Skip to main content
Cloud / Azure / Products / Device Update for IoT Hub - Over-the-Air Updates for IoT Devices

Device Update for IoT Hub - Over-the-Air Updates for IoT Devices

Device Update for Azure IoT Hub deploys over-the-air updates to IoT devices with group management, gradual rollouts, A/B rollback and compliance reporting.

internet-of-things
Pricing Model Used together with Azure IoT Hub; terms per vendor / see official documentation
Availability Cloud-hosted service; regional availability per vendor / see official documentation
Data Sovereignty Update files are uploaded to an Azure Storage container; region depends on your configuration
Reliability SLA per vendor / see the official SLA page SLA

What is Device Update for IoT Hub?

Azure Device Update for IoT Hub is a service that enables you to deploy over-the-air updates for your IoT devices in a cloud-based IoT solution. It is an end-to-end platform for publishing, distributing and managing over-the-air updates for everything from tiny sensors to gateway-level devices. It lets you operate, maintain and update devices at scale, for example to respond rapidly to security threats or roll out new features.

Device Update integrates closely with Azure IoT Hub, making it easy to adopt on any existing IoT Hub-based solution, including Azure IoT Edge devices. The service builds on Microsoft Azure’s cloud-to-edge security and the proven reliability of the Windows Update platform, so you don’t need to configure the security mechanisms yourself.

Core Features

Package-based and image-based updates: Package-based updates target a specific component or application; image-based updates update an entire OS partition.

Management and reporting: Update management integrated with Azure IoT Hub, programmatic APIs for automation and custom portals, subscription- and role-based access controls, and at-a-glance compliance and status views across heterogeneous device fleets. Azure CLI supports creating and managing Device Update resources, groups and deployments.

Gradual rollouts: Device grouping and update scheduling enable step-by-step rollouts. Resilient A/B updates deliver seamless rollback, complemented by automatic rollback to a fallback version.

Delta updates (public preview): Generate smaller updates that contain only the changes between the current and the target image.

Offline and edge scenarios: On-premises content cache and nested edge support enable updating cloud-disconnected devices.

Typical Use Cases

Security patches in the field: Rapid response to security threats across the entire device fleet.

Feature rollouts: New capabilities reach devices without physical access.

Heterogeneous fleets: Compliance and status views across different device types.

Industrial edge environments: Updating IoT Edge and nested edge devices, even with limited cloud connectivity.

Benefits

  • End-to-end platform for publishing, distributing and managing updates
  • No need to build your own update platform, reducing development and maintenance effort
  • Automatic device grouping through compatibility properties and device twin tags
  • Rollback mechanisms and per-device failure details reduce the risk of field updates
  • Broad platform support through Linux agents, Eclipse ThreadX samples and open-source agent code

Integration with innFactory

As a Microsoft Solutions Partner, innFactory supports you in building update processes for IoT fleets: choosing between package-based and image-based updates, building the import pipeline, defining group and rollout strategy, and integrating with existing IoT Hub and IoT Edge solutions.

Contact us for a no-obligation consultation on Device Update for IoT Hub.

Typical Use Cases

Rapid response to security threats across large device fleets
Rolling out new features to IoT devices in the field
Gradual rollouts across device groups with update scheduling
Updating Azure IoT Edge devices from an existing IoT Hub solution
Updating cloud-disconnected devices via on-premises content cache and nested edge

Technical Specifications

0th Two update forms: package-based updates for a specific component or application, and image-based updates for an entire OS partition
1st Agent integration with download, install and apply phases; status reported through IoT Hub device twin properties
2nd Import via an import manifest and upload to an Azure Storage container, then import through the Azure portal or the Device Update REST API
3rd Device groups based on compatibility properties and device twin tags
4th Resilient device updates (A/B) with seamless rollback and automatic rollback to a defined fallback version
5th Delta updates (public preview) generate smaller updates representing only the changes between the current and target image
6th Agents for various Linux operating systems, Eclipse ThreadX samples co-developed with semiconductor partners, plus a Raspberry Pi reference Yocto image and an agent simulator
7th Works with IoT Plug and Play; management through the Azure portal, Azure CLI and programmatic APIs
8th Sensitive update content can be protected with shared access signatures (SAS) for Azure Blob Storage

Frequently Asked Questions

Which update types does Device Update for IoT Hub support?

The service supports package-based and image-based updates. Package-based updates target only a specific device component or application and consume less bandwidth and time. Image-based updates provide a high level of confidence in the device end state, for example in A/B failover models.

Are delta updates generally available?

No. Microsoft documents delta updates as public preview. They allow you to generate smaller updates representing only the changes between the current image and target image, reducing bandwidth and download time.

Which devices and operating systems are supported?

Device Update is a cloud-hosted solution that, through its integration with Azure IoT Hub, can connect virtually any IoT Hub device including Azure IoT Edge. Agents are provided for various Linux operating systems. For Eclipse ThreadX, samples co-developed with STMicroelectronics, NXP, Renesas and Microchip are available. The agent is open source and can be ported to other distributions.

How are rollouts controlled?

Devices can be grouped based on compatibility properties and device twin tags. Rollouts happen gradually with update scheduling, typically starting with a test group. Deployment status is visible and deployments can be cancelled at any time.

What happens when an update fails?

Device Update supports resilient device updates (A/B) to deliver seamless rollback, plus automatic rollback to a defined fallback version for managed devices that meet the rollback criteria. Per-device failure details support root cause analysis, and agent check and device sync are available as troubleshooting features.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Device Update for IoT Hub - Over-the-Air Updates for IoT Devices?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation