# macOS Patch Deployment Policy Last Updated On: 21 Sep 2026 A macOS deployment policy defines when patches and OS updates are deployed through the agent-based flow. Use this guide to configure deployment controls, missed-window behavior, enforcement settings, and user notifications, and apply the policy to automated or manual patch deployments. ## Create a macOS Deployment Policy To create a new deployment policy for Mac devices: 1. Navigate to **Threats & Patches → Deployment → Deployment Policies**. 2. Click the **Create Policy** button and select **Mac** from the dropdown menu. 3. Under **Name & Description**: - Enter a descriptive **Name** for the policy. - Optionally, enter a **Description** detailing the policy's purpose or target deployment scope. ## Configure Deployment Controls and Schedules Under **Deployment Controls**, specify when patches and software packages should be deployed through the agent-based flow. 1. Under **Deploy based on**, choose one of the following scheduling modes: - **Weeks & Days:** Choose the applicable values under **Select Weeks** and **Select Days**. - **Patch Tuesday (Tue to next Mon):** Schedule deployment during the Patch Tuesday cycle. - **Calendar Dates:** Choose the applicable calendar dates. 2. Specify the **Deployment Time Period**, which is the time interval during which deployment can occur on the client computer. The minimum permitted duration is 3 hours, ensuring that the agent has sufficient time to communicate with the product server and receive the inputs required to initiate deployment. 3. Under **Month(s) for deployment**, select the months during which the policy applies. Use **Deselect All** to clear selections or click **Add more schedules** to define multiple deployment intervals. ![Mac Deployment Controls showing the scheduling mode, selected weeks and days, deployment time period, and deployment months](https://www.manageengine.com/sites/meweb/images/desktop-central/help/patch-management/deployment-controls.png) ## Configure Missed Window and Enforcement Settings 1. Under **If an endpoint misses deployment windows**, choose how overdue updates are handled: - **Deploy at any time after:** Specify the number of days after which an update becomes eligible for deployment outside the configured time period. After this threshold, deployment proceeds when the endpoint is reachable. - **Retry during the next window:** Waits until the endpoint enters its next scheduled deployment window before attempting installation. 2. Under **If an update requires closing applications or restarting the endpoint**, choose an enforcement option: - **Enforce closure or restart after:** Specify the number of days after which the agent can force running applications to close or restart the endpoint when required by the update. - **Do not enforce:** Does not force application closure or restart. The update remains dependent on the user closing the application or initiating the required restart. ### Deployment precedence and conflict resolution If the same patch is targeted at a Mac endpoint across multiple deployment tasks, the nearest enforcement deadline among those deployments becomes the effective enforcement time. ### How the enforcement day and time are calculated For agent-based deployments, the "days after" threshold used for missed-window and closure or restart enforcement settings is calculated in calendar days. The deployment start day differs by deployment type: - **Manual Deployment** tasks: The configured **Install After** date is used as the deployment start day. If **Install After** is not configured, the task creation date is used. - **Automate Patch Deployment (APD)** tasks: The deployment start day is calculated by applying the delay configured under **Deploy patches after** to the selected option. **Days from release** uses the vendor release date, while **Days from approval** uses the patch approval date. - **Test and Approve** workflows: The deployment start day is calculated by applying the delay configured under **Deploy patches after** to the vendor release date. The threshold takes effect at 12:00 AM on the date obtained by adding the configured number of calendar days to the applicable deployment start day. This calculation uses the endpoint's local time zone. **Example** If a task is created on 21 August 2026 at 3:00 PM, and the enforcement threshold is set to **5 days**, enforcement takes effect from 26 August 2026, 12:00 AM — the start of the day the 5-day period elapses — not 26 August 2026, 3:00 PM. ## Configure User Notifications 1. Under **Notify end users when action is required**, select: - **Enable:** Displays an interactive notification when an update requires closing applications or entering credentials, allowing the user to proceed or postpone. When the user chooses to postpone, the notification reappears based on the selected reminder interval. The available reminder interval is constrained by the effective enforcement time and cannot postpone enforcement beyond it: | Reminder interval | Next notification display | |---|---| | 1 hour | One hour after the user selects **Remind Me**. | | 6 hours | Six hours after the user selects **Remind Me**. | | Remind Me Later | After 24 hours have elapsed, during the next scheduled deployment window. | - **Disable:** Suppresses end-user notifications and displays a confirmation before the policy is saved. ![Update notification showing the options to install the update or select a reminder interval](https://www.manageengine.com/sites/meweb/images/desktop-central/help/patch-management/reminder-notification.png) **Caution** Forcing deployment without notifying the user may cause sudden restarts or application crashes. OS updates and upgrades that require credentials cannot be applied without notifying the user. ## Save and Apply the Policy 1. Review the configured schedule, missed window behaviors, and notification preferences. 2. Click **Save** to store the policy. 3. Select the saved policy when creating: - **Automate Patch Deployment (APD) tasks:** Under **Choose Deployment Setting → Apply Deployment Policy**. - **Manual Deployment tasks:** Under the *Deployment Policy* dropdown. - **Test and Approve workflows:** Under **Deployment Policy → Apply Deployment Policy**. **Note** When selecting a deployment policy for a **Manual Deployment** task, you can optionally override the policy's configured settings for that task. ## Preview the Password Prompt On Apple silicon Macs, macOS uses an available bootstrap token to authorize an OS update. If a bootstrap token is unavailable and the update is handled through the agent-based flow, macOS can display a password prompt to the logged-in user. Ensure users are informed about the prompt format so they can authenticate securely during scheduled update cycles. ![Password prompt requesting credentials to authorize an OS update on an Apple silicon Mac](https://www.manageengine.com/sites/meweb/images/desktop-central/help/patch-management/password-prompt.png) **Prerequisite** MDM enrollment alone does not guarantee that macOS can authorize an update silently. A bootstrap token must be available to authorize the update without prompting for credentials. See [Deploy OS Updates on Apple Silicon Macs Without User Intervention](https://www.manageengine.com/products/desktop-central/help/mac-patching-user-intervention.html) for more information. ## Related - [Deployment Policy](https://www.manageengine.com/vulnerability-management/help/patch-management/patch-deployment-policy.html) - [Automate Patch Deployment](https://www.manageengine.com/vulnerability-management/help/patch-management/apd.html) - [Manual Deployment](https://www.manageengine.com/vulnerability-management/help/patch-management/manual-deployment.html) - [Best Practices for Automatic Patch Deployment](https://www.manageengine.com/vulnerability-management/help/patch-management/best-practices-for-automatic-patch-deployment.html)