"Action not allowed" on Android OS update screen on Esper-managed devices: expected behavior when OTA is controlled by MDM
Android
Title: "Action not allowed" on OS update screen — MDM controls updates on managed devicesWhen you attempt to manually trigger an Android OS update on an Esper-managed device from the device's Settings app, Android displays the message Action not allowed. You do not have permission to perform this action.
Why this happens
When a device is enrolled in Device Owner mode, Android removes direct user access to system update controls and hands that authority exclusively to the MDM. This message is expected behavior — it is not a misconfiguration or a blocking policy. OS updates on Esper-managed devices are delivered through the System Updates policy in your applied Blueprint, not through manual checks in Settings. Additionally, the availability of a specific Android version (for example, Android 14 → Android 15) depends entirely on your device manufacturer and carrier rollout schedule, not on Esper.
Steps
- Confirm your Blueprint's System Updates policy. In the Esper Console, navigate to Devices & Groups → [Device Name] → Blueprint and review the Applied Blueprint. Verify that the System Updates policy is set to Automatically install or your preferred maintenance-window option. If the policy is correctly configured, no further action is required — the device will update automatically the next time your manufacturer releases a qualified OTA for your model and region.
- Check whether a Blueprint at the group or device level is overriding your policy. Navigate to Devices & Groups → [Device Name] → Blueprint → Applied Blueprint and confirm which Blueprint is active. A device-level Blueprint always overrides a group-level Blueprint, so ensure the correct Blueprint is applied at the right scope.
- Verify that your manufacturer has released the update for your model and region. Esper cannot push an OS version that your manufacturer has not yet published. Visit your manufacturer's official update support page (for example, Samsung's software update page) and search for your specific model and region. If no new OS version is listed, the update is not yet available for your device — this is outside Esper's control.
- Verify the device's current OS version. Navigate to Devices & Groups → [Device Name] → Device Info and confirm the OS version shown. If the version matches the latest release your manufacturer has published for your model and region, the device is already up to date.
- Review the Activity Feed for update events. Navigate to Devices & Groups → [Device Name] → Activity Feed and look for any recent system update commands, policy pushes, or errors. This confirms whether Esper has already attempted to deliver the update.
If this doesn't resolve it
If your manufacturer has confirmed an OTA is available for your device model and region, your Blueprint's System Updates policy is correctly configured, and the device still has not updated after several days, contact Esper Support with the following information:
- Device serial number
- Esper Blueprint ID (visible under Devices & Groups → [Device Name] → Blueprint → Applied Blueprint)
- Current Esper Agent version (visible under Devices & Groups → [Device Name] → Device Info)
- Manufacturer's confirmation of OTA availability for your specific model and region (for example, a link to the release notes or update support page)
Still need help?
If you're still seeing unexpected behavior with OTA updates on your Esper-managed devices, please submit a support ticket and include your device model, Android OS version, and whether MDM control of OTA updates is enabled in your Esper console.
Please sign in to leave a comment.
Comments
0 comments