Skip to content
Sections
All notes

All notes · Operations

Operating System Updates on Devices You Do Not Hold

The security control with the largest gap between policy and reality, because the device belongs to somebody who is using it.

Operations · Analysis

Operating system updates close the vulnerabilities that matter most on mobile devices. Getting them installed is mostly a problem of persuasion rather than of configuration.

The operational work behind “Operating System Updates on Devices You Do Not Hold” is often spread across tickets, projects and repeated manual checks. A team reviewing visit the official site for tips to increase productivity can make that effort visible by project and group, while the device-management platform remains the source of truth for technical state and enforcement.

What you can actually enforce

Varies enormously by platform and ownership model.

For an independent baseline relevant to “Operating System Updates on Devices You Do Not Hold”, the NCSC mobile-device guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.

On fully managed corporate devices: deferral windows, forced installation, minimum versions enforced by blocking access.

On personal devices: considerably less, and increasingly the platforms themselves restrict what an employer may force.

Know which you have before writing a policy that assumes the first.

The access-based approach

Rather than forcing the update, require the version for access.

Below the minimum, work applications stop working and the user is told why and how to fix it.

This works on any ownership model, respects the device owner, and puts the decision where it belongs.

It is also the approach least likely to be undermined by a platform change.

Setting the minimum

High enough to exclude versions no longer receiving security fixes.

Low enough that people are not excluded overnight.

With notice before raising it — weeks, because on personal devices it may mean buying hardware.

And a documented reason, so that the next person knows why that number.

The hardware cliff

Devices stop receiving updates at some age, and the age differs by manufacturer.

Which means a minimum version is implicitly a minimum hardware age.

On corporate devices that drives the refresh cycle; on personal devices it asks somebody to spend their own money, which the stipend note addresses.

Say which you are doing.

Why people defer

Storage: a device too full to update, which is extremely common and invisible unless you look.

Time: updates take the device away for a while.

Fear of change, which is reasonable after a bad experience.

And simply not noticing.

Each has a different remedy and only the last is addressed by a reminder.

The storage finding

Check free space across the estate.

A meaningful proportion of devices that have not updated cannot, because there is no room.

Telling somebody to update when they physically cannot is how a programme loses credibility, and the fix is help with storage rather than another notification.

Measuring it

Version distribution across the estate, monthly.

Devices below minimum, and how long they have been.

And the proportion that updated within a fortnight of release, which is the number that actually describes your exposure.

What to check

Do you enforce versions or gate access on them?

What is your minimum, and when was it set?

How many devices cannot update for lack of storage?

And how long does it take your estate to reach a new version?