Operations

OS Version Control

Manage minimum OS version thresholds for Android, iOS, Windows, and macOS across compliance and app-protection baseline policies from a single view. Latest OS versions are fetched automatically for each platform so you always know the current release. CONFIG365 reads Defender for Endpoint device backups to show which devices in each tenant fall below the configured minimum, then applies threshold updates to the baseline in one operation.

5 min read Updated April 28, 2026

Overview

Platforms

Android, iOS, Windows, macOS

Policy groups

App Protection (MAM) + Compliance

Device data

Defender for Endpoint backup

How thresholds apply: OS Version Control reads the existing JSON for each matched policy in the baseline repository, merges the updated field values, and pushes the result as a new commit. It does not touch any other fields in the policy file. An optional deploy step can trigger the baseline pipeline immediately after the update.

Platform Support

Each platform exposes different policy fields across its two policy groups — app-protection (MAM) and compliance. App-protection policies are only available for Android and iOS.

Android

Policy group Field JSON key
App Protection Min required OS minimumRequiredOsVersion
App Protection Min warning OS minimumWarningOsVersion
App Protection Min wipe OS minimumWipeOsVersion
App Protection Min required patch minimumRequiredPatchVersion
App Protection Min warning patch minimumWarningPatchVersion
App Protection Min wipe patch minimumWipePatchVersion
Compliance Min OS version osMinimumVersion
Compliance Min security patch level minAndroidSecurityPatchLevel

iOS

Policy group Field JSON key
App Protection Min required OS minimumRequiredOsVersion
App Protection Min warning OS minimumWarningOsVersion
App Protection Min wipe OS minimumWipeOsVersion
Compliance Min OS version osMinimumVersion

Windows

Policy group Field JSON key
Compliance Min OS version (build number) osMinimumVersion

macOS

Policy group Field JSON key
Compliance Min OS version osMinimumVersion

How It Works

1

Select platform and load policies

The portal reads all app-protection and compliance policy files from the baseline repository that match the selected platform, using filename and @odata.type to identify the correct files.

2

Review current thresholds

Current field values are extracted from each matching policy and displayed per policy group. Fields highlighted in green have been changed from the stored value.

3

Fetch latest versions and load impacted devices

CONFIG365 automatically fetches the latest released OS version for each platform from a public source and displays it alongside the current threshold. It then reads the Defender for Endpoint device backup for each tenant and compares each device's OS version against the configured minimum. Devices below the threshold are listed per tenant with their current version.

4

Apply to baseline

Updated field values are merged into each matched policy file. CONFIG365 pushes a single commit to the baseline repository containing all changed files. An optional deploy trigger runs the baseline pipeline immediately.

  • – Only fields listed in the platform support table above are written — all other policy fields are preserved exactly as stored in the baseline.
  • – Android app-protection policies are identified by filename match (case-insensitive "android"). iOS policies match "ios".
  • – Compliance policies are matched using the @odata.type property in the JSON (e.g. #microsoft.graph.androidCompliancePolicy).
  • – The deploy trigger requires that the baseline Gitea Actions workflow is enabled and the tenant is fully onboarded in the CONFIG365 portal.

Required Permissions

The following delegated permissions must be granted to the CONFIG365 Graph access app (not Application permissions).

Permission scope
DeviceManagementConfiguration.ReadWrite.All
DeviceManagementApps.ReadWrite.All
Machine.Read

Device backup reads also require that the Defender for Endpoint backup pipeline has run at least once for the tenant. See Defender for Endpoint Device Backup for setup details.