Skip to main content
This Library Item is available for Windows computers
Managed OS Library Items let you pin devices to a Windows 11 feature version and set deadlines for installation and restart. Iru Endpoint provides one Library Item per supported Windows 11 release, for example Windows 11, Version 24H2 or Windows 11, Version 25H2. Devices do not move past that version while the Library Item is assigned. Monthly quality updates within the version continue. Managed OS sets the version and when it is enforced. For notifications, active hours, and optional content, use the Windows Update Library Item.
For details on each setting, see Microsoft’s Update Policy CSP documentation.

Create a Managed OS Library Item

To add this Library Item to your Iru Endpoint Library, follow the steps in the Library Overview article.
1

Navigate to Library

Go to Library and select Add Library Item.
2

Select the Windows 11 version

Search for and select the Windows 11 version you want to enforce, such as Windows 11, Version 25H2.
3

Name the Library Item

Give the Library Item a Name.
4

Assign to Blueprints

Assign the Library Item to one or more Blueprints. Only Windows computers in those Blueprints receive the Managed OS settings. You can use Assignment Maps within Blueprints for conditional logic if needed.
5

Configure settings

Set your deferral, deadline, grace period, and pause settings for both feature and quality updates. See Settings below.
6

Save the configuration

Select Save in the bottom right corner.
Only one Managed OS Library Item can be assigned to a device at a time. If a device already has one assigned, Iru Endpoint prompts you to confirm before replacing it.

Settings

The Settings tab has two sections: Feature updates and Quality updates.
Feature updates are major Windows 11 version upgrades (for example, moving from 24H2 to 25H2). These settings control when that version becomes available to devices, when installation is required, and how restarts are handled.Defer feature updates forDelays how many days after Microsoft releases a feature update before devices are offered the update. Range: 0 to 365 days. Default: 0 days.Deadline for feature update installNumber of days after the end of the deferral period before the feature update must be installed and the device can be forced to restart. Range: 0 to 14 days. Default: 7 days.Grace period for restartMinimum number of days after the feature update is installed before an automatic restart is forced. Range: 0 to 3 days. Default: 2 days.Pause start dateSets a specific date to begin pausing feature updates. While a pause is active, the feature update is not offered to devices. Leave empty if you do not need to pause updates.
Quality updates are the monthly cumulative updates released within a feature version. These settings mirror the feature update controls and apply independently based on each device’s current feature version.Defer quality updates forDelays how many days after Microsoft releases a quality update before devices are offered it. Range: 0 to 30 days. Default: 7 days.Deadline for quality update installNumber of days after the end of the deferral period before the quality update must be installed and the device can be forced to restart. Range: 0 to 30 days. Default: 7 days.Grace period for restartMinimum number of days after the quality update is installed before an automatic restart is forced. Range: 0 to 7 days. Default: 2 days.Pause start dateSets a specific date to begin pausing quality updates. While a pause is active, quality updates are not offered to devices for up to 35 days from the pause start date. Leave empty if you do not need to pause updates.

Status

The Status tab shows whether each assigned device has reached the Windows 11 build the Library Item requires. Iru Endpoint compares the build the device reports against the required build for the targeted feature version. Status reflects the state of the device, not just whether the settings were delivered. Install date is when the Library Item was installed on the device. Last install, in the expanded row, is the last successful Windows update. A device shows Pending until it checks in and reports its build. Devices check in every 15 minutes, so a device should not sit in Pending for longer than that after the Library Item is assigned. Once it reports its build, the status moves to Pass, Update past due, or Error. Expand a device row for build details. On Pass, Current build matches Required build.
Status tab with a Pass device expanded, showing matching required and current builds
On Update past due, Current build is still below Required build and the install enforcement date has passed.
Status tab with an Update past due device expanded, showing current build below required build
A device can report a current build that is newer than before and still below Required build. Compare Current build with Required build to see what is left.

Considerations

Only one Managed OS Library Item can be assigned to a Blueprint at a time. If you assign a new version to a Blueprint that already has a Managed OS Library Item assigned, Iru Endpoint prompts you to confirm the replacement. The previous Library Item is removed from the Blueprint when you confirm.
A Managed OS Library Item acts as a ceiling on the feature version. Devices will not advance beyond the targeted version while the Library Item is assigned. Monthly quality updates within that version continue unaffected.
Deferral and pause control when an update becomes available to devices. Deadline and grace period control how soon installation and restart are enforced once the update is available. Pausing an update stops it from being offered, but does not reset the deferral timeline once the pause ends.
If you set the grace period to a value greater than 0, the device will not force a restart at the deadline until the grace period ends. Setting the grace period to 0 allows the device to restart at the deadline without waiting.

Best Practices

Use multiple Library Items to create rings

Create multiple Library Items with different deferral periods so the update rolls out over time. Set a deferral of 0 days for the first ring so those devices get updates as soon as Microsoft releases them.

Start with a deferral period

A deferral of 7 to 30 days gives you time to validate updates on a small group of devices before they roll out to the full fleet.

Set a deadline for compliance

Set a deadline so devices install required updates in a known window.

Use pause for planned freezes

Use the pause start date during major business events or when a release has known issues. Pausing stops the update from being offered without changing your deferral configuration.

Pair with the Windows Update Library Item

Managed OS controls version enforcement. Assign a Windows Update Library Item to the same Blueprint to also manage active hours, notifications, and end-user update experience settings.

Troubleshooting

Possible causes:
  • The device encountered an issue receiving the Managed OS settings via MDM.
  • A conflicting policy from another source is preventing the settings from applying.
Solutions:
  • Check the device record for recent activity and error details.
  • Confirm no other MDM profiles or policies are setting conflicting Windows Update CSP values on the device.
Possible causes:
  • The device has been offline or has not checked in since the update became available.
  • Users are deferring the restart that completes installation.
  • The update downloaded but has not finished installing.
  • Microsoft releases updates on a regional rollout. Iru Endpoint can detect that Microsoft has published a new build before the update is available to the device in its region, so a device can sit short of the required build until the rollout reaches it.
  • Windows Update decides when to install. Managed OS settings control the deferral and enforcement dates, but Windows Update determines the automatic install time for each device, so two devices with identical settings can install on different days.
Solutions:
  • Check the device record for its last check-in and confirm the device is online.
  • Compare Current build against Required build on the Status tab to see whether the device has made any progress.
  • Review the Grace period for restart setting. A long grace period lets devices sit past the install enforcement date before restarting.
Possible causes:
  • The pause start date is set in the future and has not taken effect yet.
  • The device has not checked in since the pause was configured.
Solutions:
  • Confirm the pause start date is set to today’s date or earlier.
  • Trigger a device check-in or wait for the next scheduled check-in.

Library Overview

Learn how Library Items work and how to assign them to Blueprints

Configure the Windows Update Library Item

Configure end-user update experience settings, active hours, and optional content for Windows computers

Configure Managed OS for macOS

Configure managed OS updates for Mac computers

Using Conditional Logic in Blueprints

Use Assignment Maps to target Library Items to specific groups of devices within a Blueprint