Require devices to run a minimum operating system version so security patches and app compatibility stay current across your fleet. This article explains how to configure the control, what employees see on each platform, and how to resolve failed updates.
Platforms: macOS, Windows, iOS/iPadOS. Not available on Linux or Android.
Overview
Use this control when you need every device on a minimum OS version — after a vendor security advisory, ahead of an audit, or as standing policy. You set a deadline relative to each update's release date, and devices enforce it automatically.
The deadline counts from the update's availability date, not from the day you configured the policy. Employees already on an older version are prompted immediately.
How to use
-
Choose when to force the update. Pick how long employees have after an OS update becomes available:
- 1 month
- 1 week
- 1 day
- Set the enforcement time (macOS only). Choose the hour of day the update is enforced. This uses the device's local time.
- Set the grace period (Windows only). Set how many days employees have before the device restarts on its own to apply the update.
- Select targeting. Apply the control to all devices, to specific device groups, or to a custom target.
To stop enforcing, disable the control in the profile settings. Existing configurations stay on the devices.
What employees see on macOS:
macOS 14 and later — a native macOS notification appears once a day. Employees can update early or schedule it for that night.
| When | Notification behaviour |
| More than 24 hours before deadline | Once a day |
| Within 24 hours | Hourly, ignoring Do Not Disturb |
| Within 1 hour | Every 30 minutes, then every 10 |
| Device was off at the deadline | Update scheduled 1 hour after it turns on |

Devices enrolled through Automated Device Enrollment (ADE) that fall below the minimum version must update before setup and enrolment can continue.
macOS 13 and earlier — employees are prompted through Nudge.

| More than 1 day before | Less than 1 day before | Past deadline | |
| Window frequency | Daily at 8pm GMT | Every 2 hours | On every login |
| Employee can defer | Yes | Yes | No |
| Window can be dismissed | Yes | Yes | No |
What employees see on Windows:
Employees are prompted through the native Windows update dialog.

Before the deadline, employees can defer the automatic restart. After it, they cannot. If someone was away when the deadline passed, the grace period you configured starts before the device restarts.
Tips and best practices
- Start with the 1 month deadline when you first enable the control. Employees get time to adjust before you tighten it.
- On macOS, set the enforcement time outside working hours. The setting uses each device's local time, so distributed teams are covered without extra rules.
- Check free disk space across the fleet before a major OS release. Disk space is the most common cause of failed updates, and no platform frees it up on its own.
Troubleshooting
Updates fail because of low disk space. No platform manages disk space automatically, so an administrator usually has to step in.
- macOS 14 and later — the employee gets a system notification and a warning in System Settings. The prompts stop once they free up space.
- macOS 13 and earlier — the Nudge window sends the employee to System Preferences, where the download fails. After the deadline the window cannot be dismissed until the update installs.
- Windows — the employee is told the update failed and must free up space.
FAQ
-
Does the deadline start when I enable the policy?
No. It starts when the OS update becomes available. Employees on older versions are prompted as soon as you enable the control.
-
Can an employee skip an update after the deadline?
No. Past the deadline, deferral and dismissal are both disabled on every platform.
-
What happens if a device is switched off when the deadline passes?
On macOS the update is scheduled for 1 hour after the device turns on. On Windows the configured grace period applies before the automatic restart.