Dear community,
We are introducing Controlled Updates for WithSecure Elements agents, giving you the ability to align agent updates with your own change and maintenance windows rather than receiving them as soon as they are published.
What is changing?
Until now, Elements agents have updated automatically as new versions became available. You can now choose the update mode per profile:
- Automatic Updates — devices receive new agent versions as they are released. This remains the default, and nothing changes for profiles you leave as they are.
- Controlled Updates — devices stay on an assigned release group until you upgrade them, or until that group expires.
Because the setting is applied per profile, you can mix modes across your estate — for example, keeping workstations on Automatic Updates while applying Controlled Updates to servers.
What to know before you start
- Security intelligence updates are not affected by this setting. They continue to be delivered to all devices regardless of the update mode you choose.
- This is not a way to postpone updates indefinitely. Devices are brought up to date automatically once their assigned release group expires.
- Controlled Updates is not supported alongside the Elements Connector.
- Available for Windows, macOS, and Linux Elements agents.
For release group schedules, configuration steps, and how to assign devices, see Controlled Updates in the user guide.
We believe this improvement will give administrators working under strict change control the predictability they need, without weakening the protection on the devices themselves.