Patch Revert Troubleshooting
A patch job finishes in ServiceOps and shows Successful. The endpoint reboots as part of the job. After it comes back up and gets scanned again, the same patch shows as Missing or Failed - as if the install never happened. There is no error anywhere in the ServiceOps job history, which is normal for this issue.
Why This Happens
ServiceOps handles the scan, the download, and pushing the patch to the endpoint. It also starts the install. All of that finishes correctly, which is why the job shows as successful.
The reboot and the final install step happen at the OS level, not in ServiceOps. On Windows this is Windows Update servicing; on macOS or Linux it is the OS's own update process. If that step runs into a problem, the OS undoes the update on its own to keep the system working. ServiceOps has no visibility into that step, so nothing shows as failed on its side.
In short: the ServiceOps part of the job worked. The patch was removed afterward by the operating system.
Common Causes
- Damaged or inconsistent OS system files
- An earlier update that did not finish installing
- A driver that does not work with the new update
- Low disk space at the time of reboot
- A file that is locked or blocked by permissions during install
- Security software on the endpoint blocking the update
How to Fix It
Check the endpoint first. Look for unfinished updates, low disk space, or security software that might be interfering. Fixing these alone often solves the problem.
Run OS repair tools if you have them. Most operating systems have a built-in tool for fixing update problems. Run it, reboot once, and then move to the next step.
Push the patch again from ServiceOps. Once the endpoint is clean, redeploy the patch as usual.
If it still fails, collect logs and escalate. Gather the ServiceOps agent log from the endpoint and the OS update/event log from the time of the reboot, then send both to support.