macOS 27 upgrade checklist for UK businesses
macOS 27 drops every Intel Mac, retires the old update controls, and lands mid-September. Here is the checklist to run before your fleet upgrades.

Stabilise

macOS 27 Golden Gate is expected in mid-September 2026, and it is the first macOS that runs only on Apple silicon. Every Intel Mac stays behind on macOS 26, which keeps getting security patches for roughly two more years on Apple's track record. You do not need to upgrade on day one, and most fleets should not: set a deferral, run a pilot group, and let your software vendors catch up. But two things need doing before a single Mac moves. Check your MDM manages updates through Declarative Device Management, because the old update commands stop working entirely on macOS 27. And rebuild any Accessibility permissions on the new Privacy key, because macOS 27 removes the old PPPC route for Accessibility altogether.
That is the short version. The rest of this post is the reasoning and the runway.
When does macOS 27 come out, and should you upgrade on day one?
Apple has not announced a date. What we know: beta 7 shipped on 24 August, there is no release candidate yet, and the new Mac mini and Mac Studio ship on 22 September with macOS 27 preinstalled (opens in a new tab). The press reads that as a GA somewhere in the 14 to 21 September window. Treat it as an estimate.
Day one is for your pilot ring, not your fleet. There is no compliance clock forcing you onto 27 at release. Cyber Essentials cares that your OS is supported and patched, and macOS 26 will be both for a long while yet. The 14-day patching window applies to security updates within your version, so staying on a patched 26 while 27 settles costs you nothing.
What day one is good for is learning. A handful of Macs on 27 from the start, in your MDM, running your real app stack, tells you more than any compatibility matrix.
Which Macs can run macOS 27?
This is the cleanest break in the Mac's recent history. macOS 27 runs on Apple silicon only. No Intel Mac gets it, and Boot Camp goes with them.
The supported list: Apple silicon MacBook Air and MacBook Pro (2020 onwards), Mac mini (2020 onwards), iMac (2021 onwards), Mac Studio (2022 onwards), the 2023 Mac Pro, and the MacBook Neo. The last Intel holdouts, the 2019 Mac Pro, the 2019 16-inch MacBook Pro, the 2020 iMac and the four-port 2020 13-inch MacBook Pro, all stop at macOS 26.
One more lifecycle note that matters for planning a little further out: Apple has said macOS 27 is the last release with full Rosetta 2, the translation layer that runs Intel-built apps on Apple silicon. After 27, only a limited subset survives for older games. If your business still leans on an Intel-only app, an old accounting package, a vertical tool the vendor never rebuilt, this is the final full cycle to find out and deal with it.
What happens to the Macs that get left behind?
Here is the part that turns a software release into a budget item.
Apple does not publish a support policy for old macOS versions. In practice, and it has held for years, Apple patches the current release and the two before it. Right now that means macOS 26, 15 and 14 all receive security updates (opens in a new tab). When 27 ships, macOS 14 Sonoma falls off the end of the queue. Carnegie Mellon's IT group expects the last Sonoma patches around November 2026 (opens in a new tab). Nobody outside Apple knows the exact date, because Apple never announces it. The updates just stop.
For a UK business, an unsupported OS is not an abstract risk. Three concrete consequences:
Cyber Essentials fails automatically. Under CE v3.3, software that no longer receives security updates is an automatic fail, no remediation window. The NCSC's guidance on obsolete products is blunt: "The only fully effective way to mitigate this risk is to stop using the obsolete product."
Your cyber insurance may not pay. Hiscox, to pick one UK insurer that publishes its exclusions, lists "use of any outdated or unsupported software or systems" (opens in a new tab) among them. A breach traced to an unpatched, out-of-support Mac is exactly the claim dispute you do not want.
Your management tools move on too. Microsoft has announced that Intune, Company Portal and the Intune MDM agent move to a macOS 15 minimum shortly after macOS 27 releases. Macs already enrolled on 14 stay enrolled, but new enrolments on 14 or older get blocked. If you manage Macs through Intune and still have Sonoma-era machines, the walls close in from two directions at once.
So the Intel maths goes like this. Intel Macs top out at macOS 26. On Apple's observed pattern, 26 keeps receiving patches until roughly autumn 2028. That is a genuine two-year runway, and pretending otherwise would be scaremongering. But it has an end, and the end lands mid-certification-cycle for a lot of businesses. Put the refresh on the 2027 budget and stagger it, rather than replacing everything in a panic the week before a renewal.
Will your apps and security tools work on macOS 27?
Honest answer as of late August: mostly unknown, because vendors publish support statements at GA and rarely before.
Jamf has announced same-day support for every major Apple release since 2019, and there is no reason to expect 27 breaks the streak, but the formal statement is not out yet.
Kandji's requirements page still lists 26 as the ceiling. Mosyle, SentinelOne and Microsoft Defender had published nothing macOS 27 specific that we could find. CrowdStrike compatibility during the betas was reported by admins as build-dependent, working on one beta and broken on another, though none of that is vendor-confirmed. Slack and 1Password publish a minimum of macOS 12 with no ceiling, which mechanically covers 27.
The beta cycle has also produced a steady trickle of community-reported breakage in exactly the category you would predict: software that hooks the network stack or the endpoint. Little Snitch blocking all connectivity on beta 1. Tailscale surviving the OS upgrade but breaking when its own app updated. VPN split-tunnel extensions forgetting permissions.
All of it is beta-era and much of it will be fixed by GA. But the pattern tells you where to point the pilot group: your EDR agent, your VPN or zero-trust client, your backup tool, your remote support software. The boring apps will be fine.
The practical rule: no broad rollout until your security stack has a published macOS 27 statement, and your pilot ring has run it for real.
The bit most people miss: your update controls change underneath you
Everything above is standard major-release hygiene. This section is the part specific to 27, and it is the part that will catch fleets that skip it.
The old update controls stop working. Apple's deployment guide states it flatly: software update commands, queries and restrictions no longer function on any of the 27.0 operating systems. If your update deferrals live in an old-style profile, the moment a Mac reaches 27 they stop meaning anything. Update management on 27 runs through Declarative Device Management only.
The DDM replacement is better, once you have it. You get deferrals up to 90 days by update type, plus enforcement that sets a real deadline, warns the user with escalating prompts, and installs at the cut-off whether they clicked or not.
But it only helps if your MDM speaks it. Jamf added DDM update management for on-premises servers in Pro 11.29, cloud customers have had it longer, and every vendor exposes it differently. Confirm yours before September.
Accessibility permissions need rebuilding. We covered the new privacy framework when it was announced: most old PPPC payloads are deprecated in 27 but keep functioning. Accessibility is the exception. Apple's guide says granting Accessibility access through the old profile was deprecated in 26.2 and is removed in macOS 27. Removed means removed. Remote support agents, automation tools, screen readers, anything that pushes an Accessibility grant needs that permission rebuilt on the new Privacy key before the upgrade reaches it, or the tool starts prompting users, or quietly stops working.
One rename to know about. Rapid Security Responses are now called Background Security Improvements as of 26.1, applied as small patches on restart. Your MDM's settings still call the control RapidSecurityResponse, so do not be thrown when the console and the release notes use different names for the same thing.
The September runway
Here is the order we are running for managed fleets, and the order we would suggest for anyone doing this in-house.
- Inventory the hardware. List every Intel Mac. Those stay on 26 and go on the refresh budget with a 2028 horizon.
- Inventory the Intel-only apps. This is the last full Rosetta cycle. Find anything still running translated and ask the vendor the awkward question now.
- Confirm your MDM does DDM update management. If your deferrals live in a legacy profile, rebuild them declaratively before any Mac reaches 27, because on 27 the old ones are dead.
- Set the deferral today. Ninety days is the maximum and there is no prize for using less while the release settles.
- Rebuild Accessibility on the new Privacy key. Do it for every tool that needs it, and test on a beta or day-one Mac, because this is the one permission that does not survive the upgrade.
- Pilot at release. A handful of Macs, the full real app stack, your actual security agents. Watch the EDR, VPN and backup tools first.
- Roll out on your schedule, with a deadline. Once vendor statements are in and the pilot is clean, typically around the first point release, use DDM enforcement to set an install-by date. A rollout without a deadline is a suggestion, and half the fleet will still be on 26 in February.
None of this is difficult. All of it is easier in September than in a hurry in November, with an assessor booked and a Sonoma Mac nobody remembered.
If you would rather this happened without you carrying it, managing exactly this kind of transition is what we do: the pilot, the DDM migration, the permission rebuilds and the rollout deadline, planned around your certification dates rather than Apple's.
Frequently asked questions
- Can I stop my employees upgrading to macOS 27?
- You can delay them, up to a point. MDM deferral hides a major upgrade from users for up to 90 days after release, using Apple's software update settings declaration. That is a ceiling rather than a policy: after 90 days the upgrade becomes visible again. The stronger control works the other way, with DDM enforcement setting a deadline by which the update must be installed. The catch for macOS 27 is that the old MDM update commands and profiles stop working entirely on it, so deferral and enforcement both need your MDM talking Declarative Device Management.
- Do we have to replace our Intel Macs before macOS 27 ships?
- No. Intel Macs stay on macOS 26 Tahoe, and based on Apple's long-observed practice of patching the current release plus the two before it, Tahoe should keep receiving security updates until around autumn 2028. That is a proper runway. It still has an end, though, so the sensible move is to put the Intel exit on next year's budget instead of discovering it during a compliance renewal.
- Is running an old macOS version a Cyber Essentials problem?
- Yes, once it stops receiving security updates. Cyber Essentials v3.3 makes unsupported software an automatic fail, with no remediation window. Apple currently patches macOS 27's two predecessors, so a fleet on 26 or 15 passes today. The version that falls out of support when 27 ships is macOS 14 Sonoma, so any Mac stuck on Sonoma needs upgrading or removing from scope before your next assessment.
- Should we upgrade to macOS 27 on release day?
- Not the whole fleet. Put a small pilot group on it at release, keep everyone else deferred, and watch what your security tools and business apps do. Most vendors had not published macOS 27 support statements as of late August, and beta testing surfaced real friction in network and endpoint tools. A staged rollout a few weeks behind release, once the first point update and the vendor statements have landed, gets you the same result without the day-one surprises.
- What breaks in MDM when macOS 27 lands?
- Two things, both confirmed by Apple. The legacy software update commands, queries and restrictions stop functioning entirely on macOS 27, so update management has to run through Declarative Device Management. And granting Accessibility access through the old PPPC profile is removed outright, so any tool that relies on a pushed Accessibility permission needs rebuilding on the new Privacy key before the upgrade reaches it.


