Installing iOS and iPadOS Updates

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

You can update iOS or iPadOS on an individual device or group of devices by sending an update command to devices. When you use an update command to update the operating system for devices not using the desired iOS or iPadOS target version, a workflow is initiated where multiple commands are used to query the device for available updates before a specific iOS or iPadOS update is scheduled in a separate command. Sending an update command can be used for both updates and upgrades.

For more information, see About software updates for Apple devices in Apple Platform Deployment.

Requirements
  • Target devices with iOS 14 or later, iPadOS 14 or later, or tvOS 14 or later, supervised or enrolled via Automated Device Enrollment in Jamf School

  • A valid push certificate in Jamf School

  • If you are updating a Shared iPad, ensure the following:
    • The device has enough storage capacity available for the update
      Note:

      If there are five or more users using the Shared iPad, there may not be enough storage space and you may need to remove one or more of the users.

    • No users are logged in to the device
      Note:

      Jamf recommends restarting the Shared iPad before updating to ensure no users are logged in.

    • The device has a battery level of more than 50%

  1. In Jamf School, navigate to Devices > Updates in the sidebar.
    Note:

    If Updates does not display in the sidebar, navigate to Organization > Settings in the sidebar and select the Allow Jamf School to check for OS updates (supervised only) checkbox. Available OS version updates display after device inventory data is refreshed.

  2. Expand the Filter pane and use the pop-up menus to set the criteria for the target group of devices you want to update.
    Example:

    If you want to create a target group for devices located in a particular region, use the Current Region pop-up menu to select the region the target devices are located in.

  3. Select the OS version tab at the top of the pane. All devices that have reported the selected OS version update as available during regular inventory collection are displayed.
  4. Select the devices you want to update.
  5. Choose the install action from the Update pop-up menu.
    The following install actions are available:
    • To download the update or upgrade without installing it on the device, select Download.

    • To download the update or upgrade and begin the device restart countdown notification, select Install.

      If you want to clear the passcode on devices, select the Clear the passcode(s) checkbox. If a device is locked with a passcode, the update will download but remain uninstalled until the user acknowledges the update. The user is prompted to enter their passcode to install the update or defer for an overnight installation. The user can defer the prompt up to three times before they are required to schedule an update.
      Important:

      Jamf does not recommend clearing passcodes during update workflows for security and privacy reasons. For example, clearing a passcode from an iOS or Shared iPad device with an update command will disable security functions such as FaceID and TouchID, and will remove passcode-secured items from Apple Wallet. This allows anyone with physical access to the device to use it. If a configuration profile with a passcode requirement was set, the next person to use the device is prompted to set a new passcode. Consider how this may impact your organization before using this option.

      For more information about Apple's security capabilities, see Apple Platform Security.

If the device was manually supervised with Apple Configurator, the user may be prompted to accept Terms and Conditions before the update completes.

When the update is complete, you can navigate to Devices > Inventory and click on the device you want to view. If declarative device management is enabled on the device, the OS Version field displays the updated OS version immediately. If it is not enabled, the updated OS version is displayed after the device inventory refreshes.