Plan for Change: Removal of legacy Apple MDM software updates
🚨 The Signal: Apple and Intune are removing legacy MDM software update methods for iOS/iPadOS and macOS. Organisations must transition to Declarative Device Management (DDM) to ensure Apple devices continue receiving critical security updates.
The Impact
Intune admins are affected, risking unpatched Apple devices and increased vulnerability.
- Intune admins: Must update policies to DDM to maintain device patching.
- Apple device users: May experience unpatched devices if policies aren't updated.
- Security teams: Face increased risk from unpatched vulnerabilities on Apple devices.
The Action
- Review existing iOS/iPadOS and macOS update policies in Intune.
- Identify policies using legacy MDM software update settings.
- Create new policies or modify existing ones to use Declarative Device Management (DDM).
- Deploy DDM-based update policies to all relevant Apple devices.
- Monitor device update status to confirm successful transition to DDM.
Domain: Intune · Impact: high · Workload: Intune · Essential Eight: Patch Operating Systems · ISM: ISM-1407, ISM-1501, ISM-1621, ISM-1622, ISM-1623, ISM-1654, ISM-1655, ISM-1694, ISM-1695, ISM-1696, ISM-1701, ISM-1702, ISM-1877, ISM-1889, ISM-1902