Patch and Update Management with Endpoint Central

To stay on top of the large number of patches released every day, you need an effective patch management software. Endpoint Central offers a fully automated patch management for Windows, Mac, Linux and third party applications (view the complete list of supported applications here) and large-scale distribution of app updates, across iOS, Android, tvOS and Chrome OS. The following features and capabilities give you granular control over the entire patch management process and enable you to keep your endpoints secure and up-to-date:

Patch management dashboard that gives you insights on your network in one go Patch-based view System based view: Allows you to identify Healthy, Vulnerable and highly vulnerable systems at a glance Deploy patches manually or schedule the deployment at off hours Deployment policies that give you granular control over patch deployment Test and approve patches before deployment: manually or automatically Set it and forget it: Automate the complete patch management lifecycle with comprehensive customization optionsNumerous pre-defined pach reports that can be scheduled, shared or downloaded easily

Updated Vulnerability Database

Patch Management Architecture

Zohocorp continuously probes the internet for newly released patches and vulnerabilities. Once a new patch is discovered, it is added to Zohocorp's Central Patch Repository after ample verification and testing. This repository can be accessed by Endpoint Central server installed within a client's environment and is used to evaluate vulnerabilities within the network.

On the client's site, Endpoint Central Server maintains a Vulnerability Database which is synced periodically with the Central Patch Repository. This sync is done in two ways:

  • Daily sync: The server syncs its vulnerability database with the central patch repository every day. You can configure the time at which this sync will take place.
  • On-demand Sync: The vulnerability database can be updated anytime by initiating an on-demand sync.

Third-party app and OS updates

Be it smartphones or laptops or desktops, it is vital to ensure both the OS and apps are running the latest version to ensure optimal security. However, manual updating is a tedious task as it is dependent on the user and might affect the productivity. Endpoint Central supports patching for 850+ third-party apps which can deployed silently over-the-air without any user intervention. It lets you schedule both app and OS updates in case of mobile devices as well as workstations.

System Health Policy

Patch Management Dashboard

Endpoint Central allows you to classify the health status of the systems within your network via the system health policy. You can specify the number of missing patches for which the systems should be classified as healthy, vulnerable and highly vulnerable. Based on this classification, you will be able to narrow down the systems that need immediate attention and take effective measures.

Automate Antivirus Updates

Endpoint Central also helps automate antivirus definition updates. Such updates are quite frequent and may happen several times a day which might result in high bandwidth consumption. To avoid it, you can schedule these updates once every day at a convenient time.

Disable Automatic Updates

You can disable automatic updates using Endpoint Central in just a few clicks. This enables you to have complete control over any updates that are installed within your network.

Automatically Test and Approve Patches before Deployment

It is always recommended to test patches before installing them on all the systems in your network to ensure that there is no downtime due to faulty patches. Using Endpoint Central, you can form test groups and automate installation of patches on test systems before rolling them out to the entire network. You can also specify the number of days after which the patches should be approved automatically for installation on the rest of the systems.

Decline Patches for Specific Applications

You can choose to decline patches for certain applications (legacy applications) or in case there's a patch that causes instability while it's installed on test systems. Endpoint Central allows you to decline non-severe patches as well as patches for a specific group of computers.

User-centric deployment policies

Schedule Patch Deployment

To avoid bandwidth issues and ensure system availability, system administrators can schedule the installation of patches on a convenient day and time by configuring a deployment policy. In the deployment policy, you can configure the week(s) and day(s) on which the deployment should take place, the time interval within which the patch should be installed, and the reboot policy. You can also allow the user to skip deployment. Endpoint Central has the capability to wake computers on LAN before deployment, if the computers are shut down at that moment. You can also create pre-deployment configurations to execute scripts before the patching is initiated as well as post-deployment scripts that need to run after the patch has been successfully deployed.

Automated Patch Deployment

Using Endpoint Central you can automate patch deployment every step of the way and save time, resources and effort. You can automate it for specific applications or departments within your network, on the desired day and time, at a convenient frequency. You only need to schedule it once, and the entire process will be automated and you will be notified at each step. Visit this web page to know more about this.

 

Patch Management using Mobile App

You can manage patches on the go with our mobile app. In just a few taps, you can install patches, approve/decline patches, view detailed patch reports, initiate patch scanning and much more! What's better is that you don't even have to do these tasks yourself, just ask Zia, Endpoint Central's IT Assistant, and she'll do them for you.