Skip to content

Apple OS 27 Is Here. Iru Is Ready.

Adam Henry Adam Henry
Apple OS 27 Is Here. Iru Is Ready.

Apple's OS 27 releases are available now, bringing new management capabilities across iPhone, iPad, Mac, Apple TV, and Vision.

At Iru, we're proud to deliver Day 0 support for all of these new releases. From the moment your users update their devices, our platform is ready to help you deploy, manage, and secure Apple's latest innovations, without disruption. Not only will all existing Iru functionality work seamlessly on these new operating systems, we're excited to introduce new features that take advantage of Apple's latest device management improvements.

Some of what's below is already available, with more landing Wednesday, September 16 or shortly after.

AppleCare enhanced log collection

When a device needs deeper diagnostics for an AppleCare support case, admins can now start an enhanced log collection session directly through MDM instead of requiring the end user to manually gather logs. A new Trigger enhanced log collection option in the device action menu initiates the session. Once it finishes, the logs are sent to Apple for the AppleCare team to review.

Support cases that used to require walking a user through manual log collection can now be resolved remotely. That's less back-and-forth for your team and less disruption for the end user, especially for hard-to-reproduce issues.

Available now. Requires OS 27+.

Device Health attributes

Iru now surfaces Apple's on-device health signals on the Device > Details tab of the device record and are also available in the enterprise API. A new Device System Health section shows the status of these hardware components, so you can spot a failing or non-genuine part at a glance.

  • Baseband: ok or error
  • Camera: ok, error, or non-genuine
  • Display: ok, error, or non-genuine
  • Face ID: ok or error
  • NFC: ok or error
  • Touch ID: ok or error
  • UWB: ok or error

Only components present and reportable on a given device appear; a device without Face ID, for example, won't show a Face ID row.

Hardware issues, like a non-genuine display or camera, often show up as vague user complaints long before anyone traces them back to the part itself. Having this visible on the device record means your team can catch it during a routine check instead of after a user escalation.

Available now. Requires iOS/iPadOS 27+.

Retry enrollment with Return to Service

If a device fails its automatic re-enrollment after a Return to Service erase, like from a flaky Wi-Fi connection or a transient server error, it can now retry automatically instead of getting stranded at Setup Assistant. This is on by default for eligible erases, and available through the web app, Enterprise API, and Self Service.

Return to Service is built for zero-touch redeployment: shared-device fleets, seasonal turnover, loaner devices. A one-shot enrollment attempt undermines that if it fails, since it means someone has to walk over and finish the job by hand. Automatic retry keeps the process actually hands-off.

Available now. Requires iOS/iPadOS 27+.

Detailed status for composite Library Items

Library Items that combine an MDM profile with one or more declarations, or that deliver settings over the user channel, now report status with more granularity, so what you see in the Iru web app better reflects what's actually applied on the device.

Available now, with more improvements planned over the coming weeks.

New Setup Assistant skip keys

Three new panes can now be skipped during Setup Assistant: Accessibility Appearance, Liquid Glass, and Device Features Tour. All three are configurable from both the Automated Device Enrollment Library Item and the Setup Assistant Library Item.

Skip keys keep enrollment focused on what your organization actually needs users to configure. As Apple adds more panes to Setup Assistant each release, keeping this list current means fewer screens standing between enrollment and a usable device.

Available now: Accessibility Appearance (iOS/iPadOS 17+) and Liquid Glass (OS 27+). Coming Wednesday, September 16: Device Features Tour (iOS/iPadOS 27+).

New Restrictions

The Restrictions and Login Window Library Items gain several new controls this cycle, covering lock screen network access, Siri, and other Apple Intelligence features.

Enable captive Wi-Fi portal at login and unlock

Coming Wednesday, September 16 to Login Window Library Item. Requires macOS 27+.

Enable Wi-Fi network selection at login and unlock

Coming Wednesday, September 16 to Login Window Library Item. Requires macOS 27+.

Automatic app downloads, camera, and app allow/block list restrictions extended to Vision

Available now. Requires visionOS 27+.

Both lock screen Wi-Fi controls are off by default, so a locked Mac stays locked down. Turning them on is useful for shared and kiosk-style deployments that need network access at the lock screen, like reaching a captive portal to get online before anyone signs in. As Apple ships more AI-driven features on-device, the new Siri and Apple Intelligence controls give you the same say over those capabilities that you already have over the rest of the system.

Recommended privacy permissions on the Privacy Library Item

Instead of an app or website asking for permissions one at a time as a user encounters them, you can now pre-configure which permissions to recommend, like camera, microphone, or location access, so the user sees a single, transparent prompt up front. It's a recommendation, not an enforced restriction: the user still makes the final choice.

Instead of a user encountering separate prompts for camera, microphone, and other permissions as they stumble into each one, they see a single upfront prompt with your justification for why the app or website needs access. That context, delivered once and clearly, makes users more likely to allow the permissions your organization actually wants them to have.

Coming Wednesday, September 16 for iPhone and iPad (iOS/iPadOS 27+). Coming soon for Mac.

Managing beta enrollments with the Software Update Library Item and Managed OS

The Software Update Library Item's beta enrollment control is now a three-way choice instead of a single checkbox: Disallow, Offer, or Enforce. Offer lets you make specific beta programs available without forcing enrollment. Enforce requires a specific program, which is useful for testing user-initiated upgrade flows without pinning to an exact OS version the way Managed OS does. If you do want to force a specific beta release, Managed OS makes that possible too. Additionally, beta releases can be enforced at enrollment time using the ADE Library Item as well.

This gives you a way to run a beta program deliberately, whether that's opting a test group in without forcing it, or validating how your fleet handles an upgrade flow.

Available now. Requires macOS 15.4+ or iOS/iPadOS 18+.

Coming Soon

The following list of improvements will be coming to Iru over the next several weeks.

New Restrictions

A handful of additional Restrictions keys covering Siri and Apple Intelligence are also on the way:

  • Disallow Siri AI
  • Reduce sensitive content
  • Disallow natural language editing in Calendar and Reminders
  • Disallow Visual Intelligence
  • Disallow Live Recognition

App preservation with Return to Service

Return to Service will be able to preserve a device's managed apps through the erase, so a redeployed device doesn't have to re-download everything before it's usable again. Only the app executables are preserved; all app data and user data are still erased.

For fleets doing frequent redeployment, app re-download is often the slowest part of the cycle. Preserving managed apps turns that wait from potentially an hour down to minutes.

Platform SSO changes for OS 27 Series

Apple's Platform SSO gained new configuration options this cycle, including web login password sync and OpenID as an authentication method for the PSSO extension's web view. These options will be made available in the SSO Library Item.

Safari Extensions Library Item on Mac

The Safari Extensions Library Item is coming to Mac, so you can manage which Safari extensions are allowed, blocked, or force-installed on managed Macs the same way you already can on iPhone and iPad.

Getting started

Everything marked "Available now" is live in Iru today, with more coming Wednesday, September 16, or soon after.

Not ready to move your fleet to OS 27 yet? The Software Update Library Item lets you defer major OS updates for up to 90 days, so you can hold devices on their current OS while you finish testing.

Recent Articles

Featured image: Remediating Windows vulnerabilities with a single tool
Matt Day 3 min read

Remediating Windows vulnerabilities with a single tool

Vulnerability Response is now available for Windows. Find, prioritize, and patch in one place, the same way you do for Mac.

Product News
Featured image: Rustbot, the macOS malware used in the latest Rust Supply Chain Attack
Cristian Molina 10 min read

Rustbot, the macOS malware used in the latest Rust Supply Chain Attack

On August 20, 2026, attackers published malicious versions of three widely used Rust packages to crates.io, the official Rust package registry. On macOS, the payload is a remote access trojan (RAT) that collects cloud credentials, SSH keys, cryptocurrency wallet data, and browser profile information, then sends it to attacker-controlled infrastructure. It installs a launch agent to survive reboots and accepts follow-on commands from its operators. Once running, it decrypts its configuration, profiles the host, Reads the local browser stores, installs persistence via LaunchAgent, and beacons out. The packages were available for approximately two hours before removal. The attackers also withdrew the previous stable versions, which pushed automated dependency resolution toward the compromised releases. Any environment that compiled an affected project during that window should be treated as compromised. This blog documents Iru's analysis of the native Apple Silicon ARM64 implant.

Threat Intelligence
Featured image: Inside the screensharingd Bugs: How macOS Screen Sharing Went from Root File Access to Pre-Auth Compromise
Csaba Fitzl 6 min read

Inside the screensharingd Bugs: How macOS Screen Sharing Went from Root File Access to Pre-Auth Compromise

In late July 2026, a cluster of vulnerabilities in macOS Screen Sharing turned what initially looked like a fairly constrained privilege problem into one of the more interesting macOS remote-attack stories in years.

Threat Intelligence

See Iru in action

Discover why thousands of teams choose Iru

By submitting this form I agree to Iru’s Privacy Policy and consent to be contacted by Iru about its products and services.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.