Explore the intersection of business and app development. Discuss topics like device management, education, and resources for aspiring app developers.

All subtopics
Posts under Business & Education topic

Post

Replies

Boosts

Views

Activity

Can an embedded macOS Login Item access an app.managed identity through ManagedApp APIs?
I’m developing a macOS application that contains an embedded User Service Login Item: Outer app bundle ID: com.xxx.app Embedded User Service bundle ID: com.xxx.app.service Team ID: DE8Y96K9QP The User Service is embedded at: OuterApp.app/Contents/Library/LoginItems/UserService.app I deployed a com.apple.configuration.app.managed declaration through an MDM server, with an asset declaration of type: com.apple.asset.credential.identity, the declaration uses: "AppComposedIdentifier": "com.xxx.app (DE8Y96K9QP)" When the ManagedApp APIs are called from the outer ZTA app, the app successfully receives the identity. However, when the same ManagedApp APIs are called from the embedded User Service, the identity list is empty. When I instead use the embedded service’s identifier: "AppComposedIdentifier": "com.xxx.app.service (DE8Y96K9QP)", macOS reports either Error.InvalidCodeSignature or Error.NotPresent. My questions are: Can an embedded Login Item or embedded subsystem be the target of an app.managed declaration and access managed identities through ManagedAppIdentitiesProvider? Or must AppComposedIdentifier always identify the top-level application that contains the embedded Login Item? If the declaration targets the outer application, is there a supported way for the embedded User Service to access the same managed identity—for example, through XPC communication with the outer application? The outer application and embedded User Service are signed by the same Team ID, and both signatures validate successfully when checked with codesign. Thanks, Ying
0
0
436
2d
Enterprise WatchOS App Won't Install on WatchOS 26.5
We have an Apple Watch app and companion iPhone app that we distribute via Enterprise Distribution using OTA manual installation. (We are on an Apple Enterprise Developer Team) With WatchOS 26.4 and earlier, the app would install fine on both the phone and the watch. However, after updating to WatchOS 26.5 (and iOS 26.5), the app will not install on the watch. It will install on the phone and we can trust the developer/run the phone app. However, when we go into the Apple Watch app on the phone and choose "Install" for the app, it tries to install for a minute and then returns an error "The app could not be installed at this time". We have tried the following remedies: Restarting both watch and phone, and reinstalling the app on phone Factory resetting both the watch and the phone, then reinstalling app Generating a new Distribution Certificate and new manual profiles for the app in Apple Developer Looking through console logs from both the phone and the watch Confirmed that we can install other (non-Enterprise) apps on the watch Try installing a basic example app (the default Xcode watch + companion app project) There does not seem to be anything obviously amiss about the app or its packaging, it seems to be something to do with the update to WatchOS 26.5. The closest related errors we have found seems to be these: appconduitd 0x16d43f000 -[ACXInstallQueue _onQueue_deQueueNextOperation]_block_invoke_3: Failed to install app .EnterpriseInstallTest.watchkitapp (p = Y, ui = Y) : Error Domain=ACXErrorDomain Code=8 "Failed to create socket" UserInfo={NSUnderlyingError=0xcf9138e10 {Error Domain=com.apple.identityservices.error Code=20 "Socket open timed out" UserInfo={NSLocalizedDescription=Socket open timed out}}, FunctionName=-[ACXServerInstallOperation _onQueue_prepForTransferAndInstall]_block_invoke, SourceFileLine=370, NSLocalizedDescription=Failed to create socket} appconduitd 0x16d89f000 -[ACXCompanionSyncConnection _installQueuedOrCompletedForWatchBundleID:companionAppBundleID:withName:userInitiated:withError:withCompletion:]_block_invoke: Failed to install app .EnterpriseInstallTest.watchkitapp : Error Domain=ACXErrorDomain Code=8 "Failed to create socket" UserInfo={NSUnderlyingError=0xcf9138e10 {Error Domain=com.apple.identityservices.error Code=20 "Socket open timed out" UserInfo={NSLocalizedDescription=Socket open timed out}}, FunctionName=-[ACXServerInstallOperation _onQueue_prepForTransferAndInstall]_block_invoke, SourceFileLine=370, NSLocalizedDescription=Failed to create socket}
14
6
7.0k
4d
Locked field in the W-8BEN tax form
I'm a tax resident of the Netherlands and have a Ukrainian citizenship. The field "Country or Region of Citizenship" is locked and prefilled with "Netherlands". I don't want to provide incorrect information and still waiting for the support answer. This is obviously a bug. How can I change it? I've seen some similar posts, but there is no useful answers.
2
2
2.9k
4d
macOS 27 gives no password-change UI on forced password expiry — permanent lockout
Environment macOS 27.0, build 26A428. Platform SSO via an MDM-managed third-party SSO extension (Microsoft Entra ID / Company Portal), Apple Silicon (Mac16,x family). Not seen on macOS 26 or 15 with the same configuration. Symptom When the identity provider expires a user's password under Platform SSO (Secure Enclave method), the expected flow is: unlock with the old or new password at the login window, then get prompted to reconcile the local credential. Instead, no password-change UI ever appears. The user is logged out and can't log back in with either password. Only Recovery Mode or an MDM-driven reset gets the device usable again. Reproducibility Confirmed independently on several separate Macs (some migrated from another MDM, others freshly provisioned), on and off corporate network — ruling out a local network/proxy cause. Diagnostic evidence (from sysdiagnose, both devices) com.apple.PlatformSSOUIAgent — the per-user LaunchAgent that renders Platform SSO's interactive prompts — shows runs = 0 for the entire session in launchctl dumpstate, even though the backend PlatformSSO.daemon-xpc/service-xpc endpoints are alive. It's simply never invoked. opendirectoryd shows multiple unrelated processes system-wide blocked via kernel turnstile, "after 2 hops," waiting on specific opendirectoryd threads, while those threads themselves show almost no CPU time across a 10-second spindump — consistent with the daemon idling while blocked rather than working. This reproduced within minutes of a fresh reboot/reset on one device, suggesting an immediately-recurring condition rather than a one-off. What's been ruled out Deprecated Password-type PSSO auth (already on Secure Enclave), the new OpenID-based PSSO login-window mode (IdP doesn't support it yet), TLS-inspecting proxies, and the MDM-side SSO profile itself (rebuilt and validated against current vendor docs).
0
1
1.1k
1w
Need help with Developer Account ownership change!
We had a number of personnel changes in our startup back in December. One of the people who left the company was our Chief Product Officer, and the account owner for our developer account. I have admin privileges but need to change the ownership to me so I can pay the renewal fee and conduct other tasks associated with account owner. Our prior employee cannot be reached. He has gone off-grid it seems and is not responding to our inquiries and pleas for help. Who can I speak/correspond with at Apple to get this account updated to reflect our new organization?
3
1
3k
1w
Apple Developer Program membership purchase stuck in "Pending" for over a week
Hi everyone, I'm hoping someone has experienced a similar issue. My Apple Developer Organization enrollment has already been approved, and my developer account now shows my organization as "(Pending)". On July 15, 2026, I received the following email: "Thank you for your order. Here's a summary of your order request, which will be processed within 2 business days." However, it has now been over a week, and nothing has changed. Current status: My credit card has not been charged. I have not received a payment receipt. I have not received a membership activation email. My developer account still displays: Purchase your membership To continue your enrollment, complete your purchase now. Your purchase may take up to 48 hours to process. I have already contacted Apple Developer Program Support. Case ID: 102945548446 Support history: Email with Apple Developer Support — Saturday, July 18, 2026 (GMT+7) Follow-up email with Apple Developer Support — Wednesday, July 22, 2026 (GMT+7) Unfortunately, I have not yet received a response from the support team. I also have one question regarding the payment. The organization owner is a different person, but the credit card used to purchase the Apple Developer Program membership is under my name. Could this affect the membership purchase process, or should the cardholder's name not matter as long as the payment method is valid? Has anyone experienced a similar situation? Is this a known billing issue? Could the order be stuck in Apple's payment processing system? Should I continue waiting, or should I contact Apple again? Any advice or shared experiences would be greatly appreciated. Thank you!
1
2
2.7k
1w
Supported mechanism to provision Accessibility for an MDM-managed security agent on supervised macOS 27, after PPPC removal
We develop an endpoint security agent that customer IT deploys and manages via MDM on supervised, ADE-enrolled Macs. The agent requires Accessibility permissions to perform core security functions. Historically, IT provisioned this via the PPPC payload which granted Accessibility as a managed control without end-user interaction. In macOS 27 this path for Accessibility has been removed. The documented replacement — the Privacy key in com.apple.configuration.app.settings — is consent-based: on a supervised device it presents the user a consolidated prompt with "Allow" preselected, which the user may decline. We are seeking guidance on the supported approach for macOS 27 GA: On a supervised macOS 27 device, is there a supported mechanism for an MDM-managed, code-signature-verified application to be provisioned with Accessibility as a managed security control, without depending on individual end-user consent? (i.e. an equivalent to what PPPC provided for enterprise-managed endpoints.) If the consent-based com.apple.configuration.app.settings Privacy declaration is the only path, what is Apple's recommended approach for enterprise-mandated security agents that must have Accessibility to function — including handling the case where a user declines or dismisses the prompt? We have also filed this as an enhancement request via Feedback Assistant (FB23531820). Environment for context: macOS 27 supervised via Automated Device Enrollment, managed by Jamf Pro.
12
6
10k
2w
Unable to enrol macOS 27 beta VMs in to Jamf
I have so far been unable to enrol a macOS 27 beta VM in to Jamf since initial beta release. Is this by design? I can’t find any documentation or posts on apple developer forums about this anywhere. My agentic coding session has done some probing around in the VM and it thinks something is going wrong with Secure Keychain within the VM. Everybody on my team is observing the same behaviour as this, and I’ve had it happening across two different laptops (one of them which is, itself, running the latest macOS 27 Beta, and the other which I created a Beta VM by installing Tahoe in the VM, logging in to iCloud, and enabling Beta channel updates) The only thing we’ve found we can do so far is to join to Jamf in Tahoe first, but the problem I have there is, often times the option for Beta channel updates just doesn’t present itself in System Settings -> Software Update after signing in to iCloud, and I don’t know why it sometimes does but often doesn’t. Logs from agentic coding session below: The core log evidence This is the whole causal chain, from the 27 guest's unified log, inside 370 microseconds. Innermost failure first: 05:24:04.967316 apsd: (CryptoTokenKit) [com.apple.CryptoTokenKit:sepkey] <sepk:* kid=0000000000000000>: (apsd) unable to generate key: error e00002e2(-536870174) ACL=<SecAccessControlRef: dk;ock(true);odel(true);osgn(true);oa(true);okd(true)> 05:24:04.967433 apsd: (Security) [com.apple.security:seckey] SecKeyCreateRandomKey_ios failed: NSOSStatusErrorDomain Code=-25308 "Failed to generate keypair" (errSecInteractionNotAllowed / Interaction is not allowed with the Security Server.) 05:24:04.967574 apsd: (DeviceIdentity) com.apple.MobileActivation.ErrorDomain Code=-1 "Failed to create reference key." 05:24:04.967600 apsd: [com.apple.apsd:courier] APSBAAClientIdentityProvider failed to obtain a BAA cert, error: com.apple.MobileActivation.ErrorDomain Code=-1 "Failed to create reference key." 05:24:04.967686 apsd: [com.apple.apsd:courier] <APSCourierConnectionManager; production>: Stream error occurred for : APSErrorDomain Code=1 "Told not to connect after fetching server bag: (null) - closing stream" Read bottom-up: Secure Enclave key generation fails, so MobileActivation cannot create the reference key, so apsd cannot obtain its BAA device-identity certificate, so APNs tells it not to connect. kid=0000000000000000 means there is no key id at all. Then every courier line reports Connected on 0 interfaces, and mdmclient sets its PushWakeTopics only to get Connection Invalid for service com.apple.apsd and tear down. The command to regenerate it: log show --predicate 'process == "apsd"' --last 60m --info | grep -iE 'BAA|unable to generate key|server bag'. New control, collected just now mac26 happened to be running, so I got the comparison. macOS 26.6 (25G72) guest, same host, same network, 3 days uptime: BAA_FAILURES: 0 SEPKEY_FAILURES: 0 APNS_SOCKETS: 192.168.64.8.52286 -> 17.57.146.7.443 ESTABLISHED 192.168.64.8.52285 -> 17.253.77.203.443 ESTABLISHED (+ 3 more into 17.0.0.0/8) No BAA or courier complaints at all over 6 hours, and live connections into Apple's network. So a virtualised guest per se is fine; the 27 guest specifically cannot mint the key. The physical host, also on macOS 27.0, likewise logged zero of both failures over 3 hours.
13
5
7.9k
2w
How to obtain Apple Account ID
Could you please advise us on how to obtain the Apple Account ID in the following cases? The Apple Account ID currently signed in on an iOS device. The Managed Apple Account ID associated with the Apple Business Manager (ABM) or Apple School Manager (ASM) account that manages the Apps and Books token. We would appreciate it if you could let us know whether there is an API, MDM command, or other supported method to retrieve these IDs.
0
0
309
2w
App Store Small Business Program application pending
Hi everyone, We submitted our enrollment application for the App Store Small Business Program on August 9, 2026 (almost 1 month ago) and received the confirmation email, but have not had any status update since. Our Agreements, Tax, and Banking page in App Store Connect has been fully set up and Active since February 2026 (Paid Apps Agreement, Bank Account, W-8BEN, DSA Compliance all active). We are well under the $1M threshold with no associated accounts. We have open cases with Developer Support (Case #20000152216769) and Finance Support (Case #22032895, Team ID: N2WHU2B9BC). Could an Apple staff member or moderator kindly help escalate this to the Agreements & Contracts review team? Thank you!
1
0
983
2w
App Store Small Business Program application pending
Hi everyone, We submitted our enrollment application for the App Store Small Business Program on August 9, 2026 (almost 1 month ago) and received the confirmation email, but have not had any status update since. Our Agreements, Tax, and Banking page in App Store Connect has been fully set up and Active since February 2026 (Paid Apps Agreement, Bank Account, W-8BEN, DSA Compliance all active). We are well under the $1M threshold with no associated accounts. We have open cases with Developer Support (Case #20000152216769) and Finance Support (Case #22032895, Team ID: N2WHU2B9BC). Could an Apple staff member or moderator kindly help escalate this to the Agreements & Contracts review team? Thank you!
0
0
125
2w
DisableGuestAccount can be overridden by Admin on macOS 26
Hi Apple Team, We are using the Accounts MDM payload with: PayloadType: com.apple.MCX DisableGuestAccount: true On macOS 26, even after the MDM profile is successfully applied, a local Administrator can still toggle the Guest User setting in System Settings. Expected: The setting should be enforced by MDM and should not be modifiable by an Administrator. Interestingly, the same configuration works as expected on macOS 27 beta, where the Guest User setting is shown as “This setting has been configured by a profile” and cannot be modified. Could you please confirm whether this is a known issue/regression in macOS 26 and whether there is a workaround or any permanent solution in later patches ? Environment: macOS 26.x Payload: com.apple.MCX DisableGuestAccount = true macOS 27 beta: Works as expected
0
0
1.3k
3w
Using ACME certificates for TLS client authentication on macOS
Hello, I'm trying to use a certificate provisioned through the com.apple.security.acme payload for TLS client authentication in Safari on macOS. Provisioning the certificate via ACME using the device-attest-01 challenge is working fine and the signed certificate includes the Extended Key Usage: TLS Web Client Authentication. Unfortunately on macOS in Safari I can't find a way to choose this identity when a server requests client authentication. Using the same method works flawlessly on iOS. If a server requests client authentication Safari prompts the option to use the certificate and the connection to the web server succeeds as intended. On macOS I have tried adding a com.apple.security.identitypreference payload to the profile, linking the certificate from the ACME payload to the domain name of a web server that requires client authentication, but that did not change the behavior in any way. The following payload is used to request the certificate on both my MacBook and iPhone: <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>PayloadDisplayName</key> <string>ACME Certificate Request</string> <key>PayloadIdentifier</key> <string>com.example.net.acmeprofile</string> <key>PayloadType</key> <string>Configuration</string> <key>PayloadUUID</key> <string>UUID-1111-1111-1111-111111111111</string> <key>PayloadVersion</key> <integer>1</integer> <key>PayloadContent</key> <array> <dict> <key>PayloadType</key> <string>com.apple.security.acme</string> <key>PayloadIdentifier</key> <string>com.example.net.acme</string> <key>PayloadUUID</key> <string>UUID-2222-2222-2222-222222222222</string> <key>PayloadVersion</key> <integer>1</integer> <key>DirectoryURL</key> <string>https://acme.example.net/acme/apple-acme/directory</string> <key>ClientIdentifier</key> <string>XXXXXXXXX</string> <key>KeyType</key> <string>ECSECPrimeRandom</string> <key>KeySize</key> <integer>256</integer> <key>UsageFlags</key> <integer>1</integer> <key>ExtendedKeyUsage</key> <array> <string>1.3.6.1.5.5.7.3.2</string> </array> <key>HardwareBound</key> <true/> <key>Attest</key> <true/> <key>AllowAllAppsAccess</key> <true/> <key>Subject</key> <array> <array> <array> <string>CN</string> <string>XXXXXXXXX</string> </array> </array> </array> </dict> </array> </dict> </plist> And this is the identity payload I have added to the profile on macOS: <key>PayloadType</key> <string>com.apple.security.identitypreference</string> <key>PayloadIdentifier</key> <string>com.example.net.identitypreference</string> <key>PayloadUUID</key> <string>UUID-3333-3333-3333-3333333333333333</string> <key>PayloadVersion</key> <integer>1</integer> <key>Name</key> <string>mtls-endpoint.example.net</string> <key>PayloadCertificateUUID</key> <string>UUID-2222-2222-2222-222222222222</string> Neither device is managed by an MDM service and they run macOS 26.6.1 and iOS 26.6 respectively. Is there any additional configuration required on macOS to make an ACME-provisioned certificate available for client authentication in Safari? Or is this simply the expected behavior, and client authentication requires a traditional certificate-key pair in the macOS Keychain? Any help would be greatly appreciated!
1
2
2.2k
Aug ’26
Radius servers: requirements for trusted certificates
We deploy WPA3-EAP for co-working spaces (EU/US). That means BYOD and no ability to enforce MDM. Each co-working space issue wifi credentials to their individual members, usually in the form of PEAP/TTLS. The user joins the SSID for EAP and is prompted to enter username + password, and then to accepts our radius certificate (prompted as "not trusted" of course). Does the certificate validity period of 825 days or fewer apply to our radius leaf certs? The question has come up as we read: https://support.apple.com/en-us/102028 --"This change will not affect certificates issued from user-added or administrator-added Root CAs" https://support.apple.com/en-ca/103769 --"Additionally, all TLS server certificates issued after July 1, 2019 (as indicated in the NotBefore field of the certificate) must follow these guidelines:" ..... "TLS server certificates must have a validity period of 825 days or fewer (as expressed in the NotBefore and NotAfter fields of the certificate)." lastly, while PEAP/TTLS is the primary method. Second is delivering a .mobileconfig that can be downloaded by the user containing EAP-TLS authentication. These also require user acceptance as there again is no MDM possible. We dont have any issues currently, but are we going to wake up one morning and find that all apple devices have dropped off the networks?
0
0
1.4k
Aug ’26
As a Developer, how do you find the EVID (ExternalVersionID) for App pinning
This page: https://developer.apple.com/documentation/devicemanagement/installing-managing-updating-and-removing-apps#Pin-the-version-of-an-app States the following: To find the EVID of an App Store app, use one of these procedures: If the device management service manages the app using declarative management, look for the external-version-id key in the StatusAppManagedList status item that the device reports to the service. If the device management service manages the app using MDM commands, look for the ExternalVersionIdentifier key in the Installed Application List command response that the device returns to the service. Use the Apps and books metadata for organizations API to look up the externalVersionId key in the Apps.Attributes for the app. Ask the app developer to provide the value. The first 2 require access to an MDM and the third in order to use the Appsand books metadata you need to turn your account into an MDM vendor developer account. So the final option is to "ask the app developer". I am the app developer and have no idea how to get this value. As a normal iOS developer is there no other way than to either contract an MDM or turn your account into an MDM vendor?
0
0
854
Aug ’26
Apple Configurator and Apple TV
Ever since tvOS 26.4, we've had some difficulties in discovering, pairing, and supervising Apple TV 4K devices using Apple Configurator 2.20. We submitted a feedback report about this issue (FB22525540). The issue has improved somewhat for me when using the latest tvOS 26.6, if the Apple TV is connected via Ethernet during the initial paring step. Sometimes the pairing still fails, but eventually I can get it to work. However, some others on our dev / QA teams haven't had the same luck in even seeing the device as available to pair (even when the Apple TV is at the welcome screen or Remote and Devices screen, nearby, and on Ethernet along with the Mac). I've seen other cases where the pairing seems to work, but then the device doesn't appear in the Apple Configurator devices list, and therefore it’s not possible to supervise and install profiles onto it. Are they any workarounds or other steps we can try?
0
1
864
Aug ’26
PPPC Accessibility Profile Not Applied on Golden Gate Beta When Deployed via Jamf
We are experiencing an issue with Privacy Preferences Policy Control (PPPC) profiles deployed through Jamf Pro on the Golden Gate beta. We use the following Jamf configuration profiles to pre-approve Digital Guardian Accessibility permissions: DG – Grant Accessibility Access to DgSessionSvc.app DG – RME These profiles are intended to grant Accessibility permissions automatically for Digital Guardian under: System Settings → Privacy & Security → Accessibility On macOS Tahoe and macOS Sequoia, these PPPC profiles work as expected. After deployment, the required Accessibility permissions are granted automatically and users are not prompted. However, on the Golden Gate beta, the same configuration profiles are installed successfully, but the required Accessibility permissions are not granted. As a result, users continue to receive the Accessibility permission prompts. We also observed a difference when inspecting the installed profile under: System Settings → General → Device Management → Profile On macOS Tahoe, the installed profile contains the following entry: Control the Computer — com.verdasys.DgSessionSvc — Allowed On the Golden Gate beta, this entry is missing, even though the identical Jamf PPPC profile has been installed successfully. For reference, we have attached: The Jamf PPPC configuration profiles (.mobileconfig) DGSessionSvc MobileConfig RME MobileConfig Comparison screenshots from macOS Tahoe and the Golden Gate beta Could you please confirm whether this is: a known issue in the Golden Gate beta, an intentional change in PPPC behavior, or an issue with our PPPC configuration profile? If this is an operating system issue, we would appreciate it if it could be investigated and addressed in a future Golden Gate beta release. Environment Affected OS: Golden Gate 27.0 Beta (26A5388g) Working OS versions: macOS Tahoe and macOS Sequoia MDM Solution: Jamf Pro 11.30.1 Affected Application: Fortra Digital Guardian Required Permission: Accessibility (Control the Computer) Architecture: Apple silicon We would also appreciate it if you could review the attached .mobileconfig files and let us know whether any modifications are required to make the PPPC profiles compatible with the Golden Gate beta, or if any additional information would be helpful for your investigation.
6
5
3.7k
Aug ’26
iOS 27 terminates a running app while MDM converts it to a managed app
We're working on an iOS app distributed through the App Store and installed on an MDM-enrolled device. Our MDM server uses InstallApplication to take management of the already-installed and running app. On iOS 27 betas 3 and 4, processing this command causes iOS to terminate the app and its extensions with SIGKILL. The same flow and MDM payload work without terminating the app on earlier iOS versions (iOS <=26). Environment OS: iOS 27 betas 3 and 4 Does not happen: iOS 26 or iOS 16.7.15 Device: iPhone SE 2nd Gen Enrollment: MDM-enrolled device Distribution: App Store app App state: Already installed and running when management is requested MDM command: InstallApplication Minimal MDM command The MDM server sends an InstallApplication command for the already-installed app: Attributes = { Removable = false; }; ChangeManagementState = Managed; Identifier = "APP_BUNDLE_ID"; InstallAsManaged = true; ManagementFlags = 1; RequestType = InstallApplication; We also tested the equivalent command using iTunesStoreID = APP_STORE_ID instead of Identifier, and removing InstallAsManaged. The targeted running app was terminated in the same way. Steps to reproduce Install and launch the App Store app as an unmanaged app. Enroll the iPhone in MDM. While the app is running, send the MDM InstallApplication command to take management of the existing installation. Observe the unified logs for mdmd, appstored, manageddeviced, installcoordinationd, and runningboardd. The issue can also be reproduced by initiating the same server-side flow while the app is already in the background. iOS 27 log sequence The command is accepted and appstored starts the managed-app tasks. manageddeviced then attempts to mark the app as managed using a null persona (this differs from iOS <26): The running app has a valid persona. After the failed mapping, installcoordinationd explicitly asks RunningBoard to terminate the app to disassociate that persona: After termination, removing the valid persona also fails. The managed-app task later reports success despite the mapping failures and termination. Earlier iOS comparison As an example, on iOS 16.7.15, using the same MDM command, **iOS routes the request through dmd with persona: default. The app remains alive and receives managed-app change notifications. Expected The existing installation becomes managed without terminating the running app, consistent with the behavior on earlier iOS versions. Actual manageddeviced tries to associate the app with persona (null) and fails with MIInstallerErrorDomain Code 191. That failure causes installcoordinationd to request termination of the app and its extensions to disassociate their valid persona. runningboardd terminates them with SIGKILL (isUserKill=0). The subsequent removal of the only valid persona fails with Code 242, although the managed-app task later reports success. Documentation checked The payload follows the documented InstallApplication flow for taking management of an existing app: Apple Docs WWDC26 app MDM updates We have not found a malformed field that explains the iOS 27-only failure. More info Detailed logs and additional info can be found on the Feedback report.
4
5
3.3k
Aug ’26
Can an embedded macOS Login Item access an app.managed identity through ManagedApp APIs?
I’m developing a macOS application that contains an embedded User Service Login Item: Outer app bundle ID: com.xxx.app Embedded User Service bundle ID: com.xxx.app.service Team ID: DE8Y96K9QP The User Service is embedded at: OuterApp.app/Contents/Library/LoginItems/UserService.app I deployed a com.apple.configuration.app.managed declaration through an MDM server, with an asset declaration of type: com.apple.asset.credential.identity, the declaration uses: "AppComposedIdentifier": "com.xxx.app (DE8Y96K9QP)" When the ManagedApp APIs are called from the outer ZTA app, the app successfully receives the identity. However, when the same ManagedApp APIs are called from the embedded User Service, the identity list is empty. When I instead use the embedded service’s identifier: "AppComposedIdentifier": "com.xxx.app.service (DE8Y96K9QP)", macOS reports either Error.InvalidCodeSignature or Error.NotPresent. My questions are: Can an embedded Login Item or embedded subsystem be the target of an app.managed declaration and access managed identities through ManagedAppIdentitiesProvider? Or must AppComposedIdentifier always identify the top-level application that contains the embedded Login Item? If the declaration targets the outer application, is there a supported way for the embedded User Service to access the same managed identity—for example, through XPC communication with the outer application? The outer application and embedded User Service are signed by the same Team ID, and both signatures validate successfully when checked with codesign. Thanks, Ying
Replies
0
Boosts
0
Views
436
Activity
2d
when platform SSO is enabled on MAC OS 27, users are not receiving the password prompt where the same working in MAC OS 26
Password prompt are not working with PSSO enabled in MAC OS 27 while the same working in MAC OS 26. Issue is observed after updating to OS 27. Is there a known issue reported with OS version 27 and any fix expected in upcoming versions.
Replies
0
Boosts
0
Views
631
Activity
3d
Enterprise WatchOS App Won't Install on WatchOS 26.5
We have an Apple Watch app and companion iPhone app that we distribute via Enterprise Distribution using OTA manual installation. (We are on an Apple Enterprise Developer Team) With WatchOS 26.4 and earlier, the app would install fine on both the phone and the watch. However, after updating to WatchOS 26.5 (and iOS 26.5), the app will not install on the watch. It will install on the phone and we can trust the developer/run the phone app. However, when we go into the Apple Watch app on the phone and choose "Install" for the app, it tries to install for a minute and then returns an error "The app could not be installed at this time". We have tried the following remedies: Restarting both watch and phone, and reinstalling the app on phone Factory resetting both the watch and the phone, then reinstalling app Generating a new Distribution Certificate and new manual profiles for the app in Apple Developer Looking through console logs from both the phone and the watch Confirmed that we can install other (non-Enterprise) apps on the watch Try installing a basic example app (the default Xcode watch + companion app project) There does not seem to be anything obviously amiss about the app or its packaging, it seems to be something to do with the update to WatchOS 26.5. The closest related errors we have found seems to be these: appconduitd 0x16d43f000 -[ACXInstallQueue _onQueue_deQueueNextOperation]_block_invoke_3: Failed to install app .EnterpriseInstallTest.watchkitapp (p = Y, ui = Y) : Error Domain=ACXErrorDomain Code=8 "Failed to create socket" UserInfo={NSUnderlyingError=0xcf9138e10 {Error Domain=com.apple.identityservices.error Code=20 "Socket open timed out" UserInfo={NSLocalizedDescription=Socket open timed out}}, FunctionName=-[ACXServerInstallOperation _onQueue_prepForTransferAndInstall]_block_invoke, SourceFileLine=370, NSLocalizedDescription=Failed to create socket} appconduitd 0x16d89f000 -[ACXCompanionSyncConnection _installQueuedOrCompletedForWatchBundleID:companionAppBundleID:withName:userInitiated:withError:withCompletion:]_block_invoke: Failed to install app .EnterpriseInstallTest.watchkitapp : Error Domain=ACXErrorDomain Code=8 "Failed to create socket" UserInfo={NSUnderlyingError=0xcf9138e10 {Error Domain=com.apple.identityservices.error Code=20 "Socket open timed out" UserInfo={NSLocalizedDescription=Socket open timed out}}, FunctionName=-[ACXServerInstallOperation _onQueue_prepForTransferAndInstall]_block_invoke, SourceFileLine=370, NSLocalizedDescription=Failed to create socket}
Replies
14
Boosts
6
Views
7.0k
Activity
4d
Locked field in the W-8BEN tax form
I'm a tax resident of the Netherlands and have a Ukrainian citizenship. The field "Country or Region of Citizenship" is locked and prefilled with "Netherlands". I don't want to provide incorrect information and still waiting for the support answer. This is obviously a bug. How can I change it? I've seen some similar posts, but there is no useful answers.
Replies
2
Boosts
2
Views
2.9k
Activity
4d
macOS 27 gives no password-change UI on forced password expiry — permanent lockout
Environment macOS 27.0, build 26A428. Platform SSO via an MDM-managed third-party SSO extension (Microsoft Entra ID / Company Portal), Apple Silicon (Mac16,x family). Not seen on macOS 26 or 15 with the same configuration. Symptom When the identity provider expires a user's password under Platform SSO (Secure Enclave method), the expected flow is: unlock with the old or new password at the login window, then get prompted to reconcile the local credential. Instead, no password-change UI ever appears. The user is logged out and can't log back in with either password. Only Recovery Mode or an MDM-driven reset gets the device usable again. Reproducibility Confirmed independently on several separate Macs (some migrated from another MDM, others freshly provisioned), on and off corporate network — ruling out a local network/proxy cause. Diagnostic evidence (from sysdiagnose, both devices) com.apple.PlatformSSOUIAgent — the per-user LaunchAgent that renders Platform SSO's interactive prompts — shows runs = 0 for the entire session in launchctl dumpstate, even though the backend PlatformSSO.daemon-xpc/service-xpc endpoints are alive. It's simply never invoked. opendirectoryd shows multiple unrelated processes system-wide blocked via kernel turnstile, "after 2 hops," waiting on specific opendirectoryd threads, while those threads themselves show almost no CPU time across a 10-second spindump — consistent with the daemon idling while blocked rather than working. This reproduced within minutes of a fresh reboot/reset on one device, suggesting an immediately-recurring condition rather than a one-off. What's been ruled out Deprecated Password-type PSSO auth (already on Secure Enclave), the new OpenID-based PSSO login-window mode (IdP doesn't support it yet), TLS-inspecting proxies, and the MDM-side SSO profile itself (rebuilt and validated against current vendor docs).
Replies
0
Boosts
1
Views
1.1k
Activity
1w
Need help with Developer Account ownership change!
We had a number of personnel changes in our startup back in December. One of the people who left the company was our Chief Product Officer, and the account owner for our developer account. I have admin privileges but need to change the ownership to me so I can pay the renewal fee and conduct other tasks associated with account owner. Our prior employee cannot be reached. He has gone off-grid it seems and is not responding to our inquiries and pleas for help. Who can I speak/correspond with at Apple to get this account updated to reflect our new organization?
Replies
3
Boosts
1
Views
3k
Activity
1w
Waive yearly fee for non-profit
I represent a 501C3 non-profit in the United States. We are a small organization and sell books and other items to students and teachers. Would we qualify for a waiver of the $99 fee?
Replies
2
Boosts
0
Views
3.1k
Activity
1w
Apple Developer Program membership purchase stuck in "Pending" for over a week
Hi everyone, I'm hoping someone has experienced a similar issue. My Apple Developer Organization enrollment has already been approved, and my developer account now shows my organization as "(Pending)". On July 15, 2026, I received the following email: "Thank you for your order. Here's a summary of your order request, which will be processed within 2 business days." However, it has now been over a week, and nothing has changed. Current status: My credit card has not been charged. I have not received a payment receipt. I have not received a membership activation email. My developer account still displays: Purchase your membership To continue your enrollment, complete your purchase now. Your purchase may take up to 48 hours to process. I have already contacted Apple Developer Program Support. Case ID: 102945548446 Support history: Email with Apple Developer Support — Saturday, July 18, 2026 (GMT+7) Follow-up email with Apple Developer Support — Wednesday, July 22, 2026 (GMT+7) Unfortunately, I have not yet received a response from the support team. I also have one question regarding the payment. The organization owner is a different person, but the credit card used to purchase the Apple Developer Program membership is under my name. Could this affect the membership purchase process, or should the cardholder's name not matter as long as the payment method is valid? Has anyone experienced a similar situation? Is this a known billing issue? Could the order be stuck in Apple's payment processing system? Should I continue waiting, or should I contact Apple again? Any advice or shared experiences would be greatly appreciated. Thank you!
Replies
1
Boosts
2
Views
2.7k
Activity
1w
Supported mechanism to provision Accessibility for an MDM-managed security agent on supervised macOS 27, after PPPC removal
We develop an endpoint security agent that customer IT deploys and manages via MDM on supervised, ADE-enrolled Macs. The agent requires Accessibility permissions to perform core security functions. Historically, IT provisioned this via the PPPC payload which granted Accessibility as a managed control without end-user interaction. In macOS 27 this path for Accessibility has been removed. The documented replacement — the Privacy key in com.apple.configuration.app.settings — is consent-based: on a supervised device it presents the user a consolidated prompt with "Allow" preselected, which the user may decline. We are seeking guidance on the supported approach for macOS 27 GA: On a supervised macOS 27 device, is there a supported mechanism for an MDM-managed, code-signature-verified application to be provisioned with Accessibility as a managed security control, without depending on individual end-user consent? (i.e. an equivalent to what PPPC provided for enterprise-managed endpoints.) If the consent-based com.apple.configuration.app.settings Privacy declaration is the only path, what is Apple's recommended approach for enterprise-mandated security agents that must have Accessibility to function — including handling the case where a user declines or dismisses the prompt? We have also filed this as an enhancement request via Feedback Assistant (FB23531820). Environment for context: macOS 27 supervised via Automated Device Enrollment, managed by Jamf Pro.
Replies
12
Boosts
6
Views
10k
Activity
2w
Unable to enrol macOS 27 beta VMs in to Jamf
I have so far been unable to enrol a macOS 27 beta VM in to Jamf since initial beta release. Is this by design? I can’t find any documentation or posts on apple developer forums about this anywhere. My agentic coding session has done some probing around in the VM and it thinks something is going wrong with Secure Keychain within the VM. Everybody on my team is observing the same behaviour as this, and I’ve had it happening across two different laptops (one of them which is, itself, running the latest macOS 27 Beta, and the other which I created a Beta VM by installing Tahoe in the VM, logging in to iCloud, and enabling Beta channel updates) The only thing we’ve found we can do so far is to join to Jamf in Tahoe first, but the problem I have there is, often times the option for Beta channel updates just doesn’t present itself in System Settings -> Software Update after signing in to iCloud, and I don’t know why it sometimes does but often doesn’t. Logs from agentic coding session below: The core log evidence This is the whole causal chain, from the 27 guest's unified log, inside 370 microseconds. Innermost failure first: 05:24:04.967316 apsd: (CryptoTokenKit) [com.apple.CryptoTokenKit:sepkey] <sepk:* kid=0000000000000000>: (apsd) unable to generate key: error e00002e2(-536870174) ACL=<SecAccessControlRef: dk;ock(true);odel(true);osgn(true);oa(true);okd(true)> 05:24:04.967433 apsd: (Security) [com.apple.security:seckey] SecKeyCreateRandomKey_ios failed: NSOSStatusErrorDomain Code=-25308 "Failed to generate keypair" (errSecInteractionNotAllowed / Interaction is not allowed with the Security Server.) 05:24:04.967574 apsd: (DeviceIdentity) com.apple.MobileActivation.ErrorDomain Code=-1 "Failed to create reference key." 05:24:04.967600 apsd: [com.apple.apsd:courier] APSBAAClientIdentityProvider failed to obtain a BAA cert, error: com.apple.MobileActivation.ErrorDomain Code=-1 "Failed to create reference key." 05:24:04.967686 apsd: [com.apple.apsd:courier] <APSCourierConnectionManager; production>: Stream error occurred for : APSErrorDomain Code=1 "Told not to connect after fetching server bag: (null) - closing stream" Read bottom-up: Secure Enclave key generation fails, so MobileActivation cannot create the reference key, so apsd cannot obtain its BAA device-identity certificate, so APNs tells it not to connect. kid=0000000000000000 means there is no key id at all. Then every courier line reports Connected on 0 interfaces, and mdmclient sets its PushWakeTopics only to get Connection Invalid for service com.apple.apsd and tear down. The command to regenerate it: log show --predicate 'process == "apsd"' --last 60m --info | grep -iE 'BAA|unable to generate key|server bag'. New control, collected just now mac26 happened to be running, so I got the comparison. macOS 26.6 (25G72) guest, same host, same network, 3 days uptime: BAA_FAILURES: 0 SEPKEY_FAILURES: 0 APNS_SOCKETS: 192.168.64.8.52286 -> 17.57.146.7.443 ESTABLISHED 192.168.64.8.52285 -> 17.253.77.203.443 ESTABLISHED (+ 3 more into 17.0.0.0/8) No BAA or courier complaints at all over 6 hours, and live connections into Apple's network. So a virtualised guest per se is fine; the 27 guest specifically cannot mint the key. The physical host, also on macOS 27.0, likewise logged zero of both failures over 3 hours.
Replies
13
Boosts
5
Views
7.9k
Activity
2w
How to obtain Apple Account ID
Could you please advise us on how to obtain the Apple Account ID in the following cases? The Apple Account ID currently signed in on an iOS device. The Managed Apple Account ID associated with the Apple Business Manager (ABM) or Apple School Manager (ASM) account that manages the Apps and Books token. We would appreciate it if you could let us know whether there is an API, MDM command, or other supported method to retrieve these IDs.
Replies
0
Boosts
0
Views
309
Activity
2w
App Store Small Business Program application pending
Hi everyone, We submitted our enrollment application for the App Store Small Business Program on August 9, 2026 (almost 1 month ago) and received the confirmation email, but have not had any status update since. Our Agreements, Tax, and Banking page in App Store Connect has been fully set up and Active since February 2026 (Paid Apps Agreement, Bank Account, W-8BEN, DSA Compliance all active). We are well under the $1M threshold with no associated accounts. We have open cases with Developer Support (Case #20000152216769) and Finance Support (Case #22032895, Team ID: N2WHU2B9BC). Could an Apple staff member or moderator kindly help escalate this to the Agreements & Contracts review team? Thank you!
Replies
1
Boosts
0
Views
983
Activity
2w
App Store Small Business Program application pending
Hi everyone, We submitted our enrollment application for the App Store Small Business Program on August 9, 2026 (almost 1 month ago) and received the confirmation email, but have not had any status update since. Our Agreements, Tax, and Banking page in App Store Connect has been fully set up and Active since February 2026 (Paid Apps Agreement, Bank Account, W-8BEN, DSA Compliance all active). We are well under the $1M threshold with no associated accounts. We have open cases with Developer Support (Case #20000152216769) and Finance Support (Case #22032895, Team ID: N2WHU2B9BC). Could an Apple staff member or moderator kindly help escalate this to the Agreements & Contracts review team? Thank you!
Replies
0
Boosts
0
Views
125
Activity
2w
DisableGuestAccount can be overridden by Admin on macOS 26
Hi Apple Team, We are using the Accounts MDM payload with: PayloadType: com.apple.MCX DisableGuestAccount: true On macOS 26, even after the MDM profile is successfully applied, a local Administrator can still toggle the Guest User setting in System Settings. Expected: The setting should be enforced by MDM and should not be modifiable by an Administrator. Interestingly, the same configuration works as expected on macOS 27 beta, where the Guest User setting is shown as “This setting has been configured by a profile” and cannot be modified. Could you please confirm whether this is a known issue/regression in macOS 26 and whether there is a workaround or any permanent solution in later patches ? Environment: macOS 26.x Payload: com.apple.MCX DisableGuestAccount = true macOS 27 beta: Works as expected
Replies
0
Boosts
0
Views
1.3k
Activity
3w
Using ACME certificates for TLS client authentication on macOS
Hello, I'm trying to use a certificate provisioned through the com.apple.security.acme payload for TLS client authentication in Safari on macOS. Provisioning the certificate via ACME using the device-attest-01 challenge is working fine and the signed certificate includes the Extended Key Usage: TLS Web Client Authentication. Unfortunately on macOS in Safari I can't find a way to choose this identity when a server requests client authentication. Using the same method works flawlessly on iOS. If a server requests client authentication Safari prompts the option to use the certificate and the connection to the web server succeeds as intended. On macOS I have tried adding a com.apple.security.identitypreference payload to the profile, linking the certificate from the ACME payload to the domain name of a web server that requires client authentication, but that did not change the behavior in any way. The following payload is used to request the certificate on both my MacBook and iPhone: <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>PayloadDisplayName</key> <string>ACME Certificate Request</string> <key>PayloadIdentifier</key> <string>com.example.net.acmeprofile</string> <key>PayloadType</key> <string>Configuration</string> <key>PayloadUUID</key> <string>UUID-1111-1111-1111-111111111111</string> <key>PayloadVersion</key> <integer>1</integer> <key>PayloadContent</key> <array> <dict> <key>PayloadType</key> <string>com.apple.security.acme</string> <key>PayloadIdentifier</key> <string>com.example.net.acme</string> <key>PayloadUUID</key> <string>UUID-2222-2222-2222-222222222222</string> <key>PayloadVersion</key> <integer>1</integer> <key>DirectoryURL</key> <string>https://acme.example.net/acme/apple-acme/directory</string> <key>ClientIdentifier</key> <string>XXXXXXXXX</string> <key>KeyType</key> <string>ECSECPrimeRandom</string> <key>KeySize</key> <integer>256</integer> <key>UsageFlags</key> <integer>1</integer> <key>ExtendedKeyUsage</key> <array> <string>1.3.6.1.5.5.7.3.2</string> </array> <key>HardwareBound</key> <true/> <key>Attest</key> <true/> <key>AllowAllAppsAccess</key> <true/> <key>Subject</key> <array> <array> <array> <string>CN</string> <string>XXXXXXXXX</string> </array> </array> </array> </dict> </array> </dict> </plist> And this is the identity payload I have added to the profile on macOS: <key>PayloadType</key> <string>com.apple.security.identitypreference</string> <key>PayloadIdentifier</key> <string>com.example.net.identitypreference</string> <key>PayloadUUID</key> <string>UUID-3333-3333-3333-3333333333333333</string> <key>PayloadVersion</key> <integer>1</integer> <key>Name</key> <string>mtls-endpoint.example.net</string> <key>PayloadCertificateUUID</key> <string>UUID-2222-2222-2222-222222222222</string> Neither device is managed by an MDM service and they run macOS 26.6.1 and iOS 26.6 respectively. Is there any additional configuration required on macOS to make an ACME-provisioned certificate available for client authentication in Safari? Or is this simply the expected behavior, and client authentication requires a traditional certificate-key pair in the macOS Keychain? Any help would be greatly appreciated!
Replies
1
Boosts
2
Views
2.2k
Activity
Aug ’26
Radius servers: requirements for trusted certificates
We deploy WPA3-EAP for co-working spaces (EU/US). That means BYOD and no ability to enforce MDM. Each co-working space issue wifi credentials to their individual members, usually in the form of PEAP/TTLS. The user joins the SSID for EAP and is prompted to enter username + password, and then to accepts our radius certificate (prompted as "not trusted" of course). Does the certificate validity period of 825 days or fewer apply to our radius leaf certs? The question has come up as we read: https://support.apple.com/en-us/102028 --"This change will not affect certificates issued from user-added or administrator-added Root CAs" https://support.apple.com/en-ca/103769 --"Additionally, all TLS server certificates issued after July 1, 2019 (as indicated in the NotBefore field of the certificate) must follow these guidelines:" ..... "TLS server certificates must have a validity period of 825 days or fewer (as expressed in the NotBefore and NotAfter fields of the certificate)." lastly, while PEAP/TTLS is the primary method. Second is delivering a .mobileconfig that can be downloaded by the user containing EAP-TLS authentication. These also require user acceptance as there again is no MDM possible. We dont have any issues currently, but are we going to wake up one morning and find that all apple devices have dropped off the networks?
Replies
0
Boosts
0
Views
1.4k
Activity
Aug ’26
As a Developer, how do you find the EVID (ExternalVersionID) for App pinning
This page: https://developer.apple.com/documentation/devicemanagement/installing-managing-updating-and-removing-apps#Pin-the-version-of-an-app States the following: To find the EVID of an App Store app, use one of these procedures: If the device management service manages the app using declarative management, look for the external-version-id key in the StatusAppManagedList status item that the device reports to the service. If the device management service manages the app using MDM commands, look for the ExternalVersionIdentifier key in the Installed Application List command response that the device returns to the service. Use the Apps and books metadata for organizations API to look up the externalVersionId key in the Apps.Attributes for the app. Ask the app developer to provide the value. The first 2 require access to an MDM and the third in order to use the Appsand books metadata you need to turn your account into an MDM vendor developer account. So the final option is to "ask the app developer". I am the app developer and have no idea how to get this value. As a normal iOS developer is there no other way than to either contract an MDM or turn your account into an MDM vendor?
Replies
0
Boosts
0
Views
854
Activity
Aug ’26
Apple Configurator and Apple TV
Ever since tvOS 26.4, we've had some difficulties in discovering, pairing, and supervising Apple TV 4K devices using Apple Configurator 2.20. We submitted a feedback report about this issue (FB22525540). The issue has improved somewhat for me when using the latest tvOS 26.6, if the Apple TV is connected via Ethernet during the initial paring step. Sometimes the pairing still fails, but eventually I can get it to work. However, some others on our dev / QA teams haven't had the same luck in even seeing the device as available to pair (even when the Apple TV is at the welcome screen or Remote and Devices screen, nearby, and on Ethernet along with the Mac). I've seen other cases where the pairing seems to work, but then the device doesn't appear in the Apple Configurator devices list, and therefore it’s not possible to supervise and install profiles onto it. Are they any workarounds or other steps we can try?
Replies
0
Boosts
1
Views
864
Activity
Aug ’26
PPPC Accessibility Profile Not Applied on Golden Gate Beta When Deployed via Jamf
We are experiencing an issue with Privacy Preferences Policy Control (PPPC) profiles deployed through Jamf Pro on the Golden Gate beta. We use the following Jamf configuration profiles to pre-approve Digital Guardian Accessibility permissions: DG – Grant Accessibility Access to DgSessionSvc.app DG – RME These profiles are intended to grant Accessibility permissions automatically for Digital Guardian under: System Settings → Privacy & Security → Accessibility On macOS Tahoe and macOS Sequoia, these PPPC profiles work as expected. After deployment, the required Accessibility permissions are granted automatically and users are not prompted. However, on the Golden Gate beta, the same configuration profiles are installed successfully, but the required Accessibility permissions are not granted. As a result, users continue to receive the Accessibility permission prompts. We also observed a difference when inspecting the installed profile under: System Settings → General → Device Management → Profile On macOS Tahoe, the installed profile contains the following entry: Control the Computer — com.verdasys.DgSessionSvc — Allowed On the Golden Gate beta, this entry is missing, even though the identical Jamf PPPC profile has been installed successfully. For reference, we have attached: The Jamf PPPC configuration profiles (.mobileconfig) DGSessionSvc MobileConfig RME MobileConfig Comparison screenshots from macOS Tahoe and the Golden Gate beta Could you please confirm whether this is: a known issue in the Golden Gate beta, an intentional change in PPPC behavior, or an issue with our PPPC configuration profile? If this is an operating system issue, we would appreciate it if it could be investigated and addressed in a future Golden Gate beta release. Environment Affected OS: Golden Gate 27.0 Beta (26A5388g) Working OS versions: macOS Tahoe and macOS Sequoia MDM Solution: Jamf Pro 11.30.1 Affected Application: Fortra Digital Guardian Required Permission: Accessibility (Control the Computer) Architecture: Apple silicon We would also appreciate it if you could review the attached .mobileconfig files and let us know whether any modifications are required to make the PPPC profiles compatible with the Golden Gate beta, or if any additional information would be helpful for your investigation.
Replies
6
Boosts
5
Views
3.7k
Activity
Aug ’26
iOS 27 terminates a running app while MDM converts it to a managed app
We're working on an iOS app distributed through the App Store and installed on an MDM-enrolled device. Our MDM server uses InstallApplication to take management of the already-installed and running app. On iOS 27 betas 3 and 4, processing this command causes iOS to terminate the app and its extensions with SIGKILL. The same flow and MDM payload work without terminating the app on earlier iOS versions (iOS <=26). Environment OS: iOS 27 betas 3 and 4 Does not happen: iOS 26 or iOS 16.7.15 Device: iPhone SE 2nd Gen Enrollment: MDM-enrolled device Distribution: App Store app App state: Already installed and running when management is requested MDM command: InstallApplication Minimal MDM command The MDM server sends an InstallApplication command for the already-installed app: Attributes = { Removable = false; }; ChangeManagementState = Managed; Identifier = "APP_BUNDLE_ID"; InstallAsManaged = true; ManagementFlags = 1; RequestType = InstallApplication; We also tested the equivalent command using iTunesStoreID = APP_STORE_ID instead of Identifier, and removing InstallAsManaged. The targeted running app was terminated in the same way. Steps to reproduce Install and launch the App Store app as an unmanaged app. Enroll the iPhone in MDM. While the app is running, send the MDM InstallApplication command to take management of the existing installation. Observe the unified logs for mdmd, appstored, manageddeviced, installcoordinationd, and runningboardd. The issue can also be reproduced by initiating the same server-side flow while the app is already in the background. iOS 27 log sequence The command is accepted and appstored starts the managed-app tasks. manageddeviced then attempts to mark the app as managed using a null persona (this differs from iOS <26): The running app has a valid persona. After the failed mapping, installcoordinationd explicitly asks RunningBoard to terminate the app to disassociate that persona: After termination, removing the valid persona also fails. The managed-app task later reports success despite the mapping failures and termination. Earlier iOS comparison As an example, on iOS 16.7.15, using the same MDM command, **iOS routes the request through dmd with persona: default. The app remains alive and receives managed-app change notifications. Expected The existing installation becomes managed without terminating the running app, consistent with the behavior on earlier iOS versions. Actual manageddeviced tries to associate the app with persona (null) and fails with MIInstallerErrorDomain Code 191. That failure causes installcoordinationd to request termination of the app and its extensions to disassociate their valid persona. runningboardd terminates them with SIGKILL (isUserKill=0). The subsequent removal of the only valid persona fails with Code 242, although the managed-app task later reports success. Documentation checked The payload follows the documented InstallApplication flow for taking management of an existing app: Apple Docs WWDC26 app MDM updates We have not found a malformed field that explains the iOS 27-only failure. More info Detailed logs and additional info can be found on the Feedback report.
Replies
4
Boosts
5
Views
3.3k
Activity
Aug ’26