Apple released iOS, iPadOS, and tvOS 27 on September 14, 2026. With this release, Apple removed the software update management mechanism that Esper and every other MDM has used for years, replacing it with Declarative Device Management (DDM).
Nothing on your devices broke when Apple shipped 27, and the change does not happen to your whole fleet at once — it applies to each device individually, when that device installs 27. This article explains what changes, what to check today, and what Esper is doing. This is important to review regardless of if you wish to move all or some of your fleet to iOS 27, or if you wish to ensure you fleet stays on an earlier iOS release.
In this article:
- What changed
- What this means for your devices
- What to do now: check your update deferral
- If devices are already on 27
- What Esper is doing
- FAQ
What changed
In iOS, iPadOS, and tvOS 27, Apple removed the legacy software update commands, queries, and deferral restrictions from the device management protocol. On a device running 27, these no longer function including the update deferral you set in a blueprint.
Apple's replacement is Declarative Device Management. Esper's DDM-based update controls are built and are being enabled across managed fleets.
What this means for your devices
Devices below iOS/iPadOS/tvOS 27. No change. Your update deferral works as it always has, and so does everything else in your blueprint — apps, restrictions, Wi-Fi, kiosk and multi-app modes, enrollment.
Devices that install iOS/iPadOS/tvOS 27. Once a device is on 27, it no longer honors the deferral you set, and Esper cannot control its OS updates until it has been switched to Apple's new protocol. Esper performs that switch; the action required by you is to notify either your account team or Esper Support that this switch needs to be completed by Esper.
Kiosk mode devices. Users typically can't reach Settings, so these devices don't move to 27 on their own. If your deployment is Autonomous Single App Mode and your app exits or crashes, this may expose Settings.
Multi-app mode devices. If a user can open Settings > General > Software Update, they can install 27 as soon as your deferral no longer hides it. If you are restricting the home screen via approved apps using allowedApplications, be aware of the risk if you include Settings on the allowed list. Devices can also download an update on their own and then prompt the user to install it.
What to do now: check your update deferral
The deferral hides a new release from your devices for up to 90 days after Apple publishes it. While the release is hidden, it does not appear in Software Update and the device does not prompt anyone to install it.
To check or change it:
- Go to Blueprints Manager and open the blueprint applied to your Apple devices.
- Click the iOS tab.
- Open the System Updates section.
- Confirm the deferral period. If you used the default setting in your blueprint or set it to 0, iOS 27 is visible to those device users now.
- Set it to 90 days for maximum protection, then save, publish, and converge the blueprint.
Check every blueprint that applies to Apple devices, not only your main one. It is common for a subset of devices to sit on a different blueprint with a different deferral value.
Setting a deferral does not prevent you from updating. It hides new releases from device users. Updates you initiate as an operator are unaffected, so you can hold your fleet steady and still move it on a date you choose.
If devices are already on 27
Devices on 27+ can't be managed for OS updates until Esper switches them to Apple's new protocol. They continue to work normally in every other respect: apps, restrictions, kiosk and multi-app modes, and all other blueprint settings are unaffected.
If you try to run an OS update command against a device running 27, the command will fail. This is expected and is not a fault with the device or your configuration.
What Esper is doing
Esper's DDM-based OS update controls are built. Bringing them to your fleet happens in two steps:
1. Switching devices to the new protocol. Each enrolled device needs a one-time, server-side switch to Apple's declarative protocol. Esper performs this. It changes nothing on the device and nothing for your users, and your current update settings are unaffected. You can request this switch today by contacting our support team.
2. New update controls in your blueprint coming soon. Once devices are switched, the System Updates section will offer release holds and update behavior settings built on the new protocol, including control over whether devices download and install updates on their own, and which versions they offer users. These are in development; we will announce availability in our release notes.
Update controls are also available through the Esper API. Contact your Esper representative or Esper Support if you want to drive OS updates programmatically using our API.
FAQ
Will my devices update to iOS 27 by themselves?
A device can download an update on its own and then prompt the user to install it. Installing a major version like 27 requires someone to act on the device. This is not possible in kiosk mode. A deferral prevents the release from being offered at all, which is why setting one matters on devices where users have access to Settings.
Does the deferral block security updates?
The deferral applies to releases published within the deferral window. It is a delay, not a permanent block (after the window passes, the release becomes available on the device).
My fleet is on iOS 17. Am I affected?
Only when a device installs 27. Devices staying on earlier versions keep working with existing update controls. Note that hardware capable of running iOS 26 is also capable of running 27, so a device's current version doesn't tell you whether it can move.
Can I go back after a device installs 27?
No. Apple does not support downgrading to an earlier iOS version.
We want to move to iOS 27 deliberately. What's the right order?
Validate your apps on 27 using a small group of test devices first, keep the rest of the fleet held with a deferral, and let us know your planned date by contacting your Esper representative or our support team. We'll fire the command to switch your target devices to the new protocol before you move, so your update controls are in place when you install version 27.
What about Apple TV?
The same change applies to tvOS 27. Apple's new update controls require tvOS 18.4 or later, so Apple TVs on older tvOS versions should be updated while existing controls still work on them.
Who do I contact if I have questions?
Your Esper account representative or the Support Team.