Category filter

Enforce Patch Deadlines in Hexnode UEM: Configuration Guide

TL;DR

The Enforce Patch Deadline automation action in Hexnode UEM ensures that required updates are installed on managed Apple devices within a specified timeframe. This guide helps administrators configure patch deadlines, select when the action should be delivered, specify the required OS and build versions, target devices, and understand how the update is enforced on the device.

Quick Summary

The Enforce Patch Deadline automation action in Hexnode UEM allows IT administrators to ensure that targeted Apple devices are updated to a specified OS and build version within a defined deadline. If the update is not installed by the deadline, Hexnode enforces the update on the device. Administrators can set a patch deadline — the date and time by which the specified update must be installed on the device. This is useful when administrators need to ensure that devices meet organizational requirements, such as maintaining a minimum OS version for access to corporate resources, meeting security standards, or supporting business applications that require a specific OS version.

Supported Platforms

Platform Supported Version
iOS 17.0+
macOS 14.0+
Apple TV 18.4+
visionOS 26.0+

Prerequisites

Ensure the following requirements are met before configuring Enforce Patch Deadline:

  • Declarative Device Management (DDM): DDM must be active on the device. For more information, see Declarative Device Management.
  • Enrollment Type: User Enrollment is not supported. The action is supported on all other Apple enrollment types. For more information, see Apple Enrollment Types.

Steps to configure Patch Deadline

  1. Log in to Hexnode UEM.
  2. Navigate to the Automate tab and click New Automation.
  3. Select the required platform.
  4. Under Create New Automation, select Quick.
  5. Under Triggers and Schedules, select when the configured action should be sent to the target devices. The selected trigger determines when the patch deadline configuration is delivered to the devices.
    • Apply Now – Sends the configured action to the target devices immediately.
    • On a Schedule – Sends the configured action to the target devices according to the selected schedule. Each time the schedule runs, the action is sent to the devices.
    • Event – Sends the configured action to the device when the selected event occurs.

Apply Now

Select Apply Now to send the configured action to the target devices immediately.

On a Schedule

Select On a Schedule to send the configured action at a specified date and time or at a recurring frequency.

Under Schedule Settings, configure the following;

  1. Frequency – Specifies how often the configured action is sent to the device.
    • Run Once – Sends the action once at the specified date and time.
    • Every Day – Sends the action every day at the specified time.
    • Weekly – Sends the action on the selected days of the week at the specified time.
    • Monthly – Sends the action on the specified day of each month at the specified time.
  2. Scheduled Date (for Run Once) – Select the date on which the automation should run in MM/DD/YYYY format.
  3. Scheduled Time – Specify the time at which the automation should run in HH:MM format and select the required time zone.

Event

Select Event to send the configured action to the device when the selected device event occurs. For example, select On Device Enrollment to send the configured action when a device is enrolled in Hexnode UEM.

The available events vary by platform. For details on the events supported for each platform, see the Event page.

Select the required trigger and click Next.

  1. Under Choose Actions, navigate to Patches and Updates and select Enforce Patch Deadline.
  2. Configure the following settings:
    • Target OS version – Select the OS version to be enforced on the device.
    • Target build version – Specify the build version to be enforced on the device.
    • Time for enforcing the update – Specify the date and time by which the update must be installed on the device.
    • Details URL – Enter the URL of a webpage containing additional information about the update.

    After configuring the settings, click Confirm.

  1. Under Assignments, specify the devices or users to which the automation should apply. You can target devices or users using:
    • Included Groups – Select the device or user groups to which the automation should apply.
    • Excluded Groups – Select the device or user groups to exclude from the automation.
    • Filters – Create custom filters to target devices or users based on specific attributes.
  2. Under Review, verify the configured automation settings.
  3. Click Save to create the automation.

What Happens at the Device End?

Once the configured trigger is met, the action is sent to the device, the specified update becomes available for installation. The user is notified about the available update and can choose to install it or defer the update until the configured deadline. If the update is not installed by the deadline, Hexnode enforces the update on the device.

Frequently Asked Questions

What happens if the device is offline when the patch deadline is reached?

If the device is offline when the configured patch deadline is reached, the update is not pushed immediately. Once the device comes online, the update is pushed after one hour.

What happens if the device already has the target OS version or a newer version?

If the device already has the target OS version or a newer version, the Enforce Patch Deadline action is ignored for that device.

Automations
Patches and Updates