Next Topic

Previous Topic

Book Contents

Configuring Patch Management

Analyzing Patch Status

You can determine the patch status of managed machines using the following pages:

  • Determine what patches are missing on managed machines using Scan Machine.
  • Display a summary view of installed, missing and denied patches for each managed machine using Patch Status.
  • Display a detailed view of patch scan results for each managed machine using Patch History.

Configuring Patch Management

Patch Management configuration options directly or indirectly affect the four Patch Management methods of installing patches as follows:

 

 

Initial Update

Automatic Update

Patch Update

Machine Update

Create/Delete

Create a patch policy.

 

 

Membership

Assign machine IDs to a patch policy.

 

 

Approval by Policy

Set patch approval policies.

 

 

Approval by Patch

Set patch approval policies.

 

 

KB Override

Overrides patch approval policies.

 

 

Pre/Post Procedure

Run procedures before or after Initial Update and Automatic Update.

 

 

Reboot Action

Change the reboot policy for machine IDs.

 

File Source

Change the file source location machines use to download patches.

Command Line

Change command line parameters for installing selected patches.

Patch Location

Change the download URL for patches.

Patch Alert

Configure alerts for patch-related events.

Office Source

Create an alternate source location for Office patches. A credential must be defined to use the Office Source page.

Note: Windows Auto Update enable or disables Windows Auto Update on managed machines regardless of whether patches are installed on machine IDs.