Today, Apple released the 27 series of operating systems, including macOS 27 and iOS 27, representing the culmination of years of work by engineers that you’ll (probably) never meet. This latest release is a “modern day Snow Leopard” release which is focused on reliability and refinements after a particularly rocky release last year.
Last year, on the release of the 26 series of operating systems, we did not defer the update, but rather messaged that we would support any of our users who updated as best we were able. Day Zero support has long been a professional standard of excellence, an indication that your IT department is operating on all cylinders, ready to support the people who choose to use Apple devices at work.
This year, I made a different decision: a short delay of 25 days. Let’s make it to the other side of our busiest days of the 2026 calendar. We’re welcoming dozens of bands to Merriweather as part of All Things Go in less than two weeks, and some of the world’s best musicians as part of Tom Morello’s Power to the People the weekend after. Now is not the time to introduce any kind of change that doesn’t drastically make our lives better.
By Apple’s own definitions, this year’s releases are incremental refinements, albeit ones that come with a better Siri, and security enhancements that may or may not make it to our fleet of machines running the 26 series. There’s risk in staying behind, but the risk of updating amidst the preparations for these business critical days was a more pressing factor.
My cap is off to everyone who has been cranking hard in Cupertino and parts elsewhere to make these new releases sing. My beta testing has largely been free of the kind of show-stoppers that have happened in previous years, and there have been some wholesale improvements (especially to local search and AI-driven retrieval) that have a lot of potential for making my coworkers’ lives better.
As the Go/No-Go card in our Jira board came up last week, I found myself asking a set of questions that would guide our decision:
- Is there a real risk of show-stopping issues in the new version?
- Is there a real risk of critical security vulnerabilities in the 26.x series of OS that will only be fixed in the new version?
- Does anything we deploy not work in macOS 27?
- Does anything we deploy work substantially differently in macOS 27?
- What is the possible friction of making an update available while we’re operating at a very rapid cadence?
Is there a risk of show-stoppers in the new version?
The answer for us is, as of the release candidate, there has not been an issue found in our (detailed, recorded, and measured) testing that would slow us down. That’s the ideal result of any testing cycle. Thankfully, we got that this year. With only two full business days to test the release candidate, even though we got a green board, it involved weekend testing to accomplish. Not ideal.
So, why delay? Hedging against what we don’t know yet. Tests are not real world usage. Tests are short-term build-by-build rubric-driven experiences that are done in hours, not experienced over days.
Is there a real risk of a security problem only fixed in 27?
Yes, that’s possible. We’re still resolving the list of CVEs and KEVs that have been fixed in 27 but not by a 26.x update. If this list proves… problematic, there’s an easy fix here to remove the upgrade block and gently encourage an update.
For now, the risk of bugs versus the risk of security is leaning more toward the former being a bigger risk than the latter. If the balance tips, we can adjust.
Does anything we deploy not work?
As of the release candidate build late last week, we are showing a green board on all our critical tools, at least in sparing testing.
Does anything we deploy work differently?
There are a couple major changes in the 27 series of releases that are different, and have management differences:
- Siri is brand new, and is a major improvement.
- Search is drastically different, and every device upgraded will likely spend its first 24-48 hours updating its indices, if it’s upgrading from 25.5.2 or earlier.
- There are changes to the management systems for permissions around centrally-delivered tools. We were able to adapt our profiles appropriately, thanks to hard work done by our team and by the team at SimpleMDM and Apple alike. We’re not all the way here yet, but there’s no major annoyance chain here that we can’t resolve.
We’re largely good here.
What is the possible friction of making an update available while we’re operating at a very rapid cadence?
And here’s the one that led me down the path of delay.
In all of these choices, there’s an element of dry choices that assume that we’re operating at the same cadence every day. Right now, we’re in the height of busy season, and we’ll do more than 200 shows in the 75 days between September 1 and November 15. This is the worst possible time to spring change on people.
But, beginning in about 3 weeks, we’ll be through the hardest part of that 75-day period, and we can start to give every one of our staff the opportunity to upgrade if they want to try the new versions. We won’t interfere in anyone’s personal devices, and if we get requests to upgrade (or if someone evades our blocks somehow) we’ll support them as best we can.
Balancing deployment against your busiest season and the sheer frustration of getting upgraded outside of your control is an avoidable compromise.
As Mac Admins, we get to make these choices with the help of our coworkers. For now, I’m keeping mine safe and productive where they have been. We’ll enforce an upgrade once we’re through the worst, and I’ll never deploy a blanket 90-day delay when I can answer the middle 3 questions positively. I see a lot of admins reflexively pushing a 90-day delay even when those answers check out, and that always bums me out. There’s never a perfect time to upgrade, just a time that you can live with.
We’re always going to be moving forward, adapting to new technologies. Choosing when to make the push, though, that’s a business decision as much as it is an IT one.
For all out there making these decisions elsewhere, what are you seeing? Let me know in the comments.

