How to block OS updates in the Android Device?

How to block OS updates in the Android Device?

The System Update feature in WeGuard allows administrators to control how operating system updates are installed on managed Android devices. Managing system updates is important in enterprise environments to ensure device security, stability, and uninterrupted business operations.

Through this setting, administrators can define how and when devices should receive Android system updates. This helps organizations prevent unexpected device restarts during working hours, test updates before deployment, and ensure that all company-owned devices remain secure with the latest security patches.

By configuring the appropriate update policy, IT administrators can maintain better control over device behavior, reduce disruptions for end users, and ensure compliance with organizational update policies.


Blocking OS Updates

  • Log in to the WeGuard Console.
  • Click on Policy and select the Policy.
  • Go to Security, and locate System Updates on the right. By default, it shows an Unspecified.

  • Click on the drop-down, and you will see the options. Unspecified, Automatic, Windowed, and Postponed.

Let's see what happens when each one is selected:

Unspecified: Triggers update prompts until installations are complete. Opting for the Unspecified policy prompts users to update their OS, granting them the choice to proceed with installation.

Automatic: Installs system updates upon availability without user interaction, bypassing potential delays.

Windowed: Updates install daily within a user-defined window (0-1439 minutes after local midnight), no user interaction.

Postpone: Defers system update installation for 30 days. After this period, a notification prompts the user to install updates. The installation is necessary once the 30-day duration ends.



  • Admins choose a preferred option and click SAVE to apply the chosen policy to devices




We hope this article was helpful. For additional support:

    • Related Articles

    • Device Security Features - What is Device Hardening?

      ​​Hello and Welcome to WeGuard Enterprise Visual Knowledge-base Series. In this KB article, We will explain how to harden your device for security measures.  ​ We will discuss the process of securing a device by reducing its surface of vulnerability. ...
    • Rebooting a Windows Device

      The Reboot Device feature in the WeGuard Console allows administrators to remotely restart a managed Windows device. This can be useful when a device requires a restart for troubleshooting, applying changes, or resolving temporary issues. Rebooting a ...
    • Finding the Package ID (APK ID) and Enabling a System Application

      System applications are pre-installed applications that are available on the device by default. WeGuard allows administrators to add these applications to a policy so they can be managed and made available on enrolled devices. To manually add a ...
    • Android Device Removal and Unenrollment Guide

      IT admins need to delete devices from the organization that are no longer in use or no longer supported. To streamline this process, WeGuard provides the option to remove the MDM with or without resetting the device. This document explains how to ...
    • Managing Device Password Policies and Enforce Password on Android Devices

      WeGuard provides administrators with two levels of password management: Restrictions, which define the rules for user-created passwords, and Enforcement, which allows an administrator to push a specific password to all devices in a policy group. This ...