# Manage System Updates on Android

> Control when Android devices install operating system updates, set a daily maintenance window or freeze periods, and find devices that are missing updates.

Source: https://docs.capaone.com/capaone/mobile-manager/android/manage-system-updates-on-android/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

Use the **System Update** setting in an Android configuration to control how enrolled devices
install Android operating system updates. You can let devices install updates as soon as they're
available, limit installation to a daily maintenance window, or postpone updates. You can also
block updates during fixed periods of the year, for example during a busy season.

:::note[Before you start]
- You need access to Android management in CapaOne, and Android Enterprise must be set up. See
  [Android Enterprise Setup](/capaone/mobile-manager/android/android-enterprise-setup/).
- The system update policy applies to company-owned devices. On personally owned (BYOD) devices,
  the user controls system updates. See
  [Android Enrollment](/capaone/enrollment/android-enrollment/#management-modes).
:::

## Choose an update type

| Type | What it does |
|---|---|
| **Install automatically when available** | The device installs an update as soon as it's available. |
| **Install automatically within daily maintenance window (Strongly recommended for kiosk devices)** | The device installs updates only inside the daily time window you set. The same window also applies to app updates from Google Play. |
| **Postpone automatic install up to 30 days** | Automatic installation of an update is postponed for up to 30 days. |

## Set the system update policy

1. Go to **Android → Configurations**.
2. Click **New** to create a configuration, or open an existing configuration and edit it.
3. Enter a configuration name.
4. In the list on the left, select **System** (category **System**). Use
   **Category or Configuration** to search the list.
5. Under **System Update**, select a **Type**.
6. If you selected the maintenance window type, enter **Start Minutes** and **End Minutes**. See
   [Set a maintenance window](#set-a-maintenance-window).
7. Optional: add one or more freeze periods under **Freeze Periods**. See
   [Block updates in freeze periods](#block-updates-in-freeze-periods).
8. Click **Create**, or **Save** if you edited an existing configuration.
9. Assign the configuration to groups or endpoints. See
   [Android Configurations](/capaone/mobile-manager/android/android-configurations/#assign-configurations-to-endpoints-or-groups).

The devices get the new policy the next time they sync. To send it to a device right away, use
the **Synchronize** command. See
[Android Device Commands](/capaone/mobile-manager/android/android-device-commands/).

## Set a maintenance window

The maintenance window is set in minutes after midnight, in the device's local time:

- **Start Minutes** is the start of the window, and **End Minutes** is the end.
- Both values must be between `0` and `1439`. For example, `120` is 02:00 and `240` is 04:00.
- If **End Minutes** is less than **Start Minutes**, the window spans midnight. For example,
  `1380` to `180` runs from 23:00 to 03:00.
- If the window is shorter than 30 minutes, it's extended to 30 minutes after the start time.

Choose a time when the devices are switched on but not in use, for example at night for kiosk
devices that stay on.

## Block updates in freeze periods

A freeze period is a time of year when over-the-air system updates are postponed, so the
operating system version stays the same. Freeze periods repeat every year.

1. Under **Freeze Periods**, click the add icon (**Add Freeze Period**).
2. Under **Start Date**, enter the **Month** and **Day** the period starts.
3. Under **End Date**, enter the **Month** and **Day** the period ends.

Rules for freeze periods:

- Don't set **Year**. Leave it empty or `0`, because the period repeats every year.
- Both dates are included in the period.
- A freeze period can be at most 90 days long.
- Separate freeze periods by at least 60 days, so devices aren't frozen indefinitely.
- If the end date is earlier than the start date, the period runs over the turn of the year. For
  example, 1 December to 15 January.

## When several configurations set System Update

If a device gets more than one configuration that sets **System Update**, only the setting from
the configuration with the highest priority applies. Configurations assigned directly to the
device come before configurations assigned through groups. See
[Android Configurations](/capaone/mobile-manager/android/android-configurations/#priority).

To check which policy a device uses, open the device and select
**Configurations → Applied**.

## Find devices that need updates

- **On the endpoint list:** go to **Android → Endpoints** and use the **System Update Status**
  and **Critical System Update** quick filters. **Critical System Update** set to `Yes` lists the
  devices with a pending security update. See
  [Android Endpoints](/capaone/mobile-manager/android/android-endpoints/#filter-the-list).

  ![Android endpoint list with the Filters panel open showing the System Update Status and Critical System Update filters](/attachments/capaone/manage-system-updates-on-android--endpoint-filters.png)
- **On a device:** the **Dashboard** tab shows the device's update status. The
  **Inventory → Hardware → System** tab shows **OS version**, **Update status**, and
  **Last policy sync**.

  ![Android device Dashboard tab showing Android 13, last check-in, battery level and the System is up-to-date badge](/attachments/capaone/manage-system-updates-on-android--dashboard-status.png)

The update status is one of the following:

| Update status | Meaning |
|---|---|
| **System is up-to-date** | No system update is waiting on the device. |
| **Security update available** | A security update is waiting. It counts as a critical system update. |
| **OS update available.** | An operating system update is waiting. |
| **System update available** | An update is waiting, but its type isn't known. |
| **Unknown update status** | It isn't known whether an update is waiting, for example because the device runs an old Android version. |

## Related

- [Android Configurations](/capaone/mobile-manager/android/android-configurations/)
- [Android Endpoints](/capaone/mobile-manager/android/android-endpoints/)
- [Android Applications](/capaone/mobile-manager/android/android-applications/)
