Category filter

Platform Support Matrix for Patch Management

TL;DR

Hexnode’s patch and update capabilities exist at two tiers. The advanced patch engine — CVE-based targeting, rollback, maintenance windows, RBAC-gated approvals, a curated 1,300+ app patch catalog, and SLA-driven compliance auditing — is available for Windows and macOS. Every other supported platform (Linux, iOS/iPadOS, tvOS, visionOS, Android, ChromeOS) has baseline OS-update scheduling and enforcement, delivered through each platform’s native MDM update mechanism rather than through the advanced engine. Use the matrix below to confirm exact capability-by-platform support before scoping a deployment or answering a platform-support question.

How to Read This Matrix

  • ✅ Full support — the capability is available for this platform with a dedicated help article.
  • 🔶 Partial / baseline support — a related capability exists on this platform but is more limited in scope than the advanced-engine version (Windows/macOS), or is delivered through a different mechanism (e.g., app-level enforcement instead of a centralized patch catalog).
  • ⛔ Not available — no supported mechanism for this capability is currently available for this platform or is in the roadmap.

Capability Matrix by Platform

Patch Management Capabilities by Operating System
Capability Windows macOS Linux iOS / iPadOS tvOS / visionOS Android (Device Owner) ChromeOS
Baseline OS update scheduling & enforcement Automated Patch Management Automate Patch Deployment 🔶 Install OS Updates on Linux (on-demand action, not scheduled) Configure DDM Software Updates, Enforce Software Updates, Delay iOS Updates 🔶 Configure DDM Software Updates (preferences only) 🔶 Schedule OS Updates Manage ChromeOS Updates
Automated third-party app patch deployment (Patch Catalog, 1,300+ apps) Windows App Patch Configuration 🔶 Manage App Patches (VPP apps only) 🔶 Install Application via action 🔶 Update Required Apps (managed-app version enforcement, not catalog-based patching)
CVE-based patch targeting Patch by CVE Patch by CVE
Patch rollback Patch Rollback Patch Rollback
Maintenance windows / scheduled deployment windows Maintenance Windows and Patch Scheduling 🔶 Maintenance Windows
Patch approval workflows (RBAC) Patch Operations RBAC Patch Operations RBAC
Compliance auditing & SLA reporting Enterprise Patch Compliance Enterprise Patch Compliance
Manual, on-demand patch deployment Manual Patch Deployment Deploy Patches Manually Install OS Updates on Linux 🔶 Enforce Software Updates (Update OS action) 🔶 Enforce Apple TV software updates 🔶 Deploy OS Updates (custom ROM + Hexnode System Agent required) 🔶 Manage ChromeOS updates

Patch Delivery Mechanism by Platform

Because “how a patch reaches the device” differs by platform even where the capability itself is supported, delivery mechanism is broken out separately rather than folded into the matrix above.

Platform Delivery Mechanism Source
Windows Agent-native (Hexnode agent installed on the endpoint) Patch Delivery Architecture
macOS OS-native MDM commands (no dedicated patch agent) Patch Delivery Architecture
Linux Remote action (“Update OS”) triggered from the console Install OS Updates on Linux
iOS / iPadOS / tvOS / visionOS Apple Declarative Device Management (DDM) / native MDM update commands Configure DDM Software Updates
Android (Device Owner) Android Enterprise OS-update API via Hexnode System Agent Deploy OS Updates on Android
ChromeOS Chrome policy — release channel and update schedule management Manage ChromeOS Updates

Platform Notes

Windows

Windows has full coverage across both tiers: the advanced patch engine (CVE targeting, rollback, RBAC, maintenance windows, patch catalog, compliance auditing, metrics) plus the legacy Windows Update preference controls (Windows Update Preferences, Windows Update End-User Experience, WSUS specific settings, App Patches Configuration).

macOS

macOS shares the advanced engine with Windows for CVE targeting and rollback, and RBAC applies across both platforms.

iOS, iPadOS, tvOS, visionOS

Apple platforms get baseline update management through Declarative Device Management: preferences (DDM Software Updates), enforcement (Enforce Software Updates), and delay windows (Delay iOS Updates). tvOS and visionOS inherit the same DDM-based preferences.

Android (Device Owner / Android Enterprise)

Android’s OS-update support is scoped to Device Owner mode: Schedule OS Updates covers Android Enterprise scheduling, while Deploy OS Updates requires Android 5.0+ with a custom ROM and the Hexnode System Agent.

ChromeOS

ChromeOS update management is release-channel and bandwidth-schedule based (Manage ChromeOS Updates), covering both ChromeOS and ChromeOS Flex. It does not currently have CVE targeting, rollback, RBAC, or compliance-auditing integration.

Choosing the Right Approach for Your Fleet

  • Single-OS Windows or macOS fleets, or mixed Windows/macOS fleets needing vulnerability-driven remediation, approval workflows, or audit-ready SLA reporting should use the advanced patch engine — start with Patch by CVE and Maintenance Windows and Patch Scheduling.
  • Mixed fleets that include Linux should plan Linux patching as a manual/on-demand process today.
  • Mobile and embedded fleets (iOS/iPadOS, tvOS, visionOS, Android, ChromeOS) should use each platform’s native baseline scheduling and enforcement controls linked above.

Frequently Asked Questions

Does Hexnode support CVE-based patching on Linux, iOS, Android, or ChromeOS?

Not currently. CVE-based targeting and rollback are available on Windows and macOS only. Other platforms use native OS-update scheduling and enforcement instead.

Is Linux fully covered by Hexnode's patch management?

Linux has on-demand OS-update deployment, but does not have scheduled/automated deployment, CVE targeting, rollback, or RBAC-gated approvals at the moment.

Patches and Updates