WWDC.ai

What's new in managing Apple devices

Updates for Apple device management in 2026: Apple Business APIs, declarative management, app controls, Platform SSO, and education workflows.

Watch on Apple Developer

TL;DR

  • Apple Business is expanded as an all-in-one platform with new APIs for Blueprints, configurations, users, groups, app license information, and audit events.
  • Declarative device management is positioned as the standard, with new managed Mac migration, credential assets, status items, system health reporting, enhanced log collection, and Content Caching controls.
  • macOS 27 gains declarative app configuration, package cleanup, consolidated privacy consent prompts, Safari website permission management, and binary execution controls.
  • Platform SSO adds required Touch ID as a second factor, web-based login and QR-code flows, FileVault support for Authenticated Guest Mode, while education updates add Authenticated Guest Mode for Shared iPad and guided browsing in Classroom.

Apple services for business and education

Apple Business is presented as a new all-in-one platform for organizations, available in more than 200 countries and regions. It includes zero-touch deployment, Managed Apple Accounts, and built-in device management capabilities intended to help businesses start managing Apple devices more quickly.

New Apple Business APIs support automation across Blueprints, configurations, users and groups, app license information, and audit events. These join existing APIs for servers, devices, inventory assignment to device management servers, and AppleCare warranty details.

  • Volume licensing is being extended to subscriptions in App Store apps, allowing IT administrators to purchase, manage, and assign app subscriptions through device management workflows.
  • The subscription licensing mechanism will be available later in Apple Business and Apple School Manager.
  • For subscription implementation details, the session points to "Offer subscriptions to groups and organizations."

Declarative device management is the standard

The session emphasizes that declarative device management is no longer a future direction but the standard model for Apple device management. New capabilities rely on the declarative data model, status channel, assets, and configurations to reduce polling and make state changes more efficient.

A new managed migration feature for Mac lets IT migrate user data while preserving device management enrollment and settings. A declarative configuration is deployed immediately after enrollment, and IT controls which accounts, files, and security and privacy settings are migrated. Migration Assistant reports declarative management status so administrators can monitor progress.

  • New declarative controls are available for Apple Intelligence, Siri, and keyboard settings, with more granular controls for individual Apple Intelligence and Siri features.
  • Credential-backed configurations are moving from monolithic configuration profiles toward declarative assets, allowing multiple configurations to reference a single certificate, identity, or password asset.
  • When a credential changes, the server updates the asset and the device updates all dependent configurations.
  • New declarative status items include enrollment type, awaiting device configuration, return-to-service state, Shared iPad state, current push token, Lockdown Mode state, and more.

Fleet health, support, and Content Caching

iOS and iPadOS 27 can report device system health through a declarative management status item. Reported components include hardware areas such as baseband, camera, Face ID, Touch ID, and others, giving IT teams a fleet-wide view of device health.

AppleCare support workflows are streamlined with the new TriggerEnhancedLogCollection command for organization-owned devices on iOS, iPadOS, tvOS, and macOS 27. Declarative status can be used to monitor the enhanced log collection process.

  • macOS 27 adds a declarative configuration to control the Content Caching service on Mac.
  • New declarative status items report Content Caching service state for monitoring cache server health.
  • Content cache servers can send their own reports to an arbitrary HTTPS endpoint, enabling more advanced monitoring consoles.
  • Declarative status adoption is described as a subscription model: the server subscribes to status items, and devices send changes as they occur.

App management, privacy prompts, and binary controls

Declarative app configuration, previously available on iOS, iPadOS, and visionOS, comes to macOS 27. It supports secure provisioning of managed apps with credentials and configuration, including hardware-bound keys and Managed Device Attestation for authenticating apps and extensions with enterprise services.

macOS 27 also lets administrators remove all files and directories installed by a declarative management package when the package configuration is removed, reducing leftover data after managed software is no longer needed.

  • The session recommends that enterprise app developers adopt the ManagedApp framework for managed app configuration and enterprise integration.
  • iOS, iPadOS, and macOS 27 introduce a consolidated privacy consent prompt for managed apps and Safari websites, showing the organization, app or website, administrator justification, requested components, and app-provided justifications.
  • If users choose Allow, recommended privacy defaults are applied and additional prompts are avoided; if users choose Not Now, standard prompts appear when access is requested.
  • macOS 27 adds declarative binary execution controls using the Endpoint Security framework to allow or deny binaries and terminate processes associated with denied binaries.
  • Binary matching rules use code-signing properties, and administrators can automatically allow managed apps without writing rules for each one.
  • App privacy controls and binary blocking live in a new declarative app.settings configuration; Safari website permissions are part of the existing safari.settings configuration.

Identity integrations and Platform SSO

macOS 27 enhances Platform SSO with a new login and unlock experience that clearly presents organization credentials. Administrators can require Touch ID in addition to a password on organization devices, making Touch ID a built-in second factor enforced at login, screen unlock, and FileVault unlock.

A new web-based authentication option for Platform SSO allows identity providers to render modern authentication flows in a secure system-managed web view at the login window and screen unlock. Supported flows include one-time codes, conditional access prompts, QR-code sign-in, custom challenge-response flows, and offline authentication.

  • The web view runs in a tightly controlled operating-system context.
  • For QR-code sign-in, the camera runs in a secure system process isolated from the web view; the page receives decoded QR data, not image frames or a raw camera feed.
  • Web authentication works across login window, screen unlock, and FileVault unlock.
  • Authenticated Guest Mode on macOS 27 can unlock FileVault-protected Macs, allowing temporary shared sessions while preserving full-disk encryption.
  • The session names Authentik, ClassLink, and Identity Automation as identity developers working on web login and QR-code support for Platform SSO.

Education updates

Authenticated Guest Mode is coming to Shared iPad later in the release. When enabled, iPad starts in a temporary session and presents a login screen where users sign in with a Managed Apple Account using native or federated authentication with Single Sign-On support.

When the user signs out from the lock screen, local data and the Managed Apple Account are automatically removed. The temporary session shares device capacity with the system without hard quotas, making storage use more flexible.

  • Classroom gains guided browsing for keeping students focused on specific websites or tabs.
  • Teachers can lock students to one or more websites, or to a single tab for an immediate focal point.
  • Teachers can configure websites directly or use prepared bookmarks.
  • Teachers can limit navigation inside or outside websites and grant access to camera and microphone, while students retain agency over whether those remain enabled.
  • Guided browsing can be applied to one student or many students, opening the guided browser with the selected websites on student devices.
Unofficial, not associated with Apple. BySuperwall

On this page

Ask AI