Automatic patching with policies
A policy patches a set of hosts in a maintenance window you choose, on every run, without anyone starting a job.
Create a policy
On Policies, choose New policy.
Targets
- All devices, or Selected groups (make groups first on Device groups).
- Narrow by OS family (optional): only Linux, Windows or macOS hosts.
What to patch
- Only security, By severity (choose the Severities to patch; Unknown includes updates with no known CVE), or All updates.
- Include third-party software: also update programs from vendor repositories, winget and Homebrew.
- Major-version upgrades: Allow in the job, or Hold for deliberate approval so an update from, say, version 2 to 3 is listed but not installed.
- Package exclusions: names or patterns, such as
kernel*, that this policy never installs.
When
- Weekly on chosen Days of week, Monthly on days, or Monthly weekday (for example the second Tuesday).
- Start time, Time zone and Window minutes: hosts that have not picked up their run when the window closes skip it until the next one.
Reboot and approval
- Reboot: Never or If required.
- Approval: Automatic, or Manual inbox approval, where each run waits on Approvals for someone to approve its exact plan before the window closes. Organization admins and Security reviewers can approve.
Preview before it runs
The Live preview shows the hosts and packages the policy would install right now, and Held or excluded updates with the reason for each:
| Reason | Means |
|---|---|
| Never patched (policy exclusion) | Matches the policy's exclusions |
| Held for review (major version) | The policy holds major-version upgrades |
| Held on the host | Pinned by the host's administrator |
| Intel Mac: Homebrew | Homebrew no longer has ready-built packages for Intel Macs, so policies skip it; Patch now on the device can still install it |
After a run
Each run appears on the policy's page and on Jobs, with its plan and results.