Apple’s Worldwide Developers Conference (WWDC) 2025, this week brought a number of fantastic updates and features to all Apple platforms. During the opening keynote, Apple announced the convergence of their version numbers, conveniently moving all their platforms, macOS, iOS, iPadOS, tvOS, visionOS and watchOS, to version 26! In addition to showcasing many impressive consumer features, Apple announced important enhancements coming to their device management protocol as well as Apple Business Manager and Apple School Manager.
The information provided below documents the new enterprise-related updates and features announced in Apple’s WWDC information sessions. You can access these sessions at your convenience through Apple’s Developer Program website https://developer.apple.com/wwdc25/.
Bookmark this page! In the coming weeks, we’ll update this article, adding more details as they become available. Although beta releases are not supported with Omnissa Workspace ONE UEM, we are currently testing to ensure backward compatibility with existing Workspace ONE UEM features upon software upgrade launch in Q3 2025.
Note: This article does not indicate support for any of the features below with Workspace ONE UEM.
Device Management Updates
Software Update Management
Apple has finalized the shift to declarative software update management, extending support to Apple TV (tvOS 18.4 or later) and Apple Vision Pro (visionOS 26). This modern approach replaces the older MDM-based process involving commands, queries, configuration profiles, and restrictions. Updates can now be enforced using the Software Update Enforcement configuration, with proactive status reporting enabled. The Software Update Settings configuration allows fine-tuning of update behavior on supervised devices, including notification timing, version deferrals, automatic download and install settings, etc.
Note: Software update management using mobile device management commands, restrictions, the com.apple.SoftwareUpdate payload, and queries is deprecated and Apple will remove it next year. Going forward, organizations can manage and enforce software updates using only declarative software update management.
App Preservation and VisionOS support for Return to Service
Return to Service is now supported on Apple Vision Pro, extending the existing functionality from iPhone, iPad, and Apple TV. It allows a device to be reset and automatically reconfigured for the next user—without manual setup. On iOS, iPadOS, and visionOS 26, it can also preserve Managed Apps by securely erasing user data while keeping app binaries intact for faster redeployment. Vision Pro users can trigger it via the Lock Screen or Control Center, and it can also be set to launch automatically after a defined period of inactivity using the TemporarySessionTimeout key in SharedDeviceConfiguration.
Battery health for iPad
The DDM status report now also provides the battery health information, which provides increased visibility of device health. On an iPad with iPadOS 15.4 or later, the following iPad models can report their battery health status:
- iPad Pro (M4)
- iPad Air (M3)
- iPad Air (M2)
- iPad (A16)
- iPad mini (A17 Pro)
Safari management
On iOS, iPadOS, macOS, and visionOS 26, new MDM keys and declarative configurations provide greater control over Safari. Admins can preconfigure bookmarks in organized folders for quick access to key sites, define what users see when opening new tabs or windows, and customize additional Safari settings to align with organizational needs.
Managed Setup Assistant on Apple Vision Pro
Automated Device Enrollment on Apple Vision Pro with visionOS 26 offers a seamless, zero-touch setup experience for managed devices. It supports skipping specific Setup Assistant panes, such as location selection and terms and conditions, defaulting to the most privacy-focused settings for each. When used with Return to Service, additional panes can also be skipped, including Optic ID, Passcode, and Data & Privacy, helping streamline setup and enhance user privacy during device re-provisioning.
Apple Intelligence features management on VisionOS
On an Apple Vision Pro with visionOS 2.4 or later, devices can use Apple Intelligence features and can also have device management controls similar to those available on iPhone, iPad, and Mac.
Messaging and Calling App Restrictions
With iOS 18.4 and iPadOS 18.4 or later, admins can prevent users from changing the default calling and messaging apps. Starting with iOS and iPadOS 26, they can also preconfigure which apps are set as default for Calling and Messaging using Settings command. On cellular devices running iOS and iPadOS 26, access to iMessage, FaceTime, and RCS can be limited to managed services by restricting usage based on specific SIM profiles (ICCIDs), ensuring only approved lines are used for communication.
Network Relay Hostname Support
Network relays offer a secure, seamless alternative to VPN for tunneling traffic. With iOS 18.4, iPadOS 18.4, macOS 15.4, tvOS 18.4, and visionOS 2.4 or later, the com.apple.relay.managed configuration now supports fully qualified domain names (FQDNs) alongside domain-based rules. This update provides greater flexibility in managing which traffic is routed through the relay. When MatchDomains is specified, only subdomains of excluded FQDNs are bypassed. If no match rules are set, all traffic—except explicitly excluded FQDNs—is routed through the relay.
Audio Accessory Settings Enhancements
iPhone and iPad now show the friendly name of nearby AirPods (with H1 or later chip) during setup, making it easier for users to identify their own device. If multiple AirPods are in pairing mode, users are directed to Bluetooth settings to manually select the correct one. On supervised devices running iOS and iPadOS 26 including Shared iPad, a new configuration for Audio Accessory Settings supports temporary pairing of AirPods and Beats (H1/H2) without syncing to iCloud. These temporary pairings automatically clear at midnight by default (customizable by admins), and users can optionally convert them into permanent local pairings via a new button in Headphone Settings. This is ideal for shared-use environments like classrooms or shift-based workplaces.
Automatic Reboot
Introduced in iOS 18.1 and iPadOS 18.1, Automatic Reboot enhances device security by rebooting locked devices after prolonged inactivity, clearing sensitive data from memory. Starting with iOS and iPadOS 18.4, admins can control this behavior via a management setting - IdleRebootAllowed. While useful for security, Automatic Reboot is off by default on supervised devices and may disrupt Wi-Fi connectivity, potentially affecting device management tasks that rely on constant network access.
App Management Updates
Declarative App Management
Continuing down the Declarative Device Management track, Apple has brought more App Management enhancements into the picture. This shift will not only apply to App Store based apps for iOS, iPadOS, macOS and visionOS devices, but also to packages (.pkg) for Mac devices. With this shift it will allow organizations to:
- Control the app update behavior on a per-app basis
- Pin an app to a specific version
- Restrict app downloads over cellular networks (iOS and iPadOS)
Configuring Managed Apps
Also announced was an enhanced structure to configure managed applications called the ManagedApp framework. This framework not only allows you to configure static variables, such as a server or timeout value (like the previous AppConfig), but also secrets. Secrets could be an API token or identities used for authentication, and they are handled in a highly secure manner. This will be available for iOS & iPadOS 18.4+ and visionOS 2.4+, and requires the app to be managed using DDM.
Identity Management Enhancements
Two years ago, Apple introduced Platform Single Sign On (SSO) for macOS, allowing users to log in to their Mac device using credentials from a supporting Identity Provider (IdP). Omnissa customers were able to adopt Platform SSO from day one. Platform SSO requires 3 components, an SSO Extension profile deployed by Workspace ONE UEM, a Platform SSO extension installed on the Mac (Okta Verify or Microsoft Company Portal App today), and a supported IdP (Okta or Entra ID today).
At WWDC, Apple announced a number of new improvements and enhancements to Platform SSO.
Platform SSO and Device Attestation
Platform SSO extensions can now use device attestation to ensure the device it is running on is trusted, and furthermore, use this trust to silently and securely perform device registration.
Platform SSO and Automated Device Enrollment
Platform SSO can now be enforced at setup, so that users must authenticate using credentials from their organization's IdP before proceeding. When enabling this, Platform SSO will be the first setup pane users will see.
Platform SSO and Automated Enrollment and Sign In
Once authenticated, SSO can now provide an authenticated enrollment into Workspace ONE UEM. If using the same IdP for Managed Apple Accounts, the user can also be automatically signed into their Managed Apple Account. A local account is created based on the user’s IdP and Platform SSO now supports syncing a user's profile picture from the IdP too.
Platform SSO and Authenticated Guest Mode
Platform SSO supports a shared device use case where users can log in to any Mac using their IdP credentials. The user will get SSO for their applications and websites. Once the user logs out, their local data is erased for that account. This feature is called Authenticated Guest Mode.
Platform SSO and Tap To Login
To support a shared device use case, Apple has introduced Platform SSO Tap to Login, which allows users to log in by tapping their iPhone or Apple Watch on a connected NFC reader. The feature uses an access key credential tied to the user’s IdP account.
These improvements to Platform SSO make the entire Platform SSO setup experience and enrollment more seamless for the user as well as introducing support for shared devices and Tap to Login.
Finally, Apple announced they are deprecating the com.apple.sso (SSO) profile for iPhone and iPad. This profile can no longer be used to configure Kerberos SSO, and so the com.apple.extensiblesso (SSO extension) profile should be used instead.
Apple Business Manager and Apple School Manager Updates
Apple Business Manager (ABM) received several significant updates at WWDC 2025, enhancing control, automation, and integration for IT administrators, especially those using MDM products like Workspace ONE UEM.
Device Management Migration
A major improvement is the ability to migrate devices between management services without requiring a full device erase, streamlining transitions during mergers or infrastructure changes.
Apple introduced console functionality and an API in ABM to re-assign devices to a different Device Management server. Once configured, Apple allows a device to enroll into the new device management system without requiring a device reset. Migration is limited to devices enrolled with Automated Device Enrollment.
Migration still requires the need to manually migrate profiles, policies, and applications. At Omnissa, this is something we already help many customers with through our Workspace ONE Migration Tool.
With the new functionality from Apple and the Workspace ONE Migration Tool, organizations will be able to seamlessly migrate to Workspace ONE UEM in order to consolidate their device management tooling.
Restrict Sign-in To Managed Apple Account
A new access management setting allows organizations to restrict sign-ins on corporate-owned devices to only Managed Apple Accounts, improving security and compliance.
New APIs
The platform now supports APIs for automating device management tasks, such as assigning devices and retrieving device information. Warranty and AppleCare coverage details, along with IMEI, EID, and MAC address data, will also be made available for better asset tracking.
Additionally, alternative service discovery for account-driven enrollments and more granular privileges for the Device Enrollment Manager role provide greater flexibility and control.
Summary
These updates collectively enhance the scalability, security, and efficiency of managing Apple devices in business environments.
If you would like to dig in on all the products and features Omnissa offers to help you manage Apple devices at scale, please visit https://www.omnissa.com/apple.
For more information on Apple’s new enterprise features, check out the following WWDC 25 session What’s new in Apple device management and identity.
Workspace ONE App and Feature Support
Based on internal testing, the following is a list of compatible versions of our apps.
| Name of the App | iOS 26 supported version | iPadOS 26 supported version | macOS Tahoe supported version |
|---|---|---|---|
| Intelligent Hub | 25.07 | 25.07 | 24.11.3 |
| Boxer | 25.07 | 25.07 | N/A |
| Content | 25.06.1 | 25.06.1 | N/A |
| Web | 25.06 | 25.06 | N/A |
| Tunnel | 25.04.1 | 25.04.1 | 25.04 (Outside App Store) 22.04.6 (App Store) |
| Assist | 25.08 | 25.08 | 25.09 |
| PIV-D Manager | 25.05 | 25.05 | N/A |
| Intelligence SDK | 25.7.0 | 25.7.0 | N/A |
| SDK (Swift) | 25.06.0 | 25.06.0 | N/A |
| Send | 25.05 | 25.05 | N/A |
| Mobile Threat Defense | 25.08 | 25.08 | N/A |
| Freestyle | All supported versions of UEM | All supported versions of UEM | All supported versions of UEM |
| Employee Experience (DEEM) | N/A | N/A | 25.03 |
此頁面對您有幫助嗎?