Skip to main content

Patch Control

Patch Control streamlines patch management by centralizing patch approval and exclusion rules, enhancing security and operational efficiency.

Patch Control allows you to define rules for approving patches for deployment and excluding specific patches or applications from being deployed across your IT assets. This ensures systematic patch management, aligning with your organizational policies and minimizing security risks.

To view the Patch Control page, navigate to Admin > Patch Management > Patch Administration > Patch Control.

Patch Control page

The Patch Control page provides two main tabs: Approval Policy and Decline Policy.

Approval Policy

This tab enables you to set the approval policy for patch deployment.

Approval Policy

  1. Pre-Approved: All incoming patches (both new and missing) are Pre-Approved by default. A user can manually change the Approval status of a patch to Reject or Approved. The Automatic Patch Test fails to function with this selection. This selection comes into effect for incoming future patches, while it remains ineffective on already existing patches in the product.
note

By default, the Definition Updates Patches will always be pre-approved.

  1. Manually Approve: All new incoming patches have the Approval status Not Approved by default. A user has to change the status manually to either Approved or Reject.
  2. Test and Approve: All new incoming patches have the status Not Approved by default. You can manually set the status. Also, you can create a Test Task. Once enabled, select the Time when the patch is to be tested and approved. A Test Task, also known as Automatic Patch Test, deploys a selected set of patches to a specific set of computers. If deployment is successful in all the computers, the patches are auto-approved after a set number of days. Test Task only works in this setting.

Select an approval policy type and click Update.

Define policies and manage deployment targets for patches. For details, see Deployment Management