Apple @ Work is exclusively brought to you by Mosyle, the only Apple Unified Platform. Mosyle is the only solution that integrates in a single professional grade platform all the solutions necessary to seamlessly and automatically deploy, manage, and protect Apple devices at work. Over 45,000 organizations trust Mosyle to make millions of Apple devices work ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.
For my entire IT career, software updates have operated on a predictable schedule. IT administrators have been conditioned to build workflows around quarterly point releases or monthly patching cycles (Patch Tuesday). However, as AI tools become very proficient at automatically discovering software vulnerabilities, threat actors are moving faster than ever before. With that being said, I very much miss 18th-month macOS/OS X releases.
We are rapidly entering an era in which software updates will look less like traditional operating system updates and more like continuous cloud updates. To survive this shift, IT teams must understand the three prongs of modern patch management.
About Apple @ Work: Bradley Chambers has been an Apple IT admin since 2009. Through his experience deploying and managing firewalls, switches, a mobile device management system, enterprise grade WiFi, 1000s of Macs, and 1000s of iPads, Bradley will highlight ways in which Apple IT managers deploy Apple devices, build networks to support them, train users, share stories from the trenches of IT management, and ways Apple could improve its products for IT departments.

Prong 1: Re-educating the end user
The first pillar of this new world has to center completely on user experience and education. End users will have to accept a much more aggressive update approach. For years, users have treated operating system updates as optional annoyances that can be deferred until the last possible minute. In an era where zero-day vulnerabilities can be weaponized in just a few hours, that behavior is a massive liability. We might be entering an era in which zero-day issues occur almost monthly.
IT departments must prepare their workforces for frequent, mandatory interruptions. Much like applications such as Zoom or web browsers, which update constantly in the background, operating systems will require similar frequency of updates. Employees must understand that short-term disruption to their immediate productivity is a necessary trade-off to prevent data breaches for their organization.
Prong 2: Shrinking IT deployment windows
The second prong places an immense operational burden directly on IT deployment teams. Historically, an administrator might take 90 days to test a major operating system update against corporate applications before pushing it to production fleets. That timeline is completely dead, and I think 90 days might turn into 9 days or even 9 hours.
Testing windows must shrink from months to weeks, days, or even hours, depending on the severity of the threat found. IT teams will need to lean heavily on device management tools to enforce compliance rules instantly. If a critical patch drops, administrators might need to prepare to automatically lock any device that remains unpatched by the end of the week or the end of the day, forcing the update before the user can resume work.
There might also need to be a distinction for different classes of employees as well. Developers with privileged access might need to see shorter windows than those in roles without it.
Prong 3: The operating system architecture burden
The final prong lies squarely on the shoulders of the operating system vendors themselves. Google had a massive advantage when designing ChromeOS because they built a cloud-first platform from the ground up to support silent, background updates with near-instantaneous reboots. I manage 100s of Chromebooks, and it’s incredible how they stay up to date. Apple and Microsoft are carrying decades of legacy desktop architecture originally optimized for physical media installation.
Apple has made significant strides here with declarative device management and Rapid Security Responses, enabling smaller security fixes to be installed without massive downtime. However, a standard macOS point release can still take 20 minutes of install time. Apple must continue to re-engineer the update process so that reboots happen seamlessly and, perhaps most importantly, application state is perfectly restored upon login, so users do not lose their active workspace layouts. I will say, Apple is light-years ahead of Microsoft, though. I’ve had Macs major releases (Ventura) behind and I can get them up to date with round of updates/reboot. I’ve had Windows 11 PCs that come out of the box, which take 4-5 rounds of reboots, random updates fail, and then you still have firmware updates on top of that.
9to5Mac’s take
The acceleration of security threats because AI means that patch management can no longer be a secondary task handled on a very predictable schedule. It must become a core, continuous discipline. In Apple environments, the infrastructure to support this is already being delivered through declarative device management technology. The technology exists, but IT leaders must shift their organizational mindsets to keep pace with modern threats. If you make the update process too slow or too painful, your users will fight it, and in the AI era, a delayed patch is an invitation for a breach. Apple has some work to do, though. More updates are needed across macOS and iOS without requiring a reboot, and it’s not going to be easy for Apple to retool how they work.
Apple @ Work is exclusively brought to you by Mosyle, the only Apple Unified Platform. Mosyle is the only solution that integrates in a single professional grade platform all the solutions necessary to seamlessly and automatically deploy, manage, and protect Apple devices at work. Over 45,000 organizations trust Mosyle to make millions of Apple devices work ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.
FTC: We use income earning auto affiliate links. More.

Comments