Forum Discussion
Understanding Automatic Operating system update behaviour
Hello GMenzies,
Great to meet you.
Good question. As Jason mentions, if you apply an 'Automatic' policy on updates then this policy will automatically install updates as soon as they are available and will trigger a reboot if required. I know if this is not always a viable option depending on the business type and set up.
There are a number of different options you could explore though, I wonder have you come across this recent Help Center article which gives an overview of the different options: Google system updates on device enrolled on Android Enterprise
Is there anything else on the automatic policy you are keen to explore? Do you think the 'Windowed' option may work for you?
Thanks,
Lizzie
- GMenzies2 years agoLevel 2.0: Eclair
Hi,
Thanks for your responses Jason and Lizzie.
I hadn't found that article so thank you for providing it.
I'd like to see an Automatic update policy where it updates when the device isn't in active use for 30 minutes etc, unfortunately our devices are used worldwide 24/7 so we wouldn't be able to deploy a Windowed option for a specific time frame.
Also, what's the best method to request new features for COWP? We have a few in mind that we are losing going from POWP and would like to understand alternatives or if they will ever be implemented.
Thanks for your help.
- Lizzie2 years agoGoogle Community Manager
Thanks so much for the follow up information GMenzies. Glad the article is useful. I'll ask internally about your use case and see what we would suggest here. I'll get back to you.
Regarding your feature requests, are these things you are happy to share publicly here in the Community? If so, it would be great to hear if these requests are things that would help others and understand the use cases. It make it easier for me to report back to our product team. If you'd prefer not to share here, just let me know and I can follow up via direct message.
Thanks so much,
Lizzie
- GMenzies2 years agoLevel 2.0: Eclair
Hi Lizzie,
Honestly most of this is small requests and some perhaps need to be managed through Microsoft (Our EMM is Intune) or are just how we manage things today and probably need to change.
- We're unable to provide our internal Google Workspace users with the ability to add their domain accounts to the devices, we work alongside Google for Chromebook development so having this option for COPE would be beneficial to improve their workflows and the customer experience we provide to these users so they can use their Android Mobile Devices and Chromebooks side by side, I know this is available for POWP (BYOD) devices in Intune today and we've created a DCR with Microsoft for this. Whether it's a requirement from Microsoft or Google is the next question.
- Our users like to add Work Profile app Widgets to their Home screen, this doesn't seem to be available as a setting for COPE devices (We're working with Microsoft on this to determine if it's available or not for COPE devices, again not sure on who the requirement falls on).
- We deploy a compliance policy with Intune to block devices that have been rooted for our POWP (BYOD) devices, this setting doesn't seem to be available for COPE devices in Intune today (We were told by Microsoft this would be a requirement for Google to make available), the best we can do is use our Device Security solution and a combination of ensuring Device Integrity with Google Play Protect, if you can confirm if Device Integrity is a suitable to detect rooted devices that would be great - https://developer.android.com/google/play/integrity/verdicts#kotlin:~:text=The%20app%20is%20running%20on%20a%20device%20that%20has%20signs%20of%20attack%20(such%20as%20API%20hooking)%20or%20system%20compromise%20(such%20as%20being%20rooted)%2C%20or%20the%20app%20is%20not%20running%20on%20a%20physical%20device%20(such%20as%20an%20emulator%20that%20does%20not%20pass%20Google%20Play%20integrity%20checks).
As I've said these are just a few that we've seen so far and perhaps most fall on Microsoft but I'd love to be able to provide this feedback to Microsoft that they are available and require actions on their end.
Thanks for your help, I've found this forum to be very valuable.