# Patch Management FAQ **Last Updated On:** 05 Aug 2026 **72 minutes read** ## Patch Detection and Deployment ### How can we perform patch deployment using Vulnerability Manager Plus? You can deploy a patch either [manually](https://www.manageengine.com/vulnerability-management/help/patch-management/manual-deployment.html) or using an [automated patch deployment task](https://www.manageengine.com/vulnerability-management/help/patch-management/apd.html). ### What happens if Microsoft releases a faulty patch in the new distributed model? How can Vulnerability Manager Plus remove it? It is recommended to use the "Test and Approve" feature, which can test the patches on lab machines and then approve them automatically before deployment. We also have the patch removal/roll back option, which can be used to handle these situations. ### How can I add patches for applications that aren't supported by the product? To add patches for applications that aren't supported by the product, please fill out the [feature request form](https://www.manageengine.com/products/desktop-central/need-features.html). This will allow us to understand your needs and potentially incorporate support for those applications in future updates. Your feedback is valuable in helping us enhance our offerings to better serve your needs. ### Is it possible to target specific device types, like laptops or desktops, for patch deployment? Yes, the target machines can be defined based on system type, such as laptops and desktops. A custom group can also be created with system type as criteria. ### Can I schedule reboots for servers and desktops after patch installation? We do support reboot scheduling in deployment policy with "Reboot Window/ Specify Reboot Time" for Force Reboot. ### Can we create a restore point before deploying a Windows update? Yes. It is possible by configuring a pre-deployment script in the deployment policy to create a restore point before deploying the Windows update. - Create a script that generates a system restore point on the target Windows device. - Add that script to the product and select it under the Deployment Policy as a pre-deployment script. - Test the policy on a pilot group first, verify restore point creation, and then roll it out to the wider environment. ### How can I be notified about zero-day patches availability for download to ensure timely deployment instead of having to wait for the scheduled policy? You can create an Automated Patch Deployment task to deploy patches with critical severity, including zero-day patches. Set the deployment policy timeframe to "as soon as possible". ### How does the patch scan process work? Does it scan all computers simultaneously or one at a time? Scanning will be initiated incrementally in order to avoid bandwidth bottlenecks. ### Will an automatic scan overburden the server with multiple requests? Will it choke the network traffic? Definitely not. The scan happens right after the database is synced. Every time the scan happens, the latest missing patches are detected and downloaded onto the server. We employ this effective mechanism of posting only the diff scan data (difference in the scan data between two consecutive scans), so it will not overburden the server. Also, it will not affect network traffic, since we don't initiate an on-demand scan from the server. ### Does the computer need to be logged into an admin account for patch deployment? No, as the agent installed in the managed computers would have the privilege to install the patches, the regular user account can be used for patch deployment. ### How to specify languages for patches? Vulnerability Manager Plus will automatically detect the language based on the operating system. ### What happens if a user accidentally turns off the computer while patches are being installed? Vulnerability Manager Plus will retry to install the patch during the subsequent deployment window, and the installation status will be updated. ### Is it possible to schedule patch installations followed by automatic reboot and shutdown? You can configure the Deployment Policy to schedule patch installation, as well as reboot or shutdown tasks, within pre- or post-deployment activities. ### How can we switch from WSUS to Vulnerability Manager Plus for MS patch management? You can disable auto-updates from WSUS and install Vulnerability Manager Plus agent on the computers to be managed, scan the computers and start deploying the patches. To know how to disable automatic updates, refer to [this page](https://www.manageengine.com/products/desktop-central/how-to/patch-management/disable-automatic-updates.html). ### How can I selectively deploy Mozilla updates to specific computers while excluding others? You can create a custom group with the computers that you wanted to exclude. Decline the application by navigating to Threats & Patches → Settings → Decline Patch → Decline Patch for Group and specifying the application. ### How can I prevent individual computers from downloading patches directly from the internet, ensuring that all updates are sourced from the centralized patch management system? You can see the "Installed Time", against the patch, if it is installed using Vulnerability Manager Plus. If you do not find the "Installed Time", then it could be patched using automatic updates. In such cases, you will have to disable auto-updates from Configurations → Script Repository → Templates tab → Search for AutomaticUpdates.exe → add to repository. Create a configuration, select the target computers, and deploy it. To know how to disable automatic updates, refer to [this page](https://www.manageengine.com/products/desktop-central/how-to/patch-management/disable-automatic-updates.html). ### Is there a way to configure the lists of computers, etc., to permanently display more than 25 at a time? You can customize the count of computers displayed. The changes you make will persist only for the technician and the view. ### If I want to schedule patches to run in the next 20 minutes, is there a way to force the Vulnerability Manager Plus agent on client machines to talk to the server, thus getting that task quicker than the 90-minute policy refresh? You can achieve this by using the "Deploy Immediately" option when you deploy a patch configuration. This will wake up the target computer on-demand to perform the task initiated by Vulnerability Manager Plus. ### Is it possible to allow a Java update for compatibility with an application and preserve the legacy version for compatibility with another application? You can create a dynamic custom group and choose to decline the patches for the specific application like JRE. By doing this, you can maintain multiple versions of the JRE in your network. ### What changes should I make in my firewall and proxy to patch computers? [Refer to this article](https://www.manageengine.com/products/desktop-central/kb/vmdr/patch-download-failure-error-403.html) to find the list of domains, which need to be excluded. ### How do you make a separate policy that is specifically for server OSs and does not automatically restart the server? This can be achieved by configuring the deployment policy and excluding servers from reboot. Navigate to Threats & Patches → Deployment → Deployment Policies → Create Policy → Deployment Window → Reboot Policy → Exclude Servers from Reboot. ### We currently use McAfee encryption on some of our devices. How to continue auto deployment after hours once everything is encrypted? This can be achieved by configuring the deployment to happen after the encryption time window. You can configure it from Threats & Patches → Deployment → Deployment Policies → Create Policy → Deployment Schedule. ### How does the "wake and deploy" feature work for patching offline computers? You can wake up the computers and deploy the patches by configuring Threats & Patches → Deployment → Deployment Policies → Create Policy → Pre-deployment Activities → Wake-on LAN. ### How to identify servers from the Vulnerability Manager Plus web console? Navigate to Agent → Computers in the console interface. Create a filter for Operating System with tags "server" and "Oracle". The Red Hat Enterprise Linux OS server machines cannot be identified using the web console as its subscription has to be checked. ![identify servers](https://cdn.manageengine.com/products/desktop-central/images/identify-servers.png) ### How to deploy Older version (6, 7) Java patches? To deploy Older version (6,7) Java patches, [refer to this page](https://pitstop.manageengine.com/portal/en/community/topic/workaround-for-java-6-7-patch-download-failure-29-5-2017-1). ### How to resolve patch deployment issues? For resolving patch deployment issues, refer to [this page](https://www.manageengine.com/vulnerability-management/help/patch-management/patch-deployment-troubleshooting.html). ## Automatic Patch Deployment ### How does Vulnerability Manager Plus handle automated download and cleanup of patches? Vulnerability Manager Plus allows you to automate the complete process. You can create an APD task, which will automatically scan computers, detect missing patches, automatically download the required patches and deploy it to the target computers. You can configure the "Cleanup Settings" to delete the unwanted patches automatically. ### Is there a feature for creating a test group to pilot patch deployments? Yes, you can use the Test & Approve feature to create a test group of computers and pilot patch deployments before rolling them out to the entire organization. You can configure automatic approval after a specified period if no issues are detected, or manually approve the patches based on test results. ### Is it possible to set the patch deployment policy schedule to run every 3rd Sunday of the month? Yes, when you create a Deployment Policy, under Scheduler Settings, select Monthly option and choose 3rd Sunday. ## BIOS and Driver Updates ### Are Lenovo BIOS updates available for patching? No. Only the mentioned Drivers and BIOS in [this page](https://www.manageengine.com/vulnerability-management/help/patch-management/biosdriverupdates.html#sdb) are supported by Vulnerability Manager Plus for patching. ## Microsoft 365 Deployment ### Why does a 404 error occur when downloading Microsoft Office patches? The 404 error occurs when customers try to download superseded patches i.e. old patches or patches removed/modified by vendors. Refer to [this page](https://www.manageengine.com/products/desktop-central/patch-download-failure-cases.html) to learn more. ## Linux Patch Management ### Does Vulnerability Manager Plus patch Linux? Yes, refer to [this page](https://www.manageengine.com/vulnerability-management/help/patch-management/linux-patch-management.html) to see supported Linux flavors. ## Patch Audit & Reports ### Can I create a report for systems that need patches older than 30 days? Yes, you can create a report from Threats & Patches → Patches → Missing Patches and create a filter based on the "Release Date". ## Integrations ### Can I integrate Vulnerability Manager Plus with Nessus? Since Nessus does not support APIs for integration, it is not possible to integrate it with Vulnerability Manager Plus. ## Miscellaneous ### Can I deploy/uninstall applications using the Patch Management module? No, the Patch Management module is specifically designed for managing and deploying patches to operating systems and third-party applications that are installed in your endpoints. For application deployment and uninstallation, refer to the [Software Deployment](https://www.manageengine.com/products/desktop-central/help/software-deployment/software_deployment_setup.html) module. For any queries, contact [vulnerabilitymanagerplus-support@manageengine.com](mailto:vulnerabilitymanagerplus-support@manageengine.com).