Approval by PolicyThe Approval by Policy page approves or denies the installation of Microsoft patches on managed machines by patch policy. Patches pending approval are considered denied until they are approved. This gives you the chance to test and verify a patch in your environment before the patch automatically pushes out. See Methods of Updating Patches, Configuring Patch Management, Patch Processing, Update Classification and Patch Failure for a general description of patch management. Setting Patch Approval Policies Patch policies contain all active patches for the purpose of approving or denying patches. An active patch is defined as a patch that has been reported by a patch scan by at least one machine in the VSA. Any machine can be made a member of one or more patch policies. For example, you can create a patch policy named
Superceded Patches A patch may be superceded and not need to be installed. See Superceded Patches for more information. Policy Select a patch policy by name from the drop-down list. Save As... Click Save As... to save the currently selected patch policy to a new policy with identical settings. All patch approval/denial statuses are copied as are the default approval statuses for the policy. Machine membership is not copied to the new policy. Copy Approval Statuses to Policy <Policy> / Copy Now Select a policy to copy approval statuses to, from the currently selected policy. Then click Copy Now. This enables you to perform patch testing against a group of test machines using a test policy. Once testing has been completed and the patches have been approved or denied, use the copy feature to copy only the approved or denied statuses from the test policy to a production policy. Policy View / Group By Display patch groups by classification or product. Patch Approval Policy Status This table displays the approval status of patches by update classification or product group. Approved, Denied, Pending Approval, and Totals statistics are provided for each update classification or product group. Select a Default Approval Status for any category for this patch policy. Newly identified patches for this patch policy are automatically set to this default value. Choices include:
Note: If the same patch is assigned two different Default Approval Status settings—one by update classification and the other by product group—then the more restrictive of the 2 defaults has precedence: Denied over Pending Approval over Approved. Click any link in this table to display a Patch Approval Policy Details page listing individual patches and their approval status. The list is filtered by the type of link clicked:
In the Patch Approval Policy Details page you can:
Override Default Approval Status with Denied for "Manual Install Only" updates in this policy If checked, all existing and future Override Default Approval Status with Denied for "Windows Update Web Site" updates in this policy If checked, all existing and future Note: Checking these two override checkboxes has a one-time effect on existing patches for these two categories of patches. If you approve an existing patch for one of these two categories after checking these boxes, the patch will remain approved regardless of the settings of these two checkboxes. Future patches will continue to default to denied. | |||
Topic 2173: Send Feedback. Download a PDF of this online book from the first topic in the table of contents. |