×
×
×
×

Installing Service Pack

Best Practices for Upgrading Endpoint Central

Follow these recommendations to ensure a smooth upgrade every time.

Before Every Upgrade

  • Verify the Target Build: Always check ManageEngine's official website before starting an upgrade to confirm your applicable upgrade version. For more details, refer your current build number and upgrade notifications.
  • Backup: Ensure a full backup is in place before proceeding. The method depends on your deployment type:
    • Endpoint Central built-in backup: Use the Backup-Restore Utility (backuprestore.bat) or a recent scheduled backup as your primary supported backup. This captures both the application files and the database together in a single restorable archive. For more details, refer manual backup
    • VM snapshot: A VM snapshot can be used as an additional safety measure, especially when Endpoint Central and the bundled PostgreSQL database are on the same server. However, it should be treated as supplementary protection rather than a replacement for the built-in backup.
    • External database: If you are using MSSQL or Remote PostgreSQL, a VM snapshot of the Endpoint Central server does not cover the remote database server. Coordinate with your DBA to take an independent database backup (for example, an MSSQL full backup or a PostgreSQL dump) before proceeding.
    • Do not rely on file-only or DB-only rollback: The application files and database must remain in sync. Restoring only a VM snapshot of the application server or only a native database backup can leave the installation in an unusable state.
  • No active EC processes: Stop the Endpoint Central service and verify no UEMS.exe, wrapper.exe, or java.exe processes remain running before launching the Update Manager. File locks from lingering processes are a leading cause of upgrade failure.
  • When SGS is deployed: The Endpoint Central web console will notify you if an SGS upgrade is required after the server upgrade. Upgrade SGS only when prompted — not automatically after every EC Server upgrade. If an SGS upgrade is required, treat it as a separate component upgrade from the EC Server upgrade; both can be completed in the same maintenance window. The Central Server upgrade does not upgrade SGS automatically. When an SGS upgrade is needed, record the current SGS build, confirm the compatible target version, and keep time for post-upgrade remote connectivity validation.

Timing, Maintenance Windows and Downtime

Schedule upgrades during low-activity periods(i.e during non business hours) to minimize impact on end users and provide a sufficient time for post-upgrade validation.

Choosing Your Window

Always schedule a maintenance window larger than your estimated upgrade time. The upgrade itself has two phases: a backup phase where the Update Manager compresses and saves the existing installation, followed by an installation phase where the new build is applied. Both phases run sequentially without user interaction.

For smaller environments the total downtime is typically under an hour. Larger environments with significant patch history and many managed endpoints take longer — primarily due to the backup phase. It is normal for the Update Manager progress bar to appear stalled at around 40% ("Backing up significant files") for an extended period during this phase; this does not indicate failure.

Upgrade Path involving multiple PPM's

If your upgrade path requires multiple PPM steps (intermediate builds followed by the final target), there is no need to halt operations between stages. Once Stage 1 completes and the "Installation Successful" screen appears, simply close the existing Update Manager wizard and invoke a fresh updatemanager.bat to begin Stage 2. All the stages can be completed within the same maintenance window.

After finishing the final stage, dependent components upgrade automatically — agents and Distribution Servers will self-update to the latest version without any manual intervention. No additional steps are required to push the new agent version to endpoints.

Warning
Do not open the console while the Update Manager is running. Wait for the "Installation Successful" confirmation before accessing the console or restarting the service.
Note
If processes remain locked after stopping the service: wait a few minutes and verify in Task Manager that UEMS.exe, wrapper.exe, and java.exe have exited before launching the Update Manager. If they continue running unexpectedly, resolve the service state first and then retry the upgrade.

Pre-requisites for PPM upgradation

  1. Confirm a recent Endpoint Central backup is available
    Verify that a recent backup created through the built-in backup process is available. Use a scheduled backup or create one manually with backuprestore.bat before the upgrade so you have a complete application-and-database backup in a single archive.
  2. Take a VM snapshot only as an additional safeguard
    If the server is virtualized, you may take a VM snapshot for extra rollback protection. This is most useful when Endpoint Central and the bundled PostgreSQL database are on the same server, but it should not replace the built-in backup.
  3. Coordinate a separate backup for remote databases
    If Endpoint Central uses MSSQL or Remote PostgreSQL, arrange an independent database backup with your DBA before the upgrade. A VM snapshot of only the Endpoint Central server does not cover the remote database server.
  4. Download and validate the PPM file
    Save the PPM to a local drive and verify its checksum. For more details, refer Checksum Validation.
  5. Stop the Endpoint Central Server service
    Open services.msc → locate ManageEngine UEMS - Server → click Stop. Wait for the status to show Stopped.
  6. Verify no Endpoint Central processes remain running
    After stopping the service, check Task Manager for any remaining UEMS.exe, wrapper.exe, or java.exe processes. Wait a few minutes for them to exit naturally before launching the Update Manager.
  7. Verify free disk space
    Ensure free disk space of at least 1.5× the size of the UEMS_CentralServer folder on the installation drive. For more details, refer removing unwanted files from Endpoint Central.
  8. Confirm you are logged in with Domain Administrator credentials
  9. If Secure Gateway Server (SGS) is in use, check whether an SGS upgrade is required

Steps for upgradation

  1. Stop the Server. Open services.msc and stop the ManageEngine UEMS - Server service.
  2. Start the Update Manager by executing the script UpdateManager.bat located in the UEMS_CentralServer/bin directory.
  3. Click Browse and select the Service Pack file (.ppm) to be installed. You can view the Readme file by clicking Readme.
  4. Click Install to start the installation.
  5. Restart the Endpoint Central Server service after successful ppm installation.
  6. Verify the new build number.
  1. Stop the Endpoint Central Secondary Server. Open services.msc and stop the ManageEngine UEMS - Server service.
  2. If the server version is 10.1.2137.03 or higher, navigate to UEMS_CentralServer/bin on the secondary server and execute the script SecondaryServerPPMHandler.bat. Otherwise, skip this step.
  3. Stop the Endpoint Central Primary Server, once the Secondary Server is successfully stopped.
  4. Navigate to UEMS_CentralServer/bin and run UpdateManager.bat.
  5. Click Browse and select the Service Pack file (.ppm) that you downloaded. Click Install. The installation may take a few minutes to complete. Once finished, exit the Update Manager Tool.
  6. Note: If the upgrade fails, the system will automatically revert to the previous version.
  7. Start the Endpoint Central Primary Server. Once it is completely up and running, start the Secondary Server. The Secondary Server will automatically synchronize with the Primary Server to replicate the updated files and database changes upon startup.

Post-requisites for PPM upgradation

  1. Agents and Distribution Servers will upgrade automatically within a 90-minute refresh interval.
  2. Agents will only upgrade after their respective Distribution Servers have been upgraded.
  3. Successful communication between the Distribution Server and agents, as well as between the Endpoint Central Server and agents, is mandatory for the agent upgrade.
  4. Only after the agents are successfully upgraded can you proceed with other activities such as patching, software deployment, and remote control.
  5. Ensure that the machine where the Endpoint Central Server is installed has sufficient upload/download speed to distribute upgrade files to clients and the Distribution Server.
  6. Avoid scheduling any patching activities until the agent upgrade is completed, as it may delay the process.

Distribution Server and Agent Status

How Upgrades Propagate After the Central Server is Updated
  • Distribution Servers — Once the Central Server is upgraded, each Distribution Server will initiate the upgrade at its next scheduled replication cycle, as defined in the Replication Policy.
  • Agents — Agents initiate their upgrade based on the Refresh Policy interval (default: every 90 minutes). Once their Distribution Server has upgraded, agents will pick up and apply the new package at their next refresh cycle.
Warning
Important: Upgrade will be triggered on the Distribution Server and agents only when a version change is detected. If the Central Server is updated to a build that carries the same DS or agent version as already installed, no upgrade will be initiated — the existing DS and agent version will continue to function with full compatibility.