Create a device SR requirements profile to manage software updates

You can use a device SR requirements profile to control how device software updates are installed on iOS 18 or later, macOS, Android Enterprise, Android Management, and Samsung Knox devices.

For more information about how certain settings in this profile interact with existing iOS and macOS IT policy rules, see Controlling how software updates are installed on devices. This profile does not apply to iOS 17 devices.

For Android devices, OS update rules apply only to Android Enterprise and Android Management devices with Work space only and Work and personal - full control activation types. App update rules apply to all Android Enterprise devices. Currently, suspending OS updates and automatic app updates are not supported for Android Management devices. See Considerations for Android Management activation types.

  1. In the management console, on the menu bar, click Policies and profiles > Compliance > Device SR requirements.
  2. Click Add icon..
  3. Type a name and description for the profile.
  4. Select the applicable device types.
  5. If you want to manage software updates for iOS devices, on the iOS tab, do the following:
    1. If you want software update notifications to display on users' devices, select the Show software update notifications check box.
    2. In the Recommended software update cadence drop-down list, click one of the following options:
      • To show all available OS updates, click All.
      • To show only the latest OS update, click Newest.
      • To show only the oldest OS update, click Oldest.
    3. If you want to defer software updates by a defined period of days, select the Enable update deferrals check box. In the Combined update deferral period field, specify the deferral period in days (1 to 90).
    4. If you want to turn on automatic OS updates, select the Enable automatic update actions check box. In the Automatic download, Automatic OS update installation, and Automatic security update installation drop-down lists, select whether you want each update action to be Allowed (the user can control when it occurs), Always on (the update action occurs automatically), or Always off (the update action does not occur automatically).
    5. If you want to allow users to install background security improvements, verify that the Enable Background Security Improvement installation check box is selected.
    6. If you want users to have the option to roll back background security improvement installs, verify that the Enable Background Security improvement rollbacks check box is selected.
    7. In the Beta section, in the Program enrollment drop-down list, do one of the following to control whether users can access Apple beta programs in the software update settings on their device:
      • If you do not want users to have the option to enroll in a beta program, click Always off.
      • If you want to allow users to enroll in any Apple beta program that is associated with their Apple account, click Allowed. To offer additional beta programs to users, click Add icon. and specify a beta program name and the enrollment token for the beta program. To obtain an enrollment token, see Apple Platform Deployment: Test software updates with the AppleSeed for IT beta program.
      • If you want users to have access only to Apple beta programs that you specify, click Always on. In the Program selection drop-down list, click Require program to automatically enroll devices in the specified beta program, or click Offer programs to give users the option to enroll in multiple beta programs. Click Add icon. and specify a beta program name and the enrollment token for that beta program. To obtain an enrollment token, see Apple Platform Deployment: Test software updates with the AppleSeed for IT beta program.
  6. If you want to manage software updates for macOS devices, on the macOS tab, do the following:
    1. If you want to allow standard user accounts to install OS updates, select the Allow standard user OS updates check box. If this setting is not selected, only an administrator account can install OS updates on the device.
    2. If you want software update notifications to display on users' devices, select the Show software update notifications check box. This setting applies only to devices with macOS 15 or later.
    3. If you want to defer software updates by a defined period of days, select the Enable update deferrals check box. Specify the deferral period in days (1 to 90) for major OS updates, minor OS updates, and non-OS system updates. This setting applies only to devices with macOS 15 or later (the major and minor settings require macOS 15.2 or later).
    4. If you want to turn on automatic OS updates, select the Enable automatic update actions check box. In the Automatic download, Automatic OS update installation, and Automatic security update installation drop-down lists, select whether you want each update action to be Allowed (the user can control when it occurs), Always on (the update action occurs automatically), or Always off (the update action does not occur automatically). These settings apply only to devices with macOS 15 or later.
    5. If you want to allow users to install background security improvements, verify that the Enable Background Security Improvement installation check box is selected.
    6. If you want users to have the option to roll back background security improvement installs, verify that the Enable Background Security improvement rollbacks check box is selected.
    7. In the Beta section, in the Program enrollment drop-down list, do one of the following to control whether users can access Apple beta programs in the software update settings on their device:
      • If you do not want users to have the option to enroll in a beta program, click Always off.
      • If you want to allow users to enroll in any Apple beta program that is associated with their Apple account, click Allowed. To offer additional beta programs to users, click Add icon. and specify a beta program name and the enrollment token for the beta program. To obtain an enrollment token, see Apple Platform Deployment: Test software updates with the AppleSeed for IT beta program.
      • If you want users to have access only to Apple beta programs that you specify, click Always on. In the Program selection drop-down list, click Require program to automatically enroll devices in a specific beta program, or click Offer programs to give users the option to enroll in multiple beta programs. Click Add icon. and specify a beta program name and the enrollment token for that beta program. To obtain an enrollment token, see Apple Platform Deployment: Test software updates with the AppleSeed for IT beta program.
  7. If you want to manage software updates for Android devices, on the Android tab, do the following:
    1. If you want to allow Android OS update rules to be applied to Samsung devices, select the Apply restriction to all Android Enterprise devices check box.
    2. To configure OS update rules for Work space only and Work and personal - full control devices, in the OS update rule section, click Add icon.. Select the appropriate device model and OS version, and the desired update rule:
      • Default: The user can choose when to install updates. Users with the Work space only (fully managed device) activation type cannot choose when to install updates.
      • Update automatically: Updates are installed without prompting the user.
      • Update automatically between: Updates are installed in a time frame that you specify, without prompting the user. The user can choose to install updates outside of this window.
      • Postpone up to 30 days: Block installation of updates for 30 days. After 30 days, the user can choose when to install an update. Depending on the device manufacturer and wireless service provider, security updates might not be postponed.
    3. Click Add.
    4. Add additional OS update rules as necessary.
    5. To specify time periods when OS updates should not occur for Work space only and Work and personal - full control devices, in the Suspend OS updates section, click Add icon., then do the following:
      1. In the Start month field, type the numerical month value for the suspension period.
      2. In the Start day field, type the first day of the suspension period.
      3. In the Duration field, type the duration of the suspension period in days.
    6. Repeat the previous step to add additional suspension periods. There must be at least 60 days between suspension periods.
    7. To specify an update period for apps that are running in the foreground, select the Enable update period for apps that are running in the foreground check box. Set the start time and duration.
    8. To specify how Google Play applies the changes to apps running in the foreground (the Auto-Update Apps setting in Google Play), in the App auto update policy drop-down list, select one of the following:
      • Always: Apps will always update. For apps that are always running (for example, the BlackBerry UEM Client, BlackBerry Work, or BlackBerry Connectivity), if you don't select the Enable update period for apps that are running in the foreground option, the app will not update until the user manually updates it.
      • Wi-Fi only: Apps will update only when the device is connected to a Wi-Fi network. For apps that are always running (for example, the UEM Client, BlackBerry Work, or BlackBerry Connectivity), if you don't select the Enable update period for apps that are running in the foreground option, the app will not update until the user manually updates it.
      • User can allow: The user is prompted to allow apps to update on the device.
      • Disable: Apps will never update.

      If you select Always, Wi-Fi only, or Disable, the user cannot select a different option on the device. Users can still manually update apps in Google Play.

  8. Click Save.