Skip to content

Managed OS for Windows: Enforce updates on your timeline

Lance Crandall Lance Crandall
Managed OS for Windows: Enforce updates on your timeline

Target a Windows feature release, set a deadline, and know that devices will be running that version when it arrives.

If you manage Macs with Iru, you understand the simplicity of enforcing OS: set a policy in a Blueprint, and the device follows it. Windows updates have rarely felt this way. You schedule the rollout and the device updates on its own schedule.

Iru now configures Windows Update for Business settings, and the OS enforces them on the timeline the admin sets. Set your version target, configure your timeline, and every device in your fleet runs that version, with no way for users to defer past the window. You can also configure rings by creating multiple Managed OS library items and targeting them to different user groups, giving you staged rollouts without additional tooling.

 

Version control with a deadline you set

Managed Windows OS works through a library item you add to any Windows Blueprint. Pick a feature release, assign the library item, set the timeline for when updates should occur, and the device targets that version and holds it. Monthly quality updates within the release continue on schedule, but the device doesn't advance to the next annual release on its own.

The version target holds because that's what the library item targets: your devices stay on the major feature release you want, and it installs on the timeline you expect. Define a deferral window before the update becomes eligible, a deadline by which installation must complete, and a grace period during which users choose their own restart window. When the grace period closes, the device restarts on its own.

Devices run one Managed OS library item at a time, and replacing an existing assignment requires a confirmation step before the change takes effect.

The full update surface, covered

Iru covers the full Windows update surface through two library items, each with a distinct job.

Managed OS controls what version of the operating system, both feature releases and quality updates, the device should move to and by when. Pick a feature release, configure your timeline, and Iru targets that version across your fleet.

Windows Update (already available) controls end-user behavior: notifications, reboot behavior, active hours, and more. For most environments, the defaults are the right starting point: quality updates defer seven days, active hours protect the standard workday, and users can't pause updates unless you configure that access. Admins who need more control can configure scheduled install windows, WSUS source routing, and driver update handling in the Advanced section.

Get started

Managed Windows OS is available now in Iru Endpoint. Assign the library item to your Windows Blueprint and Iru manages version enforcement from there. If you're already an Iru customer, the feature is live in your account.

If you're new to Iru, book a demo to see Windows, Mac, iPhone, iPad, and Android management from a single platform.

Recent Articles

Featured image: Feature engineering for a macOS malware classifier, and why the Mac makes it harder than Windows
Calvin So 13 min read

Feature engineering for a macOS malware classifier, and why the Mac makes it harder than Windows

The threat landscape for macOS malware is expanding, while the number of specialists dedicated to defending against it has not kept pace. Unlike Windows, where machine learning (ML) models are supported by extensive documentation and standardized datasets, the macOS environment presents a significant knowledge gap. At Iru, we captured SSTAR Agent, a crypto drainer targeting web3 technology developers via a fake interview lure, which we documented in an earlier post using an ML triage we built.

Threat Intelligence
Featured image: How-to guide: Changing and resetting Mac passwords
Arek Dreyer 8 min read

How-to guide: Changing and resetting Mac passwords

This post was originally published in May 2023 and has been updated in July 2026 to reflect the latest information. When was the last time you or someone in your organization needed their Mac password to be something different than what it previously was? There are two ways to do that: change or reset. But although those two words might seem similar, their difference is significant.

Educational
Featured image: Teams running Vulnerability Response patch critical CVEs in half the time
Matt Day 2 min read

Teams running Vulnerability Response patch critical CVEs in half the time

We recently measured remediation behavior across anonymized customer fleets. Customer accounts running Vulnerability Response closed more of their critical vulnerabilities, and closed them faster. The pattern held across every customer cohort.

Educational

See Iru in action

Discover why thousands of teams choose Iru

By submitting this form I agree to Iru’s Privacy Policy and consent to be contacted by Iru about its products and services.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.