
WWDC Revisited: The MacAdmin Checklist
Adam Selby
Every year at WWDC, Apple outlines its vision for its platforms for the next year. This means OS updates for iOS and macOS of course, but it also means updates to how MacAdmins manage Macs in their organizations. After the keynote Apple publishes dozens of sessions, including one called “What's New in Managing Apple Devices”. There are two changes I specifically want to revisit and callout, along with a checklist of what you should do during this public beta period.
In this session each year, Cyrus Daboo conveys the direction that Apple is moving towards with device management. We’ve been told that declarative was the future of device management, but this year we’ve crossed over to an important milestone. Now, the standard for device management is declarative management. This year alone, Apple introduced nearly a dozen new declarations, along with improvements to existing ones. Beyond just what’s new or changed, Apple has also removed some previously deprecated legacy controls. As one prominent example, software update management MDM commands and restrictions are not present in macOS 27. The only way to manage software update now is with declarative management. Luckily, if your device management service already had made this transition, there isn’t much that changes for you.
Privacy management also got a huge improvement, with the introduction of a new consolidated privacy consent prompt. In the past, users opening a meeting app for the first time would receive individual permission prompts for camera, microphone screen recording, etc. While Apple’s focus on privacy is great, this experience was always less than ideal. Now, MacAdmins can use a new declaration to unify these privacy consent prompts, complete with custom text to provide context to users. User privacy is still respected, but now there is an easy way for your users to know what these permissions are used for. One caveat as of the public beta: Screen Recording isn’t included here, so be sure to file feedback.
Apple has lots of detail on all the changes in What’s New for IT at WWDC26 in the Apple Platform Deployment guide, but here are the top items I think MacAdmins should focus on before macOS 27 is available later this year.
The Checklist
- Test and confirm your software update configurations and workflows
- Test for dependencies on Rosetta (it’s removed when upgrading to macOS 27)
- Prepare your network environment for stricter security requirements (macOS 27 includes new requirements for network connections, test with your network teams)
- Adopt new consolidated privacy consent prompts (legacy profiles are deprecated)
- Move Apple Intelligence and Siri configurations to declarative (legacy MDM restrictions keys are deprecated in macOS 26.4)
- Confirm you have no dependency on
com.apple.applicationaccess.newfor app allowlist and denylisting (deprecated in macOS 27) - Move network configurations to declarative
- Plan replacement of any Intel-based Macs: macOS 26 was the last release with support (with security updates until Fall 2028) — macOS 27 is only supported on Macs with Apple Silicon
- Optionally, suppress user notifications about apps that require Rosetta with
allowRosettaUsageAwareness
- Test and adopt Managed Migration Assistant if it makes sense for your organization
Want to hear more about this year's beta cycle? Join David Starr and Tom Bridge for a practical conversation on the 2026 macOS beta cycle in our webinar Beyond WWDC: What the 2026 macOS beta cycle looks like in the field. They'll talk through what’s actually working, what’s still rough, and what IT teams should be paying attention to as the fall release gets closer.