- Published on
MDMs such as Addigy are beginning to incorporate and support reading device declaration logs. This exposes the many technical errors and issues that DDM updates tend to face. Here are the errors showing up and what each one means.
DDM Errors:
• Update Failed The software update failed to install. This is a general failure that can be caused by a missing Bootstrap Token, insufficient storage, or a network issue.
• Credential Stash State Error macOS tried to save the user's update credentials, but no valid prepared update was available at that moment. This is a sequencing error between the prepare and commit phases.
• Update Access Denied The update access request was denied because another update process was already running on the device.
• Update Service Error The device's software update service encountered an internal error while trying to check for or schedule an OS update.
• Descriptor Reload Failed The device failed to reload the software update download descriptor. A network issue is one possible cause, but not the only one.
• Credentials Save Failed macOS was unable to save the user credentials required to authorize the update. Common underlying causes include boot policy failures and volume-ownership issues.
More telemetry is always welcome. However we have found that these errors are generally quite obscure, and are unclear what an actual fix would be - whether that means escrowing a bootstrap token, or dealing with a user who lacks admin rights.
What Error Rates Look Like
Update error percentages are not a constant. They can fluctuate daily, and we have seen error rates climb above 80% before. In our latest snapshot, Update Failed led the list at 32.6%, but that number can swing quickly from one day to the next.
Data from macOS 27 upgrades shows that DDM has a high error rate, as we discussed in our earlier blog post, "What about DDM?".
A Clearer Alternative: Proximos Telemetry
Proximos has its own set of telemetry metrics on pending macOS updates, and they are more straightforward and useful than the DDM errors. They are provided as MDM extension attributes:
|
Attribute |
Type |
What It Tells You |
|
currentMode |
String |
Returns "minor", "major", or "enrollment", the current operating mode of the last engine run |
|
daysRemaining |
Integer |
Negative means days remaining before the enforcement deadline. Positive means days past the deadline |
|
isLicensed |
Boolean |
true if a valid Proximos license key is present and successfully decoded |
|
LastRun |
Date |
ISO-8601 timestamp of the most recent Proximos update check run |
|
majorInstallerDownloadError |
Integer |
Non-zero exit code from `softwareupdate --fetch-full-installer` if the major installer download failed |
|
majorReleaseName |
String |
The detected macOS major release marketing name (e.g., "Tahoe") |
|
skipmacOSVersion |
String |
The macOS version string currently set as the skip sentinel, if any |
|
softwareupdateError |
Integer |
Exit code from `softwareupdate --list` if it failed. 0 means it ran cleanly but reported no updates available for this Mac |
|
updateAvailable |
Boolean |
true if a macOS update is currently required for this Mac |
|
updateVersion |
String |
The currently detected available macOS version (e.g., "15.5", "26", or "enrollment" during the grace period) |
Instead of decoding an obscure error string, you get clear answers: is an update required, how close is the deadline, and did the download or update check fail along the way. More information on our MDM Extension Attributes / Custom Facts is provided on our documentation site.
Don't leave patching compliance to chance: Proximos adds a dedicated layer of patching compliance and telemetry on top of DDM, with clear, actionable data in your MDM, notifying users and empowering them to get compliant, so fewer devices slip through the cracks of obscure update failures.