Posted on 09-26-2023 07:21 PM
Hi,
Is there a plist or config I can manually push to devices that allows me to defer an update for more than 90 days?
When Apple releases a new major OS, we typically wait until they are in the 14.3.or 14.4 version since I started working in a company with Apple enviornment as we have see many bugs popup for various apps. Some of the apps we use on company level take couple months as well
Posted on 09-27-2023 03:29 AM
no
Posted on 09-27-2023 04:29 AM
No, not more than 90 days. That is the official answer you will get from Apple or JAMF.
But
I have 3 macs that should have gone on to OSX 13 9 months ago, because our defer was expired, but they are still running OSX 12. So in some way ignoring it will stop the updates from instaling. Not a clue it this is a loophole that is now closed.
Posted on 09-27-2023 04:39 AM
Nope, you can only defer MacOS Updates by 90 days. Lucky for us that is December 26th, so its a good Merry Christmas for organizations that are not ready. At least we know Apple is thinking about us over the holidays.
Posted on 09-27-2023 07:39 AM
Apple will only allow you to defer macOS upgrades for 90 days. However, you can use a software restriction payload to keep users from installing macOS 14. After the 90 days run out, users will be able to download the installer, but not launch it to complete the install. Define "Install macOS Sonoma.app" in the Process Name field.
I use both restrictions in my environment in case I need longer than 90 days to test or resolve an issue.
Posted on 09-27-2023 07:54 AM
That will only work if the upgrade is being installed through the app. A couple years back, they started upgrading through the "Software Update" pane. That method doesn't run an app at all. I think OP is looking for a way to block that method. I know I'm here looking for ideas for the same thing...
Posted on 09-27-2023 08:01 AM
Not trying to start a fight or anything, but the only thing that changed when Apple switched to the "Software Update" pane for upgrades is that it does not direct you to the App Store anymore. It just downloads the app and launches it. Restricting the app still works. Give it a shot.
Posted on 09-27-2023 08:09 AM
Sometimes it works and sometimes not. Last time this happened when users were on macos12 and had the option to upgrade to 13. The Config payload works fine upto a point.
Jamf said this was a bug with Apple OS itself where they had seen this issue popup with other orgs as well
Posted on 09-27-2023 08:14 AM
That makes sense. I've seen some issues with the relationship between the config profile and how the "Software Update" panel behaves.
Posted on 09-28-2023 02:59 PM
Several of my users were able to do the install despite having the macOS Sonoma installer being blocked by restricted software. I put the restriction in place just after WWDC. For some reason the profile I created to delay macOS Sonoma wasn't installed on some systems. On my test Mac, I noticed that the installer app did not launch. The Mac simply upgraded to Sonoma in a way similar to if it had updated to 13.6. The profile I created does keep the Sonoma upgrade from appearing in Software Update, so that is how I am keeping people from upgrading along with the software restriction. I was expecting this since this was the way Ventura was released last year.
Posted on 10-12-2023 10:41 PM
Hello @jwbeatty , I'm agree with you but Apple change the habits. macOS 14 is not an app. When you click on 'Upgrade now', the system start the download and install it directly. We have a restriction profile in place to restrict major upgrade but Sonoma bypass it.
09-27-2023 07:45 AM - edited 09-27-2023 07:46 AM
The issue is sometimes an installer major upgrade acts like an inline minor update in the software update pane which bypasses the restrictions all together. which is why I asked in my original response.
yesterday
Starting with Ventura, Apple began offering OS upgrades as a delta update, reducing the size of the download. The problem with this is that these delta updates / upgrades are dynamic and don't make use of the installer app. If the OS you're using is several versions back, it will still get deployed via the full installer app, but for anything fairly recent like going from Ventura to Sonoma, it will most likely be in the form of the smaller and unfortunately, unblockable delta releases.