Login to participate
Endpoint Management & Virtualization IdeasRSS
2

Automatically Staged Patch Management

Clint's picture

I'm running Patch Management Solution 6.x and think it'd be cool if there was some automatic mechanism to stage then deploy the patches on different schedules to different collections.  For awhile now, per our internal desktop patch management agreement, I've been testing the updates on 2 or 3 of my PCs when Microsoft's "Patch Tuesday" rolls around and if I don't encounter any problems, I'll deploy to desktops in just my department (IT) a week later (i.e. the 3rd Tuesday of the month).  If I get no complaints from my staff, I'll then change the s/w update tasks' target collections to the default "All Computers with Software Update Agent Installed" on the 4th Tuesday of the month to hit everyone.

Again, it would be really nice if this could all be automated as well as what updates are deployed based upon a chosen severity level (e.g. push all updates, just critical/important ones, or combinations thereof).  Naturally if my fellow IT co-workers discover an application compability issue with one or more of the patches on my 3rd Tuesday deployment, I should be able to make adjustments to either cancel the widespread deployment of the update(s) in question on the 4th Tuesday or modify the target collection to exclude a particular department or collection whose machines would be adversely affected by the patch(es).