A cloud-based device management dashboard syncs and secures phones, tablets, and laptops.
Microsoft Intune’s September 24, 2026 update adds Apple OS 27 management settings, remote AppleCare log collection, and iOS app-protection controls, while putting administrators of iPhone, iPad, and Mac fleets on notice that legacy software-update management must move to Apple’s declarative model. The immediate work is to identify policies that depend on retiring Apple commands and test their replacements. Intune’s October 2026 service release is the next deadline: Microsoft says it will remove the corresponding legacy update-policy and reporting views from the admin center.

Intune’s Apple OS 27 settings catalog puts more controls in declarative management​

Microsoft’s Intune Customer Success team says it has updated the Apple settings catalog for iOS/iPadOS and macOS 27. Most of the additions it highlights use declarative device management (DDM), Apple’s model for sending configurations to devices and receiving status about them. The catalog also still contains conventional mobile device management (MDM) payloads; the new macOS Login Window settings are one example. Administrators creating a policy choose the Apple platform and Settings catalog under Devices > Manage devices > Configuration > Create > New policy, then select the relevant configuration.

The useful change is the range of Apple behavior administrators can express there. DDM App Settings can allow or deny app launches on supervised iPhones, iPads, Apple TVs, and Apple Vision Pro devices, or binary execution on supervised Macs. The same area offers organization-suggested privacy-permission defaults for capabilities such as the camera, microphone, location, and local network. Apple confirms that device management can present those permissions in a consolidated consent prompt; administrators should treat it as a way to streamline user consent, not as a promise that every requested permission is silently granted.

Other DDM groups address Apple Intelligence features—including Visual Intelligence, Writing Tools, Genmoji, Image Playground, and features in Mail, Notes, and Safari—alongside on-device dictation and translation requirements. Separate configurations cover accessibility preferences; Safari behavior and website camera or microphone defaults; and Siri availability, locked-device access, AI features, and content controls. These are distinct policy choices, so an organization reviewing its AI rules should look beyond a single “Apple Intelligence” switch.

The network and Mac-management additions are more operational. DDM settings can configure macOS Content Caching to keep Apple-distributed software and iCloud content locally and define which clients it serves. DNS Proxy and Web Content Filter configurations specify the provider app and associated settings for those functions; Intune supplies the management configuration, not the filtering or proxy provider itself. Microsoft also lists a conventional MDM Login Window category for controlling information and options presented at Mac sign-in. Availability for any individual setting still depends on its Apple platform, OS-version, enrollment, and supervision requirements.

Apple OS 27 makes the DDM software-update migration urgent​

Apple states that legacy software-update management no longer functions in any 27.0 operating system. Its list includes update commands and queries, recommended cadence settings, and restrictions such as deferrals and Background Security Improvements. This is the platform-side change: an old policy cannot keep controlling OS 27 updates simply because its configuration remains visible in Intune. Apple directs administrators to declarative software-update management.

In Intune, DDM software-update controls live in the settings catalog. Microsoft describes a Software Update configuration for enforcing an update at a specified time and Software Update Settings for deferrals and users’ interactions with updates. Under this model, the device handles the update lifecycle—including prompting, downloading, preparation, and installation—according to the assigned declaration. Administrators should identify the update outcome each existing policy is meant to produce before building its DDM replacement.

Microsoft says the October 2610 Intune service release will remove legacy iOS/iPadOS and macOS update policies from the admin center, along with the per-device macOS software-updates report and the iOS and macOS update-installation-failure views. That is an announced console change, separate from Apple’s already effective OS 27 behavior. Teams relying on those views for update investigations should account for their removal as part of the policy migration, rather than treating the old and new interfaces as interchangeable.

The retirement reaches beyond updates. Microsoft lists legacy MDM payload areas being deprecated with OS 27, including content caching, DNS settings and DNS proxy, parental-controls application restrictions, Privacy Preferences Policy Control, and passcode. It maps affected Restrictions settings into DDM App Settings, External Intelligence Settings, Intelligence Settings, Keyboard Settings, and Siri Settings. For example, app bundle-ID allow and block rules move to App Settings, while controls for Genmoji, Writing Tools, and on-device dictation move to Intelligence Settings. This calls for a policy-by-policy inventory, particularly where an existing restriction has a new DDM home under a different name.

Setup Assistant changes reduce enrollment steps, while AppleCare logs gain a remote path​

Intune now includes Setup Assistant skip keys for Liquid Glass and Accessibility Appearance in Apple Automated Device Enrollment profiles. Skipping a pane removes that setup interaction from the supported enrollment flow; it is a choice about what users encounter during setup, not a blanket policy for the feature after enrollment. Apple independently confirms that management can skip the Liquid Glass pane.

A separate device action addresses AppleCare escalations. For a supervised Mac, iPhone, or iPad running macOS 27 or iOS/iPadOS 27 or later, Intune can request enhanced diagnostic logs using a token supplied by AppleCare. The device collects the logs in the background and uploads them directly to the associated AppleCare case. Apple describes remote AppleCare collection on supervised tvOS 27 devices too, but Microsoft’s documented Intune action lists macOS and iOS/iPadOS, so administrators should not assume the same Intune procedure is available for Apple TV.

For a supported device and an open AppleCare case, Microsoft documents this workflow:

  1. Use an Intune account assigned Remote tasks/Trigger enhanced log collection, and obtain the token from AppleCare.
  2. In the Intune admin center, go to Devices > All devices, select the supervised device, then choose More (…) > Trigger enhanced log collection.
  3. Enter the AppleCare token and confirm. Check Device actions status on the device’s Overview page for the request’s progress.

Pending means the request has not reached the device; Acknowledged means collection has begun; Completed means collection and upload finished. Failed can indicate an offline device, a device that is not supervised, or an OS below version 27. Intune also records requests in audit logs and provides a cancellation action for accounts with the corresponding cancellation permission. The resulting bundle is reviewed through the AppleCare case—there is no Intune download of the logs.

Intune App SDK 21.8.0 determines which iOS apps get the MAM changes​

Microsoft’s mobile application management changes operate inside apps integrated with Intune App SDK for iOS version 21.8.0 or later. The first is a revised app-protection experience: clearer account identification on conditional-launch screens such as the MAM PIN prompt, updated messages, and a Remove Account option for a blocked managed account. Using that option removes the account and its organizational data from the app. Microsoft describes the revision as a user-experience update, with no change to the underlying app-protection policies.

The second change has a more direct data-sharing consequence. In apps using the required SDK, Intune’s Screen capture app-protection setting also governs Siri onscreen awareness for work or school data. Setting Screen capture to Block prevents Ask Siri from appearing in the context menu for that organizational data. Microsoft says Allow is the default; leaving it there permits sharing that data through Siri onscreen awareness. An administrator should check both the assigned policy value and each affected app’s SDK integration: changing the policy alone does not give an older SDK-integrated app the newly described behavior.

This app-level control serves a different purpose from the OS-level Siri and Apple Intelligence configurations in the settings catalog. A fleet can have device-management rules for Apple features and separate app-protection rules for organizational content. Reviewing one set without the other leaves the reader with an incomplete picture of what users can do with managed app data.

Intune’s user-less Apple version guidance needs a careful reading​

Microsoft also discusses supported versus allowed OS versions for devices enrolled without user affinity, such as shared iPads or Automated Device Enrollment devices without an assigned user. In its terminology, supported versions receive applicable Intune MDM functionality and eligible new features. Older allowed versions can still enroll and use eligible MDM-protocol features, but Microsoft warns that OS changes or defects may affect them. The allowed-version provision does not extend support to user-affinity enrollment or apps requiring user sign-in.

There is a material inconsistency in the published numbers. The September 24 Intune post names iOS/iPadOS 26.x, 18.x, and 17.x as supported user-less versions, while its own table puts the supported floor at iOS/iPadOS 18.x and macOS 15.x, and the allowed floors at iOS/iPadOS 16.x and macOS 13.x. Microsoft’s general supported-platform page, last updated earlier in 2026, shows different floors again. Administrators deciding whether an older shared device can remain in service should not treat the post’s conflicting numbers as a reliable eligibility calculation; verify the applicable support guidance and the enrollment type before planning that device’s next OS move.

What this means for you​

Prioritize the update-policy migration if your fleet is moving to Apple OS 27; it is the change with an immediate platform consequence and a scheduled Intune console cleanup. The other additions warrant targeted checks according to the devices, apps, and support workflows your organization actually uses.

  • Inventory legacy Apple update policies and build the needed DDM Software Update or Software Update Settings replacements in the Intune settings catalog before relying on OS 27 update enforcement.
  • Review deprecated MDM payloads and Restrictions settings by workload, then match each required control to its DDM category instead of assuming the old policy name still identifies its replacement.
  • Check whether Liquid Glass and Accessibility Appearance should appear during Automated Device Enrollment; use the new skip keys only where removing those setup steps suits your deployment.
  • Use enhanced logging for an AppleCare case only with a supported, supervised OS 27 device, the AppleCare token, and the required Intune remote-task permission; expect the logs in AppleCare, not as an Intune download.
  • For organizational data in iOS apps, review Screen capture and confirm the apps integrate Intune App SDK 21.8.0 or later before expecting the Siri onscreen-awareness control.
  • Assess older shared-device eligibility separately from user-affinity enrollment, and resolve Microsoft’s conflicting version floors before making a keep-or-replace decision.

Apple OS 27 gives Intune administrators more specific controls, but the practical dividing line is whether existing Apple policies still do the job they were assigned to do. Moving update management to DDM now addresses Apple’s OS 27 retirement and leaves teams better prepared for Intune’s announced 2610 cleanup in October.