What's new for enterprise in macOS Golden Gate 27

Learn about the enterprise content that Apple has released for macOS Golden Gate 27.

macOS updates improve the stability, performance, or compatibility of your device and are recommended for all users. Device administrators can manage software updates using a device management service.

For information about general improvements, learn about updates to macOS Golden Gate.

For details about the security content of these updates, see Apple security releases.

macOS Golden Gate 27

macOS Golden Gate includes new features such as management for launching app and binaries, consolidated privacy consent for apps and websites, and enhancements for Platform Single Sign-on (SSO).

Device management

  • Device management can manage which apps or binaries are allowed to run.

  • Device management can configure a consolidated consent prompt for users to grant an app or website the necessary default privacy permissions.

  • Platform SSO can be configured to authenticate with your identify provider using OpenID at FileVault unlock, the Lock Screen, and at the login window. This supports multi-step and multi-factor authentication flows as well as QR code sign-in.

  • Additional enhancements for Platform SSO include network controls and captive network support at login or unlock, options to require Touch ID or Apple Watch at login or unlock, and FileVault support for Authenticated Guest mode.

  • On devices with iOS 27, iPadOS 27, macOS 27, and tvOS 27, log collection required as part of an AppleCare ticket can be started remotely on supervised devices using device management.

  • New network configurations are available in declarative device management including VPN, DNS, and relay.

  • New reporting options are available for content caching using declarative device management.

  • The ManagedApp framework is now available on macOS.

  • Device management can restrict the use of Siri AI, Visual Intelligence, and Natural Language Calendar Event Editing.

  • Device management can configure the desired behavior when a managed package is removed, ensuring unwanted data and files are not left behind on devices when no longer needed.

  • New assessment mode features on macOS for education assessment will help app vendors manage standardized testing using Apple devices.

  • ACME and SCEP credential asset declarations have new controls to configure whether the certificate credential is only available after first unlock.

  • New status items are available that provide proactive information about a device, including the enrollment type, lockdown mode status, and when it is waiting in Setup Assistant for the device management service.

  • Legacy MDM profiles can now be delivered as declarative assets.

  • The new Liquid Glass setup pane can be skipped by device management.

  • Reliability is improved when enrolling a Mac in a device management service for the first time during setup using Automated Device Enrollment.

  • When applying the deprecated Accessibility key in the Privacy Preferences Policy Control payload, the user is shown a notification once for each configured app so they are aware the app can access their data, monitor their keyboard and websites, record their screen, and more. Additionally, the user can disable accessibility permissions granted by device management in System Settings.

  • Legacy software update management no longer functions in all 27.0 operating systems. This includes: software update commands, software update queries, recommended cadence settings, and software update restrictions, like deferrals and Background Security Improvements. IT teams should use declarative software update management to configure and enforce updates on devices with increased user transparency and more control.

Bug fixes and other improvements

  • The macOS menu bar dynamically adapts when there isn't enough space to show every item. Menu bar items are hidden and replaced with a compact overflow indicator that surfaces the hidden items when pressed.

  • App Attest is now available to verify the authenticity of Mac apps.

  • The new tccutil list command can report current privacy authorizations for specified services or apps on managed devices. Refer to tccutil --info for more information.

  • Apps can no longer access the local TCC database directly.

  • If Rosetta was previously installed, it will not be automatically restored upon upgrading to macOS 27. Rosetta will continue as a general-purpose compatibility tool through macOS 27.

  • File enumeration performance is improved for SMB directories with a large number of files.

  • Resolved an issue where shared Mac computers may display a black screen after a user logs in.

Published Date: