Skip to content

macOS 27: Great new privacy capabilities for IT… if you can use them

Mike Boylan Mike Boylan
macOS 27: Great new privacy capabilities for IT… if you can use them

Apple's newest privacy controls in macOS 27 only work if your users are MDM-enabled, and only once they've actually shipped in your device management platform. A lot of fleets will hit both walls.

For years, Apple has said that all new device management capability will only be delivered through declarative device management (DDM). That's been true, and the surface area covered by DDM has expanded every year since. macOS 27 continues that trend, but with a twist that's easy to miss: several of this year's most useful new capabilities only work through the user channel, not the device channel, and not every managed Mac has a user enabled to receive them.

Device settings vs. user settings

Most of what admins configure day to day, Wi-Fi, restrictions, enforcing FileVault, applies at the device level. That's made sense for a long time: most organizations assign one Mac to one employee, so there's no real need to differentiate settings by who's signed in.

But device management has always had a separate channel for settings tied to the specific user account on a device. Historically that channel mattered most in shared environments, like education, where different users signing into the same Mac needed different settings. These sign-ins were often backed by a directory service. As more organizations moved to one-to-one assignment, the user channel saw less use.

macOS 27 changes that. A meaningful set of new capabilities requires the user channel specifically, because Apple has drawn a hard line: some settings are user consent decisions, not organizational device configuration, and Apple wants the user in the loop.

What requires the user channel

AppleCare Enhanced Logging. Using MDM, this allows IT teams to request Apple diagnostic logs for use with AppleCare Enterprise cases. iOS and iPadOS do offer a way to request these logs silently, but at least for now, on macOS, the request always requires the user’s consent.

Recommended privacy permissions. Every app that requests camera, microphone, or location access today prompts the user individually. macOS 27 introduces the ability for IT teams to create a consolidated prompt: IT can recommend an Allow or Deny for a set of apps at once, with an optional justification message explaining why. The user still has final say though, and can always override the recommendation.

Website camera and microphone permissions in Safari. The same recommended-permission model extends to website-level access, not just native apps.

Safari extension management for Mac (last year). Allows IT teams to define which Safari extensions should or should not be able to run on managed Mac computers.

The catch: not every Mac has an MDM-enabled user

Here's the part that requires action from you regardless of rollout timing. Whether a user account is MDM-enabled isn't something a device management vendor controls. It's a macOS decision made at enrollment time, and a significant percentage of managed fleets, likely in the high double digits, are in a state where the primary user isn't enabled.

Here's a general framework for how macOS enables user channel MDM:

  • Automated Device Enrollment with account creation in Setup Assistant → user is MDM-enabled. This is the standard, expected flow.
  • Manual enrollment while already logged in (common during device management migrations) → typically MDM-enabled.
  • Skipping account creation in Setup Assistant, common when using tools like Iru Passport that handle login-window authentication separately → the user is often not MDM-enabled.
  • Some Platform SSO setups, before registration in Setup Assistant → the user is often not MDM-enabled.

Given how common it is for a user to not be enabled for user channel MDM, it’s important to audit your fleet's status. Check whether your device management console surfaces this today. Iru currently surfaces the MDM enabled state of users on devices on the device record, and soon in Prism.

If your fleet falls into the not-enabled bucket, recommended privacy permissions and the other user-channel capabilities in macOS 27 won't apply or be able to be used with those users, regardless of which device management tool you're running.

An arduous remediation path

Re-enrolling an already-enrolled Mac can turn on the user channel after the fact. But it requires the end user to take action on their own device, and requires some coordination from IT. That's a manageable ask for a handful of Macs. It's not a realistic plan for a fleet of a few hundred or a few thousand.

If you're affected at scale, the fix has to come from Apple, not from your device management vendor. File feedback through AppleSeed for IT describing your enrollment workflow, current state of your fleet, and the specific gap(s).

The bottom line

macOS 27 doesn't just add powerful new management capabilities; it also exposes an enrollment gap that's likely been sitting quietly in your fleet for years. The fix isn't something any device management vendor can deliver on its own; it starts with knowing where your fleet actually stands and requires help from Apple to fix.

See it in Iru. Book a demo to see how the Privacy Library Item, Restrictions Library Item, and SSO Library Item are handling macOS 27's rollout, including how Iru surfaces which of your devices have the user channel enabled.

Mike Boylan, Director, Product
At Iru, Mike oversees the teams responsible for Apple and Android device management, compliance automation, and customer experiences. A former engineer turned product leader, he has over 20 years of experience in deploying and managing devices of all types, including many years at Apple as a Senior Consulting Engineer. At Apple, he led field and customer platform readiness for macOS, including speaking at numerous industry conferences and events, such as Apple’s Worldwide Developers Conference (WWDC).

Recent Articles

Featured image: Introducing macOS LAPS in Iru: Secure, automated local admin passwords
Mike Boylan 4 min read

Introducing macOS LAPS in Iru: Secure, automated local admin passwords

Local administrator accounts are indispensable for troubleshooting and recovery, but the passwords behind them can also become a serious security liability. Shared credentials, long or nonexistent rotation intervals, and inconsistent storage practices give attackers more time and opportunity to move laterally after a compromise.

Product News
Featured image: Apple OS 27 is here. Iru is ready.
Adam Henry 8 min read

Apple OS 27 is here. Iru is ready.

Apple's OS 27 releases are available now, bringing new management capabilities across iPhone, iPad, Mac, Apple TV, and Vision.

Product News
Featured image: Remediating Windows vulnerabilities with a single tool
Matt Day 3 min read

Remediating Windows vulnerabilities with a single tool

Vulnerability Response is now available for Windows. Find, prioritize, and patch in one place, the same way you do for Mac.

Product News

See Iru in action

Discover why thousands of teams choose Iru

By submitting this form I agree to Iru’s Privacy Policy and consent to be contacted by Iru about its products and services.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.