Patch management

Scan for missing OS and third-party patches, approve updates, and schedule maintenance windows.

Overview

Patch management in Xcellerate RMM covers both operating-system updates (Windows Update, apt/yum on Linux, softwareupdate on macOS) and third-party application patches. It gives you a centralised view of patch compliance across all endpoints and lets you approve, defer, or block individual updates.

Patching is policy-driven: you define patch policies at the group level that control which patches are auto-approved, when they are installed (maintenance windows), and whether endpoints should reboot automatically.

1,24798.2%
The patch compliance dashboard showing overall status and critical missing patches

Key concepts

  • Patch scan — the agent checks for available updates and reports them to the server. Default frequency: once per day.
  • Patch policy — rules that govern auto-approval, deferral periods, maintenance windows, and reboot behaviour. Attached to groups.
  • Approval status — each patch can be Auto-approved, Manually approved, Deferred, or Blocked.
  • Maintenance window — a recurring time slot during which the agent is allowed to install patches and reboot (e.g. Sundays 02:00–05:00).
  • Compliance score — the percentage of applicable patches that have been successfully installed on an endpoint or group.

Step-by-step walkthrough

1

Review the compliance dashboard

Go to Patch management → Dashboard. The top-level view shows overall compliance, a breakdown by severity (critical, important, moderate, low), and the number of endpoints pending reboot.

2

Create a patch policy

Navigate to Patch management → Policies → New policy. Name the policy, then configure: auto-approve critical patches after 3 days, auto-approve all others after 7 days, set a maintenance window, and enable auto-reboot with a 15-minute user warning.

3

Assign the policy to a group

Open the target group, go to the Policy tab, and select your new patch policy under the Patching section. Save.

4

Manually approve or block patches

Under Patch management → All patches, you can filter by severity, product, or status. Select one or more patches and click Approve, Defer, or Block.

5

Monitor installation progress

Go to Patch management → History to see a log of all patch installations: which endpoint, which patch, the result (success/failure), and the timestamp.

The patch policy editor with maintenance window configuration

Third-party patching

Xcellerate RMM includes a third-party patch catalogue covering 150+ popular applications (Adobe Reader, Java, Chrome, Firefox, Zoom, and more). Third-party patches follow the same approval and scheduling workflow as OS patches.

Third-party patch definitions are updated daily. Ensure your server has outbound internet access to download the latest catalogue.

Tips & best practices

  • Set a deferral period of at least 3–5 days for critical patches to catch regressions reported by the broader community.
  • Create separate maintenance windows for servers (off-peak hours) and workstations (lunch break or end of day).
  • Use the compliance report export to share patch status with clients or auditors.
  • Block known-problematic patches immediately and add a note explaining why — this helps future you (or your team) remember.
  • Combine patch management with Monitoring & alerting to get notified when compliance drops below a threshold.
Avoid enabling auto-reboot on servers without a maintenance window. Unexpected reboots can cause downtime for critical services.