Patch Management Solution

 View Only
  • 1.  Patch applicability does not match installed client count.

    Posted Sep 23, 2014 09:04 PM

    We are aware that some bulletin applicability will never match the total count of manage PC.

    But for a particular bulletin, MS14-052 that is a patch for IE, all machines have IE installed by default.

    Total computer with agent is 1160 and applicable count is 700 +...

    Could someone enlighten us on this?

     

    Thanks!!!

     



  • 2.  RE: Patch applicability does not match installed client count.

    Posted Oct 08, 2014 03:40 PM

    Hello Marilou,

    I confirmed the MS14-052 was not Partially Superseded, and that is usually the cause for behavior such as this, for the newer update would cover vulnerabilities.

    The IsApplicable=TRUE is a conjunction of the Client's Patch Inventory, referenced against the Applicable Rule via PMImport, and the Client is placed in the 'Patch Filter' (intersect collection). The Compliance Reports pull directly from the same tables as the Patch Filter and display applicability accordingly.

    If your clients are not displaying as vulnerable to an update that is blatantly applicable; this could be caused by several issues.

    Here is the breakdown of how reports could be failing:

       1. PMImport is failing to update and replicate Assessment data to Clients.

       2. Client Patch Inventory is failing to return to the SMP.

       3. SMP is failing to process the Client Patch Inventory to the Database.

    These checks are detailed in KM: HOWTO60750 as part of the troubleshooting process.

    Although, the quickest way to check this would be to view the SMP > Reports > Software > Patch Management > Diagnostics > Windows System Assessment Scan Summary Report and see if the clients are all listed, and if they returned data recently.

    You may also RDP to a client that should be listed and review the Altiris Agent GUI > Software Updates Tab > Windows System Assessment Scan > Run History tab. Additionally, run the Windows System Assessment Scan now (as detailed in the article above) and view the Client Logs to see if there are any related errors.

    Unfortunately, there isn't a quick answer, for if the updates show vulnerable via Windows Update Tool, and the Patch Compliance Reports are not in line with that, digging is needed to find out why. It could be simple like Licensing, or it could be problematic like environmental GPO's are preventing agent processes / communications.

    Further digging may take Support Team assistance, but please let me know if you have any questions and I will be happy to help.

    Thank you,

    Joshua

     



  • 3.  RE: Patch applicability does not match installed client count.

    Posted Oct 08, 2014 09:50 PM

    Last time I have check the status of assessment scan result it's just 30-40 computers...

    I will check the NSE or any information that can be relevant to our issue.

    Thanks for your reponse Joshua.