# Platform Support Matrix for Patch Management

How to Read This Matrix
-----------------------

- **✅ Full support** — the capability is available for this platform with a dedicated help article.
- **🔶 Partial / baseline support** — a related capability exists on this platform but is more limited in scope than the advanced-engine version (Windows/macOS), or is delivered through a different mechanism (e.g., app-level enforcement instead of a centralized patch catalog).
- **⛔ Not available** — no supported mechanism for this capability is currently available for this platform or is in the roadmap.

Capability Matrix by Platform
-----------------------------

Patch Management Capabilities by Operating SystemCapabilityWindowsmacOSLinuxiOS / iPadOStvOS / visionOSAndroid (Device Owner)ChromeOSBaseline OS update scheduling & enforcement✅ [Automated Patch Management](https://www.hexnode.com/mobile-device-management/help/automated-patch-management-windows/)✅ [Automate Patch Deployment](https://www.hexnode.com/mobile-device-management/help/automate-patch-deployment-mac/)🔶 [Install OS Updates on Linux](https://www.hexnode.com/mobile-device-management/help/how-to-install-os-updates-on-linux-devices/) (on-demand action, not scheduled)✅ [Configure DDM Software Updates](https://www.hexnode.com/mobile-device-management/help/configure-ddm-software-updates/), [Enforce Software Updates](https://www.hexnode.com/mobile-device-management/help/enforce-ios-updates-using-hexnode-mdm/), [Delay iOS Updates](https://www.hexnode.com/mobile-device-management/help/how-to-delay-ios-updates-on-ios-11-3-devices-using-hexnode/)🔶 [Configure DDM Software Updates](https://www.hexnode.com/mobile-device-management/help/configure-ddm-software-updates/) (preferences only)🔶 [Schedule OS Updates](https://www.hexnode.com/mobile-device-management/help/how-to-schedule-os-updates-in-android-devices-using-hexnode/)✅ [Manage ChromeOS Updates](https://www.hexnode.com/mobile-device-management/help/manage-chromeos-updates/)Automated third-party app patch deployment (Patch Catalog, 1,300+ apps)✅ [Windows App Patch Configuration](https://www.hexnode.com/mobile-device-management/help/configure-app-patches-for-windows-devices-using-hexnode-uem/)🔶 [Manage App Patches](https://www.hexnode.com/mobile-device-management/help/manage-app-patches-macos/) (VPP apps only)🔶 Install Application via action🔶 Update Required Apps (managed-app version enforcement, not catalog-based patching)⛔⛔⛔CVE-based patch targeting✅ [Patch by CVE](https://www.hexnode.com/mobile-device-management/help/patch-by-cve-automating-vulnerability-remediation-across-enterprise-fleets/)✅ [Patch by CVE](https://www.hexnode.com/mobile-device-management/help/patch-by-cve-automating-vulnerability-remediation-across-enterprise-fleets/)⛔⛔⛔⛔⛔Patch rollback✅ [Patch Rollback](https://www.hexnode.com/mobile-device-management/help/patch-rollback/)✅ [Patch Rollback](https://www.hexnode.com/mobile-device-management/help/patch-rollback/)⛔⛔⛔⛔⛔Maintenance windows / scheduled deployment windows✅ [Maintenance Windows and Patch Scheduling](https://www.hexnode.com/mobile-device-management/help/configure-app-patches-for-windows-devices-using-hexnode-uem/#maintenance-window)🔶 [Maintenance Windows](https://www.hexnode.com/mobile-device-management/help/manage-app-patches-macos/#maintenance-window)⛔⛔⛔⛔⛔Patch approval workflows (RBAC)✅ [Patch Operations RBAC](https://www.hexnode.com/mobile-device-management/help/patch-operations-rbac-separating-approval-deployment-and-reporting-in-hexnode-uem/)✅ [Patch Operations RBAC](https://www.hexnode.com/mobile-device-management/help/patch-operations-rbac-separating-approval-deployment-and-reporting-in-hexnode-uem/)⛔⛔⛔⛔⛔Compliance auditing & SLA reporting✅ [Enterprise Patch Compliance](https://www.hexnode.com/mobile-device-management/help/auditing-patch-compliance/)✅ [Enterprise Patch Compliance](https://www.hexnode.com/mobile-device-management/help/auditing-patch-compliance/)⛔⛔⛔⛔⛔Manual, on-demand patch deployment✅ [Manual Patch Deployment](https://www.hexnode.com/mobile-device-management/help/manual-patch-deployment-windows/)✅ [Deploy Patches Manually](https://www.hexnode.com/mobile-device-management/help/deploy-patches-manually-macos/)✅ [Install OS Updates on Linux](https://www.hexnode.com/mobile-device-management/help/how-to-install-os-updates-on-linux-devices/)🔶 [Enforce Software Updates](https://www.hexnode.com/mobile-device-management/help/enforce-ios-updates-using-hexnode-mdm/) (Update OS action)🔶 [Enforce Apple TV software updates](https://www.hexnode.com/mobile-device-management/help/how-to-enforce-software-updates-on-apple-tv/)🔶 [Deploy OS Updates](https://www.hexnode.com/mobile-device-management/help/how-to-deploy-os-updates-on-android-devices-using-hexnode-mdm/) (custom ROM + Hexnode System Agent required)🔶 [Manage ChromeOS updates](https://www.hexnode.com/mobile-device-management/help/manage-chromeos-updates/)Patch Delivery Mechanism by Platform
------------------------------------

Because “how a patch reaches the device” differs by platform even where the capability itself is supported, delivery mechanism is broken out separately rather than folded into the matrix above.

PlatformDelivery MechanismSourceWindowsAgent-native (Hexnode agent installed on the endpoint)[Patch Delivery Architecture](https://www.hexnode.com/mobile-device-management/help/patch-delivery-architecture/)macOSOS-native MDM commands (no dedicated patch agent)[Patch Delivery Architecture](https://www.hexnode.com/mobile-device-management/help/patch-delivery-architecture/)LinuxRemote action (“Update OS”) triggered from the console[Install OS Updates on Linux](https://www.hexnode.com/mobile-device-management/help/how-to-install-os-updates-on-linux-devices/)iOS / iPadOS / tvOS / visionOSApple Declarative Device Management (DDM) / native MDM update commands[Configure DDM Software Updates](https://www.hexnode.com/mobile-device-management/help/configure-ddm-software-updates/)Android (Device Owner)Android Enterprise OS-update API via Hexnode System Agent[Deploy OS Updates on Android](https://www.hexnode.com/mobile-device-management/help/how-to-deploy-os-updates-on-android-devices-using-hexnode-mdm/)ChromeOSChrome policy — release channel and update schedule management[Manage ChromeOS Updates](https://www.hexnode.com/mobile-device-management/help/manage-chromeos-updates/)Platform Notes
--------------

### Windows

Windows has full coverage across both tiers: the advanced patch engine (CVE targeting, rollback, RBAC, maintenance windows, patch catalog, compliance auditing, metrics) plus the legacy Windows Update preference controls ([Windows Update Preferences](https://www.hexnode.com/mobile-device-management/help/manage-windows-update-preferences-and-settings/), [Windows Update End-User Experience](https://www.hexnode.com/mobile-device-management/help/configure-windows-update-end-user-experience/), [WSUS specific settings](https://www.hexnode.com/mobile-device-management/help/how-to-configure-wsus-specific-settings-for-windows-devices/), [App Patches Configuration](https://www.hexnode.com/mobile-device-management/help/configure-app-patches-for-windows-devices-using-hexnode-uem/)).

### macOS

macOS shares the advanced engine with Windows for CVE targeting and rollback, and RBAC applies across both platforms.

### iOS, iPadOS, tvOS, visionOS

 Apple platforms get baseline update management through Declarative Device Management: preferences (DDM Software Updates), enforcement (Enforce Software Updates), and delay windows (Delay iOS Updates). tvOS and visionOS inherit the same DDM-based preferences.

### Android (Device Owner / Android Enterprise)

Android’s OS-update support is scoped to Device Owner mode: Schedule OS Updates covers Android Enterprise scheduling, while Deploy OS Updates requires Android 5.0+ with a custom ROM and the Hexnode System Agent.

### ChromeOS

ChromeOS update management is release-channel and bandwidth-schedule based (Manage ChromeOS Updates), covering both ChromeOS and ChromeOS Flex. It does not currently have CVE targeting, rollback, RBAC, or compliance-auditing integration.

Choosing the Right Approach for Your Fleet
------------------------------------------

- Single-OS Windows or macOS fleets, or mixed Windows/macOS fleets needing vulnerability-driven remediation, approval workflows, or audit-ready SLA reporting should use the advanced patch engine — start with Patch by CVE and Maintenance Windows and Patch Scheduling.
- Mixed fleets that include Linux should plan Linux patching as a manual/on-demand process today.
- Mobile and embedded fleets (iOS/iPadOS, tvOS, visionOS, Android, ChromeOS) should use each platform’s native baseline scheduling and enforcement controls linked above.

Related Documentation
---------------------

- [Patches and Updates Deployment overview](https://www.hexnode.com/mobile-device-management/help/patches-and-updates-deployment/)
- [Patch by CVE: Automating Vulnerability Remediation](https://www.hexnode.com/mobile-device-management/help/patch-by-cve-automating-vulnerability-remediation-across-enterprise-fleets/)
- [Patch Rollback](https://www.hexnode.com/mobile-device-management/help/patch-rollback/)
- [Patch Operations RBAC](https://www.hexnode.com/mobile-device-management/help/patch-operations-rbac-separating-approval-deployment-and-reporting-in-hexnode-uem/)
- [Maintenance Windows and Patch Scheduling](https://www.hexnode.com/mobile-device-management/help/maintenance-windows-patch-scheduling/)
- [The Hexnode Patch Catalog](https://www.hexnode.com/mobile-device-management/help/patch-catalog-curation-validation/)
- [Patch Delivery Architecture](https://www.hexnode.com/mobile-device-management/help/patch-delivery-architecture/)
- [Enterprise Patch Compliance](https://www.hexnode.com/mobile-device-management/help/auditing-patch-compliance/)
- [Automating OS Updates for Security Compliance](https://www.hexnode.com/mobile-device-management/help/automate-os-updates-security-compliance/) (cross-platform overview)
- [Hexnode UEM Feature Comparison Based on OS Platforms](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-feature-comparison-based-on-os-platforms/)