Mobile Security· By Venkatesh AGE

How to Keep Company Android Phones Updated and Patched

How to check the Android security patch level on one phone or a whole fleet, and a 20-minute monthly routine that keeps every company phone updated.

To keep company Android phones updated, run a short routine once a month: pull a report of every phone’s security patch level, find out why each laggard is behind, fix the ones you can and write down the ones you can’t. To check the patch level on a single phone, open Settings and look under About phone for the Android security update date. That date is the best single clue to how exposed a phone is.

It takes about 20 minutes for a 20-phone fleet. The alternative is finding out a phone is two years behind when something goes wrong.

What is an Android security patch level?

It is a date, a month and year, that tells you which set of Google’s published security fixes the phone has installed. A phone showing last month’s patch has last month’s fixes. A phone showing a patch from two years ago is missing everything published since, and those gaps are public knowledge.

Think of a dental clinic with four phones and a front-desk tablet. If the tablet’s patch date is far older than the phones’, that tablet is the weakest device in the building, even if it looks and works fine.

How to check the patch level on one phone

On most phones:

  1. Open Settings.
  2. Tap About phone (on some models, Security or Software update instead).
  3. Look for Android security update or Android security patch level.

While you are there, note the Google Play system update date as well. Two different dates on the same phone is normal, for reasons covered below.

Doing this for three phones is fine. Doing it for 25 phones spread across a plumbing company’s vans every month is not going to happen.

How to check patch levels across every company phone

This is the job an Android MDM does better than a spreadsheet. The phone reports its own patch level, and you read the list.

In NounDesk, go to Reports and open the patch age report. It shows how old each device’s security patch is, and exports to CSV if someone else needs a copy. The Android versions report sits next to it and shows which major versions your fleet runs. Phones that fall behind count toward the fleet health rating on the dashboard, which reads Healthy, Needs attention or Critical with the rule behind it in plain English. Device Trust also checks every enrolled phone for a security update under 90 days old, and rates a phone At risk or Not trusted with the reason when it fails.

Why one date doesn’t tell the whole story

Google has said as much itself. In September it released the AndroidX Security State Libraries, which let apps and device management tools check security at the level of individual components instead of relying on one patch date.

The libraries look at three parts of the phone:

  • System, the core of Android, updated by the phone maker’s over-the-air updates.
  • System modules, pieces of Android updated separately through Google Play system updates.
  • Kernel, tracked by its long-term support release version rather than a monthly date.

For each part, they compare three patch levels:

  • Device SPL, what is installed on the phone now.
  • Published SPL, the latest level published in the Android Security Bulletin.
  • Available SPL, what is ready to download and install on that particular phone.

The gap between installed and available tells you whether the phone just needs to install something. The gap between available and published tells you whether the maker has shipped the fix at all. Google also describes checking pending updates and auditing against known vulnerabilities using public CVE data.

This is plumbing for app developers, device management providers and phone makers. You won’t open it yourself. It matters because it changes the question from “how old is this date” to “is this phone missing a fix it could have right now”.

Why do updates arrive at different times?

Because Google, the phone maker and sometimes the carrier all sit between a release and your staff. Android 17 is a live example. Samsung began rolling out Android 17 and One UI 9 to the Galaxy S26 in the US after a delay, reaching T-Mobile phones before unlocked ones, as a download of roughly 4GB. Google is still testing Android 17 QPR2 with Beta 6 for Pixel, a build that fixes crashes and freezes seen in earlier betas. And the Nothing Phone (4a) and (3a) Pro can now join the Android 17 open beta, with the stable release planned for early November.

So a small business with a mix of phones will have a Galaxy that updated this week, a Pixel on last month’s release and a Nothing phone that hasn’t seen Android 17 at all. None of that is a problem on its own. What you need to know is which phones are behind, and whether they will catch up. For the release itself, see Android 17 for business.

Rule one: keep company phones out of beta programs

Beta builds are for testing. The Pixel Beta 6 release notes list fixes for kernel crashes, camera crashes and devices hanging while scrolling. That is useful work, but not something you want on the phone a technician uses to take a card payment.

Tell staff plainly: no Android Beta Program and no manufacturer open betas on company devices. If someone is curious, they can try it on their own phone.

The monthly update routine

Pick a fixed day, such as the first Monday of the month, and put it in your calendar with one named owner.

Step 1: see who is behind

Open the patch age report and the Android versions report. You are looking for phones more than a couple of months behind on patches, and phones stuck on an old major version.

Step 2: work out why each one is behind

There are usually four reasons:

  • The update hasn’t reached that model or carrier yet. The Galaxy S26 situation above. Wait a week and check again.
  • The phone hasn’t been on Wi-Fi. A 4GB download won’t happen on a phone that lives on cellular data in a van.
  • Someone keeps tapping “later”. Common with phones used all day.
  • The phone is too old to get updates at all. This one doesn’t fix itself.

And a fifth to rule out first: the phone hasn’t checked in. The dashboard shows it as Recently offline or Offline (24 hours or more). Find the phone before worrying about its patch.

A plumbing company with six technicians found two phones behind in its first month. One hadn’t joined Wi-Fi in weeks because the tech never came back to the office. The other was an older model that had stopped getting updates.

Step 3: fix what you can

For the Wi-Fi problem, push the office Wi-Fi network to every phone through your policy so they join automatically when in range.

For the “later” problem, set an update schedule in your policy. It tells the phone when it may install updates, such as overnight, so installs stop landing in the middle of a job. Be clear about the limit: no MDM can make a manufacturer ship an update sooner, and NounDesk has no button that forces an OS update to install right now. The schedule and the visibility are the levers.

Step 4: write down what you can’t fix

Keep a short list of devices that are out of support or stuck, with a replacement date next to each. A clinic with a front-desk tablet that stopped getting patches last year should budget for a new one, not hope it gets another update.

This list is also what an insurer or a client’s security questionnaire will ask about. “We check monthly, and these two are scheduled for replacement” is a good answer.

How a major release like Android 17 fits in

A major version is not an emergency, and there is no prize for being first. Let it arrive through the normal channel, then check two things:

  1. Do your apps still work? Test the job app, the payments app and anything built in-house on one updated phone before the rest follow. If a vendor ships an Android 17 fix, set it as the minimum app version so every phone is required to have it.
  2. Do your policies still apply? Every policy setting in NounDesk shows the Android version it needs, and the publish preview lists what changes and how many devices are affected before you save. A fleet on mixed Android versions is normal.

Other device health settings worth checking

Patch age is the headline, but a healthy phone has a few other settings in place. In a NounDesk security policy you can require encryption, Play Protect, screen lock and auto-lock, and block apps from outside Google Play.

That last one matters more than it sounds. Recent Android spyware aimed at logistics companies was installed from fake Play pages, not from Google Play. We explain how in Corp MDM spyware: settings that stop fake Play installs. If you’re unsure which devices should be kiosks, see fully managed vs kiosk Android devices, and if you’re still deciding whether a fleet your size needs device management at all, read do I need MDM for 10 company phones.

What to do this week

  1. Check three phones by hand. Note the Android security update date and the Google Play system update date, so you know what normal looks like.
  2. Pull a fleet-wide patch age report and list every device more than a couple of months behind.
  3. Sort the laggards into “update available”, “no update available” and “not checking in”.
  4. Push office Wi-Fi and set an update schedule in your policies so updates download and install overnight.
  5. Tell staff the beta rule and start your replacement list.
  6. Put the monthly check on the calendar. Same day each month, 20 minutes, one owner.

FAQ

How do I check the security patch level on an Android phone?

Open Settings, go to About phone, and look for Android security update or security patch level. Menu names vary by manufacturer, so try Security or Software update if you don’t see it.

What is a good patch level for a business phone?

One from the last month or two. A much older date means the phone is missing published fixes, either because it hasn’t installed an update or because the maker no longer ships them.

How often should I check updates on company phones?

Once a month is enough for most small businesses. Security patches ship roughly monthly, so a monthly check catches any phone that has fallen behind before the gap gets large.

Can mobile device management force an Android update to install?

No. No MDM can make a manufacturer or carrier release an update sooner. You can set an update schedule and see which phones are behind, but there is no “install now” button in NounDesk.

What are the AndroidX Security State Libraries?

Google libraries released in September 2026 that let apps and device management tools check a phone’s installed, published and available patch levels for the system, system modules and kernel separately.

When you’re ready to run this routine from one screen, try NounDesk free for 14 days and see patch age for every company phone.