Manage device updates
Use a staged rollout so new FydeOS versions reach pilot devices before the full fleet. Update policy is configured per organisational unit.
Before you begin
- Create pilot, broad rollout, and exception organisational units.
- Inventory device models, current OS/browser versions, critical web apps, Android apps, peripherals, VPNs, and printing workflows.
- Decide the maintenance window and rollback owner.
- Keep automatic updates enabled unless a verified compatibility incident requires a temporary restriction.
Configure the update policy
- Open Business+ → Device Settings.
- Select the pilot organisational unit.
- Open Device update settings, or search for the setting name.
- Review and set the required fields:
| Setting | How to use it |
|---|---|
| Auto-update | Choose Allow updates for normal operation. |
| Target version | Use the latest version by default. Pin only for a documented compatibility reason. |
| Roll back to target version | Enable only for an approved rollback. The console warns that rollback restarts the device and wipes local data. |
| Release channel | Use Stable for production unless your test plan requires another available channel. |
| Rollout plan | Stage the update instead of changing every device at once. |
| Additional blackout windows | Pause automatic checks during critical operating periods. |
| Auto reboot after updates | Decide when unattended devices can restart safely. |
| Updates over cellular | Enable only when data cost and reliability are acceptable. |
| Peer-to-peer | Consider for sites where local distribution reduces external bandwidth. |
| Enforce updates | Use when devices must complete updates by policy. |
| Update downloads | Keep HTTPS unless your deployment has a validated requirement. |
- Confirm Updated setting entries contains only the intended changes.
- Click Save.
Roll out in stages
- Apply the policy to representative pilot devices.
- Keep the devices online through download and restart.
- Verify OS/browser version, sign-in, network, apps, printing, peripherals, kiosk or guest-session behaviour, and remote support.
- Monitor for at least one normal operating cycle.
- Move or target the next organisational unit.
- Pause the rollout when the failure rate or business impact exceeds your change threshold.
Rollback warning
danger
The console warns that Roll back to target version restarts the device and wipes all local data. Confirm backups, re-enrolment or sign-in access, and the approved target version before enabling it.
Do not use rollback as the first response to a policy, network, or application problem. First confirm the problem is caused by the OS version and reproduce it on a pilot.
Verify fleet status
Use Devices → Device Overview to compare OS and browser versions across organisational units. Open an individual device to check Last Active and Last Policy Sync when it does not update.
Common causes include:
- The device is offline or lacks disk space.
- The update policy is inherited from an unexpected parent unit.
- A target version, channel, blackout window, or rollout stage delays it.
- The device has downloaded an update but has not restarted.
- Proxy, firewall, DNS, or TLS inspection blocks update traffic.
What's next
- Configure device policies, apply settings through an organisational unit.
- Device inventory and monitoring, find devices and verify their state.
- Troubleshooting checklist, diagnose common device problems.