User guidePolicies

Automatic patching with policies

A policy patches a set of hosts in a maintenance window you choose, on every run, without anyone starting a job.

Create a policy

On Policies, choose New policy.

Targets

  • All devices, or Selected groups (make groups first on Device groups).
  • Narrow by OS family (optional): only Linux, Windows or macOS hosts.

What to patch

  • Only security, By severity (choose the Severities to patch; Unknown includes updates with no known CVE), or All updates.
  • Include third-party software: also update programs, not only the operating system.
  • Major-version upgrades: Allow in the job, or Hold for deliberate approval so an update from, say, version 2 to 3 is listed but not installed.
  • Package exclusions: names or patterns, such as kernel*, that this policy never installs.

When

  • Weekly on chosen Days of week, Monthly on days, or Monthly weekday (for example the second Tuesday).
  • Start time, Time zone and Window minutes: hosts that have not picked up their run when the window closes skip it until the next one.

Rollout

Leave Roll out in stages off to patch every targeted host in the same window. Turn it on to try updates on a few hosts first:

  1. Add ring for each group, in order, with its After days: for example a pilot group after 0 days, then early adopters after 2 days.
  2. Optionally include Every other device with its own days, for all remaining targeted hosts. A host in none of the rings' groups goes with the last ring.

An update reaches each ring once its version has been out that many days. If it fails to install on any host of an earlier ring, later rings wait until it installs there. A policy can have up to five rings.

Reboot and approval

  • Reboot: Never or If required.
  • Approval: Automatic, or Manual inbox approval, where each run waits on Approvals for someone to approve its exact plan before the window closes. Organization admins and Security reviewers can approve.

Preview before it runs

The Live preview shows the hosts and packages the policy would install right now, and Held or excluded updates with the reason for each:

Reason Means
Never patched (policy exclusion) Matches the policy's exclusions
Held for review (major version) The policy holds major-version upgrades
Held on the host Pinned by the host's administrator
Waiting for its ring The policy rolls out in stages and this host's ring is not due yet; the date it installs from is shown
Halted after a failure It failed on a host in an earlier ring in the last 7 days; it continues once it installs there
Intel Mac: Homebrew Homebrew no longer has ready-built packages for Intel Macs, so policies skip it; Patch now on the device can still install it

After a run

Each run appears on the policy's page and on Jobs, with its plan and results.

Automatic patching with policies | RemediForge