The reference for Apple system administrators

WWDC25 APPLE DEVICE MANAGEMENT UPDATES

Author

Published

Tags

Category

As every June, Apple is once again hosting the developer conference WWDC this year. Throughout the week starting June 9, hundreds of technical sessions will be held for developers. Alongside these technical sessions, Apple has also released the first developer beta versions of the upcoming fall releases for its platforms — macOS, iOS, iPadOS, visionOS, tvOS, and watchOS — and presented the new features to come.

There is an important part of this conference that also concerns us, Apple system administrators. Every year, Apple introduces the upcoming innovations in device management at WWDC.

Here is a brief summary of the updates we will encounter in Apple Business Manager and the MDM framework when the 2026 versions of macOS, iOS, iPadOS, visionOS, tvOS, and watchOS are released.

Apple Account List

On accounts with domain verification, it was already possible to lock the domain address and prevent new users from creating personal Apple Accounts with the domain owned by the organization. ABM administrators can now download a list of personal Apple Account holders who created their accounts with the organization’s domain address before the Lock command was issued.

Personal Apple Account Restriction

For devices registered in Apple Business Manager, it will be possible to restrict which Apple accounts users can use on the device through the Access Management section. This way, the use of personal Apple Accounts on corporate devices can be restricted — and without MDM.

Device Inventory Records

There is new information that will be visible among device inventory records in Apple Business Manager. For example, iPad battery health status, Bluetooth/Wi-Fi MAC addresses for iPhone and iPad, and AppleCare coverage information.

Additionally, when a device is removed from ABM using the Release command, a record of which user performed this action and on which date will also be visible.

Apple Business Manager API

ABM/ASM APIs are being opened for organizations. Information such as the list of MDM servers registered in ABM, the list of all devices in ABM, device details, and the MDM server a device is assigned to will be viewable by an externally connected inventory management system using an API account.

Apple Vision Pro

Apple Vision Pro can now be manually added to Apple Business Manager, just like other Apple devices. The Apple Configurator for iPhone application can be used for this. To learn how to do this for an iPad, you can refer to our article Adding an iPad (or iPhone) to Apple Business Manager.

In addition, all configurations that we could previously apply for Apple Intelligence on iPhone, iPad, and Mac now cover visionOS as a whole as well.

Account Driven Enrollment

There is a simplification in the Account Driven Enrollment methods used to enroll personal or corporate devices used in the company to the MDM server via Managed Apple Accounts. The currently used method requires a proxy URL to forward the request from the device to the MDM server. With the new feature to be added in the 2026 versions, if this URL is determined by the MDM server, the device will fall back to Apple Business Manager and go to the MDM server automatically assigned for the device type to retrieve the enrollment profile. This means the entire process can be completed with just the MDM server and ABM, without the need for a third party.

Get Ready for the Real Bombshell: Device Management Migration

Let’s say you have an MDM server and you’re using this product on-premises. When you want to switch to the cloud version of the same MDM product, the devices needed to be reset in order for the Automated Device Enrollment process to be valid on the new MDM.

In scenarios where you are migrating to another MDM, you make a Device Management assignment for your devices through Apple Business Manager. And you can set a deadline date and time for this migration. At this point, a notification is sent to the devices in use, informing them that this migration will take place. The moment the user presses the Start Enrollment button, the process begins. Profiles related to the old MDM server are deleted. The new MDM server takes over Activation Lock management; if the device is a Mac, it uses the Bootstrap Token to change the FileVault key. During this process, all configuration profiles from the old MDM are also deleted. It is important that the same policies are prepared in the new MDM so that users can have a smoother transition.

DDM Software Update

Apple has started changing the device management architecture. It has transitioned to a new model that will reduce the load on the APNS server and is gradually moving some features to the new management model called Declarative Device Management. The DDM Software Update feature, already available for Mac, iPhone, and iPad, will also be coming to visionOS and tvOS in the coming months.

Safari Management

Speaking of DDM, all manageable keys related to Safari have been migrated to the DDM model. We can now also manage bookmarks for Safari and determine which URL will open as the homepage.

Return to Service

When we want to reset a device and give it to a new user, the Wipe command we send to the device would delete everything on the device except the operating system. On iPhone and iPad, to speed up the process of handing the device to a new user, managed applications on the device continue to remain on the device just like the operating system. All user data within the applications is deleted. When the device is reactivated, there is no need to wait for these applications to be re-downloaded to the device.

This method can also be applied to Apple Vision Pro just as it is on iPhone and iPad. This speeds up the process of an Apple Vision Pro being started by another user.

Application Management

App Store applications, Custom applications, and applications installed as .PKG can all now be distributed using the DDM method. Applications can be tagged as Required or Optional. When you want to make a change related to an application’s own settings within a managed application, application configurations will also be managed with a new API. In this context, application settings, user identities, passwords, and certificates can be managed as part of this.

Application updates have also become separately manageable. You can force or disable automatic updates for applications. It is also possible to pin a specific application version to remain fixed.

Platform SSO

As long awaited, Platform SSO can now be part of Setup Assistant. When a device enrolls in MDM via Automated Device Enrollment, users can sign in with credentials provided by the IdP, a local user account can be created, and the user’s photo and password can work in sync with the IdP.

An important update has also come to the Guest account that has existed in macOS for years. When the feature called Authenticated Guest Mode is activated, guest users will be able to sign in with credentials determined by the IdP, use their credentials to sign in to websites and applications as well. When they end their session, all data will be automatically deleted.

In addition, with the Tap to Login feature, iPhone and Apple Watch users will also be able to sign in to Authenticated Guest Mode. User credentials will exist as an access key in the Wallet application and will be shared with the Mac via NFC. Of course, these keys will be stored in Secure Enclave and will be protected from external interference. A NFC reader connected to the Mac is required to use this method.

You can watch the full “What’s new in Apple device management and identity” session here.


Settings Blog’a Abone Olun

Yayınlanan her yazı annıda e-posta adresinize gelsin.

Comments

Leave a Reply

Settings Blog'a Abone Olun

Yayınlanan her yazı anında e-posta adresinize gelsin.

Okumaya devam edin