Get the latest product updates, ask technical questions, and learn best practices
Recently active
Through this partnership, Automox customers will gain access to Splashtop’s industry-leading remote control technology, trusted by millions of users worldwide for its efficiency, reliability, and security. By integrating Splashtop’s best-in-class remote control into Automox’s autonomous endpoint management platform, IT teams can expect faster issue resolution, improved user experiences, and a unified approach to device management and support.🗓️ The joint solution will be made available to Automox customers early next year!Learn more about the strategic partnership here!
We have a Windows 11 Golden Image running for VDI.We noticed that MS Teams wasn’t being upgraded to latest version.I found a worklet.Windows - Software Lifecycle - Upgrade to the New Microsoft Teams (MSIX)I created a policy from it and assigned to that specific VM.The initial evaluation code runs and comes back with:The New Microsoft Teams client is already installed. Device is compliant.This is not true because when I check the version installed its: 2025 July 25 [removed by moderator] .8024 and of course, latest version is 2025 November 19 [removed by moderator] .7193 Version update history for Teams app deployments - Office release notes | Microsoft Learn When i look at the powershell code it’s running, the Evaluation Code checks the package name:# Defining the New Teams package$package = 'MSTeams_8wekyb3d8bbwe'I also check the version on the golden image and it matches this team:PackageFamilyName : MSTeams_8wekyb3d8bbwe but obviously something is off because the VDI doesn’t ha
We have Automox deployed on our users devices and overall it is great for keeping devices up to date, but if a device has need of updates that we can see on our console, the icon on the users device still says that it is up to date?
Hi, After following this documentation, as well as enabling and configuring the “Enable Apple Silicon Patching” worklet (with the correct admin credentials) I have been unsuccessful in my attempts to remediate the `_automoxserviceaccount` SecureToken authorization.First I tried sudo /usr/local/bin/amagent --adminuser '<admin_username>' --adminpass '<admin_password>' but received: ENABLE Automox service account given account not found I tried this remotely (via mdm) and locally, same result. I confirmed that _automoxserviceaccount exists at /Local/Users/_automoxserviceaccount The admin user has SecureToken enabled Then I tried the supplied automox worklet “Enable Apple Silicon Patching” I supplied the same valid as variables in the worklet: SECURE_TOKEN_ACCOUNT="_automoxserviceaccount" SECURE_TOKEN_ADMIN_USER="<Admin user>" SECURE_TOKEN_ADMIN_PASSWORD="<Admin Password>" This did not use the supplied creds and instead prompted the logged in user to en
Hi all, We are having an issue whereby our Office 365 updates are forcing apps to close and restart. This is happening to some VIP users and as a result they are complaining to IT about applications closing on them. Whilst this mostly recovers, the disruption whilst working is not ideal and it also doesn’t recover things like Mimecast searches (within Outlook via the addin). We would therefore like to approach this with a separate worklet or update policy to update just Office365. Does anybody have any recommendations on this one? Perhaps a Worklet whereby I can trigger a notification that the application will update in X minutes, and provide a user-friendly warning to the user (if it detects that the office apps are open). Alternatively, if we can update but not restart the app, and then apply the changes on the next restart of the apps (or device) that would be ideal. Thanks in advance!
Morning, events have transpired that we need to move half of our devices in one Automox account to a new one.Is there an easy way to do this? I’d rather not have to go round and uninstall and reinstall Automox with the new key. I saw a similar ticket that had a script but it doesn’t seem to be accessible now.Thanks,F_IT
Hi Automox Community,We’ve recently started integrating edge computing environments into our infrastructure primarily for retail locations and remote branches. Automox has been performing well in our core setup, and now we’re excited to extend its automation and security advantages to our decentralized edge computing environments.I’d love to hear from anyone who has experience managing patching and policy automation for edge devices using Automox. Are there specific best practices you follow for scheduling, bandwidth usage, or handling limited connectivity?So far, the flexibility of Automox policies has made initial deployments smooth, and I’m optimistic about scaling further. Any tips or lessons from real-world edge use cases would be much appreciated especially around performance, security hardening, and group structuring.Thanks in advance and looking forward to contributing more as we go deeper with this!
I would like to suggest adding when the software was installed under Software.
I have installed all available patches in Automox, but the vulnerabilities I scanned on Lansweeper have not decreased. Why is this?
Anyone using the beta agent and running into issues? I am seeing a number of failures and the log shows they failed due to execution policy issues. Unable to run the script because running scripts is disabled. This is new.
Is ARM64/Snapdragon supported by Automox on Windows 11 yet? For both install and for updating other ARM applications?
Hello!I’m trying to make it so that a user in a single Organization can use a Custom Role I have created. So far this is proving difficult, as the distinction between whatever “Account” level and “Global” level is is about as clear as mud. The descriptions of them are the same. The best I could muster was a user who had the role assigned shown via Organizations, but if you looked under Roles & Permissions the role had 0 users assigned.I had a conversation with someone who used 3 terms (Account/Zone/Organization) to refer to Organization. And also “Account” referring to… something else.I guess my 2nd question is… what is an Account in terms of Roles & Permissions Account/Global?3rd… what else is “Account?”More confusing is, as a Global Administrator, I can see users defined in 2 places. With my custom role assigned to nothing, I can see the user in question at a Global level “unassigned” but not present within the Organization I want them to be in with the custom role.This
Apple released macOS Tahoe 26 with a redesigned interface, Apple Intelligence integration, and dozens of security fixes.Automox now provides same-day patching and full support so you can:• Deploy updates across Macs immediately — in office or remote• Close vulnerabilities in core subsystems, drivers, and frameworks• Maintain compatibility with Apple’s versioning shift (v26)Automox zero-day support keeps your fleet protected from day one while enabling fast, automated deployment.✅ Day-one security for macOS Tahoe 26 starts here!
Hello,For some reason our Axonius integration with Automox (via API) has stopped working and I can’t seem to find the API key for it anywhere (but have noticed a Global level “New” Keys section just appeared). How can I create an API key specific to a read only user that we have?Thanks,Mark
The overall structure of zones vs. groups is creating a lot of redundant issues. As a service provider, we have many clients, which means a lot of consistent policies and users being made. Having clients in zones, we can assign their users the ability to view their console. But then we have to duplicate the same policies, worklets, and users from one zone to another. This is really redundant and the overall structure of zones vs. groups just makes API calls for all clients a nightmare. I see that you can customize the Automox agent installer to specify a group. Managing by the zone (top-level) and groups (clients) makes everything easier to manage. Only thing missing is limiting a user to view only specified group(s). Is there a possibility of this being added in the future? It is just very odd that there is limited to no features when administrating on a global level.
Hi all, We are currently making use of the Windows 11 Feature Upgrade worklet (Windows - Configuration - Windows 11 Feature Upgrade) and this had been working quite nicely for us, however we are recently experiencing and issue whereby this does not seem to be working. Upon checking the logs of devices, we are seeing that they have: {"args":"","response":"[\"124\",\"Device is on a Windows 10 build. Running the Windows 11 Readiness Check to determine eligibility for the Feature Upgrade.\\r\\nEligibility check passed.\\r\\nDevice is Windows 11 Ready.\\r\\nFlagging Device for remediation.\",\"COMMAND TIMED OUT.\"]"} Please can somebody advise of how I can review why these are timing out and perhaps up the timeout limit to ensure that this is back working? Thanks!
Hi all,We would like to have a download time different than the patch time.At this moment, we have a policy schedule at 00:00 and a automatic restart enabled with a deferral of 12h in order to reboot all critical systems during working hours if something happening. But if any patch installation succeed but generates any problem in the machine, it will stop working. Is there any workound or idea of how to achieve what we want? To dowload around 00:00, patch around 11:00 and then reboot at 12:00? Thank you,David.
Hello all,I’ve run into a couple of issues I’m looking for solutions for with Automox’s implementation of SAML, one of which is a security concern. Scenario 1: You have an Entra joined Windows device that you log into with an Entra ID account (joel@contoso.com). Once logged in, you open up a fresh copy of Microsoft Edge with no stored credentials, cookies, or cache. Finally, attempt to log into Automox. Expectation: Edge will use your device credential by default to SSO authenticate you into Automox, if that is rejected, you will be prompted to create a browser token via Microsoft to authenticate to Automox. Reality: The device credential created by Edge is rejected by Automox, no attempt is made by Automox to request your computer create a browser token, and there is no way to prevent Edge from using your device credential in the browser.Result: You simply cannot use Edge to log into Automox in this circumstance unless you use an incognito window.Scenario 2: You have a regular accoun
Hi, I just started creating different groups based on OS and core business functions, and came to realise that you can not really automate based on those filters, automation is based on policies. I can run a policy for all devices affected to it, but can not run all policies affected to a group. Am i missing on something, or is Automox just not built this way, and that is possible room for improvement ?
Hi Team,Is there any way to enable below through script/policy on mac rather than going and executing command individually on each systemhttps://docs.automox.com/product/Product_Documentation/Agents/Agent_Installation/Install_and_Configure_Automox_Agent_for_Apple_Silicon_Devices.htm
Not sure if this is available or not, but I’m hoping we can get a feature put in.Issue:When I go to a device, and check the software to see what needs updates, I see which ones need updates, but I don’t truly know quickly which policy is going to update it. Solution:Ideally, we have two columns.Policy Column: This will show you the name of the policy that will update the software (or one that will be doing it next if multiple) Update Scheduled for: This will show you when the software is actually going to get updatedThis way, when you are looking at a device and it’s software section, you can quickly see when the update is happening and by what policy. Just an example the current software section, and what the column would look like
It is that time of year again! What cool tech\nerdy gifts are ya asking for!?! Have a few of mine below!Outdoor projector screenI need a new Pi lolA nice new Steam Deckand the Lego Marvel X-Mansion looks SWEET!
Hi What is best possible way in automox to update zoom workspace to latest version on 25 devices.
Device Status Shows Disconnected, but user is active Logged In.Any Idea why this is showing as Disconnected?
I’ve just started looking at the API documentation, and it looks like if I don’t know the Device ID but only the name, the only way I can query the API is to return all devices and then filter my results.The only filter option I can find in the documentation for the servers ‘is_compatible’.Is getting all servers and then filtering the results the only way?Thanks!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.