Citrix Endpoint Management

Software Update Settings device policy (Technical Preview)

Note:

Features in the Technical Preview are available to use in non-production or limited production environments, and to give customers an opportunity to share feedback. Citrix does not accept support cases for features in technical preview but welcomes feedback for improving them. You can provide feedback on this feature by clicking Send us your feedback. Citrix might act on feedback based on its severity, criticality, and importance.

The Software Update Settings device policy can be used to defer OS updates and control how users can manually interact with software updates in System Settings. The policy only supports supervised devices.

To add or configure this policy, go to Configure > Device Policies. For more information, see Device policies.

Prerequisites

  • CEM version is equal to or greater than 25.5.0.

  • The feature flags ios.mdm.declarative.management and ios.mdm.software.update.setting are activated. Contact your admin to enable this feature if needed.

  • Available for iOS 18.0 or later and iPadOS 18.0 or later, only support supervised devices.

iOS settings

Software Update Settings device policy

  • Automatic Actions

    • Download: Specify whether the user can control automatic downloads of available updates. The default is Allowed.

      • Allowed - the user can enable or disable automatic downloads.
      • AlwaysOn - automatic downloads are always enabled.
      • AlwaysOff - automatic downloads are always disabled.
    • Install OS Updates: Specify whether the user can control automatic installation of available updates. The default is Allowed.

      • Allowed - the user can enable or disable automatic installation.
      • AlwaysOn - automatic installations are always enabled.
      • AlwaysOff - automatic installations are always disabled.
  • Deferrals

    • Combined Period in Days: Specify the number of days to defer a major or minor OS software update on the device. When set, software updates only appear after the specified delay, following the release of the software update. Available in iOS 18 and later. Valid values are 0–90. The default is 0, which means no delay is expected.
  • Recommended Cadence

    • Recommended Cadence: Specify how the device shows software updates to the user. When more than one update is available, the device behaves as follows. The default is All.

      • All - Shows all software update versions.
      • Oldest - Shows only the oldest (lower numbered) software update version.
      • Newest - Shows only the newest (highest numbered) software update version.
  • Notifications

    • Notifications: If On, the device shows all software update enforcement notifications. If Off, the device only shows notifications triggered one hour before the enforcement deadline, and the restart countdown notification.The default is On.
  • Rapid Security Response

    • Enable: If Off, Rapid Security Responses aren’t offered for user installation. The system can still install Rapid Security Responses with com.apple.configuration.softwareupdate.enforcement.specific configurations. If On, the system offers Rapid Security Responses to the user. The default is On.
    • Enable Rollback: If Off, the system doesn’t offer Rapid Security Response rollbacks to the user. If On, the system offers Rapid Security Response rollbacks to the user. The default is On.
Software Update Settings device policy (Technical Preview)