What Apple OS 27 changes for Intune admins

 

Apple shipped OS 27 and Microsoft has been catching up on the Intune side. Most of this is plumbing you won't notice day-to-day, but a few pieces will actually hit your task list this quarter — especially if you're still running MDM Restrictions payloads or per-device update policies. Here's what's worth your attention, based on Microsoft's own Intune Customer Success post from September 24.



New settings catalog configurations

Intune added day-zero support for a batch of new DDM (declarative device management) settings tied to OS 27. The ones that matter most for a typical fleet:

  • App settings — allow/deny rules for which apps or binaries can launch on supervised iPhones, iPads, Apple TVs, Vision Pro, and Macs. Also lets you push a single consolidated privacy consent prompt (camera, mic, location, Bluetooth, etc.) instead of the usual pile of separate iOS prompts.
  • Intelligence settings — this is your Apple Intelligence on/off switch. Controls Visual Intelligence, Writing Tools, Genmoji, Image Playground, and the Mail/Notes/Safari AI features, plus whether dictation and translation are forced to stay on-device.
  • Safari settings — cookies, JavaScript, pop-ups, private browsing, camera/mic permission defaults, and (new) summaries and new-tab start pages.
  • Siri settings — covers Siri AI features, lock-screen access, and profanity/content filtering.
  • Content caching, DNS Proxy, and web content filter — all moved to DDM. Useful if you're running local caching for software updates or routing DNS through an approved filter.
  • Login window (MDM) — customize the macOS sign-in screen and what info/options show up there.

All of this lives in the settings catalog, so if you're already building policies that way, there's nothing new to learn — just new categories to check.

The bigger deal: legacy MDM payloads are getting phased out

This is the part that actually requires action. Apple is retiring several legacy MDM commands with OS 27, and Intune is following suit:

  • Content caching service
  • DNS settings and DNS proxy
  • Parental controls application restrictions
  • Privacy preferences policy control
  • Passcode payload

On top of that, a chunk of settings inside the MDM Restrictions payload are deprecated too — things like allow/blocked app bundle IDs, most of the Apple Intelligence controls, keyboard restrictions (autocorrect, dictation, predictive keyboard, spell check), and the Siri assistant toggles. If you built policies around any of these, they need to move to the equivalent DDM settings catalog configuration. Microsoft published a mapping table in the original post if you need to match old setting to new location.

Bigger one for anyone still using update policies: starting with the October 2026 (2610) release, Intune is pulling these out of the admin center entirely:

  • iOS/iPadOS update policies
  • macOS update policies
  • macOS software updates report (per-device)
  • iOS and macOS update installation failure reports

If you're relying on any of these for compliance reporting or patch enforcement, this is the point where you need a plan to move to DDM-based software update management before October. Don't wait for the removal to notice.

Supported vs. allowed OS versions for user-less devices

For shared iPads and ADE-enrolled devices without user affinity, Intune keeps its N-2 / N-5 model:

CapabilitySupported
Allowed
Version range
3 most recent (iOS/iPadOS 18.x+, macOS 15.x+)

Up to 3 versions below supported (iOS/iPadOS 16.x+, macOS 13.x+)
Can enrollYesYes
MDM features workYes, fullyYes, but may break with OS changes/bugs
User affinity enrollmentYesNo

Nothing changed structurally here with OS 27 — just confirms Intune's existing model carries forward. If your shared-device fleet is sitting on anything older than N-5, this is your reminder that you're outside supported territory.

MAM updates worth knowing if you manage BYOD

If you're running app protection policies on unmanaged/BYOD iOS devices, two things landed with Intune App SDK v21.8.0+:

  • The app protection UI got a refresh — clearer conditional-launch and MAM PIN screens, plus a Remove Account option so users can self-service remove a blocked managed account without opening a ticket.
  • The existing Screen capture policy setting now also blocks Siri onscreen awareness from reading org data. Set it to Block if you don't want "Ask Siri" showing up in the context menu for work content.

Apps need to be built against SDK 21.8.0 or later to get these behaviors, so this is really a "check with your app vendors" item rather than something you configure directly.

What to actually do this week

  1. Audit any MDM Restrictions payload policies for the deprecated settings listed above and start migrating them to DDM settings catalog equivalents.
  2. If you use iOS/iPadOS or macOS update policies in Intune, start your migration to DDM-based software updates now — the October removal isn't far off.
  3. Check your shared iPad / ADE fleet against the supported OS version table and flag anything running unsupported versions.
  4. Ping your MAM app vendors about SDK 21.8.0 adoption if Siri onscreen awareness leaking org data is a concern for your BYOD policy.

Full detail and the deprecated-settings mapping table is in Microsoft's original post, linked at the top. Worth a full read if you're managing a mixed Apple fleet.

Comments

Popular posts from this blog

Microsoft Intune updates: what IT teams should review this month