Last Monday, June 9th, it was that time again: WWDC25! This means that Apple gives a preview of the upcoming versions of platforms like macOS, iOS, iPadOS, and more. This year was a special edition because Root3 was invited to attend the event in Cupertino at Apple Park, speak with Apple engineers, and participate in developer activities.

In this blog, we’ll take you through the most important innovations for organizations, other relevant developments, and give you a little insight into how we experienced this event.

The event

As mentioned, Root3 was present at Apple Park in Cupertino where our colleague Jordy Witteman took a seat in a pop-up open-air theater with comfortable lounge chairs for the most important software Keynote of the year. Together with more than 1000 other developers, media, and Apple engineers, we watched the Keynote and got a taste of which innovations were well-received by the audience. Afterwards, the Platforms State of the Union provided insight into new functionalities for developers and a deeper dive into the Keynote. Later in the day, there was an opportunity to ask Apple engineers questions during 1-on-1 labs, where we could specifically ask questions with “Business & Education” and “SwiftUI & UI frameworks” to improve our App Catalog and Support App and prepare them for the new versions. We even briefly met CEO Tim Cook!

The next day, additional sessions took place at the Apple Developer Center where the new “Liquid Glass” design was explained in more detail and how developers can best implement it. In sessions like these, you really notice how much attention Apple pays to design and how they come up with certain ideas to make hardware and software work together for an optimal user experience. Truly every detail is considered!
Want to know more about the event and how Jordy experienced it? You can find an article with his experience on his LinkedIn profile: Adventures in Cupertino: An Unforgettable WWDC25 Experience

Clearer version numbers

This year, Apple is adjusting the version numbers of its platforms and aligning them with the year. This means that later this year we can expect iOS 26, tvOS 26, macOS 26, and iPadOS 26, among others. That’s a big jump! Apple hopes to create clarity with this, and the numbers will be easier for everyone to remember. It will take some getting used to, but as far as we’re concerned, it’s a logical step for the future.

Liquid Glass: hierarchy, harmony, and consistency

The rumors had been persistent that a new user interface would be introduced on all platforms, and so it happened: a completely new design is being implemented in macOS, iOS, iPadOS, watchOS, and visionOS. Apple calls this design Liquid Glass, and it consists of components that mimic the optical properties of glass, ensuring fluid user interactions. The goal is to give app content even more space and provide a richer experience. This is achieved through three core principles: hierarchy, harmony, and consistency across all Apple devices and platforms. Certain elements disappear and appear at the right moments. Impressive and well thought out.

It will also be easier for developers to design app icons with Liquid Glass and use them on all Apple platforms, with the correct dimensions and rounded corners. It might take some getting used to for some, but we are convinced that this reaches a new height of user-friendliness, where only Apple can be a trendsetter. At Root3, we strongly believe in the ‘native’ Apple experience, and we will certainly get our macOS apps ready this summer to use the new design.

Control over Apple Accounts

The topic of Apple Accounts is often discussed with our customers, for example, Managed Apple Accounts, how they can be created automatically, and linking them with an identity provider. Or which functionalities of an Apple Account are permitted. A limitation is that it cannot be enforced which type of Apple Account may be used. Later this year, it will be possible for organizations to specify in Apple Business Manager that either all types of accounts can be used on devices or only a Managed Apple Account. A welcome innovation, because thanks to this setting, organizations can confidently allow (all or Managed) Apple Accounts and possibly also permit more functionalities of, for example, iCloud. After all, they then run no risk of data being stored on personal Apple Accounts, as it will always be within the managed environment.

MDM migration easier than ever

For several years, we have increasingly seen organizations switch MDM solutions for various reasons, such as from on-premises to the cloud, acquisitions, or to another provider. Until now, advanced solutions (scripts) with certain dependencies and uncertainties were required. Alternatively, users had to wipe their device and re-enroll it in the new MDM solution, resulting in the loss of settings and time. A new feature later this year in Apple Business Manager and Apple School Manager will allow administrators to easily switch devices by selecting a different MDM solution and setting a deadline. Users will be periodically notified of this and asked to complete the steps until this process becomes mandatory after the set deadline. With the necessary actions from the MDM solution, it is even possible to send the configurations for Managed Apps, FileVault, and Activation Lock so that the user does not have to perform any further actions to (re)generate recovery codes.

Apple does indicate that it is the administrator’s responsibility to ensure a smooth migration, for example, that endpoint protection continues to run without interactions or other conflicts between the two MDM solutions. Root3 can, of course, support your organization in this process to ensure that no ‘gaps’ arise and to set up the new MDM solution as optimally as possible with best practices for a smooth migration.

Better management for macOS apps

The options for app installation via Declarative Device Management (DDM) are being expanded with support for macOS. It will be possible to distribute apps from the Mac App Store, Custom Apps, or PKG installations, all natively via DDM and ‘agentless’. A ‘declaration’ can determine whether an app is required or optional, around which the MDM vendor can build an intuitive user interface. This was already available for iOS/iPadOS, and hopefully, many MDM vendors will create a great experience from this.

For a few years now, the concept of ‘Managed Apps’ has also been possible on macOS, although support for it was still relatively limited and it was required that the app be installed via the InstallEnterpriseApplicationCommand command. That changes with an extension within the AppManaged declaration, allowing administrators to make apps ‘managed,’ regardless of the installation method. This is good news for customers of App Catalog and other distribution methods, as they can now manage apps even better in combination with MDM. Some advantages of ‘Managed Apps’ include removing apps upon unenrollment or preventing data from being backed up.

iPadOS, next-level multitasking

iPadOS is getting perhaps its biggest update ever with iPadOS 26! A common piece of feedback is that the iPad is enormously powerful, but with limited multitasking and window layout flexibility. After several years of improvements, a giant leap is now being taken with almost complete freedom in arranging (multiple) windows wherever you want. You can snap windows to a corner or part of the screen with a swipe. And it works much more intuitively, so many more users will likely find and start using the options. Apple has used some familiar components and patterns from macOS, such as the colored buttons in the top-left of windows for closing or minimizing apps. And there is now even a menu bar and a download folder in the Dock. Developers can also use a new API to perform (longer) background tasks such as exporting or downloading data. All in all, it’s a huge boost for the iPad, and the expectation is that it can be used for more tasks and could replace a laptop for more users.

Platform SSO, fully streamlined

Platform Single Sign-On has been available since macOS 13, and it took a while for identity providers to offer support. Currently, Microsoft is leading the way with, among other things, support for storing the key within the Secure Enclave for phishing-resistant authentication. The user benefits from a flawless login experience on all (web) apps linked to Microsoft Entra ID. We previously wrote a blog about Single Sign-On with a focus on Platform SSO: How Root3 optimizes the Apple experience and security with Single Sign-On.

The only missing step was to apply Platform SSO directly during deployment. Until now, this required that a local account had already been created, for example, via other applications. With macOS 26, Apple will further simplify Platform SSO by including it as a step in the Setup Assistant, allowing the user to log in once and immediately complete the registration with the identity provider. It is even possible to log in directly with a Managed Apple Account during this process if it is linked to the same identity provider as Platform SSO. And for shared Macs using Auto Advance, the Platform SSO registration can even be performed completely automatically, and a user can log in directly without an administrator having touched the Mac. A zero-touch deployment will become much simpler for many organizations and users, with fewer interactions and less chance of ambiguity and IT tickets.

API for Apple Business/School Manager

For organizations that want a deeper integration with Apple Business Manager or Apple School Manager, there is also good news. Through an API, they can retrieve information from the portals and integrate it into other processes such as inventory management or device assignment. The information that can be retrieved includes a list of devices, MDM servers, device information, device assignments, and actions for assigning devices to an MDM server. And good news: this feature is available now! To get started, you can generate a Private API Key in the portal and use it in a REST API request, but of course, we hope that relevant applications will eventually build this in.

Many more innovations

That is, of course, not everything, but it is a selection of the most important innovations for organizations. But what about:

  • Unmanaged Apple Account list for your organization’s domain
  • Network Extension API for URL filtering
  • Safari management
  • App preservation for Return to Service
  • Version pinning of apps from the App Store
  • Platform SSO attestation
  • Authenticated Guest Mode with Platform SSO
  • Tap to login with Platform SSO

Want to know more? All information is available at beta.apple.com/for-it, watch this session or contact us at support@root3.nl or +31 85 400 30 30.