Create a device SR requirements profile for Android Enterprise and Android Management devices

OS update rules apply only to Android Enterprise and Android Management devices with Work space only and Work and personal - full control activation types. App update rules apply to all Android Enterprise devices. Currently, suspending OS updates and automatic app updates are not supported for Android Management devices. See Considerations for Android Management activation types.
  1. In the management console, on the menu bar, click Policies and profiles > Compliance > Device SR requirements.
  2. Click The Add icon.
  3. Type a name and description for the profile.
  4. If you want to allow Android OS update rules to be applied to Samsung devices, select the Apply restriction to all Android Enterprise devices check box.
  5. To configure OS update rules for Work space only and Work and personal - full control devices, in the OS update rule section, click The Add icon and do the following:
    1. In the Device model drop-down list, select a device model.
    2. In the OS version drop-down list, select the installed OS version.
    3. In the Update rule drop-down list, select one of the following:
      • Default: The user can choose when to install updates. Users with the Work space only (fully managed device) activation type cannot choose when to install updates.
      • Update automatically: Updates are installed without prompting the user.
      • Update automatically between: Updates are installed in a time frame that you specify, without prompting the user. The user can choose to install updates outside of this window.
      • Postpone up to 30 days: Block installation of updates for 30 days. After 30 days, the user can choose when to install an update. Depending on the device manufacturer and wireless service provider, security updates might not be postponed.
    4. Click Add.
  6. To specify time periods when OS updates should not occur for Work space only and Work and personal - full control devices, in the Suspend OS updates section, click The Add icon. Select the month and day that the suspension period starts and the duration of the suspension period.
    If you specify more than one suspension period, there must be at least 60 days between periods.
  7. To specify an update period for apps that are running in the foreground, select Enable update period for apps that are running in the foreground. Select the start time and duration.
  8. To specify how Google Play applies the changes to apps running in the foreground (the Auto-Update Apps setting in Google Play), in the App auto update policy drop-down list, select one of the following:
    • Always: Apps will always update. For apps that are always running (for example, the BlackBerry UEM Client, BlackBerry Work, or BlackBerry Connectivity), if you don't select the Enable update period for apps that are running in the foreground option, the app will not update until the user manually updates it.
    • Wi-Fi only: Apps will update only when the device is connected to a Wi-Fi network. For apps that are always running (for example, the UEM Client, BlackBerry Work, or BlackBerry Connectivity), if you don't select the Enable update period for apps that are running in the foreground option, the app will not update until the user manually updates it.
    • User can allow: The user is prompted to allow apps to update on the device.
    • Disable: Apps will never update.
    If you select Always, Wi-Fi only, or Disable, the user cannot select a different option on the device. Users can still manually update apps in Google Play.
  9. Click Add.
  • Assign the profile to users and groups.
  • If necessary, rank the profile.
  • To view a list of users who are running a revoked software release (a software release that is no longer accepted by a service provider), in Policies and profiles > Compliance > Device SR requirements, click a profile, then click the x users running revoked SR tab.