New features summary

This section provides summaries of new features and enhancements that are available in this release. References to documentation describing these features and enhancements are also provided, when available.

General features and enhancements

Android features

iOS, macOS, watchOS, visionOS, and tvOS features

Windows features

General features and enhancements

  • Enhanced macOS Package ID Handling: Improved macOS in-house PKG app deployment by automatically detecting and populating the correct package ID during app upload and ensuring the same package ID is sent to devices. This enhances app identification accuracy, resolves server-device install state mismatches, and improves installation status reporting. Bundle IDs can be reviewed and edited during upload before being locked after deployment.

  • Bundle ID Visibility for Installed Apps: The Installed Apps section on the Device Details page now includes a Bundle ID column, which can be enabled or hidden from the page settings.

  • Automatic Retry for Failed Android App Installations: Android app installations that enter an Error Install state are now automatically retried starting one hour after device registration. Installation commands are re-sent every 30 minutes for up to five attempts to improve app deployment success.

  • Device Movement Audit Trails for Spaces: Added the Enable Audit Trails for Device Enrollment and Unenrollment in Spaces setting to track device movement between spaces. For more information, see Exporting Audit Trails.

  • OS Platform filter for Device Cleanup Settings: Administrators can now filter device cleanup actions by OS platform when removing Retired and Retire Pending devices. By default, all supported platforms remain selected, preserving the existing behavior. Administrators can modify the selection and restrict cleanup operations to specific platforms as required. For more information, see Device Cleanup Settings.

  • Office 365 App Protection Policy Synchronization: Previously, administrators could select apps directly within Ivanti Neurons for MDM while creating or modifying app protection policies. Microsoft has deprecated the API that was used to retrieve the available apps list, causing protected app lists to appear empty in Ivanti Neurons for MDM. Microsoft Office 365 App Protection policy management is updated to align with changes in Microsoft Intune. Applications configured in Intune are now automatically synchronized to Ivanti Neurons for MDM, ensuring continued visibility of protected apps. While app removal remains supported from Ivanti Neurons for MDM, new app assignments must be configured in Microsoft Intune and will be reflected automatically.

  • Device Movement Audit Logging for Spaces: Administrators can now track device movement between spaces through Audit Logs. When enabled, the new audit setting records events whenever a device is removed from one space and added to another, providing greater visibility into automated and rule-based space assignments. For more information, see Exporting Audit Trails.

  • Automatic Custom Attribute assignment using Device Groups: Administrators can now assign custom attributes at the device group level. Devices that are members of a device group automatically inherit the configured attribute values, reducing manual configuration and helping ensure consistent device categorization. For more information, see Device Groups.

  • OS-Level Device Registration Restrictions: Restrict device registration by platform, allowing only approved Apple, Android, and Windows devices to enroll. For more information, see User Settings.

Android features

  • Prevent App Updates While App Is in Use: Administrators can now prevent managed Android apps from being updated while they are actively in use. When Do Not Update While App Is In Use is enabled, app updates are deferred until the user closes the app or moves it to the background, helping minimize disruptions during active sessions. For more information, see App Configuration.

  • Maintain Kiosk Mode across Lockdown Policy changes:Added support for maintaining kiosk mode across lockdown policy changes. Devices automatically return to kiosk mode after a lockdown policy update, reducing manual intervention and minimizing disruptions on dedicated-purpose devices. For more information, see Lockdown & Kiosk: Android Enterprise.

  • Enable Unredacted Notifications: Added support for configuring lock screen notification visibility on Device Owner devices. Administrators can display, hide, or redact notification content on the lock screen to help protect sensitive information while maintaining notification functionality. For more information, see Advanced Android Passcode and Lock Screen.

  • Support for Device-to-User Mapping during Bulk Enrollment of Profiles: Added support for device-to-user mapping in bulk enrollment profiles. Administrators can assign a specific user to each device through the bulk enrollment CSV file or during manual device addition, enabling automatic user assignment during enrollment and reducing post-enrollment administrative tasks. Administrators can also update user assignments before device enrollment. For more information, see Device-to-User Mapping in Bulk Enrollment Profiles.

iOS, macOS, watchOS, visionOS, and tvOS features

  • New Skip Keys for Device Enrollment profiles: Administrators can now use the following Skip Keys when creating Device Enrollment profiles:

    • Skip Liquid Glass Pane (iOS 27.0+ and macOS 27.0+)

    • Skip Accessibility Appearance Pane (iOS 27.0+)

      These skip keys help streamline the enrollment experience by allowing administrators to hide specific setup panes during device enrollment. For more information, see Device Enrollment.

  • Support for DDM Device System Health Status: Ivanti Neurons for MDM now supports the DDM Device System Health status on the Device Details page. Administrators can view this status under the Device Component Health section to monitor the system health reported by the Supervised devices. For more information, see Getting Started with Devices.

  • Added new Device Details fields for Apple devices: Added new Device Details fields to provide more visibility into Apple Device Management states. Administrators can now view the following details:

    • Multi-User Mode for devices operating on iOS 27.0+. This field indicates whether an iPad is configured as a shared device.

    • MDM Enrollment Type for devices operating on iOS 27.0+, macOS 27.0+, tvOS 27.0+, visionOS 27.0+, and watchOS 27.0+.

    • MDM Return to Service with app preservation for devices operating on iOS 27.0+ and visionOS 27.0+.

      These fields help administrators review device configuration and enrollment information directly from the Device Details page. For more information, see Getting Started with Devices.

  • Support for App Privacy Defaults Configuration: Administrators can now configure App Privacy Defaults for one or more apps using Apple Device Declarative Management (DDM). When an app first launches, users receive a single consent prompt to allow or defer recommended permissions for supported privacy components, such as camera, microphone, location, Bluetooth, and local network access. For more information, see App Privacy Defaults.

    The App Privacy Defaults configuration is now supported on macOS 27.0+ supervised devices.

  • Added new DDM app management attribute: Added the DDM app management attribute Apple DDM App Enabled field to the 'Advanced Search' and device listing pages. It shows which devices have apps distributed via DDM. Admins can turn this on through User Settings. For more information, see Getting Started with Devices.

  • Enhanced macOS Extensible SSO Configuration: Updated macOS Extensible SSO configuration to correctly map token attributes such as preferred_username and name. This resolves configuration errors caused by invalid token-to-user mappings and allows SSO profiles to be successfully deployed to devices.

  • Apple Enhanced Logging: Administrators can initiate Apple Enhanced Log Collection on supported Apple devices using an AppleCare-provided token. Device details display session status, token, and timestamp information, and active sessions can be canceled if required. For more information, see Apple Enhanced Logging.

  • Lockdown Mode Status (iOS 27+, macOS 27+): Added support for viewing and filtering devices by Lockdown Mode status using the new Security Lockdown Mode field on the Device Details page, Advanced Search, and device group rules. This field indicates whether Lockdown Mode is enabled (true) or disabled (false) on a device. For more information, see Getting Started with Devices , Device Groups and Custom Policy.

  • macOS Software Update Settings Support Update: The macOS Software Update Settings configuration is no longer supported on macOS 27 and later devices. This configuration now applies only to supported versions up to macOS 26.x. For more information, see macOS Software Update Rules Configuration.

  • Restrictions Support Update (iOS 27+, macOS 27+): Updated the Allow Background Security Improvements Installation and Allow Background Security Improvements Removal restrictions to indicate that they are no longer supported on iOS 27 and later and macOS 27 and later devices. For more information, see iOS Restrictions and macOS Restrictions.

  • Updates to Siri Settings Configuration (iOS 27.0+, macOS 27.0+, tvOS 27.0+, and visionOS 27.0+): Added support for new restriction settings in the Siri Settings configuration . For more information, see Siri Settings.

  • Updates to Intelligence Settings Configuration (iOS 27.0+, macOS 27.0+, and visionOS 27.0+): Added support for new restriction settings in the Intelligence Settings configuration. For more information, see Intelligence Settings.

  • Safari Privacy Settings (iOS 27.0+, macOS 27.0+): Added support for Safari Privacy Settings in the Safari Extension and Settings configuration, allowing administrators to configure default Camera and Microphone permissions for specific websites using Apple Declarative Device Management (DDM). For more information, see Safari Extension and Settings Configuration

Windows features

  • Windows AI Management Configuration: Windows AI Management now supports additional Windows AI CSP policies for managing Microsoft Copilot, Windows Recall, and Microsoft Paint AI features. Administrators can disable the Copilot hardware key, remove the Microsoft Copilot app, disable AI data analysis for Recall, configure Recall snapshot storage limits, and disable Image Creator, Cocreator, and Generative Fill in Paint. Support for both user-scoped and device-scoped policies has also been added, enabling more granular control of AI capabilities on Windows devices. For more information, see Windows AI Management Configuration.

Mobile Threat Defense features

Mobile Threat Defense (MTD) protects managed devices from mobile threats and vulnerabilities affecting device, network, and applications. For information on MTD-related features, as applicable for the current release, see the Mobile Threat Defense Solution Guide for your platform, available under the MOBILE THREAT DEFENSE section on the Ivanti Product Documentation page.

Each version of the MTD guide contains all Mobile Threat Defense features that are currently fully tested and available for use on both server and client environments. Because of the gap between server and client releases, new versions of the MTD guide are made available with the final release in the series when the features are fully functional.