Skip to main content

We were just made aware of this, and Jamf and Apple have confirmed. The Ventura release on Monday will be considered a minor update for anything 12.3 and higher, so major OS deferrals will not apply. Apple's recommendation is to defer all minor updates as well as major until you can get your clients to 12.6.1 (not released yet, maybe also on the 24th?). Jamf confirmed to us that you should have all your clients at 12.6.1 by Wednesday, November 23, 2022 if you wish to defer Ventura past that date.

 

Just passing on info. Hopefully this helps someone avoid a rough Monday.

Edit: Adding direct quote from our Jamf rep that explains better than I did:

Ventura major deferral bug, in a nutshell

On macOS 12.2 or earlier? - You're all good. Not affected.

On macOS 12.3 or later?

There's a bug. It's fixed in 12.6.1 and Apple has made a change so even 12.3+ will be fine for 30 days - make sure to get 12.6.1 installed

If you don't get 12.6.1 installed, Ventura updates published after 30 days might appear on Macs running 12.3 - 12.6 - even when major deferred

If you're past 30 days but not on 12.6.1, you can mitigate seeing Ventura by deferring both major and minor (but you should focus on getting to 12.6.1)

I am figuring much the same. This is going to be sloppy. Very sloppy. Apple really should have released the fix that will be coming in macOS 12.6.1 long before macOS 13 drops.

 

Knowing Apple, both macOS 12.6.1 and macOS 13 will drop on the same day next week and be covered by the same deferrals. So until MDM commands can force the OS update to 12.6.1 (assuming your environment is even ready) the users are free to update to macOS 13 within that same window and its a race to see which finishes first.


Thanks for this...


But this is only relevant if users have access to Software update?


But this is only relevant if users have access to Software update?


I think it also applies if you're updating with MDM commands or using something like superman.


Yeah, still testing Superman. In the worst-case scenario, it will be to download the full 12.6.1 installer again :-(


What's the recommended way to initiate a minor deferral? 


What's the recommended way to initiate a minor deferral? 


Config profile. This should help: https://docs.jamf.com/best-practice-workflows/jamf-pro/managing-macos-updates/Deferring_a_macOS_Update.html 


Apple has provided us with a path going forward on this issue. Please reference AppleSeed for IT notes for full details. Anything else is breaking NDA until Monday.


Apple has provided us with a path going forward on this issue. Please reference AppleSeed for IT notes for full details. Anything else is breaking NDA until Monday.


I disagree with your apparent accusation that I am somehow breaking an NDA I never signed by passing on this info, but if the Jamf community admins believe it is, they are free to delete this post.

 

Apple’s secrecy, and (in my opinion) hostility towards IT Admins is exactly why we’re looking to accelerate our plans to switch to PCs.


I disagree with your apparent accusation that I am somehow breaking an NDA I never signed by passing on this info, but if the Jamf community admins believe it is, they are free to delete this post.

 

Apple’s secrecy, and (in my opinion) hostility towards IT Admins is exactly why we’re looking to accelerate our plans to switch to PCs.


I didn't say you broke the NDA, all I'm saying is that if you would like more information about this you can go to AppleSeed for IT that has all the information you need. This info is covered by the NDA, if you installed Ventura then you agreed to it. I am not the NDA police, and think the whole thing is dumb as rocks. Especially when iOS Dev's plaster information everywhere on social media. But just because they are doing so, does not give us the right to do the same (even though it's not fair).

To your comment about Apple being hostile towards IT? Apple's own enterprise team employees have communicated with us more than they have in the last 10 years. 

Was this update thing a bad move? YES! Apple should have communicated with everyone at WWDC, but they came up with a good solution that will help many MacAdmins.

 

The whole situation is kind of sad because of how great the new upgrade system is. It should have been touted as a HUGE Ventura feature. The new upgrade will be a game changer and shows that Apple is listening.


I didn't say you broke the NDA, all I'm saying is that if you would like more information about this you can go to AppleSeed for IT that has all the information you need. This info is covered by the NDA, if you installed Ventura then you agreed to it. I am not the NDA police, and think the whole thing is dumb as rocks. Especially when iOS Dev's plaster information everywhere on social media. But just because they are doing so, does not give us the right to do the same (even though it's not fair).

To your comment about Apple being hostile towards IT? Apple's own enterprise team employees have communicated with us more than they have in the last 10 years. 

Was this update thing a bad move? YES! Apple should have communicated with everyone at WWDC, but they came up with a good solution that will help many MacAdmins.

 

The whole situation is kind of sad because of how great the new upgrade system is. It should have been touted as a HUGE Ventura feature. The new upgrade will be a game changer and shows that Apple is listening.


Oh I’m sorry, I completely misinterpreted your post. I apologize!

 

I’m glad your organization is having a better experience than mine. Not being able to defer Monterey past 90 days was very rough on us, and I’ve been working with Jamf (great) and Apple (not so great) for over a year on management issues especially around patching. Then on the other side I have a demoralized team and a bunch of frustrated end users.

Anyway sorry again and also for sidetracking this thread.


Are there any sources, links, articles that cover the topic? So far I have not been able to find anything on this error in the trade press or the relevant blogs.


Are there any sources, links, articles that cover the topic? So far I have not been able to find anything on this error in the trade press or the relevant blogs.


Not that I'm aware of. I first heard of it when our Apple rep mentioned it in a newsletter. He never responded when I asked for more info, but fortunately our Jamf rep was able to provide me with the info I added to my original post. I guess there's something in AppleSeed cloaked in an NDA.


Are there any sources, links, articles that cover the topic? So far I have not been able to find anything on this error in the trade press or the relevant blogs.


This is totally surrounded in apples NDA. Suffice it to day, be ready to update to 12.6.1 ASAP if you are wanting to block macOS 13.


From what I understand, the "fix" that Apple made for 12.3+ systems only applies to Supervised systems. That should be good for most of us, but for those that have a couple of unsupervised systems in their fleet, be advised that you may want to defer minor until there is some sort of fix.


Apple on top of things as always with documentation being a day late and a dollar short. Apple needs to do better if they hope to get anywhere with enterprise. This should have been shared before release, and we should have more than 30 days to address it.

 

https://support.apple.com/en-us/HT213471


Is no one actually bothered by the fact that Apple is releasing the fix at the same time as Ventura, which in itself is a contradiction and the solution "first install 12.6.1" works so wonderfully well with the mass command, which can take 2 weeks or longer until all devices are up to date?


Is no one actually bothered by the fact that Apple is releasing the fix at the same time as Ventura, which in itself is a contradiction and the solution "first install 12.6.1" works so wonderfully well with the mass command, which can take 2 weeks or longer until all devices are up to date?


Oh, I am irate about this one and went off on our Apple reps about it. This fix should have come out a month ago at worst. That or they should have delayed Ventura to give more than 30 days to get it out there. 

 

Event better, that 30 day grace period apple was so gracious to give us for MDM enabled devices. Ya that ends on Thanksgiving day (for the US). So most offices will be closed and users can update to Ventura while everyone is out of the office. Apple really needs to get away from 4th quarter Major OS releases. 


Is no one actually bothered by the fact that Apple is releasing the fix at the same time as Ventura, which in itself is a contradiction and the solution "first install 12.6.1" works so wonderfully well with the mass command, which can take 2 weeks or longer until all devices are up to date?


Very bothered. The cynic in me suspects Apple isn't concerned because this will help drive Ventura install numbers.

I do have a glimmer of hope because the support doc mentions "at least 30 days" a couple of times, but I'm not counting on them to give more time.


Is no one actually bothered by the fact that Apple is releasing the fix at the same time as Ventura, which in itself is a contradiction and the solution "first install 12.6.1" works so wonderfully well with the mass command, which can take 2 weeks or longer until all devices are up to date?


Super bothered. Like @AJPinto said, Apple should have provided a fix prior.

The thing that gets me is you see the Ventura logo/banner Update first. In order for users to see the 12.6.1 update, they got to click the "Additional Available" updates or whatever. 


agreed this is filed under 'bad apple' but.. if you disable SW update.. pref pane / binary..  they can't update? or.. have a missed something along the way.. 


agreed this is filed under 'bad apple' but.. if you disable SW update.. pref pane / binary..  they can't update? or.. have a missed something along the way.. 


I have done this to help deter users, but that will not stop people who know how to run OS updates with terminal. 

 

I have a feeling if you block the softwareupdate binary you will also break your ability to tell updates to install. I have not tested it, but that seems like an Apple thing to do.


I have done this to help deter users, but that will not stop people who know how to run OS updates with terminal. 

 

I have a feeling if you block the softwareupdate binary you will also break your ability to tell updates to install. I have not tested it, but that seems like an Apple thing to do.


św bin blocked.. and updates via System Prefs work fine.. been good for 12.x - 12.5 - 12.6 etc. 


Oh I’m sorry, I completely misinterpreted your post. I apologize!

 

I’m glad your organization is having a better experience than mine. Not being able to defer Monterey past 90 days was very rough on us, and I’ve been working with Jamf (great) and Apple (not so great) for over a year on management issues especially around patching. Then on the other side I have a demoralized team and a bunch of frustrated end users.

Anyway sorry again and also for sidetracking this thread.


Ray, no need to apologize. We are all in upgrade mode and are all just trying to get the job done. I'm hoping Apple will communicate more with us on things like this in the future. 👍


św bin blocked.. and updates via System Prefs work fine.. been good for 12.x - 12.5 - 12.6 etc. 


Do you have Restricted Software in place? They could download the full installer on a personal Mac and drag the 12 GB full installer over?