OS Version Control
Manage minimum OS version thresholds for Android, iOS, Windows, and macOS across compliance and app-protection baseline policies from a single view. Latest OS versions are fetched automatically for each platform so you always know the current release. CONFIG365 reads Defender for Endpoint device backups to show which devices in each tenant fall below the configured minimum, then applies threshold updates to the baseline in one operation.
Overview
Android, iOS, Windows, macOS
App Protection (MAM) + Compliance
Defender for Endpoint backup
How thresholds apply: OS Version Control reads the existing JSON for each matched policy in the baseline repository, merges the updated field values, and pushes the result as a new commit. It does not touch any other fields in the policy file. An optional deploy step can trigger the baseline pipeline immediately after the update.
Platform Support
Each platform exposes different policy fields across its two policy groups — app-protection (MAM) and compliance. App-protection policies are only available for Android and iOS.
Android
| Policy group | Field | JSON key |
|---|---|---|
| App Protection | Min required OS | minimumRequiredOsVersion |
| App Protection | Min warning OS | minimumWarningOsVersion |
| App Protection | Min wipe OS | minimumWipeOsVersion |
| App Protection | Min required patch | minimumRequiredPatchVersion |
| App Protection | Min warning patch | minimumWarningPatchVersion |
| App Protection | Min wipe patch | minimumWipePatchVersion |
| Compliance | Min OS version | osMinimumVersion |
| Compliance | Min security patch level | minAndroidSecurityPatchLevel |
iOS
| Policy group | Field | JSON key |
|---|---|---|
| App Protection | Min required OS | minimumRequiredOsVersion |
| App Protection | Min warning OS | minimumWarningOsVersion |
| App Protection | Min wipe OS | minimumWipeOsVersion |
| Compliance | Min OS version | osMinimumVersion |
Windows
| Policy group | Field | JSON key |
|---|---|---|
| Compliance | Min OS version (build number) | osMinimumVersion |
macOS
| Policy group | Field | JSON key |
|---|---|---|
| Compliance | Min OS version | osMinimumVersion |
How It Works
Select platform and load policies
The portal reads all app-protection and compliance policy files from the baseline repository that match the selected platform, using filename and @odata.type to identify the correct files.
Review current thresholds
Current field values are extracted from each matching policy and displayed per policy group. Fields highlighted in green have been changed from the stored value.
Fetch latest versions and load impacted devices
CONFIG365 automatically fetches the latest released OS version for each platform from a public source and displays it alongside the current threshold. It then reads the Defender for Endpoint device backup for each tenant and compares each device's OS version against the configured minimum. Devices below the threshold are listed per tenant with their current version.
Apply to baseline
Updated field values are merged into each matched policy file. CONFIG365 pushes a single commit to the baseline repository containing all changed files. An optional deploy trigger runs the baseline pipeline immediately.
- – Only fields listed in the platform support table above are written — all other policy fields are preserved exactly as stored in the baseline.
- – Android app-protection policies are identified by filename match (case-insensitive "android"). iOS policies match "ios".
- – Compliance policies are matched using the @odata.type property in the JSON (e.g. #microsoft.graph.androidCompliancePolicy).
- – The deploy trigger requires that the baseline Gitea Actions workflow is enabled and the tenant is fully onboarded in the CONFIG365 portal.
Required Permissions
The following delegated permissions must be granted to the CONFIG365 Graph access app (not Application permissions).
| Permission scope |
|---|
DeviceManagementConfiguration.ReadWrite.All |
DeviceManagementApps.ReadWrite.All |
Machine.Read |
Device backup reads also require that the Defender for Endpoint backup pipeline has run at least once for the tenant. See Defender for Endpoint Device Backup for setup details.