MDM Automate OS Updates vs Device Profile Restriction disallowing user to Update OS/Access firmware recovery

MDM Automate OS Updates vs Device Profile Restriction disallowing user to Update OS/Access firmware recovery

I've got several Android devices that have been set up within MDM to automate OS updates. However, the majority of these devices seem to be failing to actually update. I noticed that the device profiles I've set up for these devices restrict the user from updating their OS manually or accessing the firmware recovery (these two settings are tied together). Does the Automate OS Update feature fail due to the user restrictions set in the profile?