# Enforce Patch Deadlines in Hexnode UEM: Configuration Guide

Quick Summary
-------------

The **Enforce Patch Deadline** automation action in Hexnode UEM allows IT administrators to ensure that targeted Apple devices are updated to a **specified OS and build version within a defined deadline**. If the update is not installed by the deadline, Hexnode enforces the update on the device. Administrators can set a **patch deadline** — the date and time by which the specified update must be installed on the device. This is useful when administrators need to ensure that devices meet organizational requirements, such as maintaining a minimum OS version for access to corporate resources, meeting security standards, or supporting business applications that require a specific OS version.

Supported Platforms
-------------------

PlatformSupported VersioniOS17.0+macOS14.0+Apple TV18.4+visionOS26.0+Prerequisites
-------------

Ensure the following requirements are met before configuring Enforce Patch Deadline:

- **Declarative Device Management (DDM):** DDM must be active on the device. For more information, see [Declarative Device Management](https://www.hexnode.com/mobile-device-management/help/declarative-device-management/).
- **Enrollment Type:** User Enrollment is **not** supported. The action is supported on all other Apple enrollment types. For more information, see [Apple Enrollment Types](https://www.hexnode.com/mobile-device-management/help/intro-to-different-apple-device-enrollment-types-in-hexnode/).

Steps to configure Patch Deadline
---------------------------------

1. Log in to Hexnode UEM.
2. Navigate to the **Automate** tab and click **New Automation**.
3. Select the required platform.
4. Under **Create New Automation**, select **Quick**.
5. Under **Triggers and Schedules**, select when the configured action should be sent to the target devices. The selected trigger determines when the patch deadline configuration is delivered to the devices. 
    - **Apply Now** – Sends the configured action to the target devices immediately.
    - **On a Schedule** – Sends the configured action to the target devices according to the selected schedule. Each time the schedule runs, the action is sent to the devices.
    - **Event** – Sends the configured action to the device when the selected event occurs.

### Apply Now

Select **Apply Now** to send the configured action to the target devices immediately.

### On a Schedule

Select **On a Schedule** to send the configured action at a specified date and time or at a recurring frequency.

Under **Schedule Settings**, configure the following;

1. **Frequency** – Specifies how often the configured action is sent to the device. 
    - **Run Once** – Sends the action once at the specified date and time.
    - **Every Day** – Sends the action every day at the specified time.
    - **Weekly** – Sends the action on the selected days of the week at the specified time.
    - **Monthly** – Sends the action on the specified day of each month at the specified time.
2. **Scheduled Date** *(for Run Once)* – Select the date on which the automation should run in `MM/DD/YYYY` format.
3. **Scheduled Time** – Specify the time at which the automation should run in `HH:MM` format and select the required time zone.

### Event

Select **Event** to send the configured action to the device when the selected device event occurs. For example, select **On Device Enrollment** to send the configured action when a device is enrolled in Hexnode UEM.

The available events vary by platform. For details on the events supported for each platform, see the Event page.

Select the required trigger and click **Next**.

6. Under **Choose Actions**, navigate to **Patches and Updates** and select **Enforce Patch Deadline**.
7. Configure the following settings: 
    - **Target OS version** – Select the OS version to be enforced on the device.
    - **Target build version** – Specify the build version to be enforced on the device.
    - **Time for enforcing the update** – Specify the date and time by which the update must be installed on the device.
    - **Details URL** – Enter the URL of a webpage containing additional information about the update.
    
    After configuring the settings, click **Confirm**.

8. Under **Assignments**, specify the devices or users to which the automation should apply. You can target devices or users using: 
    - **Included Groups** – Select the device or user groups to which the automation should apply.
    - **Excluded Groups** – Select the device or user groups to exclude from the automation.
    - **Filters** – Create custom filters to target devices or users based on specific attributes.
9. Under **Review**, verify the configured automation settings.
10. Click **Save** to create the automation.

What Happens at the Device End?
-------------------------------

Once the configured trigger is met, the action is sent to the device, the specified update becomes available for installation. The user is notified about the available update and can choose to install it or defer the update until the configured deadline. If the update is not installed by the deadline, Hexnode enforces the update on the device.

Related Topics
--------------

[Patch Management with Hexnode UEM](https://www.hexnode.com/mobile-device-management/help/patch-management-with-hexnode-uem/)