Skip to main content
SolarWinds MSP
  • Login
  • Support
  • Partnerships
    • Partnerships Overview
    • Solution Provider Program
    • Technology Alliance Program
    • Distributor Program
SolarWinds MSP
  • Products
    • SolarWinds N-central Automate what you need. Tackle complex networks. Try this remote monitoring and management solution built to help maximize efficiency and scale.
    • SolarWinds RMM Start fast. Grow at your own pace. Try this powerful but simple remote monitoring and management solution.
    • SolarWinds EDR Defend against ransomware, zero-day attacks, and evolving online threats with Endpoint Detection and Response
    • SolarWinds Backup Manage data protection for servers, workstations applications, documents and Microsoft 365 from one SaaS dashboard.
    • Mail Protection & Archiving Protect users from email threats and downtime.
    • Password Management Easily adopt and demonstrate best practice password and documentation management workflows.
      • Passportal Demo
    • PSA & Ticketing Manage ticketing, reporting, and billing to increase helpdesk efficiency.
    • Remote Support Help support customers and their devices with remote support tools designed to be fast and powerful.
  • Solutions

    I'm looking for...

    • Security Solutions
    • Monitoring Solutions
    • Efficiency Solutions
  • Resources
    • Blog
    • Webcasts & Events
    • Ask the N-central Experts
    • Daily Live Demos
    • RMM Foundations Training
    • Upcoming Events
    • Upcoming Webcasts
    • Resource Center
    • COVID-19 Resources
    • Resource Library
      • Case Studies
      • Product Information
      • eBooks
      • White Papers
      • Infographics
    • SolarWinds MSP Free Tools
    • GDPR Resource Center
    • Security Resource Center
    • MSP Institute Webinar Series
    • MSP Advice Project
  • About
    • Contact
    • Customer Success
    • Worldwide sales and support
    • Careers
    • Awards and Recognition
    • Get A Quote
    • Newsroom
      • Press Releases
      • In The News
      • Media Contacts
      • COVID-19 Response
    • Leadership Team
    • Legal
      • Cookie Policy
      • Privacy Notice
      • Software Services Agreement
      • Terms of Use
      • Backup Fair Use Policy
    • Security
      • SolarWinds Security Statement
      • Vendor Data Protection Requirements
    • Support
  • IT Departments
  • Contact Sales
    • Get A Quote
    • General Inquiry
  • TRY NOW
    • SolarWinds RMM
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Passportal
    • SolarWinds N-central
    • SolarWinds Mail Assure
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
  • Request a Quote
  • Try Now
    • SolarWinds RMM
    • SolarWinds N-central
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Mail Assure
    • SolarWinds Passportal
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
Request quote
Filter Blogs
  • Filter by:
  • MSP Business
    • Automation
    • Backup & Disaster Recovery
    • Security-series
    • Best Practices
    • Business
    • Business Growth
    • Business Risk
    • Cloud Computing
    • Customer Service
    • Cybersecurity
    • Cybersecurity Awareness Month
    • Data
    • GDPR
    • Internet of Things
    • IT Support
    • ITSM
    • LOGICcards
    • Machine Learning
    • Mail
    • Managed Services
    • Marketing
    • Mobile
    • Networking
    • Operations
    • Podcast
    • Product
    • PSA
    • Remote Management
    • Research & Trends
    • Risk Intelligence
    • Security
    • Security Vlog
    • Service Desk
    • Services & Support
    • The Head Nerds
    • Tips & Advice
    • Training
Home Blog MSP Business Automation Patching Automation Best Practices—Part One
Automation

Patching Automation Best Practices—Part One

By Marc-Andre Tanguay
29 April, 2020

This two-part blog series looks at some of the best practices for patching—combining what we usually recommend and what we see our successful partners doing. While this blog series looks at best practices for patching, if you’d like more specific information on how to implement them in your business, we’ll be releasing courses for SolarWinds® RMM and N-central® in the near future.

Windows updates are a staple for all managed services providers (MSPs). As a result, this process is often either very time consuming or easily overlooked. In either case, it can create issues for MSPs—but it doesn’t have to be a major pain point. 

In most remote monitoring and management (RMM) platforms patching is flexible, easy to use, and can be configured once for most or all devices (though the amount of time this takes may vary based on which RMM platform you use).

I’ve found that partners patch in different ways. Today, we’ll break the process into five main phases and document each separately:

  1. Finding new patches
  2. Approving patches for install
  3. Downloading the patches
  4. Installing the patches 
  5. Rebooting the computer 

We’ll cover the first three phases in part one of the blog series and cover phases four and five in part two. 

Finding new patches

CTA Image

SolarWinds Remote Monitoring and Management

Get the tools you need to manage, secure, and improve all things IT—all within a single web-based dashboard.

Try It Free Learn More

Detecting new patches is the first phase. Depending on your RMM tool, you may have the option to detect patches whenever you want based on a custom schedule, or you may be forced into a fixed schedule. 

Here are some of the things we typically see our partners do if they have the flexibility to customize it:

  • check several times per day (even hourly)
  • check daily
  • check a few times per week or weekly
  • check every month or quarter, whenever they intend to do them

Detection is something you may want to do on a different schedule depending on your needs and depending on devices. If we go back a few years, Windows XP and Windows 7 patch detection was fairly CPU intensive, so patching less frequently was preferable. From Windows 8, patch detection has become much more efficient, and usually not noticeable by the end user—so running it more frequently is not as much of an issue.

My personal recommendation is to detect daily on desktop and twice a week or daily on servers. Some people will say this is overkill. But with Microsoft releasing more and more updates outside the patch Tuesday schedule, a daily check will enable you to detect new patches as they come out. This also allows you to detect patches on devices that are not often online. 

Patch approvals

Approaches to approving patches vary widely. Here are some approaches we’ve seen:

  • Approve all patches by hand
  • Approve security and critical patches automatically and others manually
  • Approve all patches automatically

In any of the above scenarios, techs either decline drive updates, approve them, or approve some of them. 

Knowing this, it’s tricky to recommend a unique way to move forward. However, most people auto-approve critical and security updates and manually approve several other patches. While lots of MSPs decline drivers, I do not typically recommend this practice as drivers often contain very important security fixes. 

If your RMM supports it, you can choose to setup a delayed approval, which is also recommended. It means you can approve patches and install them a minimum of “X” days after discovering them. We recommend delaying approval on most devices. That way you let the early birds get patches on day one and report any bugs, giving Microsoft and third parties the time to pull the patch if it’s not working, and giving you time to manually decline it if desired. 

If you have a test group, the test group probably shouldn’t delay approvals so the updates install as quickly as possible. 

With manual approval, I often hear people approve them by hand. But upon deeper inspection, the same people simply approve everything—or almost everything—giving a false sense of control over the process. If that is what you do, you may want to consider auto approving some or all of them to save yourself the time of pressing the button to approve them.

I still recommend reading up on the updates each month from an industry expert like our security nerd Gill Langston to ensure you know what updates are coming out and what you may want to delay, install immediately, or decline.

Downloading the patches

Downloading patches is usually done ahead of time. Most RMM platforms support pre-downloading patches at a convenient time, either to the end device or to a central device to minimize bandwidth on the customer’s network.  

If your RMM supports it, use a central device (probe) to download the patches once per site. In recent years, some patches have been over 4GB, so caching them centrally can make a big difference on a site with 100 devices. 

Next, consider when you want to pre-download. Some RMMs will download as soon as they’re approved, but if your RMM supports scheduling, try to schedule during lower consumption time, like at night—which is usually outside backup windows and peak network usage.

While we’ve covered a lot of information, there’s still more best practices to go over so stay tuned for my next article. We’ll cover installing patches, rebooting the end devices, and monitoring and reporting on patches.

 

If you’ve created an automation policy and would like to share it with the community, please feel free to email me at [email protected]. 

As always, don’t forget to go look in the automation cookbook at www.solarwindsmsp.com/cookbook if you’re interested in other automation policies, script checks, and custom services.

 

Marc-Andre Tanguay is Head Automation Nerd. You can follow him on Twitter at @automation_nerd

 

Additional reading

What are your options when a patch goes wrong?
Patching Automation Best Practices—Part 2
How Do You Prioritize Your Customers’ Patches?
You might also like...
Automation

Motivating Your Team to Work on Automation

Automation

Is It Worth Automating? 

Automation

Should You Have an Automation Team? 

Automation

Introducing Cisco Meraki Monitoring for N-central

Automation

Monitoring Network Devices Using Automation in N-central

Automation

Do you need to learn PowerShell? And how should you learn it?

Want to stay up to date?

Get the latest MSP tips, tricks, and ideas sent to your inbox each week.

Loading form....

If the form does not load in a few seconds, it is probably because your browser is using Tracking Protection. This is either an Ad Blocker plug-in or your browser is in private mode. Please allow tracking on this page to request a subscription.

Note: Firefox users may see a shield icon to the left of the URL in the address bar. Click on this to disable tracking protection for this session/site

Recent Posts
  • January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be
  • TAP Blog Series: Maximizing Your Service Delivery Opportunity
  • Why Do MSPs Choose SolarWinds Backup? IT Central Station Finds Out
  • Seven Features Remote Assistance Software Should Have
  • TAP Blog Series: Creating Your Automation Strategy—Three Key Components You Must Have in Place
Categories:
  • Security (229)
  • Tips & Advice (122)
  • Best Practices (94)
  • Managed Services (86)
  • Backup & Disaster Recovery (82)
  • Business Growth (75)
  • The Head Nerds (74)
  • IT Support (41)
  • Business (39)
  • Cybersecurity (37)
  • Automation (36)
  • Mail (33)
  • Operations (33)
  • Remote Management (27)
  • ITSM (25)
  • Data (21)
  • Cloud Computing (21)
  • Networking (21)
  • Marketing (14)
  • Product (11)
  • PSA (10)
  • Services & Support (4)
  • Mobile (4)
  • Risk Intelligence (4)
  • Service Desk (4)
  • Internet of Things (3)
  • Customer Service (3)
  • GDPR (2)
  • Research & Trends (2)
  • Training (2)
  • Business Risk (1)
  • LOGICcards (1)
Show moreless
SolarWinds MSP

Products
  • SolarWinds RMM
  • SolarWinds N-central
  • SolarWinds Backup
  • SolarWinds EDR
  • SolarWinds MSP Manager
  • SolarWinds Mail Assure
  • SolarWinds Risk Intelligence
  • SolarWinds Take Control
  • SolarWinds Passportal
  • All Products Use Cases
Solutions
  • Security Solutions
  • Monitoring Solutions
  • Efficiency Solutions
  • Identify which RMM solution is right for me
  • Drive Efficiency with Automation
  • Manage my MSP Business More Efficiently
  • Manage my IT Department More Efficiently
  • Layered Security
  • Cross-Platform Support
  • Data-Driven Insights
About
  • About Us
  • Careers
  • Newsroom
  • Leadership Team
  • Upcoming Events
  • Subscription Preferences
  • SolarWinds
  • SolarWinds Trust Center
  • COVID-19 Response
Support
  • SolarWinds RMM
  • Solarwinds N-central
  • SolarWinds Backup
  • SolarWinds Mail Assure
  • SolarWinds Take Control
  • SolarWinds MSP Manager
  • Solarwinds Risk Intelligence
  • Solarwinds Threat Monitor
  • SolarWinds Passportal
  • SolarWinds Take Control Downloads
  • Backup & Recovery Downloads
  • Service Status

Footer 2

  • Legal Documents
  • Privacy
  • California Privacy Rights
  • Security Information
  • Sitemap

© SolarWinds MSP Canada ULC and SolarWinds MSP UK Ltd.
All Rights Reserved.