Description
There are many ways to enforce software updates with Jamf Pro. The most common options for Apple Silicon computers are:
Apple's built in automatic updates
This article will focus on configuring Apple's automatic updates.
Automatic Updates
If your organization wants managed computers to stay up to date without having to re-send a command every update, we can use Apple's built-in automatic update feature. With this option, the update downloads automatically and the end user is prompted to restart.
We can configure this setting using either blueprints or a configuration profile in Jamf Pro.
Automatic Updates via Jamf Pro Blueprints
If you meet the requirements to use blueprints, it is the preferred option.
Requirements
Enable OIDC-based SSO through Jamf Account in Jamf Pro and sign in to Jamf Pro with Jamf ID or IdP credentials from SSO Connection in Jamf Account
Device requirements:
tvOS 18.4 or later, supervised
iOS 18 or later, supervised
iPadOS 18 or later, supervised
macOS 15 or later
Configuring the Blueprint
In Jamf Pro go to Blueprints in the left sidebar.
Either open an existing blueprint or click + Create blueprint in the top-right corner.
For new blueprints, provide a name and description and click Create.
Select Software Update Settings from the list of Blueprint options.
Click Configure for Install actions.
Check the boxes to enable the desired settings. Set automatic installs of available updates to Always for devices to automatically attempt to install available OS Updates.
Click Update.
Configure any other desired Software Update Settings and click Save.
Configure any other blueprint settings as desired.
Click Scope and check the boxes for desired device groups. Jamf recommends testing first.
Click Deploy.
Turning On Automatic Updates
We can enable Automatic Updates with a configuration profile in Jamf Pro if the requirements for blueprints are not met.
In Jamf Pro, navigate to Computers > Configuration Profiles and click New.
Provide a name and set to Install Automatically.
Click the Software Update payload and click Configure.
Check the box for Automatically install macOS updates and any other desired options here.
Click Scope and add the desired group of devices.
Click Save.