Skip to main content
SolarWinds MSP
  • Login
  • Support
  • Partnerships
    • Partnerships Overview
    • Solution Provider Program
    • Technology Alliance Program
    • Distributor Program
SolarWinds MSP
  • Products
    • SolarWinds N-central Automate what you need. Tackle complex networks. Try this remote monitoring and management solution built to help maximize efficiency and scale.
    • SolarWinds RMM Start fast. Grow at your own pace. Try this powerful but simple remote monitoring and management solution.
    • SolarWinds EDR Defend against ransomware, zero-day attacks, and evolving online threats with Endpoint Detection and Response
    • SolarWinds Backup Manage data protection for servers, workstations applications, documents and Microsoft 365 from one SaaS dashboard.
    • Mail Protection & Archiving Protect users from email threats and downtime.
    • Password Management Easily adopt and demonstrate best practice password and documentation management workflows.
      • Passportal Demo
    • PSA & Ticketing Manage ticketing, reporting, and billing to increase helpdesk efficiency.
    • Remote Support Help support customers and their devices with remote support tools designed to be fast and powerful.
  • Solutions

    I'm looking for...

    • Security Solutions
    • Monitoring Solutions
    • Efficiency Solutions
  • Resources
    • Blog
    • Webcasts & Events
    • Ask the N-central Experts
    • Daily Live Demos
    • RMM Foundations Training
    • Upcoming Events
    • Upcoming Webcasts
    • Resource Center
    • COVID-19 Resources
    • Resource Library
      • Case Studies
      • Product Information
      • eBooks
      • White Papers
      • Infographics
    • SolarWinds MSP Free Tools
    • GDPR Resource Center
    • Security Resource Center
    • MSP Institute Webinar Series
    • MSP Advice Project
  • About
    • Contact
    • Customer Success
    • Worldwide sales and support
    • Careers
    • Awards and Recognition
    • Get A Quote
    • Newsroom
      • Press Releases
      • In The News
      • Media Contacts
      • COVID-19 Response
    • Leadership Team
    • Legal
      • Cookie Policy
      • Privacy Notice
      • Software Services Agreement
      • Terms of Use
      • Backup Fair Use Policy
    • Security
      • SolarWinds Security Statement
      • Vendor Data Protection Requirements
    • Support
  • IT Departments
  • Contact Sales
    • Get A Quote
    • General Inquiry
  • TRY NOW
    • SolarWinds RMM
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Passportal
    • SolarWinds N-central
    • SolarWinds Mail Assure
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
  • Request a Quote
  • Try Now
    • SolarWinds RMM
    • SolarWinds N-central
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Mail Assure
    • SolarWinds Passportal
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
Request quote
Filter Blogs
  • Filter by:
  • MSP Business
    • Automation
    • Backup & Disaster Recovery
    • Security-series
    • Best Practices
    • Business
    • Business Growth
    • Business Risk
    • Cloud Computing
    • Customer Service
    • Cybersecurity
    • Cybersecurity Awareness Month
    • Data
    • GDPR
    • Internet of Things
    • IT Support
    • ITSM
    • LOGICcards
    • Machine Learning
    • Mail
    • Managed Services
    • Marketing
    • Mobile
    • Networking
    • Operations
    • Podcast
    • Product
    • PSA
    • Remote Management
    • Research & Trends
    • Risk Intelligence
    • Security
    • Security Vlog
    • Service Desk
    • Services & Support
    • The Head Nerds
    • Tips & Advice
    • Training
Home Blog MSP Business Automation How to Decide When to Schedule Patching—Part Two
Automation

How to Decide When to Schedule Patching—Part Two

By Marc-Andre Tanguay
8 July, 2020

Continuing on our conversation from part one of this series, scheduling patching can be quite a challenge. To do it, you must handle a large number of different devices, juggle availability, comply with a range of policies, and balance securing the environment with keeping your customers happy. 

In this blog, we’ll cover the following elements of the patching process tasks and how to schedule them:

  • approving patches (manually or automatically)
  • installing patches
  • rebooting after patching

Approving patches 

CTA Image

SolarWinds Remote Monitoring and Management

Get the tools you need to manage, secure, and improve all things IT—all within a single web-based dashboard.

Try It Free Learn More

There are a variety of ways to approve patches. While it’s not often a scheduled process, here are some of the more common ways we see MSPs approve patches:

  • manually every day/week/month
  • automatically
  • automatically as they are detected, and the rest is manual
  • automatically with a delay (if your RMM allows it), and the rest is manual

Note: some ways to approve patches may or may not be available in your RMM platform, but the general idea is the same regardless of which platform you use.

Most customers I speak to say approving patches is cumbersome. No one has time to read up on each patch to determine if they want to install it or not. Furthermore, almost no one has time to test patches one by one. 

So what should you do? It’s common to approve all patches manually. If that works for you, then do it at least weekly due to the growing number of out-of-band patches Microsoft continues to release. I also recommend you automatically approve and automatically install definition updates for Microsoft Defender (the built-in free antivirus (AV) from Microsoft) in case your customer uses it.

If you want to approve some patches automatically (with or without delay), people typically automatically approve security and critical patches. You’ll likely need to approve those regardless, so you might as well save time and auto approve them. You can then review the rest manually.

Finally, some partners automatically approve everything. This can be aggressive but if it works for you, then great. 

Whether you approve patches manually or automatically, try to adhere to these three principles:

  • Don’t leave patches unapproved: approve, decline, or set them as ignored to ensure you have a clean report and dashboard
  • Do it often: check at least weekly—Wednesday is usually a good day as most patches come out on Tuesday
  • Write a standard procedure: a standard procedure allows anyone on your team to do the approval/declines reliably and consistently since the process remains the same

Installing patches

This is another one that has some misconceptions. Lots of people say they can only install patches at night on weekends, but when do you ever see a laptop turned on at night on a weekend? if you’re like me, your laptop is in a bag at home and turned off on Saturday night. 

Fortunately, today’s patch installations don’t behave the same as they used to. In the old days, we would see patches being disruptive, crashing programs as they replaced locked files, and generally causing harm in other ways. Recently, patches have become much more stable, almost always requiring a reboot later so the patch can install without disruption since it won’t take effect until the reboot happens. 

Because of this, I can recommend installing patches on desktops during the day. If your remote monitoring and management (RMM) solution supports it, you can run patches weekly on a day of your choice and set patches to patch the next time the device reboots in case it misses its window. You can install patches at 11:30 a.m. each day (around lunch time so as to minimize potential disruption), and have it installed later if the user is on the road or offline. 

If you’re not comfortable with that, or have to do it at a specific time, then follow your own process and procedure to ensure you’re able to install patches effectively and efficiently. 

Since servers are always open, patching them on the weekend is usually best. If you have servers in clusters, or in groups (like having two domain controllers) do one first. When it’s done and rebooted do the other one. This will minimize any downtime.

Rebooting

Rebooting is tricky as it will affect the user. In recent years, Microsoft has introduced things like fast boot and hibernation, which means users think they've rebooted their machines when they actually haven’t. Since most patches these days require reboots, the patch won’t take effect until the device fully reboots. This means the security vulnerability it patches will continue to be a vulnerability until a day or a week later (whenever the device reboots next). So it’s important to properly schedule patch reboots.

To counter this issue, you can schedule a forced reboot once a week at night if the devices are typically online. However, this doesn’t work very well in my experience. For that reason, I recommend a couple of other options. First, you can monitor how long it’s been since the last reboot and use an automated popup to remind the user to reboot. Alternatively, you can do a reboot during the day (either early morning, at lunch, or at the end of the user’s work day). Depending on your RMM’s capabilities, you can allow them to delay the reboot, see a popup warning (or not), or cancel it. 

As you can see, patching isn’t super complicated to schedule, but partners can do it in a variety of ways. Hopefully this break-down can help you think of how to do it within your own business or how to improve upon your current process. 

If you have any comments/question on this topic, or have created an automation policy and would like to share it with the community, please feel free to email me at [email protected].

As always, don’t forget to look in the Automation Cookbook at www.solarwindsmsp.com/cookbook if you’re interested in other automation policies, script checks, and custom services.

 

Marc-Andre Tanguay is head automation nerd. You can follow him on Twitter at @automation_nerd.

 

You might also like...
Automation

What the Head Nerds Were Up to in 2020

Automation

Motivating Your Team to Work on Automation

Automation

Is It Worth Automating? 

Automation

Should You Have an Automation Team? 

Automation

Introducing Cisco Meraki Monitoring for N-central

Automation

Monitoring Network Devices Using Automation in N-central

Want to stay up to date?

Get the latest MSP tips, tricks, and ideas sent to your inbox each week.

Loading form....

If the form does not load in a few seconds, it is probably because your browser is using Tracking Protection. This is either an Ad Blocker plug-in or your browser is in private mode. Please allow tracking on this page to request a subscription.

Note: Firefox users may see a shield icon to the left of the URL in the address bar. Click on this to disable tracking protection for this session/site

Recent Posts
  • What the Head Nerds Were Up to in 2020
  • RMM and PSA Tools: How to Make the Most of Both
  • How to Empower an IT Help Desk Team for Success
  • Six Tips That Will Make Managing Your MSP Company Easier
  • January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be
Categories:
  • Security (230)
  • Tips & Advice (122)
  • Best Practices (94)
  • Managed Services (86)
  • Backup & Disaster Recovery (83)
  • The Head Nerds (75)
  • Business Growth (75)
  • IT Support (42)
  • Business (39)
  • Automation (37)
  • Cybersecurity (37)
  • Operations (34)
  • Mail (33)
  • Remote Management (28)
  • ITSM (25)
  • Cloud Computing (21)
  • Networking (21)
  • Data (21)
  • Marketing (14)
  • Product (11)
  • PSA (11)
  • Service Desk (5)
  • Services & Support (5)
  • Mobile (4)
  • Risk Intelligence (4)
  • Internet of Things (3)
  • Customer Service (3)
  • Research & Trends (2)
  • Training (2)
  • GDPR (2)
  • Business Risk (1)
  • LOGICcards (1)
Show moreless
SolarWinds MSP

Products
  • SolarWinds RMM
  • SolarWinds N-central
  • SolarWinds Backup
  • SolarWinds EDR
  • SolarWinds MSP Manager
  • SolarWinds Mail Assure
  • SolarWinds Risk Intelligence
  • SolarWinds Take Control
  • SolarWinds Passportal
  • All Products Use Cases
Solutions
  • Security Solutions
  • Monitoring Solutions
  • Efficiency Solutions
  • Identify which RMM solution is right for me
  • Drive Efficiency with Automation
  • Manage my MSP Business More Efficiently
  • Manage my IT Department More Efficiently
  • Layered Security
  • Cross-Platform Support
  • Data-Driven Insights
About
  • About Us
  • Careers
  • Newsroom
  • Leadership Team
  • Upcoming Events
  • Subscription Preferences
  • SolarWinds
  • SolarWinds Trust Center
  • COVID-19 Response
Support
  • SolarWinds RMM
  • Solarwinds N-central
  • SolarWinds Backup
  • SolarWinds Mail Assure
  • SolarWinds Take Control
  • SolarWinds MSP Manager
  • Solarwinds Risk Intelligence
  • Solarwinds Threat Monitor
  • SolarWinds Passportal
  • SolarWinds Take Control Downloads
  • Backup & Recovery Downloads
  • Service Status

Footer 2

  • Legal Documents
  • Privacy
  • California Privacy Rights
  • Security Information
  • Sitemap

© SolarWinds MSP Canada ULC and SolarWinds MSP UK Ltd.
All Rights Reserved.