# Manage app patches on macOS devices using Hexnode UEM

This document will guide you on how to manage app patches on macOS devices using Hexnode.

Updates and patches are released for applications on a regular basis to improve functionality, fix bugs, and address security vulnerabilities. These updates play a crucial role in keeping software reliable and secure over time. Keeping applications up to date is essential for maintaining device performance and ensuring compatibility with the latest macOS features. Outdated apps can often lead to performance issues, and potential security vulnerabilities across the organization.

Hexnode’s **App Updates** feature helps configure app updates on macOS devices, enabling IT admins to define maintenance windows, configure automatic update preferences, and ensure that critical app updates are deployed without disrupting user productivity.

 Note: 
App patch configuration using this feature is supported only for VPP apps.

 

Configure updates for apps
--------------------------

1. Login to your Hexnode UEM portal.
2. Navigate to the **Policies** tab.
3. Click on **New Policy** to create a new policy or select an existing policy. Provide a suitable **name** and **description** (optional) for the policy.
4. Navigate to **macOS > Patches & Updates > App Updates**.
5. Click on **Configure**.

[![Manage app patches on macOS using App Updates policy](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/05/App-Updates-policy-in-macOS.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/05/App-Updates-policy-in-macOS.png "App Updates policy in macOS")

### App Updates

You can configure the following options under **App Updates**:

1. **Maintenance Window**
2. **Auto-update preference**

[![Configure App Updates policy to manage app patches on macOS](http://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/05/Configuring-App-Updates-policy-in-Hexnode-UEM.png)](http://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/05/Configuring-App-Updates-policy-in-Hexnode-UEM.png "Configuring App Updates policy in Hexnode UEM")

#### Maintenance Window

This option can be used to specify the time window during which the device undergoes app updates and other maintenance tasks.

SettingDescription**Scheduled Day**You can choose between the following options to specify when the device can perform updates and device maintenance tasks. - **Everyday:** The tasks are performed every day.
- **Selected days:** The tasks are carried out on the selected days.
- **Weekly:** The tasks are carried out every week on the specified day.

**Scheduled Time**You can schedule the time window during which the updates and device maintenance tasks will be performed by setting the **Start time** and **End time**.#### Auto-update preference

The options below will help you configure the auto-update settings of applications.

SettingDescription**Update all apps**On selecting this option, all applications present on the device will be updated automatically. **Update targeted apps only**Selecting this option will update only the targeted apps selected in the **Targeted Apps** section. This is useful when IT admins need to selectively manage updates for specific applications without initiating updates for all apps on the device. To add apps under ***Targeted Apps***:

1. Click on the **Add Apps** option.
2. Select the required applications from the list.
3. Confirm the apps and click **Add**.

**Scan for updates, do not auto-update app**sOn selecting this option, the system will be scanned for any available app updates, but will not perform any automatic app updates. This allows IT admins to review the available updates and schedule the deployment as needed.Associate the policy to target devices
--------------------------------------

If the policy hasn’t been saved,

1. Navigate to **Policy Targets**.
2. Click on **+Add Devices**.
3. Search and select the required device(s) to which you need to apply the policy. Click **OK**.
4. Click on **Save** to apply the policy to the devices.

You can also choose to associate the policy with device groups, users, user groups, or domains/OUs from the left pane of the **Policy Targets** tab.

If you have already saved the policy,

1. Navigate to **Policies > My Policies** and select the required policy.
2. Click on **Manage** and select **Associate Targets**.
3. Select the required **Devices**, **Users**, **Device Groups**, **User Groups** or **Domains/OUs**.
4. Click on **Associate**.