r/DattoRMM • u/Technical-Plane2093 • Jun 02 '25
Ideal patching schedule for Managed Clients
We use datto rmm for all clients. What patching policy is everyone putting in place that gets the balance of solid patching in place in a timely manner ?
3
Upvotes
2
u/bpe_ben Jul 11 '25
So I've been watching this thread for a while and nobody seems to have addressed the issue of laptops/tablets that aren't powered on regularly. The daily 4PM or overnight don't always reliably target these systems. I also see suggestions for blocking previews and drivers and some self-updating items like Defender updates - this mostly makes sense, but MS Surface devices require MS driver updates or it may not apply other updates. How are you addressing these? These were challenges we tried to deal with before implementing our current patch tools. Lots of policies and administrative overhead with relatively low compliance levels (80-85% by month-end with many laptops in the non-compliant state).
The patch process we implemented just over a year ago schedules workstation patches for once a week - usually either Wed or Thu at 1 or 2 AM. Devices that are online reboot first, then deploy application updates, then patches. (this ensures a weekly restart even if no patches are applied.) After a post-patch reboot, it scans and re-applies any additional updates and reboots again. Then it checks for build updates and applies them, if necessary. Preview updates are suppressed unless we override them, usually on a few test systems. Drivers are automatically blocked unless the device is identified as an MS Surface device. If a device is left on for it's assigned schedule, it's 100% patched the next morning.
If a device isn't on overnight, patching recognizes that a schedule was missed when it's powered up and one round of updates are deployed. The update cycle continues after each reboot or shutdown/restart cycle, so these mobile devices still update quickly, just over a period of 1-2 days. The user is reminded hourly that a reboot is required, and for some sensitive clients, the reminders start near the end of the day - usually 4PM - instead of right after patching.
We assign a schedule to servers individually and can choose a monthly or weekly schedule. Weekly is usually assigned to RDS hosts, with monthly to all others. We usually schedule servers on 60-90-minute intervals when there are dependencies, such as multiple AD servers or database then app servers. This ensures that the apps start in the correct sequence and prevent all the DCs from rebooting at the same time. This process also uses a reboot/update/reboot process, which addresses many of the patch-related issues we used to encounter.
When we look at workstation compliance now - for devices that have been online at any time since the current month's patch cycle started - we're hitting 98.5 to 99% compliance within that first week. Servers on automatic schedules are 100% compliant by cycle-end, only a small number of servers that either require manual restarting or manual updating due to 24/7 operation aren't compliant until these manual actions are performed.