WWDC 2026 made the direction unmistakable. Declarative management is now the standard, legacy MDM is being retired, and a run of changes lands with OS 27 when it ships this spring. Here is what to prepare, and why the fleets that get ready early will barely feel the switch.
TL;DR
- Declarative Device Management is now the standard. Legacy MDM workflows, including software updates, are being retired in OS 27. If you still run legacy profiles, the time to move is before OS 27 ships.
- New native controls arrive on the Mac: allow/deny binaries, one consolidated privacy prompt replacing PPPC, declarative app configuration, and Platform SSO at the login window.
- The beta is out now; general availability is expected around September or October, which is spring here in South Africa. Apple Intelligence also becomes governable on managed devices, and Apple Business is now in more than 200 countries. The preparation window is open, and finite.
Declarative is no longer optional
At WWDC 2026 Apple was blunt: if your organisation is not using Declarative Device Management yet, you are working harder than you need to. OS 27 (iOS 27, iPadOS 27, macOS 27 and the rest of the family) continues Apple’s steady migration of legacy MDM workflows to DDM, and this year several of them complete the move, among them managed migration, keyboard settings, content caching and VPN profiles.
The change that will bite the unprepared is software updates. Apple is retiring the legacy software-update MDM commands in favour of declarative software update management. If your update enforcement still relies on the old mechanism, it needs to be rebuilt on the declarative model before OS 27 ships, or update compliance quietly stops working the day your fleet upgrades. This is not a feature you opt into later. It is the plumbing your patch and compliance posture depends on.
Native app control finally comes to the Mac
Apple ranked allow/deny binaries as the most impactful IT announcement of the release, and it is easy to see why. Admins can now define exactly which applications and binaries, including command-line tools, are permitted to run on a managed Mac, enforced by the operating system through the Endpoint Security framework. If something is not on the list, it does not execute. Managed apps are added to the allow list automatically, and the declaration replaces the old “allowed from” source restriction in one unified policy.
App lockdown on the Mac used to mean custom scripts, third-party tooling and constant maintenance. Now it is a native declaration, defined once and enforced by the OS. Alongside it, declarative app configuration arrives on macOS 27 with hardware-bound keys and Managed Device Attestation, so apps can receive settings and credentials cryptographically tied to the device. And Package Uninstall closes a long-standing gap: removing a declarative package configuration now removes the software too, so the full lifecycle is managed from one place.
One permission prompt instead of ten
OS 27 replaces PPPC with a single Privacy Management declaration. Instead of a stream of individual prompts every time an app wants the camera, microphone, Bluetooth, local network or location, the user sees one consolidated dialog and applies the expected settings in a single action. Admins configure those permissions in advance, so first run is clean and deliberate rather than a wall of pop-ups. The same mechanism extends to Safari, letting you set per-site camera and microphone rules centrally.
Identity moves to the login window
Platform SSO moves to DDM, and the Mac login experience grows up with it. A new floating login window supports fully custom, web-based authentication, with passwordless and phishing-resistant options (one-time codes, push notifications and QR sign-in) available at the login window, at unlock and at FileVault. Touch ID can be required by policy. Underpinning it is a declarative identity provider configuration: set a trusted IdP at the device level and the whole login flow inherits it, so the device and identity sign-in happen together. Authenticated Guest Mode now works on FileVault-protected Macs, which unblocks shared and loaner-device workflows.
Credentials get the same declarative treatment. Rather than editing every configuration that references a certificate or secret, credentials are declared once and referenced by the configs that depend on them, so you update in one place and everything follows. Ten network and identity configurations move to declarative in the process, from Always-on VPN and IKEv2 to encrypted DNS, network relays, content filters and extensible SSO.
You can finally see the fleet in real time
Three visibility improvements close a gap admins have lived with for years. An extended status channel, including a Device Await Config signal, confirms that declarations actually landed during enrolment before a device reaches its user, which matters when you provision at scale. Fleet monitoring surfaces hardware health for iPhone and iPad, camera, display, Face ID and baseband, at the fleet level for the first time, so you can catch a failing component before the user reports it. And enhanced logging lets you trigger a diagnostic collection remotely and submit it to AppleCare without involving the user.
Apple Intelligence becomes governable
OS 27 gives admins granular control over Apple Intelligence on managed devices. As more apps lean on on-device models, that governance layer is what lets security and compliance teams say yes with confidence. For South African organisations weighing AI use against their POPIA duty of care, on-device processing where data does not leave the device is exactly the architecture that makes AI adoption defensible. It is the same theme running through the platform: capability arriving with the controls to govern it.
Apple Business, now global
Apple Business, the service Apple has renamed from Apple Business Manager, is now available in more than 200 countries and regions, bringing zero-touch deployment, Managed Apple Accounts and volume purchasing to markets that previously had no access. For much of Africa this is the starting line for the zero-touch workflows enterprises elsewhere have relied on for years. Apple also added new APIs to automate device management across blueprints, configurations, users, groups, apps and licences, and volume app subscriptions arrive later this year.
What to do before the launch
The beta is available now and general availability is expected around September or October, so the preparation window is open and finite. The fleets that will barely notice the switch are the ones that use it. In practice that means auditing where you still depend on legacy MDM, especially software updates, and moving those workflows to declarative now. It means piloting the OS 27 beta on a representative slice of the fleet, planning your Platform SSO and identity rollout, deciding your Apple Intelligence posture, and mapping the new binary and privacy controls to how your people actually work.
Scaling Up calls this the discipline of preparing the system before the moment demands it. A dated OS launch is a deadline you can see coming. Meet it early and it is a non-event. Meet it late and it becomes a scramble across every managed device at once.
Apple keeps raising the bar for what a managed platform can do: secure by design, identity-aware, and easier to run at scale. Getting the value out of that depends on being ready for it, and that readiness is what a specialist partner is for. Onsite has spent 15 years on Apple and nothing else, and preparing fleets for exactly these transitions is the work.
If you want to know where your environment stands before OS 27 ships, book an Apple Review and we will map your readiness, from legacy profiles to identity to Apple Intelligence, against the launch timeline.
