Skip to main content
Question

How to Block Golden Gate if Blueprints is configured to update the latest MacOS version?

  • July 21, 2026
  • 3 replies
  • 60 views

TheITGuy69
Forum|alt.badge.img+7

Hi, we use a pretty basic blueprint to keep our devices up to date to the latest MacOS , we force it to install within 30 days. Without having to edit this Blueprint and redeploy, will the regular “Block” for the New MacOS Golden Gate work and only keep the updates coming for Tahoe until we unblock Golden Gate (usually for us is 90 days after it comes out.). 

3 replies

Chris_Hafner
Forum|alt.badge.img+27
  • Jamf Heroes
  • July 21, 2026

I suppose it depends on what you mean by “Block” MacOS Golden Gate. Regardless, if you do this you’ll have these two items at odds and behavior will depend on a number of things. At best, the Updates will be downloaded but not installed… 

 

I get that you’re trying to solve for this specific OS but, you should probably consider having your Blueprints set up in such a way as to anticipate this yearly occurrence. 

 

If you leave whatever that “block” is in place you should change your Update Blueprint so they aren’t at odds. Depending on how you manage your blueprints, it could be as simple as checking “Ignore Major Versions” in “Software Update”. 

 

Take this is a grain of salt. It very much depends on how you set up each of those items (both the version block and the Blueprint). In our environment. I haven’t totally made up my mind on how we’re managing that just yet, but I’ll probably stick with what we have set up right now, which is one blueprint for machines NOT on Tahoe, to enforce upgrades to our chosen version of Tahoe and then another for machines on Tahoe, to ignore major versions until we’re ready to approve it, along with a deferral policy. 

 

Just my 0.02 


TheITGuy69
Forum|alt.badge.img+7
  • Author
  • Contributor
  • July 21, 2026

I suppose it depends on what you mean by “Block” MacOS Golden Gate. Regardless, if you do this you’ll have these two items at odds and behavior will depend on a number of things. At best, the Updates will be downloaded but not installed… 

 

I get that you’re trying to solve for this specific OS but, you should probably consider having your Blueprints set up in such a way as to anticipate this yearly occurrence. 

 

If you leave whatever that is in place you should change your Update Blueprint so they aren’t at odds. Depending on how you manage your blueprints, it could be as simple as checking “Ignore Major Versions” in “Software Update”. 

 

Take this is a grain of salt. It very much depends on how you set up each of those items (both the version block and the Blueprint). In our environment. I haven’t totally made up my mind on how we’re managing that just yet, but I’ll probably stick with what we have set up right now, which is one blueprint for machines NOT on Tahoe, to enforce upgrades to our chosen version of Tahoe and then another for machines on Tahoe, to ignore major versions until we’re ready to approve it, along with a deferral policy. 

 

Just my 0.02 

Thank you for that insight. sometimes someone elses vision helps! Like i stated prior our Blueprint is basic and it geared towards all managed devices to update to the latest MacOS version it can handle since we do have some devices in our fleet that can only handle Sonoma and Sequoia. Maybe i should create multiple Blueprints and assign them by smartgoups and existing MacOS versions.


Forum|alt.badge.img+16
  • Valued Contributor
  • July 21, 2026

That’s what I was thinking. Maybe one Blueprint for general use but then switch over to another Blueprint to use during the release of the new macOS.