User guidePolicies

Automatic patching with policies

A policy patches a set of hosts in a maintenance window you choose, on every run, without anyone starting a job.

Create a policy

On Policies, choose New policy.

Targets

  • All devices, or Selected groups (make groups first on Device groups).
  • Narrow by OS family (optional): only Linux, Windows or macOS hosts.

What to patch

  • Only security, By severity (choose the Severities to patch; Unknown includes updates with no known CVE), or All updates.
  • Include third-party software: also update programs from vendor repositories, winget and Homebrew.
  • Major-version upgrades: Allow in the job, or Hold for deliberate approval so an update from, say, version 2 to 3 is listed but not installed.
  • Package exclusions: names or patterns, such as kernel*, that this policy never installs.

When

  • Weekly on chosen Days of week, Monthly on days, or Monthly weekday (for example the second Tuesday).
  • Start time, Time zone and Window minutes: hosts that have not picked up their run when the window closes skip it until the next one.

Reboot and approval

  • Reboot: Never or If required.
  • Approval: Automatic, or Manual inbox approval, where each run waits on Approvals for someone to approve its exact plan before the window closes. Organization admins and Security reviewers can approve.

Preview before it runs

The Live preview shows the hosts and packages the policy would install right now, and Held or excluded updates with the reason for each:

Reason Means
Never patched (policy exclusion) Matches the policy's exclusions
Held for review (major version) The policy holds major-version upgrades
Held on the host Pinned by the host's administrator
Intel Mac: Homebrew Homebrew no longer has ready-built packages for Intel Macs, so policies skip it; Patch now on the device can still install it

After a run

Each run appears on the policy's page and on Jobs, with its plan and results.