Automated patching for Enterprise Application Repository (EARv2) apps helps you keep commonly used third-party Windows applications current without repeatedly re-importing and reconfiguring new versions.
When activated, Workspace ONE UEM checks the repository for newer versions on a schedule you define and, when a newer version is available, automatically imports it into UEM. This reduces the operational overhead of routine patch cycles (monitoring vendor releases, validating package availability, importing, and redoing basic configuration) and helps shorten the time between a vendor release and availability in your UEM catalog—supporting more consistent application hygiene and fewer gaps caused by missed manual updates.
Why use automated patching?
Automated patching is useful when you manage a broad set of third-party apps across many smart groups and want predictable update behavior.
Instead of tracking updates per application, you define a schedule once and let UEM perform periodic version checks and imports. You can also control whether assignments from the previous version are carried forward automatically, which helps you balance:
- Operational speed (inherit assignments), vs.
- Change control (require explicit re-assignment)
How it works
-
Enable Auto-update for an app imported from EARv2 and configure a schedule. This can be done:
- When adding the app from EARv2, or
- Later, for apps already added (from the app’s Repository tab)
-
A scheduler evaluates each app’s configured schedule and runs version checks:
- At the configured interval, or
- At repository synchronization for continuous checks
-
On each check, UEM compares:
- The current app version stored in UEM, with
- The latest available repository version using the Repository ID and architecture (x86, x64, ARM)
-
If a newer version exists, UEM automatically imports the updated version.
-
Uses default repository configuration values for the new version:
- Installation command
- Uninstallation command
- Detection command
- Icon
-
Preserves existing metadata:
- App name
- Description
- Icon (as maintained)
- Reboot settings
- Vendor details
-
Applies assignment behavior based on Assignment inheritance (enabled/disabled)
-
-
If the repository cannot be reached or synchronization fails:
- UEM logs the issue and retries at the next scheduled interval
- Update checks and import actions are recorded with timestamps in system audit logs
Installer-type update compatibility
Automated patching updates an app using repository versions that match the installer type:
- MSI apps can only be updated to a newer MSI version
- EXE and ZIP installer apps can only be updated by an EXE installer version from EAR
Configure automated patching
Prerequisites
- Your admin role must allow you to add and edit applications in the Workspace ONE UEM console
- The app must be imported from EARv2 (auto-update applies only to EARv2-origin apps)
Scheduling options
You can configure one of the following schedules:
Monthly
- Day-of-month: every 1–31 day of every 1–12 month
- Nth weekday: first/second/third/fourth/last Friday of every 1–12 month
Weekly
- Every 1–4 weeks on Monday and/or Friday
Daily
- Every 1–31 days
Continuously
- Checks for new versions during each repository synchronization event
Enable auto-update when adding an EARv2 app
-
In the Workspace ONE UEM console, start adding an application from the Enterprise Application Repository
-
In the add application flow, activate Auto-update.
-
Configure the schedule.
-
Configure Assignment inheritance:
- Enabled: Assignments from the previous version are automatically added to the newly imported version
- Disabled: The new version is imported without assignments; you must create assignments manually
-
Complete the add/import flow
Result: The application is imported and scheduled for automated update checks. If you do not enable auto-update, the app does not update automatically.
Activate, deactivate, or change settings for apps that were already added
- Open the application details page for the EARv2 app.
- Select the Repository tab.
- Configure any of the following:
- Enable/disable Auto-update.
- Modify the schedule settings.
- Enable/disable Assignment inheritance.
- Save your changes.
Result: The scheduler uses the saved configuration for future update checks and imports.
View status and troubleshoot
View update status
Open the app and go to the Repository tab to see:
- Last update check timestamp
- Last successful update information
If an update does not import when expected
-
Confirm the app was imported from EARv2
-
Confirm Auto-update is enabled and the schedule is correct
-
Confirm installer-type compatibility:
- MSI → MSI only
- EXE/ZIP → update only via an EXE installer from EAR
Was this page helpful?