresponding settings in device or user policies. Changes to device and declarative policies take effect at the next device sync; changes to user policies take effect at the next login. Before the pilot, therefore, check the policies actually assigned and the device status, not just the saved policy.

Before setting an enforced deadline on a non-production pilot Mac, record its enrollment and device eligibility, macOS version/build, offered target version and matching build or available Background Security Improvement, power, free storage, and network access. Check the deadline in device time against the maintenance window and user notice. In both enforced update configurations, Information URL refers to the organisation’s own information page; users can access it when the operating system notifies them about the update. Sophos thus describes how users access the page, but these help pages do not establish whether the field is required; check this in the tenant you use rather than assuming it is either optional or mandatory. Back up documents and save work. Apple notes that when the deadline expires, macOS can forcibly close open apps even if they contain unsaved documents, then restart; on Apple silicon Macs, an existing bootstrap token is used for authorization or a login is required. Low battery, insufficient space, or a period offline can delay installation. A configured deadline is not proof that installation has completed.

Check the specific Apple prerequisites: For a Background Security Improvement on a Mac laptop, Apple specifies connection to power or at least 10% battery on Apple silicon or 20% on Intel. These are BSI requirements, not universal thresholds for every automatic OS installation. There must also be enough space for downloading, preparation, and installation. If downloading or preparation fails, check the Apple hosts required for software updates and the proxy path: Apple requires these hosts to be reachable and states that connections using HTTPS interception/SSL inspection fail. If an exception is needed, limit it to the relevant Apple hosts rather than disabling TLS inspection globally. A content cache does not replace all contact with Apple either.

Verify: On the pilot device, compare the OS version and build actually installed, or the improvement, with the selected target; monitor device sync and any available update status or error indicators. If the deadline is missed, first check the network, battery, storage, offered version/build, base version, and authorization. Apple describes further attempts after reconnection; verify their success on the affected Mac. Plan a production rollout only after reviewing the pilot results and obtaining approval for the maintenance window.

Verify the BSI separately: The installed base OS version and its build alone do not prove that a specific improvement is installed. Apple identifies the DDM status report keys StatusDeviceOperatingSystemSupplementalExtraVersion and StatusDeviceOperatingSystemSupplementalBuildVersion for the additional version identifier and supplemental build. Include these details when checking against the selected BSI target, where the management service in use provides them; this does not promise Sophos UI fields with the same names. Apple’s DDM status reports can also distinguish phases such as waiting, downloading/preparing, and installing, as well as errors. Such a phase or a successful device sync does not replace comparing the state actually installed with the target.

Rollback is limited: Before making a change, record the previously approved targets, deadlines, and settings. For a Mac, change the relevant configuration in the policy or assign another approved policy of the same type; Sophos does not describe a generic Uninstall rollback route for these policies. After the next device sync, check the actual assignment and effective state on the Mac before treating a requirement as withdrawn or a setting as restored. Do not try to remove the declarative policy on the device or delete the enrollment profile as a substitute: according to Sophos, users cannot remove the declarative policy, whereas removing the enrollment policy with admin rights takes the Mac out of management. Changing a policy does not uninstall an already installed macOS upgrade, restore lost data, or guarantee cancellation of an update already in progress. Sophos’s Allow rollback applies only to Background Security Improvements and only controls whether users are offered the option to remove them. For a problematic improvement already installed, first check the rollback Apple supports for the specific macOS version and the effective policy; for an OS upgrade, use an authorized recovery plan rather than promising a downgrade.