Hi @haanaa,
Hexnode agent updates on Android can be silent, but the behavior depends on the enrollment method, app privileges, and how the agent update is being delivered.
For silent Hexnode UEM Android app updates, check the following:
- Go to Admin > General.
- Enable Automatically Update Hexnode UEM Android App.
- If available in your portal, also enable the option that automatically grants the required permissions during Hexnode app updates.
When this automatic update option is enabled and the device has the required management privileges, the Hexnode agent update should be installed silently. If the update is handled outside this flow, or if the device lacks the required privileges, Android may display the standard install screen even when the device is in kiosk mode.
For scheduling: Hexnode supports scheduling Android OS updates during inactive hours, but there is no separate native maintenance-window scheduler specifically for automatic Hexnode agent self-updates. If you need strict out-of-hours control, the practical workaround is to disable Automatically Update Hexnode UEM Android App, upload the newer Hexnode app version as an Enterprise app, and deploy it manually during your maintenance window.
For notifications: Hexnode does not currently send a proactive alert immediately before an automatic Hexnode agent update is executed. If your environment requires version-change approval, manual Enterprise app deployment gives you the most control over when the update is pushed.
For minimum network access, no inbound management ports need to be opened for Hexnode MDM communication. The following outbound access should remain available for Android device management, command delivery, and app/agent downloads:
- HTTPS/TCP 443 to your Hexnode portal URL.
- HTTPS/TCP 443 to static.hexnodemdm.com and downloads.hexnode.com.
- HTTPS/TCP 443 to the Amazon S3 endpoints used for your Hexnode region, for app and file management.
- MQTT outbound TCP 1883 and 8883 for real-time command delivery.
- Firebase Cloud Messaging access on TCP 5228, 5229, 5230, and 443 so Android devices can receive push notifications and wake for management actions.
- DNS on TCP/UDP 53 so devices can resolve the required service hostnames.
Under a minimum-endpoints policy, keep the permanent access limited to the services required for portal communication, app/content downloads, MQTT command delivery, FCM push delivery, and DNS resolution.
Regards,
Isabel Lora
Hexnode UEM