Home » Frequently Asked Questions (FAQ)
 

Frequently Asked Questions (FAQ)

Patch Detection and Deployment

What happens if Microsoft releases a faulty patch in the new distributed model? How can Endpoint Central remove it?
Is it possible to target specific device types, like laptops or desktops, for patch deployment?
Can I schedule reboots for servers and desktops after patch installation?
How can I be notified about zero-day patches availability for download to ensure timely deployment instead of having to wait for the scheduled policy?
How frequently should patch scans be scheduled, and can they be initiated manually?
How does the patch scan process work? Does it scan all computers simultaneously or one at a time?
Does the computer need to be logged into an admin account for patch deployment?
How to specify languages for patches?
What happens if a user accidentally turns off the computer while patches are being installed?
Is it possible to schedule patch installations followed by automatic reboot and shutdown?
How can we switch from WSUS to Endpoint Central for MS patch management?
How can I selectively deploy Mozilla updates to specific computers while excluding others?
How can I prevent individual computers from downloading patches directly from the internet, ensuring that all updates are sourced from the centralized patch management system?
Is there a way to configure the lists of computers, etc., to permanently display more than 25 at a time?
If I want to schedule patches to run in the next 20 minutes, is there a way to force the Endpoint Central agent on client machines to talk to the server, thus getting that task quicker than the 90-minute policy refresh? (Example - McAfee anti-virus has a feature called "wake up agent" that tells the agent to pull down fresh)
Is it possible to allow a Java update for compatibility with an application and preserve the legacy version for compatibility with another application?
What changes should I make in my firewall and proxy to patch computers?
How do you make a separate policy that is specifically for server OSs and does not automatically restart the server?
We currently use McAfee encryption on some of our devices. We are trying to figure out how to continue auto deployment after hours once everything is encrypted. Does Endpoint Central have a method of handling this?
How does the "wake and deploy" feature work for patching offline computers?
How come I have not seen updates for Windows 10 or MS 2016?
Can I use Endpoint Central to manage 3rd Party applications?
Why are dynamic custom groups not always available?
How to disable windows automatic updates?
How can we efficiently deploy patches to laptops that are infrequently connected to the domain via VPN, while minimizing user impact and avoiding firewall compromises?
Are all patches released by Microsoft available for patching via Endpoint Central?
What is the typical turnaround time for updating patches?
If you do the cleanup and then put a newer machine and it needs an older patch, what will happen?
How do I know which updates to run and the order to run them?
After the initial agent deployment, will patch scan subnets for new machines that do not have the agent going forward?
What is the process of disabling windows 10 creep update for Windows 7 computers?
How much disk space does a Distribution Server need to cache patches?
Can one Distribution Server support multiple remote offices?
Will the client devices be able to communicate with the main server if the Distribution Server is stopped?
Is it possible to deploy patches to specific computers?
How to identify servers from the Endpoint Central web console?
How to deploy Older version (6, 7) Java patches?
Can Endpoint Central limit the storage space used for downloading patches?
Can we make a single store for all MAC patches?
Should I update the vulnerability database before configuring patch deployments?
How can I host my Patch Repository on another computer?

Automatic Patch Deployment

The patch management solution that we are using currently tells us what we need to download, and then we manually download the patches. After the patches are deployed, we can remove the downloaded patches which we no longer need. But this is manually done. How does Endpoint Central handle this requirement?
Do we have the feasibility to split the scan & download from the patch deployment?
Can I receive notifications about the patches in the "Yet to apply" status after they have been deployed or failed to be installed?
How would I automatically download and deploy the latest flash updates as they are released?
Is there a feature for creating a test group of several computers to pilot patch deployments before rolling them out to the entire organization?
How does the feature of 'Test & Approve' of patches work? Is there an option for automatic approval or do each patch need to be approved manually?
When viewing the results of an Automated Patch Deployment task, is there a way to see the history of what patches were installed by the previous runs of this task?
Where can the Antivirus definition updates be deployed in Endpoint Central?
How can the status of the automated patch deployment tasks be monitored since it is not making a configuration deployment?
How do I approve patches in the 'Test & Approve' feature?
Is it possible to set the patch deployment policy schedule to run every 3rd Sunday of the month?
How can I schedule a patch scan during the day to identify missing patches and approve the patches for overnight deployment?
Will the APD task retry in subsequent deployments?

Office 365 Deployment

Where do the Office patches get downloaded, once the Click-to-Run settings are enabled?
How to enhance bandwidth usage while using Office Click-to-Run?
Can we use Cleanup Settings to delete the Office patches specifically, before 3 months?
Why is there a size mismatch between the office patch shown in the Endpoint Central console and the patch downloaded on the server?

Linux Patch Management

How to identify servers? Are all Linux machines considered servers?
Does Endpoint Central now patch Linux?

Patch Audit & Reports

Is there a feature to pull local logs of failed deployments from Endpoint Central?
Can I create a report for systems that need patches older than 30 days?

Integrations

Will the required patches be updated automatically by Tenable or do we need to configure Endpoint Central to extract the scan result?
Do we need to perform scanning after patching or will the data be automatically updated to Tenable after Endpoint Central patches the vulnerabilities?
Do we need to install both the Tenable and Endpoint Central agents on the systems for a successful integration?
Can I integrate Endpoint Central with Nessus?
How would patches be deployed to mitigate the vulnerabilities, post-integration?
How can I selectively integrate data from Tenable for a specific group of systems?
Why are certain vulnerabilities marked as Not Available in terms of Patch Availability?
Why are the imported vulnerability details fewer than the data present in Tenable?
How is InsightVM data imported into Endpoint Central?
How patches are corelated with the vulnerabilities in Endpoint Central?
Do we need to perform scanning post-patching or, or does Insight VM automatically receive updated data once Endpoint Central patches the vulnerabilities?
Why do certain assets managed in Insight VM not listed in Endpoint Central?
Why has the vulnerability not been remediated even after deploying the corresponding patch?
How can I integrate only a specific set of computers into Rapid7?
Why are certain vulnerabilities marked as Not Available in terms of Patch Availability?
Will Spotlight automatically update the required patches, or do we need to configure Endpoint Central to extract the scan results?
Do we need to perform a scan after patching, or will the data automatically update to Spotlight once Endpoint Central patches the vulnerabilities?
Is it necessary to install both the Spotlight and Endpoint Central agents on the systems for successful integration?
How are patches deployed to mitigate vulnerabilities after integration?
Why are certain vulnerabilities marked as Not Available in terms of Patch Availability?