I had a ‘latest version’ enforcement not apply recently so I want to source the community to see if anyone else has a similar setup or came to the same conclusion. This may end in a Feature Request, but I want to understand some logistics and maybe crowd-source a solution if possible.
Let’s say I want to defer my updates for a set period of time across multiple release rings (Early Adopters, GA1, GA) but I also wanted to enforce updates as well. This would create ‘update windows’ for each ring. EA opens up after 7 days and is enforced after 10 days. GA1 is a week later and GA a week after that. Blueprints - technically - provides this and its quite simple to deploy. However…
I’m learning that the enforcement mechanism relies on the Apple GDMF feed which… is typically only a single version in a given OS family. Right now, it looks like this:

This means the Blueprint checks against this feed and enforces based off of it. If there aren’t multiple versions in the feed, then each time a new OS supplemental drops, the clock would reset for the Blueprint.
For much of the year this is probably not an issue - as long as your enforcement deadline is before the next release. But let’s pretend that patching increases in frequency due to AI threats and CVE increases - if Apple starts releasing every two weeks or even sooner, its theoretically possible that a GA deployment ring that doesn’t enforce for 28 days can keep having its ‘latest version based on device eligibility’ get pushed out indefinitely or until you get lucky and a deployment happens in 29 days.
We only recently deployed Blueprints but both my own research and the Jamf AI came to the same conclusion that I probably need to manually change the OS version so as to avoid this exact scenario - which I feel kind of defeats the point.
Would appreciate some feedback and some hole-punching in my understanding, such as you can provide.
-mC
