Controlling how software updates are installed on devices
|
Method |
OS |
Description |
|---|---|---|
|
Device SR requirements profile |
|
You can use this profile to control how device software updates are installed on iOS 18 and later, macOS, Android Enterprise, Android Management, and Samsung Knox devices. For devices running iOS 18 and later, this profile replaces the following iOS software update IT policy rules (and all associated sub-rules):
If your organization currently uses these IT policy rules, on devices running iOS 18 and later, this profile takes precedence over the IT policy rules. The profile does not apply to iOS 17 devices. For devices running macOS 15 and later, this profile replaces the following macOS IT policy rules:
For devices running macOS 15 and later, any assigned device SR requirements profiles have deferral settings that take precedence over these IT policy rules. For more information, see Create a device SR requirements profile to manage software updates. |
|
Software update enforcement profile |
|
You can use this profile to manage automatic OS updates to a required minimum version of iOS or macOS software. For iOS devices, this profile replaces the "Update schedule" iOS software update IT policy rule (and the associated sub-rules). If your organization currently uses the "Update schedule" IT policy rule, this profile takes precedence over the rule. For more information, see Create a software update enforcement profile to update devices to a required OS version. |
|
IT policy: iOS software update rules |
iOS |
You can use the iOS software update IT policy rules to control software updates on iOS devices. For devices running iOS 18 and later, any assigned device SR requirements profiles take precedence over the following iOS software update IT policy rules (and all associated sub-rules):
For all supported versions of iOS, any assigned software update enforcement profiles take precedence over the "Update schedule" IT policy rule and associated sub-rules. |
|
IT policy: macOS software update rules |
macOS |
You can use certain macOS device functionality IT policy rules and macOS user functionality IT policy rules to manage how software updates are installed, for example, you can set up rules for deferred installation. For devices running macOS 15 and later, device SR requirements profiles have deferral settings that take precedence over the following IT policy rules:
|
|
OS update command |
iOS (supervised) |
You can use the management console to manually send an OS update command to one or more supervised iOS devices. For more information, see Send an OS update command to supervised iOS devices. |
Note that BlackBerry UEM no longer supports Knox E-FOTA on MDM, but you can use Knox E-FOTA One to control when firmware updates from Samsung are installed. For instructions for migrating to and configuring integration with E-FOTA One, see KB 69901. Samsung Knox devices that are activated as Work and personal - full control (Samsung Knox), Work space only (Android Enterprise fully managed device), and Work and personal - full control (Android Enterprise fully managed device with work profile) support software restrictions using E-FOTA One. E-FOTA One is not supported for Work and personal - user privacy (Samsung Knox) or Work and personal - user privacy (Android Enterprise with work profile) activation types.