Category filter
Secure Your Mac: Scan for OS and Application Updates
The Scan for Updates remote action in Hexnode UEM provides IT administrators with real-time visibility into pending operating system and application patches, enabling data-driven prioritization of security deployments.
Why Use “Scan for Updates” on macOS?
Neglecting critical patches can compromise device security and performance. This feature allows teams to categorize updates by importance, security level, or type, ensuring a consistently secure organizational environment.
- Real-time Visibility: Instantly identifies all available updates across the entire device fleet.
- Prioritized Deployment: Enables administrators to target critical security patches before minor app updates.
- Fleet Stability: Ensures all devices remain on compatible, optimized software versions.
Prerequisites and Compatibility
To utilize this remote action, the managed endpoint must meet the following criteria:
- Operating System: The device must be running macOS 10.13 or later.
- Connectivity: The device must be online and communicating with Hexnode UEM to execute the action successfully.
- Framework Support: Hexnode detects updates relying on the Apple MDM framework, including macOS system updates and App Store applications.
Step-by-Step Guide: Executing an Update Scan
Administrators can trigger a scan for a single machine or select multiple devices for a bulk operation.
- Log in to the Hexnode UEM portal.
- Navigate to Manage > Devices.
- Select the required macOS device(s).
- Click the Actions drop-down and select Updates > Scan for Updates.
- View findings under the Patches and Updates sub-tab of the device.
Understanding Update Attributes
The Patches and Updates section organizes pending software into a structured data table for administrative review.
| Data Field | Technical Description |
|---|---|
| Name | The formal name, version, and identifier of the update or patch. |
| Type | Indicates whether the update targets the OS or a specific Application. |
| Severity | Categorized into levels: Critical, Important, Moderate, or Low. |
| Download Size | The maximum size of the update, used for network bandwidth planning. |
| Install Size | Indicates whether the update is a beta version (True or False). |
| Version | The current operating system version of the device. |
| Status | Indicates if the update is Approved for installation through Hexnode or is Pending. |
Troubleshooting Guides
| Problem | Potential Root Cause | Resolution |
|---|---|---|
| Scan remains “In Progress” | The device is offline or powered off. | Ensure the device has an active internet connection. Administrators can re-trigger the scan once the device reconnects. |
| Missing App Store updates | The app was not installed via the App Store or VPP. | Hexnode primarily manages updates that rely on the Apple MDM framework. Verify the app’s installation source. |
| Action fails to execute | OS version is older than 10.13. | Confirm the device meets the macOS 10.13+ prerequisite. |
| Attributes not populating | Sync delay between Apple servers and the UEM. | Wait a few minutes for the MDM framework to fetch metadata or re-trigger the scan to refresh the cache. |
Frequently Asked Questions (FAQs)
Is the end-user notified of the scan?
No. The “Scan for Updates” remote action is executed silently in the background and is not visible to the end-user.
Does this action initiate the installation of updates?
No. This action only checks and lists available updates. To install them, separate deployment actions must be triggered.
Can the entire fleet be scanned at once?
Yes. Administrators can select multiple devices in the Manage > Devices tab to apply the scan in bulk. Results are listed individually for each device.
Why does the “Install Size” column show True or False?
In this specific Hexnode data view, the Install Size field is utilized to indicate whether the patch is a beta version.