Windows Third Party Patch Management


 

This topic describes Third Party Patch Management (TPPM) for Windows systems.

Note.gifNote: In the case of Linux, Application patch management is similar to OS Patch management and the patches can be managed under Linux by selecting 'OS Patches' in the 'Patch Type' field in the Linux Patch Management screens,

In the case of Windows SapphireIMS uses software catalogs hosted by Chocolatey to reconcile and identify missing patches.

The steps are similar to Windows Patch Management and include patch scanning, getting the missing patches and deploying them.

 

Patch Scan

ITAutomation-Patch-WinTPScan.jpg

  Serial No

Scan Result

      Description

     1

New patch scan job is posted

 

  The patch scan job has been posted through scheduled scanning or through on-demand scan

     2

Patch scan started

The patch scan job processing is started

     3

Job completed successfully

 

Patch scan job is successfully completed

     4

Job processing aborted as the machine did not respond in stipulated days

 

If the patch scan job is posted and the machine does not respond in the stipulated job purge interval (default 3 days), then the job will get  purged and the status is updated

    5

Ping Failed

 When the target node scanned is down. Target node will automatically be scanned when it comes up

    6

Unable to retrieve Agent Information

 

This arises when the target agent version is not up to date or the scanned system is behind a firewall

ITAutomation-Patch-WinTPScanMiss.jpg

 

 

Missing Patches Approval

After the patch scan is done, the list of missing patches are displayed for approval.

ITAutomation-Patch-WinTPMissAppList.jpg

 

Patch Deployment

ITAutomation-Patch-WinTPMissDeploy.jpg

 

Patch Deployment Status and Patch Redeploy

 ITAutomation-Patch-WinTPDeplyStatus.jpg

 

 

  Sr. No

Deploy Status

   Description

     1

Patch deployment job is posted

 

Patch download job posted to download a particular patch from internet to SapphireIMS server

     2

Patch download in progress

 

Patch download from internet to SapphireIMS server is in progress

     3

Patch download is completed

 

   Patch is downloaded from internet to SapphireIMS server

     4

Master Agent started download

 

Master/Standalone agent started downloading patch from SapphireIMS server

    5

Master Agent download success

 

Master/Standalone agent successfully downloaded the patch from SapphireIMS sever

    6

Patch deploy job is posted

 

   Deployment job is posted

    7

Another deploy is in progress. Please wait

 

For that machine, another deployment job in progress.

   8

Patch deploy started

 

Agent started processing the deployment of particular patch

   9

Patch deploy completed successfully

 

Patch deployment completed without error

  10

Patch deploy completed. System needs restart

 

Deployment success. Target machine needs to be restarted so that the installed patch comes into effect.

After target machine restart, if inventory is collected, the status is updated automatically to " Patch deploy completed successfully." and Reboot column is changed to "Machine rebooted".

 

  11

Patch deploy failed

Failure during Patch Deployment

  12

Unknown error

Once deployment is completed, patch scan is performed. Sometimes, during this process the patch which is installed is  shown as missing.

 

  13

Patch is not applicable due to previous service pack installation or update roll-up installation or corresponding software is removed from the machine

 

This happens when patch deployment is posted for several patches, but due to service pack/update roll-up installation the patch is neither missing nor installed.

This may also happen when the corresponding software is uninstalled after posting a deployment job and before completion of deployment