OS 27 release: key takeaways for Apple enterprise admins 

Apple's OS 27 release brings declarative management, new identity tools and real-time fleet visibility to IT admins.

September 15 2026 by

Emma Waite

Jamf helps enterprises and schools succeed with Apple and OS 27.

This blog discusses the major feature and functionality enhancements from Apple’s latest operating system release across all their platforms.

In June, Apple hosts their Worldwide Developers Conference (WWDC), a time for them to show the world what they have been up to and what will be released for the next flagship operating systems.

They typically release new OS’s in September. And this year’s launch on September 14th includes the following:

  • macOS 27 Golden Gate
  • iOS 27
  • iPadOS 27
  • watchOS 27
  • tvOS 27
  • visionOS 27

This blog focuses on the features and enhancements that Jamf customers, IT admins and security leaders for commercial organizations should be most excited about.

Table of contents:

The declarative standard

Declarative Device Management (DDM) is no longer the future; it’s the standard and its accelerating.

Organizations are already deploying this to production fleets around the globe. Apple stressed that if your organization isn't using DDM yet, you're working harder than you need to.

OS 27 continues Apple's systematic migration of legacy MDM commands to DDM.

The direction is clear and the pace is accelerating, with the following having all made the move in this release:

  • Managed Migration Assistant
  • Keyboard settings
  • Caching service configuration
  • VPN profiles

Admins get native binary-level app control on macOS

Allow/deny binaries are, by Apple's own ranking, the most impactful IT announcement. With this release, admins can define exactly which applications and binaries are permitted to run on a managed device, including command-line tools. If something isn't on the list, the OS stops it from executing.

Managed apps are automatically added to the allow list, so you're not starting from scratch, and the declaration also replaces the legacy "allowed from" source restriction for apps in a single unified policy, covering:

  • App Store
  • Known developers
  • And other pathways

The ability to lock down apps and binaries is a management feature Apple admins have been asking for. App lockdown on macOS used to mean custom scripts, third-party tooling and a lot of maintenance. Now it’s a native declaration that’s defined once and enforced by the OS – no workarounds required.

App configuration and software removal get an upgrade

Two updates were announced that close gaps that Apple admins have been working around for years.

Declarative app configuration expands to macOS 27 with support for hardware-bound keys and Managed Device Attestation. In practical terms, apps can now receive their settings and credentials from the MDM in a way that's cryptographically tied to the device. As developers adopt this framework, deploying and configuring software becomes significantly simpler and more secure.

Package Uninstall finishes what the package declaration started. Previously, removing a DDM configuration left the software sitting on the device. Now, removing the config removes the software too. Deploy it declaratively, remove it declaratively — the full software lifecycle managed from one place.

Permission prompts go from many to one

OS 27 delivers a unified Privacy Management declaration that streamlines the app and web permissions process. Instead of navigating a series of individual permission prompts every time an app requests access to multiple sensors, like camera and location data, users will see a single, full-screen dialog that allows the user to click one simple button to apply all settings. Admins can configure the expected permissions in advance, so the experience is clean and deliberate rather than repetitive and disruptive.

This same mechanism extends to Safari, permitting admins to set per-site configurations for sensor access at once.

Configuration management at scale

Managing credentials across a fleet has always meant touching every configuration that references them whenever something changes. OS 27 fixes that by declaring credentials separately and referencing them in the configurations that depend on them. This means admins only need to update it once, and everything follows automatically.

Declarative configurations that work with the credential declaration’s update once and everything follows automatically design are:

  • DNS Proxy
  • DNS Settings
  • Network Relay
  • Always-on VPN
  • IKEv2
  • IPSec
  • VPN plugin
  • Web content filter plugin
  • Content caching service
  • Extensible SSO

Identity gets a declarative home

The Mac login experience gets a modern identity upgrade as Platform SSO moves to DDM in OS 27. The result is a login experience that reflects how enterprise identity actually works.

The new login UI presents a floating window overlay on the macOS login screen, enabling fully custom authentication flows through a web view. Policies can now require Touch ID, making biometric authentication a consistent, enforceable standard across the fleet.

For organizations that need more flexibility, the new web view supports passwordless and additional multi-factor options including:

  • One-time codes
  • Push notifications
  • And QR code scanning

All are available at the login window, screen unlock and FileVault.

The underlying capability tying this together is an Identity Provider (IdP) configuration. Admins configure a trusted IdP at the device level, and the entire login experience inherits it, so the device and IdP login happen at once. For employees, it means one set of credentials, one login flow and no friction between the device and the tools they need for work.

Additionally, Authenticated Guest Mode extends to FileVault-protected computers, removing a longstanding barrier for shared and loaner device workflows.

Improvements to fleet visibility

Admins get a real-time view of what's on managed devices with three features in OS 27 that address a persistent gap: know what's happening on managed devices, in real time, without waiting for a device to check in.

  1. Extended status channel: For the first time, admins get a reliable signal that a device was fully configured during enrollment before it reaches a user. No more assuming setup worked — Device Await Config confirms declarations landed, providing IT confidence when provisioning at scale.
  2. Fleet monitoring: Hardware health data for iOS and iPadOS devices has always existed — it just lived in a user's Settings app where IT couldn't see it. Now, it's surfaced at the fleet level. For example, catching a broken camera or failure to display before a user reports it, not after.
  3. Enhanced logging: Troubleshooting a device used to require user involvement. Now, admins can remotely trigger a diagnostic collection and submit it to AppleCare without user intervention.

New devices folded into the release

Apple's hardware lineup ships alongside OS 27, and each device is worth a quick read for fleet planning purposes.

iPhone 18 Pro and iPhone 18 Pro Max

The annual refresh introduces the new A20 Pro chip, camera and battery improvements. Publicly available on September 18 with iOS 27 already installed. For most fleets, this slots into your existing refresh cycle and enrollment workflows without any special handling.

iPhone Duo

Apple's first foldable iPhone ships October 23rd with iOS 27.1 pre-installed. This is a useful detail for planning and should be treated as its own checkpoint, since it ships after the testing wave for devices released in September.

Its larger, unfolded display is worth watching for frontline and field-use cases where more screen real estate for data entry or reference material has real value — but give yourself the extra month before committing it to a standard deployment profile.

Watch Series 12 and Watch Ultra 4

Both arrive on September 18th, with a new chip and an upgraded Health Sensing System, including more frequent HRV readings for stress and recovery insights. The latter also boasts the longest battery life of any Apple Watch to date.

For organizations with supervised Apple Watch deployments — think corporate wellness programs or healthcare — expect health data added alongside existing the enrollment workflows and DDM support.

AirPods 5

Arriving September 18th with improved noise cancellation, the management implications are minor, but asset tracking and Find My matter more for organizations running shared or loaner AirPods pools, particularly in retail and frontline environments.

Migrating to OS 27 with Jamf

Apple's continued push toward declarative management, real identity integration and real-time visibility is good news for proactive IT teams, resulting in:

  • Less custom tooling to maintain
  • Fewer manual touchpoints per device
  • A clearer picture of fleet health

All without waiting on users to report a problem.

Apple operating system releases are an exciting (and busy) time for IT and security admins. You must:

  • Prioritize
  • Test
  • Retest
  • Understand the new technologies
  • Update devices on time

At Jamf, supporting organizations by providing an easy upgrade path – while enabling the most impactful client features – is part of how we help organizations succeed with Apple.

Subscribe to the Jamf Blog

Have market trends, Apple updates and Jamf news delivered directly to your inbox.

To learn more about how we collect, use, disclose, transfer, and store your information, please visit our Privacy Policy.