Apple MDM OS Software Updates
What
Apple devices enrolled in MDM report the operating-system updates Apple makes available for their hardware and current OS. FileWave Central collects those reports, creates Software Update Filesets, and sends MDM or declarative device management (DDM) update instructions for:
- iOS
- iPadOS
- tvOS
- macOS
Apple controls update eligibility per device. An update can be available to one model or OS state without appearing as requested for every managed device.
When/Why
Legacy catalog-based workflow
Earlier macOS client-managed workflows used an Apple software update catalog delivered through FileWave Server. Administrators created a Fileset for the catalog update and assigned it to clients, and the FileWave Client handled installation.
Current MDM and DDM workflow
For MDM software updates, FileWave stores update metadata and the management instructions rather than the Apple update payload. The device downloads the applicable content from Apple. Updates reported by devices appear in the Software Updates view.
Requested only limits the view to updates that managed devices currently report as applicable. Each device check-in can refresh which updates are requested for that device.
Legacy Apple catalog Filesets could consume FileWave Server storage after creation. MDM update Filesets do not store the Apple update payload.
How
MDM Reporting
When necessary, FileWave server will send an APNs to Apple requesting devices check-in. On doing so, the FileWave Server will respond with MDM commands, one of which being a request for ‘AvailableOSUpdate’. The device should reply with all possible appropriate updates. For example:
If macOS 14.5 were the latest version, a device running 14.3.1 may request all of those between:
- 14.4
- 14.4.1
- 14.5
Apple decide which prior updates will still be available. A device may be updated to any version requested, not just latest.
Software Update View
When a device reports an update that is not already listed, FileWave adds it to the Software Updates view. Select an update to see the devices reporting it as requested, then right-click and choose Create Fileset.... Deploy the resulting Fileset to the intended test or production targets; the install is delivered through Apple's MDM/DDM framework rather than as a FileWave-hosted update package.
Current FileWave versions show the macOS MDM software update workflow. The older macOS - Apple Catalogue updates option belonged to the retired catalog-based workflow and is not available as a standard choice.
Deploy the update Fileset
FileWave 16.4.0 and later: Create a Deployment and set its timing for the Software Update Fileset. On supported earlier layouts, use the equivalent Fileset Association Install at control. The install request becomes eligible when the configured time is reached, but APNs delivery, device check-in, connectivity, available storage, and battery state can delay the device's response.
MDM Software Updates and Background Security Improvements are impacted by battery percentage of the device. Older Apple and FileWave material may still call these Rapid Security Responses (RSR). If the device is not on charge, there is a minimum percentage required for the update to commence. Please see the chart below.
| Mac Notebook Type | ASU Battery Requirement | Background Security Improvements Battery Requirement |
|
Mac with Apple silicon |
20%
|
10% |
|
Mac with Apple silicon |
50%
|
|
| Intel Based Mac | 50% | 20% |
Apple's 2026 operating systems replaced Rapid Security Response with Background Security Improvements. FileWave 16.3.x supports this newer behavior. For older OS versions and older documentation, you may still see the RSR term.
Declarative Device Management
DDM lets FileWave declare the required update state and deadline while the device downloads, prepares, installs, and reports progress. If the user has not completed the update before the configured enforcement time, the device proceeds with the enforced installation when Apple's requirements are met.
Review the enforcement time before deployment. For a DDM Software Update Fileset, Activate files at is the Force Reboot time. If it is not set, it defaults to the time the assignment is created.
MDM Process
Since FileWave does not deliver the update to devices, but a reference to the update on the App Store, devices must first fetch the update. Therefore, the installation process of an update is twofold, one to download the update and another to install the update.
Pending OS Version is the OS version currently being installed for Apple devices using a DDM Software Update fileset. It is not simply the latest version being requested by the client.
Once the scheduled installation time is reached, the device begins downloading and preparing the update, then sends the softwareupdate.pending-version status report. FileWave stores that reported value in the Pending OS Version inventory field.
Since updates can be very large, there can naturally be some delay between the initial association and the actual installation.
If the device were upgraded between the association being created and the device receiving the command to update, if the update is no longer appropriate, the device will silently ignore it.
macOS end user prompts
iPadOS end user prompts
![]() |
![]() |
![]() |
Verify the rollout
- Confirm the expected update appears in Software Updates and the intended devices report it as requested.
- Confirm the Software Update Fileset is in the intended Deployment or supported older Association, with the expected activation and enforcement timing.
- After the device begins downloading and preparing a DDM update, check Pending OS Version for the device-reported target version.
- If progress stalls, check network access to Apple, available device storage, battery or power state, and whether the update is still applicable to that device.





No comments to display
No comments to display