Endpoint Scope and Computer Groups
Endpoints and Groups centralizes the management of patch deployment targets by defining endpoint scope and organizing computers into logical groups, enhancing control and simplifying IT operations.
This page allows you to effectively manage which computers are included in Patch Management operations and how they are organized for targeted deployments. It combines functionalities for configuring the Endpoint Scope and defining Computer Groups within a single, streamlined view.
To access this management page, navigate to Admin > Patch Management > Deployment Management > Endpoints and Groups.

- Endpoint Scope
- Computer Group
Endpoint Scope
Managing the Endpoint Scope is crucial as it defines the set of computers eligible for Patch Management, based on your licensing agreement. By default, all newly discovered computers with the ServiceOps Agent installed are outside the scope and must be explicitly brought into it before they can receive patches or packages.
On the Endpoint Scope tab, you can:
- View all available computers, indicating whether they are currently in or out of the Patch Management scope.
- Add individual computers to the scope or remove them, either one by one or in bulk.
- Configure conditions for automatic inclusion of new computers into the scope.
A counter to the left of the Add Computers button displays the number of available licenses and how many computers can still be added to the scope. The total number of computers managed cannot exceed your license limit.
Only computers that have the ServiceOps Agent application installed are visible and can be managed within the Endpoint Scope.
Adding Computers to the Endpoint Scope
To manually add computers to the Endpoint Scope:
- Click the Add Computers button. A popup window will appear, listing available agents.

- In the popup window:
- Use the search bar to find specific computers. The search supports keywords across Name, Hostname, IP Address, OS Name, and Service Pack.
- Select the desired computers from the list.
- Click Add to bring the selected computers into the Endpoint Scope.
Computer Groups
Computer Groups allow you to classify and organize your endpoints into logical collections, simplifying targeted patch deployment, policy enforcement, and reporting. Leveraging Computer Groups offers several key benefits:
- Targeted Deployments: Easily deploy patches or packages to specific departments or operational units by creating a corresponding Computer Group.
- Policy Exceptions: Define Decline Patch Configuration policies to exclude specific patches for a particular group of computers.
- Automated Testing: Utilize Computer Groups for Automatic Patch Tests, allowing you to validate patch efficacy on a subset of machines before broader deployment.
To manage Computer Groups, ensure you are on the Computer Group tab of the Endpoints and Groups page.

From here, you can create, edit, and delete Computer Groups.
Creating a Computer Group
To create a new Computer Group:
- Click the Create button on the list page. A configuration popup will appear.

- Enter the following details:
- Name: Enter a unique and descriptive name for your new Computer Group.
- Description: Provide a short description of the group's purpose or criteria.
- Add Computers: Add individual computers to this group. Click the Add Computers link to display a list of available agents (only those already in the Endpoint Scope are shown). Select the desired computers and click Add.


- Once all computers are added and details are filled, click Create. The new group will appear on the list page and can now be used for various patch management activities.