<?xml version="1.0" encoding="utf-8"?><rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Ivanti Blog: Posts by </title><description /><language>en</language><atom:link rel="self" href="https://www.ivanti.com/en-gb/blog/authors/yosune-baltra/rss" /><link>https://www.ivanti.com/en-gb/blog/authors/yosune-baltra</link><item><guid isPermaLink="false">9b561ccf-8bc0-4ff4-bad1-b4bfde4ee9d1</guid><link>https://www.ivanti.com/en-gb/blog/apple-business-manager-device-migration-what-you-need-to-know</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/en-gb/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint &amp; Workspace Management</category><title>Apple Business Manager Device Migration: What You Need to Know</title><description>&lt;p&gt;With Apple’s OS 26 release, IT admins using Apple Business Manager (ABM) or Apple School Manager (ASM) have a great new tool in their toolbelt: device migration. This makes switching devices between MDM platforms much easier, with minimal disruption for end users.&lt;/p&gt;

&lt;p&gt;Here, we’ll unpack what you need to know, and how &lt;a href="https://www.ivanti.com/en-gb/blog/apple-wwdc25-announcements"&gt;ABM device migration&lt;/a&gt; makes it incredibly easy to switch to &lt;a href="https://www.ivanti.com/en-gb/products/ivanti-neurons-for-mdm"&gt;Ivanti Neurons for MDM&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;Key ABM device migration features&lt;/h2&gt;

&lt;p&gt;Apple’s new ABM device migration features make it easier to move devices between different &lt;a href="https://www.ivanti.com/en-gb/use-cases/ensure-mobile-device-management"&gt;MDM solutions&lt;/a&gt;, without manual steps or interrupting users.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;No manual re-enrollment.&lt;/strong&gt; You can transfer devices from one MDM server to another, or from one vendor’s MDM to another (including Ivanti Neurons for MDM), without erasing or manually re-enrolling devices. All existing user data and device configurations will automatically be applied during migration. The end user will be able to complete the re-enrollment with two guided clicks: one for restarting the device and one for re-enrollment into the new MDM.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enrollment deadlines.&lt;/strong&gt; This is the newest feature introduced by Apple in ABM and ASM. You can set and enforce deadlines for moving devices to the new MDM instance. If a device isn’t enrolled in time, it will be locked and the user will be asked to finish enrollment. With this deadline you will be able to trigger the automated process for re-enrollment in the new MDM. It will prompt the end user with screens to complete the re-enrollment seamlessly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;End user experience.&lt;/strong&gt; The end user experience won't notice any changes during migration, except if the enrollment deadline has passed. Once the migration is complete, the user will get a prompt to restart the device. After the device restarts, the end user will get a prompt to re-enrol the device in the new management solution, which takes one click.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;API-driven.&lt;/strong&gt; The process can also be managed through the ABM or ASM portal using Apple’s new APIs (which you need to activate). This means that customers that use an API infrastructure can &lt;a href="https://developer.apple.com/documentation/applebusinessmanagerapi/create-an-orgdeviceactivity" rel="noopener" target="_blank"&gt;bulk assign or unassign devices&lt;/a&gt; with the new Apple ABM APIs without having to access the ABM console.&lt;/p&gt;

&lt;h2&gt;ABM device migration use cases&lt;/h2&gt;

&lt;p&gt;When would you use this feature? Here are a few key use cases.&lt;/p&gt;

&lt;h3&gt;Cloud migration&lt;/h3&gt;

&lt;p&gt;ABM device migration allows you to move from on-premises MDM to cloud-based MDM without re-enrolling devices. For Ivanti customers, this feature makes it easy to move to Ivanti Neurons for MDM from Ivanti Endpoint Manager (for MacOS) or Ivanti Endpoint Manager Mobile (for all Apple devices).&lt;/p&gt;

&lt;h3&gt;Switching MDM providers&lt;/h3&gt;

&lt;p&gt;ABM device migration simplifies switching from another MDM provider to Ivanti Neurons for MDM, or consolidating all type of devices (Android, Windows, Apple,) on a single platform from MDMs that only manage Apple devices, such as Jamf or Kandji.&lt;/p&gt;

&lt;h3&gt;School district device realignment&lt;/h3&gt;

&lt;p&gt;Educational institutions can realign devices between departments or campuses while maintaining all Apple management and assignment settings.&lt;/p&gt;

&lt;h3&gt;Mergers, acquisitions or reorganisations&lt;/h3&gt;

&lt;p&gt;If you’re combining or separating IT infrastructure due to M&amp;amp;A or reorganisation, you can move devices to new MDM environments with minimal user disruption.&lt;/p&gt;

&lt;h2&gt;Setting up ABM device migration: a step-by-step guide&lt;/h2&gt;

&lt;h3&gt;Before you begin&lt;/h3&gt;

&lt;p&gt;There are two important considerations before you begin:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Device migration &lt;em&gt;only&lt;/em&gt; works on devices running iOS 26, iPadOS 26 or macOS26 (or later). Make sure your devices are updated first.&lt;/li&gt;
	&lt;li&gt;You don’t need to make any changes on the MDM server side to support device migration, but target MDM servers should be prepared to receive new device assignments and enrollment requests.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Device Migration via the ABM console&lt;/h3&gt;

&lt;p&gt;Sign in to Apple Business Manager and navigate to &lt;strong&gt;Devices&lt;/strong&gt;. From here, use the search bar to find the target devices by serial number, order number or other identifiers. Then, select the devices you wish to set a migration deadline for.&lt;/p&gt;

&lt;p&gt;Next, review the device details: Click on the device to open its detailed view and confirm that it is assigned to the correct MDM server. You can now set the migration deadline.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture1.png"&gt;&lt;/p&gt;

&lt;p&gt;From here, click on &lt;strong&gt;Assign Device Management&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture2.png"&gt;&lt;/p&gt;

&lt;p&gt;In the pop-up, you can choose the new MDM organisation that the device needs to be assigned to.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture3.png"&gt;&lt;/p&gt;

&lt;p&gt;Next, choose the deadline.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture4.png"&gt;&lt;/p&gt;

&lt;p&gt;Select the desired date and time for the deadline. This is the final date users have to migrate their device to the assigned MDM server. If users don’t follow the prompts they’ll be locked out the device. Then, click &lt;strong&gt;Continue&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture5.png"&gt;&lt;/p&gt;

&lt;p&gt;On the device the user will receive a notification to restart their device.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture6.png"&gt;&lt;/p&gt;

&lt;p&gt;After restarting, the device will request the user to enrol in the new management service.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Device Migration via the ABM console screenshot" src="https://static.ivanti.com/sites/marketing/media/images/blog/2025/9/picture7.png"&gt;&lt;/p&gt;

&lt;h3&gt;Device migration via APIs&lt;/h3&gt;

&lt;p&gt;Setting up ABM device migration via APIs is simple, and it’s done completely in ABM (or ASM), no matter which MDM you are switching to or from.&lt;/p&gt;

&lt;p&gt;First, log in to your Apple Business Manager or Apple School Manager account and navigate to &lt;strong&gt;Settings &amp;gt; Device Manager Settings&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Then, review and enable the required APIs to allow device migration. (If you’re not sure how, check the Apple admin guide for step-by-step help.)&lt;/p&gt;

&lt;p&gt;Once the APIs are enabled, you can simply follow Apple’s migration workflow to select devices and designate the new target MDM server. Optionally, you can set an enrollment deadline for migrated devices.&lt;/p&gt;

&lt;h2&gt;Additional ABM device migration resources&lt;/h2&gt;

&lt;p&gt;If you need more detailed information, you can refer to:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;a href="https://support.apple.com/guide/deployment/welcome/web" rel="noopener" target="_blank"&gt;Apple Platform Deployment Guide&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="https://support.apple.com/guide/apple-business-manager/welcome/web" rel="noopener" target="_blank"&gt;Apple Business Manager User Guide&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="https://support.apple.com/guide/apple-school-manager/welcome/web" rel="noopener" target="_blank"&gt;Apple School Manager User Guide&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href="https://success.ivanti.com/" target="_blank"&gt;Ivanti Success Portal&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Fri, 12 Sep 2025 17:27:33 Z</pubDate></item><item><guid isPermaLink="false">8413c8b6-79d5-496d-9e33-50c544b04f49</guid><link>https://www.ivanti.com/en-gb/blog/apple-wwdc25-announcements</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/en-gb/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint &amp; Workspace Management</category><title>Apple WWDC25 Announcement of Enterprise IT Enhancements</title><description>&lt;p&gt;At WWDC25, Apple announced a set of updates to simplify IT management for enterprises. These updates, spread across macOS 26, iOS 26, iPadOS 26, tvOS 26 and visionOS 26, introduce practical tools to improve device, application and user management.&lt;/p&gt;

&lt;p&gt;This article outlines the specific capabilities and how they can be applied effectively in enterprise environments.&lt;/p&gt;

&lt;h2&gt;Enhanced Apple Business Manager for flexible device management&lt;/h2&gt;

&lt;p&gt;Apple Business Manager (ABM) improvements in iOS 26, iPadOS 26 and macOS 26 bring enhanced flexibility to enterprise IT operations. Being able to migrate devices between &lt;a href="https://www.ivanti.com/en-gb/autonomous-endpoint-management/mobile-device-management"&gt;Mobile Device Management (MDM)&lt;/a&gt; solutions means that businesses can react to evolving technological requirements or vendor changes without needing to reconfigure devices manually. For example, an organisation switching to one of Ivanti’s on-premises solutions to Ivanti Neurons for MDM can retain operational continuity by utilising the new ABM Device Migration APIs while aligning configurations with the latest policies.&lt;/p&gt;

&lt;p&gt;Administrators can now enforce enrollment deadlines for Managed Apple Accounts, helping enterprises integrate new devices into their IT systems on schedule. This feature is particularly helpful for compliance with internal policies or regulatory requirements, ensuring devices are accounted for during deployments.&lt;/p&gt;

&lt;p&gt;Enhanced onboarding processes with Account Driven Enrollments, supported by the Service Discovery API, simplify enrollment by enabling preconfigured settings to guide users through setup. This reduces time spent onboarding large numbers of employees or devices.&lt;/p&gt;

&lt;p&gt;Organisations can also bolster account security with stricter access controls. By allowing only Managed Apple Accounts during device setup and login, enterprises can prevent personal accounts from compromising company data or workflows. Additionally, including warranty and AppleCare coverage details lets enterprises plan for the entire lifecycle of their devices, optimising replacement or support strategies to maintain productivity while minimising downtime.&lt;/p&gt;

&lt;h2&gt;Modernised app management with Declarative Device Management&lt;/h2&gt;

&lt;p&gt;Declarative Device Management (DDM) updates provide better tools for managing app lifecycles in enterprise environments. Administrators get granular control over app installations and updates, so you can enforce mandatory upgrades for security-critical applications or postpone non-essential updates to avoid disruptions during critical operations. Similarly, the ability to pin apps to specific versions can stabilise environments where software dependencies are tightly coupled.&lt;/p&gt;

&lt;p&gt;Real-time reporting of app installation and update statuses offers IT teams actionable insights into compliance and troubleshooting. For instance, administrators managing thousands of devices can track which apps are outdated or whether installation errors occurred, resolving issues without delays. Furthermore, organisations managing extensive mobile fleets can restrict app downloads over cellular data to conserve bandwidth and ensure adherence to security policies, useful in industries with strict data regulations or cost-control measures.&lt;/p&gt;

&lt;p&gt;Updates to macOS 26 let enterprises scale their device operations more effectively. Declarative Application Management lets administrators deploy apps — whether they are from the App Store or custom-built solutions — across thousands of devices simultaneously, streamlining rollouts during enterprise deployments or product launches. The ability to deploy .pkg files caters to organisations relying on proprietary software or specific configurations.&lt;/p&gt;

&lt;p&gt;VisionOS 26 also supports deploying managed applications via DDM.&lt;/p&gt;

&lt;h2&gt;Improved Safari configuration for efficiency and compliance&lt;/h2&gt;

&lt;p&gt;Safari updates bring practical configuration tools that enterprises can use to align browser settings with organisational needs. Administrators can now preconfigure bookmarks to direct employees to relevant software tools, company websites or knowledge bases upon login, reducing onboarding times and improving workforce efficiency. You can set landing pages to match company branding and guarantee employees start their browsing sessions on compliant and secure portals, which is especially useful for maintaining organisational policies.&lt;/p&gt;

&lt;h2&gt;Better audio accessory management for shared device scenarios&lt;/h2&gt;

&lt;p&gt;For shared device deployments, such as in healthcare, education or retail, Apple’s enhanced audio pairing management introduces useful controls to maintain security while enabling flexibility. Administrators can allow temporary audio accessory pairing without data syncing to iCloud, ensuring that employee or customer data is not inadvertently retained on shared devices. For added security, pairing data can be erased automatically based on predefined schedules, such as each night.&lt;/p&gt;

&lt;p&gt;These controls are critical for shared environments where sensitive data protection and operational continuity are key. For example, hospitals using shared iPads for patient intake can ensure that data is cleared between users while still enabling seamless accessory use for each individual session.&lt;/p&gt;

&lt;h2&gt;Platform Single Sign-On for simplified authentication&lt;/h2&gt;

&lt;p&gt;The new Platform Single Sign-On (SSO) tools in macOS 26 reduce friction during the authentication process for enterprise employees. Platform SSO can now be activated during automated device enrollment, meaning employees can immediately access managed apps, company services and their Managed Apple Accounts without additional sign-ins. This feature simplifies the device setup process for organisations onboarding large numbers of employees or contractors.&lt;/p&gt;

&lt;p&gt;The addition of Authenticated Guest Mode benefits shared environments, such as schools or hospitals, by allowing temporary logins via organisational Identity Provider (IdP) credentials. This ensures that users can access only the resources they are authorised for, while personal data is automatically erased upon logout. This is especially beneficial in environments with transient users where data security and quick turnover are priorities.&lt;/p&gt;

&lt;h2&gt;Return to Service: streamlined device reuse&lt;/h2&gt;

&lt;p&gt;Apple’s improvements to the Return to Service workflow allow enterprises to retain managed apps during device preparation for reuse. This feature significantly reduces the time needed to prepare devices for new users in shared-use scenarios. For instance, retail organisations can erase user data while retaining critical operational apps, allowing devices to be redeployed within minutes rather than hours. Automated re-enrollment into MDM ensures that settings, restrictions and compliance policies are applied quickly and consistently.&lt;/p&gt;

&lt;p&gt;If you have a healthcare use case, check out Return to Service features supported by &lt;a href="https://www.ivanti.com/en-gb/products/ivanti-neurons-for-mdm"&gt;Ivanti Neurons for MDM&lt;/a&gt;. By adding a Return to Service option on your Ivanti iOS client, your floor staff can safely repurpose devices with one click.&lt;/p&gt;

&lt;h2&gt;ManagedApp Framework for secure enterprise app configurations&lt;/h2&gt;

&lt;p&gt;The ManagedApp Framework, built on Declarative Device Management, introduces a structured approach to defining and passing configuration details to enterprise apps. This framework allows IT administrators to establish app behaviour — such as server URLs, credential parameters or connection policies — tailored to specific employees or teams.&lt;/p&gt;

&lt;p&gt;For example, an IT department can provide custom app settings for field technicians that include preconfigured server endpoints and unique digital certificates, while offering a more limited set of configurations for interns or temporary staff. The framework integrates seamlessly with features like Single Sign-On and Managed Device Attestation for secure, scalable and compliance-ready app deployments across industries. This feature requires support both from the application and from the MDM side.&lt;/p&gt;

&lt;h2&gt;Software updates changes in iOS/iPadOS/macOS 26&lt;/h2&gt;

&lt;p&gt;Apple is deprecating legacy software update management methods in iOS, iPadOS and macOS 26, and removing support in 2027 OS versions, requiring all organisations to transition to the new Declarative Management Software Update Enforcement and Software Update settings. Ivanti fully supports these new workflows, enabling automated and proactive update management. Declarative Management Updates are supported on iOS/iPadOS 17+ and macOS 14+. To prepare, customers should update their device management policies in Ivanti, configure Software Update Enforcement and settings for their devices and ensure compliance with Apple’s updated requirements—securing a smooth transition ahead of the deadline.&lt;/p&gt;

&lt;h2&gt;Key takeaways for enterprise IT&lt;/h2&gt;

&lt;p&gt;Apple’s WWDC announcements introduce meaningful improvements for enterprise IT, from streamlined device reuse to more flexible management and security controls. Using Ivanti’s endpoint management solutions alongside these new Apple features will help organisations automate deployments, ensure compliance and support diverse user needs with greater efficiency.&lt;/p&gt;
</description><pubDate>Fri, 18 Jul 2025 14:15:25 Z</pubDate></item><item><guid isPermaLink="false">ee7f5873-44ba-439b-9a99-97872feaae5a</guid><link>https://www.ivanti.com/en-gb/blog/apple-declarative-device-management-updates</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/en-gb/blog/authors/yosune-baltra</atom:uri></atom:author><category>Endpoint &amp; Workspace Management</category><title>Optimising Apple DDM with Ivanti’s Latest Innovations</title><description>&lt;p&gt;The explosion in devices—particularly Apple devices—deployed across a modern enterprise is increasing the already arduous device management burden on IT and cybersecurity teams.&lt;/p&gt;

&lt;p&gt;According to recent &lt;a href="https://www.computerworld.com/article/1634358/three-quarters-of-large-us-firms-now-using-more-apple-devices-survey.html?utm_source=chatgpt.com" rel="noopener" target="_blank"&gt;research&lt;/a&gt;, 76% of large enterprises are using more Apple devices, and 57% of US firms say Apple adoption is outpacing other options. So, it’s become crucial for more enterprises to leverage Apple Declarative Device Management (DDM) to streamline device management, automate compliance and enhance scalability.&lt;/p&gt;

&lt;p&gt;Apple's approach to DDM was introduced in 2021 and expanded with each OS release. It’s created a fundamental shift in device management, streamlining software updates and patching. Now, IT teams can define desired states so Apple devices can self-enforce configurations and updates &lt;em&gt;locally&lt;/em&gt;, reducing reliance on servers and manual intervention.&lt;/p&gt;

&lt;p&gt;Thus, updates can happen faster, errors can be minimised, and end-user experiences can be improved invisibly and proactively. Which appreciably eases IT workloads while sustaining security and operational agility.&lt;/p&gt;

&lt;p&gt;Apple is deprecating legacy software update management in iOS, iPadOS and macOS26, and they will remove support in 2027 OS versions, which means now is the time to make the switch to DDM. Let's explore how Ivanti's MDM and UEM products will enable admins to get the most out of Apple DDM.&lt;/p&gt;

&lt;h2&gt;What is declarative device management (DDM)?&lt;/h2&gt;

&lt;p&gt;DDM is an advanced approach to managing devices, primarily in enterprise or organisational IT environments. It empowers administrators to define a device or system's desired state and allows the system to automatically enforce and maintain that state.&lt;/p&gt;

&lt;p&gt;The DDM model shifts away from traditional imperative management, where configurations and actions are centrally scripted and managed by IT administrators. That approach requires direct instructions to achieve the desired outcome on each device.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key features and benefits of DDM&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;What are DDM’s advantages over a traditional device management model?&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Administrators can specify the desired state or behaviour of a device, focusing on "what" it should look like instead of "how" to achieve that state. For example, rather than scripting individual commands for configuring security settings, an admin can simply declare the required settings and the system will enforce them.&lt;/li&gt;
	&lt;li&gt;Devices autonomously monitor their configurations to ensure compliance with a predefined state. If a device deviates, it automatically corrects itself to restore compliance without manual intervention.&amp;nbsp;&lt;/li&gt;
	&lt;li&gt;DDM proves highly effective in large-scale settings since it minimises the need for repetitive and manual configuration tasks.&lt;/li&gt;
	&lt;li&gt;DDM minimises the complexity of management workflows and ensures consistency across devices.&lt;/li&gt;
	&lt;li&gt;DDMs employ modern management protocols for faster and more reliable updates to device configurations and policies.&lt;/li&gt;
	&lt;li&gt;DDM is commonly implemented in cloud-based mobile device management (MDM) solutions, leveraging the cloud for synchronisation, monitoring and enforcement, although it can also be implemented in on-prem solutions.&lt;/li&gt;
	&lt;li&gt;DDM reduces manual effort by automating configuration and enforcement processes.&lt;/li&gt;
	&lt;li&gt;Ensures consistency and compliance across devices, reducing the risk of human error.&lt;/li&gt;
	&lt;li&gt;Dynamic updates means quicker application of policies and settings versus traditional methods.&lt;/li&gt;
	&lt;li&gt;Changes are implemented seamlessly without disrupting the user experience.&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;
&lt;blockquote&gt;
&lt;h2&gt;An example DDM use case&lt;/h2&gt;

&lt;p&gt;In a hypothetical example, an IT administrator declares that all employee devices within the enterprise environment must:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Have a specific version of the operating system.&lt;/li&gt;
	&lt;li&gt;Enable encryption.&lt;/li&gt;
	&lt;li&gt;Restrict access to certain applications.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Using DDM, these requirements are automatically applied, continuously enforced and remediated if there’s any deviation.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;
&lt;h2&gt;Software updates and OS patching via Apple DDM&lt;/h2&gt;

&lt;p&gt;Utilising Apple Declarative Device Management for software updates and operating system (OS) patching seriously improves these processes, making them more proactive, efficient and seamless. It simplifies administration, cuts down on delays and guarantees a fleet of devices is always secure and up-to-date.&lt;/p&gt;

&lt;h4&gt;Software update benefits&lt;/h4&gt;

&lt;p&gt;&lt;em&gt;Centralised control with distributed execution&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Administrators set configurations centrally but rely on the device's local capabilities for execution.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Proactive local enforcement&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Updates are enforced at the device level, eliminating the need for constant server intervention. Admins set a desired OS version and deadline, and the device autonomously ensures compliance.&lt;/li&gt;
	&lt;li&gt;The device monitors itself, applying updates without the need for constant server communication.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Automation&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Admins can configure specific versions and deadlines and update schedules (e.g., after work hours), automating the process while minimising end-user disruption.&lt;/li&gt;
	&lt;li&gt;For example, a critical security patch can be scheduled for a particular time, ensuring all devices are updated without user intervention.&lt;/li&gt;
	&lt;li&gt;If a device is powered off and misses the update deadline declarative management reschedules the update automatically for a later time.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;User notification and experience&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Notifications begin 14 days before the deadline, reminding users to update at their convenience. On the deadline, the device automatically reboots and instals updates if necessary.&lt;/li&gt;
	&lt;li&gt;Admins can customise these notifications or suppress early reminders (e.g., for retail or healthcare environments).&lt;/li&gt;
	&lt;li&gt;Admins can configure the level of user interaction allowed by Apple DDM, such as permitting manual updates before the enforced deadline or limiting user deferrals.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Faster updates with reduced network dependency&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Unlike traditional MDM, where the server continuously checks device status, DDM reduces latency by shifting the compliance mechanism to the endpoint.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Enhanced status reporting&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Devices proactively report the status of updates to the server including whether an update is in progress, completed successfully or failed. In case of failure, detailed error logs are available.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;OS patching benefits&lt;/h4&gt;

&lt;p&gt;&lt;em&gt;Predicates for context-aware updates&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;DDM allows conditional rules (predicates) for updates, such as only applying a patch when a device is charging or has a battery above 80%.&lt;/li&gt;
	&lt;li&gt;These conditions are evaluated locally on the device, making updates context-sensitive and efficient.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Seamless transition to new OS versions&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;DDM automatically manages the transition to new OS releases or security patches without requiring manual admin oversight at each step.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Local action without internet&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Devices can enforce configurations and patches even when offline, applying updates based on preloaded criteria and activating changes when conditions permit (e.g., when connected to power or during off-hours).&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;
&lt;blockquote&gt;
&lt;h2&gt;Another practical use case&lt;/h2&gt;

&lt;p&gt;In an organisation with 1,000+ iPhones and MacBooks, a zero-day vulnerability requires immediate patching. The solution?&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;The admin declares a patch deadline and target version using Apple DDM.&lt;/li&gt;
	&lt;li&gt;Devices enforce the update based on local predicates, ensuring the patch is applied under optimal conditions (e.g., during low battery drain times).&lt;/li&gt;
	&lt;li&gt;Users receive notifications prior to the update so they’re informed without interrupting workflows.&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;h2&gt;Ivanti’s declarative management support&lt;/h2&gt;

&lt;p&gt;Ivanti’s declarative management support builds on Apple’s Declarative Device Management (DDM) framework to offer a seamless, proactive and efficient approach to managing Apple devices. What are some of its key components?&lt;/p&gt;

&lt;h4&gt;Integration with Apple’s DDM framework&lt;/h4&gt;

&lt;p&gt;Ivanti utilises Apple’s DDM as an enhancement to the existing Mobile Device Management (MDM) protocol – &lt;em&gt;not&lt;/em&gt; a complete replacement but an additional layer designed to:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Automate device responses: Allow devices to enforce configurations and policies locally, reducing reliance on the server for continuous checks.&lt;/li&gt;
	&lt;li&gt;Enable real-time proactivity: Devices can autonomously apply updates or configurations when predefined conditions (predicates) are met.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;Software update enforcement&lt;/h4&gt;

&lt;p&gt;Ivanti's platform supports Apple’s declarative software update management, which introduces:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Enforcement settings: Administrators can specify OS versions, deadlines and update schedules.&lt;/li&gt;
	&lt;li&gt;Proactive local actions: Devices monitor themselves and apply updates without requiring manual input or waiting for server-side triggers.&lt;/li&gt;
	&lt;li&gt;Improved communication: Devices report their update progress, success or failure directly to the Ivanti management server, providing admins with real-time visibility.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;Predicate management&lt;/h4&gt;

&lt;p&gt;A standout feature of Ivanti’s support is its handling of predicates – logical conditions that devices evaluate before applying configurations or updates. For example:&amp;nbsp;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;A policy applies only if the device’s battery is above 80%.&lt;/li&gt;
	&lt;li&gt;A configuration activates when the device is charging.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Simplified predicate management in Ivanti’s console&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Ivanti provides a dedicated interface for creating, managing and reusing predicates across configurations.&lt;/li&gt;
	&lt;li&gt;These predicates can be easily applied to declarative configurations, streamlining complex workflows.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;User experience and notifications&lt;/h4&gt;

&lt;p&gt;Ivanti enhances the user experience by leveraging Apple’s notification capabilities:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Notifications can start 14 days before the update deadline, with options to tailor their frequency and content.&lt;/li&gt;
	&lt;li&gt;Critical updates can override user deferrals by enforcing reboots and updates at the scheduled deadline.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Past-due handling&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;If a device misses the deadline (e.g., turned off), Ivanti reschedules updates automatically ensuring compliance.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Supported configurations&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Ivanti ensures backward compatibility and a smooth transition to declarative management by supporting both legacy MDM and newer DDM configurations.&lt;/li&gt;
	&lt;li&gt;Existing policies and workflows continue without disruption.&lt;/li&gt;
	&lt;li&gt;Declarative configurations (e.g., predicates and local enforcement) are gradually integrated and highlighted within the platform.&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Related: Watch the webinar &lt;a href="https://www.ivanti.com/en-gb/webinars/2024/mastering-apple-device-management-with-ivanti"&gt;Mastering Apple Device Management with Ivanti&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;Ivanti’s guidance for updating and patching Apple devices with declarative device management&lt;/h2&gt;

&lt;p&gt;Ivanti’s approach to supporting Apple DDM leverages the proactive capabilities of Apple's declarative management framework, combining it with a user-friendly interface, automation and support for complex enterprise workflows. This comprehensive guidance enhances enterprise device management efficiency and security.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enforcing updates and patches&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Automated scheduling lets admins enforce updates by specifying the target OS version along with a specific date and time for the update to occur. This eliminates the need for manual updates and ensures compliance with organisational policies.&lt;/li&gt;
	&lt;li&gt;Devices enforce update enforcement locally, applying updates based on preconfigured conditions without relying on continuous server communication.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Managing user notifications&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Notifications are sent to end users starting 14 days before the update deadline, providing transparency and encouraging users to update at their convenience.&lt;/li&gt;
	&lt;li&gt;For specific use cases such as retail or healthcare, flexible notification configurations let admins suppress early notifications and opt for last-minute alerts to minimise disruption.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Improving compliance and visibility&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Devices proactively report their update status to the Ivanti server, reporting whether updates are in progress, completed successfully or failed. Administrators also gain access to detailed error logs to troubleshoot issues.&lt;/li&gt;
	&lt;li&gt;If a device misses the deadline (e.g., if it is powered off), the device automatically reschedules the update for the next available hour.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Using predicates for conditional updates&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Administrators can define predicate logic for when updates should be applied.&lt;/li&gt;
	&lt;li&gt;Since conditions are evaluated locally, updates can happen even when the device is offline.&lt;/li&gt;
	&lt;li&gt;Ivanti provides tools for creating, managing and reusing predicates across configurations, making conditional updates simpler and easier to implement.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Enhancing user experience&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;End users get clear communication about the update schedule, including the enforced deadline. They have the option to instal updates manually before the deadline to avoid automatic enforcement.&lt;/li&gt;
	&lt;li&gt;Updates can be scheduled during off-hours to minimise disruption of the user's daily activities.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Streamlining patch management&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Ivanti supports declarative patch management -Apple system updates.&lt;/li&gt;
	&lt;li&gt;Administrators can enforce updates, including critical security patches, ensuring devices remain secure and compliant.&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Related: Read our Knowledge Base article on &lt;a href="https://forums.ivanti.com/s/article/How-to-enforce-Apple-Software-Updates-with-Neurons-for-MDM-and-EPMM?language=en_US" target="_blank"&gt;How to enforce Apple Software Updates with Neurons for MDM and EPMM&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;A standout approach to supporting Apple DDM&lt;/h2&gt;

&lt;p&gt;Ivanti's approach to Apple Declarative Device Management stands out because it extends an organisation’s automation, local enforcement and proactive capabilities.&lt;/p&gt;

&lt;p&gt;Administrators benefit from user-friendly tools, customizable notifications and detailed status reporting, while end-user disruption is minimised through scheduled updates and seamless workflows. With Ivanti, Apple DDM becomes even more efficient, secure and scalable for the organisations that rely on it.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Related: &lt;a href="https://www.ivanti.com/blog/a-guide-to-apple-declarative-device-management-for-enterprises" target="_blank" rel="noopener"&gt;A Guide to Apple Declarative Device Management for Enterprises&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;/p&gt;
</description><pubDate>Tue, 21 Jan 2025 20:10:27 Z</pubDate></item><item><guid isPermaLink="false">b690c33d-e1b2-421d-bba6-c48cbe62e86b</guid><link>https://www.ivanti.com/en-gb/blog/making-sense-of-wwdc23-what-it-admins-need-to-know-to-manage-apple-devices</link><atom:author><atom:name>Yosune Baltra</atom:name><atom:uri>https://www.ivanti.com/en-gb/blog/authors/yosune-baltra</atom:uri></atom:author><title>WWDC23: What IT Admins Need to Know to Manage Apple Devices</title><description>&lt;p&gt;Apple’s annual developer conference, &lt;a href="https://developer.apple.com/wwdc23/" rel="noopener" target="_blank"&gt;WWDC&lt;/a&gt;, is a firehose of information for anyone who manages Apple devices.&lt;/p&gt;

&lt;p&gt;New operating systems (notably iOS 17, iPadOS 17,&amp;nbsp;macOS 14 and watchOS 10) and new products (15-inch MacBook Air and Apple&amp;nbsp;Vision Pro) might have dominated the headlines, but WWDC23 also brought a host of&amp;nbsp;no less consequential new capabilities for enterprise device management.&lt;/p&gt;

&lt;p&gt;So what should IT admins pay attention to in the lead up to this fall’s OS updates?&lt;/p&gt;

&lt;h2&gt;A big step forward in declarative device management&lt;/h2&gt;

&lt;p&gt;Apple introduced &lt;strong&gt;declarative management&lt;/strong&gt; in 2021 as an extended functionality to the MDM protocol, and this year they continued the trend of releasing configurations that can coexist on MDM and declarative management at the same time as part of a gradual transition. Apple has announced a &lt;a href="https://developer.apple.com/videos/play/wwdc2023/10041/" rel="noopener" target="_blank"&gt;transition path&lt;/a&gt; from today’s MDM protocol to declarative management, which will make the changeover seamless for end users.&lt;/p&gt;

&lt;p&gt;What’s new this year is that Apple is also releasing features that can &lt;em&gt;only&lt;/em&gt; be supported via declarative management – &lt;strong&gt;passkeys&lt;/strong&gt;&amp;nbsp;and &lt;strong&gt;Apple Watch management&lt;/strong&gt;. Ivanti’s UEM products will support declarative device management, and therefore these new features, in the next few quarters.&lt;/p&gt;

&lt;h2&gt;Simpler device enrollment – for IT &lt;em&gt;and&lt;/em&gt; for end users&lt;/h2&gt;

&lt;p&gt;Getting rid of manual processes is a clear theme for the device enrollment enhancements released this year.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Return to service&lt;/strong&gt;, a new capability for bringing devices back into management, lets IT admins send a command to erase and then re-enroll a device automatically – a process that until now was manual. This feature is particularly useful for devices without dedicated users that need to be remotely reconfigured without manual intervention, for example an iPad that needs to be reset after a patient is discharged from a hospital.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Account-driven device enrollment&lt;/strong&gt; (an enhancement to account-driven user enrollment, which is already available) enrolls devices automatically when users sign in with their work or school account, rather than requiring the user to install a profile manually. Eliminating this extra step can streamline device onboarding.&lt;/p&gt;

&lt;p&gt;On the topic of device enrollment, &lt;strong&gt;Setup Assistant&lt;/strong&gt; also saw enhancements worth paying attention to: the ability to restrict enrollment to devices that meet &lt;strong&gt;minimum OS requirements&lt;/strong&gt;, and the ability to &lt;strong&gt;configure FileVault&lt;/strong&gt; during setup. These features let companies ship devices directly from the supplier to the end user without needing a manual setup to ensure basic security features are in compliance.&lt;/p&gt;

&lt;h2&gt;Easy end user authentication for a better end user experience&lt;/h2&gt;

&lt;p&gt;Updates to &lt;strong&gt;Managed Apple IDs&lt;/strong&gt; give organizations access to a range of improved authentication features that make it easier for end users to access their devices and services. Managed Apple IDs now include support for iCloud Keychain, Apple Wallet, and access management controls that enable organizations to restrict access to specific services and dictate the management state of a device when a user signs in. Additionally, passkeys can now be synced across managed devices for an even more secure authentication experience.&lt;/p&gt;

&lt;p&gt;Platform single sign-on (SSO) now lets you &lt;strong&gt;create local user accounts on a shared Mac&lt;/strong&gt; using credentials from the Identity Provider (IdP).&lt;/p&gt;

&lt;p&gt;Finally, &lt;strong&gt;Managed Device Attestation&lt;/strong&gt; is now available on macOS and offers strong assurances about the security posture and properties of a device.&lt;/p&gt;

&lt;h2&gt;Useful updates to device and application connectivity&lt;/h2&gt;

&lt;p&gt;For an alternative to VPN, you can now use a new &lt;strong&gt;built-in relay&lt;/strong&gt; to secure traffic using an HTTP/3 or HTTP/2 tunnel. The configuration is domain-based and can be applied to managed apps, domains, or the entire device.&lt;/p&gt;

&lt;p&gt;Apple has also expanded &lt;strong&gt;802.1X support for Ethernet&lt;/strong&gt;, which previously was only supported for macOS, allowing you to connect an iPhone, iPad&amp;nbsp;or Apple TV&amp;nbsp;to a restricted network&amp;nbsp;that requires authentication without needing to rely on WiFi.&lt;/p&gt;

&lt;h2&gt;Finally – private network and network slicing support&lt;/h2&gt;

&lt;p&gt;Long-awaited support for &lt;strong&gt;private 5G and LTE networks&lt;/strong&gt; is finally here for iOS 17 and iPadOS 17.&lt;/p&gt;

&lt;p&gt;Administrators can activate private SIMs automatically when a device enters a geofence in order to &lt;strong&gt;prioritize cellular over Wi-Fi&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;And with &lt;strong&gt;5G network slicing&lt;/strong&gt;, mobile network operators can customize traffic through a 5G standalone network with specific quality-of-service requirements for network latency, throughput and packet loss.&lt;/p&gt;

&lt;h2&gt;Discovering new use cases for wearables in the workplace?&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Apple Watch&lt;/strong&gt;&amp;nbsp;is newly supported as a managed device. An Apple Watch that is paired to a Supervised iPhone can now be enrolled and managed with watchOS 10 – with the very important requirement&amp;nbsp;that declarative management configuration must be enabled.&lt;/p&gt;

&lt;h2&gt;Planning ahead for this fall’s OS updates&lt;/h2&gt;

&lt;p&gt;Ivanti is actively testing the betas of iOS 17 and macOS 14 to make sure you can take advantage of these new features for a better end-user experience and streamlined IT processes.&lt;/p&gt;

&lt;p&gt;Look out for communication on compatibility as we plan for &lt;strong&gt;day zero support&lt;/strong&gt; for Ivanti products.&lt;/p&gt;
</description><pubDate>Tue, 25 Jul 2023 19:51:36 Z</pubDate></item></channel></rss>