Skip to content
Configure Android System Update Setting Using Intune

Configure Android System Update Setting Using Intune

Written By Jitesh Kumar
Last Updated September 15, 2023
Posted In Intune
SHARE

This post helps you to configure Android System Update Setting using Intune. You can create an Android device restrictions configuration profile for enrolled and managed Android Enterprise devices for managing software updates behaviour on your organization-owned devices.

As the patches, major & minor updates, and new os versions are released frequently. You must keep devices updated to get the latest security updates, by configuring the policies to control over the update behaviour provide you more flexiblity.

Intune has built-in policies that can manage software updates. You can use Intune to manage Android device updates, configure when devices are updated, and review the device update status.

For enrolled Android Enterprise devices, you can manage OS updates using the Android System update setting. This setting is configurable in an Intune device restrictions configuration profile. When you configure this setting, you choose when the updates are installed. For example, you can:

Patch My PC
  • Use the device’s default behavior, which automatically installs updates if the device is connected to Wi-Fi, is charging, and is idle.
  • Automatically install updates without user interaction. Pending updates install immediately.
  • Postpone updates for 30 days and then prompt users to install updates. Expect your device manufacturer and/or carrier to prevent important security updates from being postponed.
  • Create a maintenance window to automatically install updates during a specific time frame.

Configure Android System Update Setting

Let’s check how you can choose an option to define how the Android system update handles over-the-air updates, The device restriction policy helps you to enable or disable device features, run apps on dedicated devices, control security, and more. This profile is for fully managed, dedicated, and corporate-owned work profile devices.

  • Sign in to Microsoft Intune Admin Center https://intune.microsoft.com/
  • Click on Devices Android Configuration Policies. I selected the existing configuration profile (Device Restriction) for modification and click on General.

You can check more details, you wanted to create device restriction policies from scratch, Enforcing Screen Lock For Android Devices In Intune.

Configure Android System Update Setting Using Intune Fig.1
Configure Android System Update Setting Using Intune Fig.1

In the System update, By default the device restrictions profiles selected the Device Default option. You can choose the different available option from the drop-down list.

Configure Android System Update Setting Using Intune Fig.2
Configure Android System Update Setting Using Intune Fig.2

System update: Choose an option to define how the device handles over-the-air updates. Your options

  • Device Default (default): Use the device’s default setting. By default, if the device is connected to Wi-Fi, is charging, and is idle, then the OS updates automatically. The OS also validates for app updates if the app isn’t running in the foreground.
  • Automatic: Updates are automatically installed without user interaction. Setting this policy immediately installs any pending updates.
  • Postponed: Updates are postponed for 30 days. At the end of the 30 days, Android prompts users to install the update. It’s possible for device manufacturers or carriers to prevent (exempt) important security updates from being postponed. An exempted update shows a system notification to users on the device.
  • Maintenance window: Installs updates automatically during a daily maintenance window that you set in Intune. Installation tries daily for 30 days, and can fail if there’s insufficient space or battery levels.
    • After 30 days, Android prompts users to install. This setting applies to operating system and Play Store app updates. Any maintenance window takes precedence over in-progress device changes. Use this option for dedicated devices, such as kiosks, as single-app dedicated device foreground apps can be updated.
Configure Android System Update Setting Using Intune Fig.3
Configure Android System Update Setting Using Intune Fig.3

In the following options, you can configure the start time, end time for the System update maintenance window.

  • System update – When over-the-air updates are available for this device, they will be installed based on this policy.
  • Start time – Beginning of the maintenance window in the device’s time zone.​
  • End time – End of the maintenance window in the device’s time zone.​​
Configure Android System Update Setting Using Intune Fig.4
Configure Android System Update Setting Using Intune Fig.4

Author

About Author – JiteshMicrosoft MVP, has over six years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus is Windows 10/11 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Written by

Jitesh has over 5 years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus area is Windows 10 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Discussion · 3 comments

  1. Hey, i am having a hard time deploying this to my kiosk devices..
    they wont update even with automatic set.

  2. I am having the same issue with Kiosk-mode devices. Non-Kiosk mode devices are fine, however. Not sure how to resolve!

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read