Windows Patch Deployment


 

All the approved patches will be automatically deployed to the affected system based on the configuration. Patches can also be deployed on demand. The steps are detailed below.

 

ITAutomation-Patch-PatchDeploy.jpg

 

Patching selective systems only

This section is applicable when there are multiple affected systems which are missing the patch and you want to apply a patch to selected systems only.

 

ITAutomation-Patch-AffectedSys.jpg

 

ITAutomation-Patch-AffectedSysReboot1.jpg

ITAutomation-Patch-AffectedSysReboot2.jpg

ITAutomation-Patch-AffectedSysReboot3.jpg

 

ITAutomation-Patch-AffectedSysReboot4.jpg

 

 

Patching all systems

This section is applicable when you want to patch all affected systems with a patch.

 

ITAutomation-Patch-MissPatchDeploy1.jpg

ITAutomation-Patch-MissPatchDeploy2.jpg

ITAutomation-Patch-MissPatchDeploy3.jpg

 

 

Note: For Service Pack Updates, Roll-up and Cumulative Security Updates deployment, it is mandatory to restart the system.

 

Note.gifNotes:

1. Completed Patch management jobs are purged after 180 days irrespective of the job status of patch management jobs. To change the default setting of 180 days, change the global settings variable 'Purging interval for patch management jobs'

2. Purged jobs can be viewed as archived reports in 'Automation Summary Reports', 'Automation Analytical Reports', 'Patch Summary Reports' and 'Patch Analytical Reports'. For more information, refer Reports > IT Automation Reports

3. Retry Count and Retry Interval will assume default values of 3 and 3 minutes respectively when 'On-Demand' patch deployment is selected.

 

Patch Download Retry Count

You can set the maximum download retry count for missing patches by defining a value for Global Settings variable 'Patch Download Retries Max count'. Once the maximum retry count is exceeded click on the red 'Reset Download Count' icon and reset the count to 0.

 

reset_download_count.gif

 

Patch Deployment Status and Patch Redeploy

 ITAutomation-Patch-DeployStatusList.jpg

 

 

  Sr. No

Deploy Status

   Description

     1

Patch deployment job is posted

 

Patch download job posted to download a particular patch from internet to SapphireIMS server

     2

Patch download in progress

 

Patch download from internet to SapphireIMS server is in progress

     3

Patch download is completed

 

   Patch is downloaded from internet to SapphireIMS server

     4

Master Agent started download

 

Master/Standalone agent started downloading patch from SapphireIMS server

    5

Master Agent download success

 

Master/Standalone agent successfully downloaded the patch from SapphireIMS sever

    6

Patch deploy job is posted

 

   Deployment job is posted

    7

Another deploy is in progress. Please wait

 

For that machine, another deployment job in progress.

    8

Copying the Patch to the Target Machine

 

File copy from SapphireIMS server to agent-less target machine in progress. It includes

1. Wsusscn2.cab

2. Patch file(s) to be deployed

3. SappWUADeploy.exe

 

   9

Patch deploy started

 

Agent started processing the deployment of particular patch

  10

Patch deploy completed successfully

 

Patch deployment completed without error

  11

Patch deploy completed. System needs restart

 

Deployment success. Target machine needs to be restarted so that the installed patch comes into effect.

After target machine restart, if inventory is collected, the status is updated automatically to " Patch deploy completed successfully." and Reboot column is changed to "Machine rebooted".

 

   12

Patch deploy failed

Failure during Patch Deployment

   13

Unknown error

Once deployment is completed, patch scan is performed. Sometimes, during this process the patch which is installed is  shown as missing.

 

   14

Patch is not applicable due to previous service pack installation or update roll-up installation or corresponding software is removed from the machine

 

This happens when patch deployment is posted for several patches, but due to service pack/update roll-up installation the patch is neither missing nor installed.

This may also happen when the corresponding software is uninstalled after posting a deployment job and before completion of deployment

 

 

The status will be checked and updated after 15 minutes from the time the patch is sent for deployment to the target system. Status of Service Packs and product related updates will be updated during the next scan cycle and so the status will be shown as ‘In Progress’ until then.

 

Note.gifNotes: 1. When posting Redeploy for failed patches, reboot reminder option will not work.