Quantcast
Channel: Ivanti User Community : All Content - Patch Manager
Viewing all articles
Browse latest Browse all 1121

How to use Custom Groups to quickly bring a Computer up to date.

$
0
0

Problem:

I have several server groups that have different patching levels that are approved. Is there an easy way to bring a new server up to that level.


Solution:

You can use custom groups and a specific Scan and repair setting to bring new computers up to the approved level of patches. Below are the instructions on how to do this.

 

  1. Open the 32bit console.
  2. Click on Tools | Security and Compliance | Patch and Compliance
  3. Expand Groups
  4. Right click on Custom Group and click New Group.
    New Group.png
  5. Give the New Group an appropriate name related to a specific server group.
  6. Drag appropriate Vulnerabilities for this server group into the group. 
  7. Expand Settings.
  8. Right click on "Scan and Repair" and select New...
    SaR new.png
  9. Give the new Scan and Repair settings an appropriate name related to a specific server group.
  10. Click on Scan Tab.
  11. Click Group and Immediately Repair All Detected Items.
    Scan tab.png
  12. Click the ... button and then select the custom group.
    Group selection.png
  13. Click ok.
  14. Click the Repair tab.
  15. Check Start Repair even if reboot is already pending.
    Start repair.png
  16. Make any other changes to the Scan and repair settings as needed.
  17. Click ok.
  18. Click Create a task then security scan.
    Create a task security scan.png
  19. Give the new Security Scan an appropriate name related to a specific server group.
  20. Click Create as a policy or Scheduled tasks.
  21. Choose the Scan and Repair Setting created in step 9.
    Create security scan task.png
  22. Drag the query representing the computers you want at this level of patching into the task.
  23. Start the task according to the schedule that fits your environment.

 

 

Once this tasks has run and you make additions to the vulnerability in the group. Restarting the task will not automatically restart the task on all of the computers.

  1. Right click on the Scheduled task and choose properties.
  2. Click on Schedule task.
  3. Choose Start now or Start later.
  4. Under Schedule these devices, select All.
    Scheduled task all computers.png

 

This will rerun the security scan on all computers and install any additional patches that have been added to the group.


Viewing all articles
Browse latest Browse all 1121

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>