Field device update management: Schedule update windows after shifts to avoid interrupting customer visits.; Verify OS and app versions post-update using compliance reports or device checks.; Prioritise security fixes if exploited, following ACSC guidance for critical patches.
Image: Small Business Tech Guide

Devices

Part of Mobile devices for work

Managing updates on field devices

Plan updates for field phones and tablets, verify installation and address overdue or unsupported devices.

Plan an update window when field phones and tablets can be charged, connected and restarted without interrupting essential work. Run the OS and app updates, then verify the installed versions or compliance results. Follow up devices that remain behind and resolve the cause before closing the rollout.

Know what needs updating

Keep a register of each work device’s assigned user or team, model, operating system version, essential apps and last confirmed update. Include personal devices that receive work access, but collect only the device information covered by the agreed policy.

Track operating system and app updates separately, and check essential field apps for compatibility after either type of change. Ask the app supplier which versions it supports, especially if staff rely on offline work. Check the manufacturer’s support information for devices nearing the end of security updates, then plan to replace them or remove work access when support ends.

Make an update window workable

Choose a time when devices can be charged, connected and free to restart, often after a shift rather than during a customer visit. Tell staff how to save unfinished work and whom to contact if an update blocks sign-in. Provide an alternative way to work for roles that cannot pause.

Before widening a rollout of a critical field app, have a designated user open it, sign in, complete a safe sample task and confirm the saved item reaches its destination. Do not leave an urgent security fix waiting indefinitely for broad testing.

Use management controls within their limits

Apple’s deployment documentation describes declarative software-update settings and lists Automated Device Enrolment as an enrolment method. The Android Management API reference names SystemUpdate, SystemUpdateType and FreezePeriod; it also lists AppAutoUpdatePolicy.

Check whether the chosen management service and device configuration expose the relevant settings, then apply them using the service’s supported controls. If they do not, arrange a staff-led installation during the update window. On an employee-owned device, more of the installation step may remain with the owner.

After the window, check each device’s installed operating system and essential app versions, or its management service’s compliance result. Do not treat a dashboard’s ‘sent’ status as ‘installed’. Record the result and follow up overdue devices, noting the reason.

OS update management: Apple vs Android

Apple (iOS)
Uses declarative software-update settings; Automated Device Enrolment (ADE) for enrolment
Android
Uses `SystemUpdate`, `SystemUpdateType`, `FreezePeriod` and `AppAutoUpdatePolicy` via Android Management API

Pros and cons of automated vs staff-led updates

Automated updates (via MDM)
Consistent, scalable, reduces human error; requires compatible device and service configuration
Staff-led updates
Flexible for unsupported devices; relies on user compliance and training

Resolve exceptions

A device without a connection or sufficient charge, or one that needs a restart, can remain behind. Address the relevant cause, arrange another update attempt and check the result afterwards.

When a supplier reports active exploitation, prioritise the security fix. Consult the Australian Signals Directorate and the Australian Cyber Security Centre’s guidance on patching applications and operating systems when setting patch priorities.

If an update breaks a work app, record the affected version, device model, task and error, then ask the supplier for a supported fix or workaround. Restrict work access from an unsupported device if needed while providing a safe way for the worker to continue.

After each rollout, review overdue devices and the reason for each one. The number of update notices sent does not show whether devices are protected.

Key update management metrics to track

Devices updated successfully
Number of devices confirmed compliant
Overdue devices
Count requiring follow-up
Critical security patches applied
Number of urgent fixes deployed
Unsupported devices
Devices nearing end-of-support

More from Devices