Skip to content

DDM Software Update Not Installing

A Software Update Enforcement Specific configuration is assigned to an Apple device, but one of the following happens:

  • The deadline passes and the device is still on the old version.
  • The device reports the install state failed, or a failure count above 0.
  • The update never appears on the device.
  • The configuration itself shows an error.

With DDM, the device — not CapaOne — downloads, prepares and installs the update. It only installs when all of these are true:

  • The device runs DDM, and its OS supports the configuration (iOS or iPadOS 17 or later, macOS 14 or later).
  • Apple currently offers the target version to that device model.
  • The device can install the target version from the version it runs now — for example, a supplemental update needs its base version.
  • The device meets the install conditions: enough battery or connected to power, enough free storage, and network access to Apple’s update servers.
  • On Mac, the update can be authorized — with a bootstrap token, or by the user.

If any of these isn’t met, the configuration stays active and the device waits. It doesn’t produce an error in every case.

Work through the checks in order.

  1. Open the device in Apple → Endpoints and select the Configurations tab.
  2. Check that the enforcement is listed under Assigned with the DDM label.
  3. If it shows an error icon, look up the code in DDM Status Reason Codes.

If the configuration isn’t listed at all, check that it’s assigned to a group the device is a member of, and that the device runs DDM — its badge shows Supervised DDM, Unsupervised DDM, or Kiosk Mode DDM. See Enable Apple DDM.

2. Check that Apple offers the target version

Section titled “2. Check that Apple offers the target version”
  1. Open gdmf.apple.com/v2/pmv. This is Apple’s public list of the OS versions it currently offers, per device model.
  2. Under the platform (iOS for iPhone and iPad, macOS for Mac), find the Target OS Version from your configuration.
  3. Check that the device is listed under SupportedDevices for that version. iPhone and iPad are listed by model identifier, for example iPhone17,1. Macs are listed by board ID, for example J414cAP or Mac-….

If the version isn’t listed, or the device’s model isn’t listed for it, the device can’t install it. The configuration stays active without effect. Create a new enforcement for a version Apple offers, and remove the old one.

3. Check the path from the current version

Section titled “3. Check the path from the current version”
  • Supplemental updates — an update such as 27.0.1 (a) only installs on a device that runs exactly 27.0.1. Use two enforcements: one for the base version with an earlier deadline, then one for the supplemental version, with the build version and its letter suffix in Target Build Version. See Enforce a Specific OS Update.
  • Already newer — a device that already runs a newer version than the target doesn’t downgrade. The enforcement has no effect on it.
  • Major versions — check that the device model supports the target major version at all. Devices Apple dropped from a release are not listed for it in step 2.

DDM devices report their software update state on their own, but CapaOne doesn’t show these values as separate fields today. Check the device’s OS version on its page, the configuration’s Endpoints tab for the endpoint’s Status, and Settings → General → Software Update on the device. The values the device reports are:

What the device reports What to look for
Install state downloading or prepared — the update is on its way; wait. failed — continue below. none with the old OS version — the device isn’t processing the update; recheck steps 1–3.
Pending version Should show your target version and, for an enforced update, the enforcement date and time. If it shows another version, a different enforcement or the user started another update.
Install reason declaration means your enforcement is driving the update.
Failure reason Count, last reason, and time. The reason text usually points to the cause — for example, insufficient storage or battery.
Condition What to check
Battery The device needs enough charge, or to be connected to power. Ask the user to connect the device to power.
Storage Major updates need several GB of free space. Check free storage on the device page.
Network The device must reach Apple’s update servers. Check that your firewall or proxy allows Apple’s software update hosts. See Apple’s Use Apple products on enterprise networks.
Device off or offline at the deadline Expected. When the device is back on and connected, it shows a past-due notification and tries to install within about an hour.
Content caching If you use a content cache, check that it’s healthy — a broken cache can slow downloads.

On Apple silicon Macs, the installation must be authorized. If the update can’t be authorized automatically, the user is asked for their credentials at the deadline — and if nobody is there, the update waits. Ask a user to be at the Mac at the deadline, or choose a deadline when someone is.

  • Deferrals — a long deferral in Software Update Settings hides new updates from the user, but doesn’t stop an enforcement for a version Apple offers.
  • Automatic actions — Install OS Updates set to Always Off stops automatic installs, but not an enforced deadline.
  • Legacy software update settings — on OS 27, they’re ignored. On older versions, DDM software update configurations take precedence over the equivalent Legacy MDM commands.
  • Several enforcements — if a device has enforcements for two different versions, it processes the ones Apple offers. Remove enforcements for old versions.

If the device still doesn’t update, contact CapaOne support. Include:

  • The configuration’s name, Target OS Version, and Target Local Date/Time.
  • The device’s model, OS version, and whether it’s Supervised.
  • What the device shows in Settings → General → Software Update, and the configuration’s status on its Endpoints tab.
  • No error doesn’t mean no problem — an enforcement for a version the device can’t install stays active without an error. Always check step 2.
  • The deadline is device-local time — devices in different time zones install at the same local hour, not at the same moment.
  • The device keeps trying — DDM devices retry on their own after a failure or a missed deadline. You don’t need to resend anything.
  • Unsupervised iPhone and iPad are supported — enforcement works on unsupervised devices, even though deferrals and automatic actions don’t.
  • Source: Apple’s Software Update Enforcement Specific declaration and software update status items (Release v27.0), and Apple Platform Deployment: Install and enforce software updates.