How to push patches to a machine as soon as it logs in?
I would like to do this:
I have patches that are pushed overnight on a Thursda night. The patch is installed at 12 am and the reboot is scheduled for 3 am. Some of the users take their laptops home and end up missing the patches that night/morning. is there anyway to have patches pushed automatically to machines in the morning as soon as the machines log on to the network?
They should do this automatically
It is my understanding that if a system is in a collection to receive a task (patch) and it is not available at the time the task is scheduled to run then it should run the next time the system checks in.
How about the reboot?
It seems as if the the patch compliance for a certain machine will not be acknowledged unless the machine has also been rebooted. Is there a way to also make sure the machine reboots immedietly once it has received the patches?
Unfortunately, no
John,
Unfortunately (at least in Patch 6.2, not sure about 7.0 but I think the same holds true) it doesn't work this way. If you set your patch install time to 6:00 PM and the user shuts their machine down every day at 5:30PM, then it will never be patched. The solution to this is setting a recurring installation schedule (every 3 hours starting at 3:00 AM for 24 hours, etc). You could also try the "Wake on LAN" approach, but this has been found to be less than 100% reliable.
Thanks,
Kyle
Symantec Trusted Advisor
If your question has been resolved, please be sure to click "Mark as Solution"! Thank you.
You could create (assuming you are on v6)
a software update policy for the machines that are off, and set a different schedule for them. You could just not set them to reboot and remind them constantly to reboot.
Jim Harings
Technical Solutions Consultant
Xcend Group
http://xcendgroup.com
Reminding people to reboot has worked for us
Since we are unable to just reboot users workstations we set the policy not to reboot their computer and instead just nag them to reboot. From a user's perspective both are annoying but the nag is the lesser of two evils. We also have a schedule that runs twice a week, one in the begining of the week and one at the end of the week (Tuesday/Friday) that are set for every 4 hours.
The timing of your reminders is key
I like to run it a couple hours after lunch time once users are sleepy and calmer :) Then we remind them every 3 hours that an update has been installed and it is important they reboot the machine to ensure they are patched. One of the reminders shows up just prior to the time most people start leaving, otherwise they shut their PC down anyways. If they still haven't rebooted by the early a.m. then we force it. A message explains they are required to reboot (which menas they have ignored the reminder at least four times by now). For the 24/7 shops we have added the 15 minute pending message that counts down. This way the user has time to save their work if they truly are in the middle of something.
LOL
HAHAHAHAHA!
Thanks,
Kyle
Symantec Trusted Advisor
If your question has been resolved, please be sure to click "Mark as Solution"! Thank you.
Just after lunchtime?
Try doing a remote session with a user that only speaks
Spanish. Chat and Google Translate becomes your friend.
But all that aside, I have never had any problems with updates not getting pushed on next logon. It is automatic.
Would you like to reply?
Login or Register to post your comment.