# Patch Management FAQ **Last Updated On**: 05 Aug 2026 **72 minutes read** ## Patch Detection and Deployment ### How can we perform patch deployment using Endpoint Central MSP? You can deploy a patch either [manually](https://www.manageengine.com/desktop-management-msp/help/patch-management/manual-deployment.html) or using an [automated patch deployment task](https://www.manageengine.com/desktop-management-msp/help/patch-management/apd.html). ### What happens if Microsoft releases a faulty patch in the new distributed model? How can Endpoint Central MSP remove it? It is recommended to use the "Test and Approve" feature, which can test the patches on lab machines and then approve them automatically before deployment. We also have the patch removal/roll back option, which can be used to handle these situations. ### How can I add patches for applications that aren't supported by the product? To add patches for applications that aren't supported by the product, please fill out the [feature request form](https://www.manageengine.com/products/desktop-central/need-features.html). This will allow us to understand your needs and potentially incorporate support for those applications in future updates. Your feedback is valuable in helping us enhance our offerings to better serve your needs. ### Is it possible to target specific device types, like laptops or desktops, for patch deployment? Yes, the target machines can be defined based on system type, such as laptops and desktops. A custom group can also be created with system type as criteria. ### Can I schedule reboots for servers and desktops after patch installation? We do support reboot scheduling in deployment policy with "Reboot Window/ Specify Reboot Time" for Force Reboot. ### Can we create a restore point before deploying a Windows update? Yes. It is possible by configuring a pre-deployment script in the deployment policy to create a restore point before deploying the Windows update. - Create a script that generates a system restore point on the target Windows device. - Add that script to the product and select it under the Deployment Policy as a pre-deployment script. - Test the policy on a pilot group first, verify restore point creation, and then roll it out to the wider environment. ### How can I be notified about zero-day patches availability for download to ensure timely deployment instead of having to wait for the scheduled policy? You can create an Automated Patch Deployment task to deploy patches with critical severity, including zero-day patches. Set the deployment policy timeframe to "as soon as possible". ### How does the patch scan process work? Does it scan all computers simultaneously or one at a time? Scanning will be initiated incrementally in order to avoid bandwidth bottlenecks. ### Will an automatic scan overburden the server with multiple requests? Will it choke the network traffic? Definitely not. The scan happens right after the database is synced. Every time the scan happens, the latest missing patches are detected and downloaded onto the server. We employ this effective mechanism of posting only the diff scan data (difference in the scan data between two consecutive scans), so it will not overburden the server. Also, it will not affect network traffic, since we don't initiate an on-demand scan from the server. ### Does the computer need to be logged into an admin account for patch deployment? No, as the agent installed in the managed computers would have the privilege to install the patches, the regular user account can be used for patch deployment. ### How to specify languages for patches? Endpoint Central MSP will automatically detect the language based on the operating system. ### What happens if a user accidentally turns off the computer while patches are being installed? Endpoint Central MSP will retry to install the patch during the subsequent deployment window, and the installation status will be updated. ### Is it possible to schedule patch installations followed by automatic reboot and shutdown? You can configure the Deployment Policy to schedule patch installation, as well as reboot or shutdown tasks, within pre- or post-deployment activities. ### How can we switch from WSUS to Endpoint Central MSP for MS patch management? You can disable auto-updates from WSUS and install Endpoint Central MSP agent on the computers to be managed, scan the computers and start deploying the patches. To know how to disable automatic updates, refer to [this page](https://www.manageengine.com/products/desktop-central/how-to/patch-management/disable-automatic-updates.html). ### How can I selectively deploy Mozilla updates to specific computers while excluding others? You can create a custom group with the computers that you wanted to exclude. Decline the application by navigating to Threats & Patches -> Settings -> Decline Patch -> Decline Patch for Group and specifying the application. ### How can I prevent individual computers from downloading patches directly from the internet, ensuring that all updates are sourced from the centralized patch management system? You can see the “Installed Time”, against the patch, if it is installed using Endpoint Central MSP. If you do not find the “Installed Time”, then it could be patched using automatic updates. In such cases, you will have to disable auto-updates from, Configurations -> Script Repository -> Templates tab -> Search for AutomaticUpdates.exe -> add to repository. Create a configuration, select the target computers, and deploy it. To know how to disable automatic updates, refer to [this page](https://www.manageengine.com/products/desktop-central/how-to/patch-management/disable-automatic-updates.html). ### Is there a way to configure the lists of computers, etc., to permanently display more than 25 at a time? You can customize the count of computers displayed. The changes you make will persist only for the technician and the view. ### If I want to schedule patches to run in the next 20 minutes, is there a way to force the Endpoint Central MSP agent on client machines to talk to the server, thus getting that task quicker than the 90-minute policy refresh? You can achieve this by using the “Deploy Immediately" option when you deploy a patch configuration. This will wake up the target computer on-demand to perform the task initiated by Endpoint Central MSP. ### Is it possible to allow a Java update for compatibility with an application and preserve the legacy version for compatibility with another application? You can create a dynamic custom group and choose to decline the patches for the specific application like JRE. By doing this, you can maintain multiple versions of the JRE in your network. ### What changes should I make in my firewall and proxy to patch computers? [Refer to this article](https://www.manageengine.com/products/desktop-central/kb/vmdr/patch-download-failure-error-403.html) to find the list of domains, which need to be excluded. ### How do you make a separate policy that is specifically for server OSs and does not automatically restart the server? This can be achieved by configuring the deployment policy and excluding servers from reboot. Navigate to Threats & Patches -> Deployment -> Deployment Policies -> Create Policy -> Deployment Window -> Reboot Policy -> Exclude Servers from Reboot. ### We currently use McAfee encryption on some of our devices. How can we continue auto deployment after hours once everything is encrypted? This can be achieved by configuring the deployment to happen after the encryption time window. You can configure it from Threats & Patches -> Deployment -> Deployment Policies -> Create Policy -> Deployment Schedule. ### How does the "wake and deploy" feature work for patching offline computers? You can wake up the computers and deploy the patches by configuring Threats & Patches -> Deployment -> Deployment Policies -> Create Policy -> Pre-deployment Activities -> Wake-on LAN. ### How come I have not seen updates for Windows 10 or MS 2016? Both Windows 10 and Microsoft Office 2016 are supported by Endpoint Central MSP. You should ensure that your Patch Database is successfully synchronized in the recent past. Verify it from Threats & Patches -> Update Now -> Last Successful Vulnerability DB Update. ### Can I use Endpoint Central MSP to manage 3rd Party applications? Yes, Endpoint Central MSP supports managing 3rd party applications. Find the [list of supported 3rd party applications](https://www.manageengine.com/products/desktop-central/patch_management_supported_application.html). ### How to manage patches and vulnerabilities without overlapping with Windows Update? To manage patches and vulnerabilities via the product without overlapping with Windows Update, disable the automatic updates from Windows. Navigate to Threats & Patches -> Deployment -> Disable Automatic Updates, choose the required templates and disable. Only Windows automatic updates can be disabled by our product. To know how to disable automatic updates, refer to [this page](https://www.manageengine.com/products/desktop-central/how-to/patch-management/disable-automatic-updates.html). ### Do we need to disable automatic Windows updates on user PCs, and what happens if we do? Yes, it is recommended to disable end-user automatic Windows updates when using Endpoint Central MSP Patch Management. If you disable them, users can no longer update directly from Windows Update, and patching is managed centrally through Endpoint Central MSP policies and automated tasks. This provides better control, predictable reboot behavior, consistent compliance tracking, and fewer update conflicts. To know how to disable automatic updates, refer to [this page](https://www.manageengine.com/products/desktop-central/how-to/patch-management/disable-automatic-updates.html). ### If automatic updates are turned off, do we need to manually deploy patches for each user? No. You do not need to deploy patches manually for each user. Endpoint Central MSP supports end-to-end centralized patching using Test and Approve for pilot validation, automatic or manual approval workflows, Automated Patch Deployment (APD) for rollout, and Decline Patches for controlled exclusions. It also provides comprehensive patch reporting. ### How can End-of-Life patches such as Windows 10 ESU be managed? Refer to these pages: [Windows 10 ESU overview](https://www.manageengine.com/products/desktop-central/how-to/patch-management/windows-10-esu-verification.html) and [Windows 10 ESU verification](https://www.manageengine.com/products/desktop-central/how-to/patch-management/windows-10-esu-verification.html). ### Is one reboot enough to complete client patching? Usually, one reboot is enough, as long as the previous update has fully installed. If an earlier update is still pending and a newer update is applied on top of it, two reboots may be needed. ### How can we efficiently deploy patches to laptops that are infrequently connected via VPN? When these computers connect to the network via VPN, the deployment will be initiated during the next refresh cycle (90 minutes). ### Are all patches released by Microsoft available? Yes, most patches that have a download URL will be supported. You can get the list of patches that we support from [here](https://www.manageengine.com/products/desktop-central/patch-management/microsoft-security-bulletins.html). ### What is the typical turnaround time for updating patches? - Third-party application updates: 6–9 hours - OS security updates: 12–18 hours - Non-security updates: within 24 hours - Linux security updates: 24–48 hours - Linux non-security updates: within 72 hours - macOS updates: within 7 hours ### If you do the cleanup and then put a newer machine and it needs an older patch, what will happen? It will automatically be downloaded and installed. ### How do I know which updates to run and the order to run them? Patch interdependencies and sequencing will be automatically taken care of by Endpoint Central MSP. ### After the initial agent deployment, will patch scan subnets for new machines? No, the agent should be deployed before scanning. You can define SoM Sync Policy to automatically identify new computers added to Active Directory and install agents on them. ### What is the process of disabling Windows 10 creep update for Windows 7 computers? Under Configuration Templates, we have a template to disable the Windows 10 creep update (Disable Windows 10 Notification). ### How much disk space does a Distribution Server need to cache patches? It depends on the number of systems and patches that are maintained, and it may be up to 1 GB. It is recommended to configure patch Cleanup Settings to remove older patches automatically. ### Can one Distribution Server support multiple remote offices? Yes, if all the remote offices use the same agent and can reach the Distribution Server. This is not applicable for Endpoint Central MSP Cloud since every remote office needs a unique Distribution Server. ### Will the client devices communicate with the main server if the Distribution Server is stopped? Yes, the agents will contact the server to post the failure messages. But no deployment will happen. ### Is it possible to deploy patches to specific computers? Yes, go to the All Systems View, select the computer, and install all missing patches to this computer. ### How to identify servers from the Endpoint Central MSP web console? Navigate to Agent -> Computers in the console interface. Create a filter for Operating System with tags "server" and "Oracle". ![identify servers](https://cdn.manageengine.com/products/desktop-central/images/identify-servers.png) ### How to deploy older version (6, 7) Java patches? To deploy older version (6,7) Java patches, [refer to this page](https://pitstop.manageengine.com/portal/en/community/topic/workaround-for-java-6-7-patch-download-failure-29-5-2017-1). ### Can Endpoint Central MSP limit storage space used for downloading patches? You can configure Patch Cleanup Settings to automatically remove superseded/unused patches from the patch repository. ### How do I handle superseded patches? If a patch is marked as superseded, install the latest patch listed under Missing Patches, as it covers previous updates. ### Why is a patch visible on the endpoint but not shown in Missing Patches? This usually happens when the patch is superseded. Superseded patches are retained for up to 90 days when support is enabled. ### How can I resolve patch deployment errors related to user sessions? Ensure that the user is logged in, or enable Wake-on-LAN in the deployment policy. ### Can we make a single store for all MAC patches? Endpoint Central MSP maintains a single patch store for Windows, Mac, Linux, and 3rd party patches. ### How can I host my Patch Repository on another computer? Go to Threats & Patches -> Settings -> Cleanup Settings -> Patch Download Location and enter the new path (e.g., \\machine_name\example_patch_repository). ### Should I update the vulnerability database before configuring patch deployments? The vulnerability database syncs automatically. You can also manually sync using "Update Now". ### On what basis can I filter patches? You can filter based on: 1. **Patches**: Operating System, Application, Severity, Hardware, Bulletin ID, KB Number, CVE ID, Vendor, Patch Type, Approved Status, Download Status, Deployment Status, Release Date, Supersede Status. 2. **Systems**: Computer Name, Platform, Domain Name, Branch Office, Custom Group, Operating System, Language, Agent Live Status. ### Does Endpoint Central MSP support Windows Store updates? No. Windows Store Updates are not supported. ### Does Endpoint Central MSP provide a built-in option to push required registry changes? Yes. Upload your script to the [script repository](https://www.manageengine.com/products/desktop-central/configurations-knowledge-base.html) and configure it as a pre- or post-deployment activity. ### Can the patch deployment be scheduled to start at a specific time instead of within a deployment window? Time-specific start time for patch deployment tasks are not supported as of now. ### Why does a patch show "Not Applicable"? It may not be missing or the product may not be installed on the machine. ### How to resolve patch deployment issues? Refer to [this page](https://www.manageengine.com/desktop-management-msp/help/patch-management/patch-deployment-troubleshooting.html). ### Can I upload custom patches that are not supported? No. Refer to supported applications [here](https://www.manageengine.com/products/desktop-central/patch_management_supported_application.html). Submit requests using [this form](https://www.manageengine.com/products/desktop-central/product-roadmap-add-details.html?id=30). ### Why does the "Reboot Pending" message remain after rebooting? Ensure the agent contacts the server and run a fresh scan. Windows may still report pending reboot due to uncleared registry keys. ### How do I confirm a patch installation is complete when a reboot is required? Go to **Patches → Detailed View**, filter **Patch Status = Installed**, and check Deployed Using, Deployed Date, and Deployed By. ### Why does patch installation fail with error code -1073741515? Upgrade Endpoint Central MSP server to the latest available build. ## Automatic Patch Deployment ### How does Endpoint Central MSP automate patch downloads and cleanup? Create an APD task to scan, download, and deploy patches automatically. Configure Cleanup Settings to delete unwanted patches. ### Can I receive notifications about patch deployment status? Yes, configure notification settings in the APD task. ### How would I automatically download and deploy the latest flash updates? Configure an Automated Patch Deployment task to run daily. ### Is there a feature for pilot testing patches? Yes, use Test & Approve to create a test group and validate patches before full rollout. ### How does Test & Approve work? You can approve patches automatically after a specified number of days if no failures occur, or approve them manually. ### Will the APD task retry in subsequent deployments? Yes. It retries unless there are repeated machine-level installation failures. ### Is it possible to set the deployment policy to run every 3rd Sunday? Yes, choose Monthly and select 3rd Sunday in Scheduler Settings. ## BIOS and Driver Updates ### Are Lenovo BIOS updates available? No. Only the mentioned Drivers and BIOS in [this page](https://www.manageengine.com/desktop-management-msp/help/patch-management/biosdriverupdates.html#sdb) are supported. ### Why is the latest BIOS/Firmware version not visible? Ensure BIOS and Driver categories are enabled in Patch Database Settings, sync the database, and trigger a fresh patch scan. ## Microsoft 365 Deployment ### Where are Office patches downloaded? They are downloaded to the Patch Repository Location on the server (and Distribution Server if applicable). ### How to enhance bandwidth usage with Office Click-to-Run? Set the download source as Microsoft CDN in Office Click-to-Run Settings. ### Why does a 404 error occur when downloading Microsoft Office patches? It occurs when downloading superseded patches. Refer to [this page](https://www.manageengine.com/products/desktop-central/patch-download-failure-cases.html). ## Linux Patch Management ### Are all Linux machines considered servers? Systems are considered servers if: - OS name contains "server" - RHEL has a Server subscription - Oracle Linux OS ### Does Endpoint Central MSP patch Linux? Yes. Refer to supported Linux flavors [here](https://www.manageengine.com/desktop-management-msp/help/patch-management/linux-patch-management.html). ### What third-party Linux patches are supported? Refer to [this page](https://www.manageengine.com/products/desktop-central/patch_management_supported_application.html). ## Patch Audit & Reports ### Can I pull local logs of failed deployments? Yes, from Support -> Create Support File. ### Can I create a report for patches older than 30 days? Yes, filter by Release Date under Missing Patches. ### How to configure weekly patch reports? Navigate to Reports -> Schedule Report and select Patch Report. ## Integrations ### Will Tenable automatically update required patches? Configure Tenable API in Endpoint Central MSP. Vulnerabilities will be imported and mapped. ### Can I integrate with Nessus? No, Nessus does not support APIs for integration. ### How are patches correlated with vulnerabilities? Using associated CVE IDs. ### Why are certain vulnerabilities marked as Not Available? Only patches supported by Endpoint Central MSP are mapped. Refer to [supported applications](https://www.manageengine.com/patch-management/supported-applications.html). ### How is InsightVM data imported? Using provided credentials and Reports API. ### Why are certain vulnerabilities not remediated? Some vulnerabilities require multiple patches. ![InsightVM](https://cdn.manageengine.com/patch-management/images/insightvm-op-5.png) ## Miscellaneous ### What is the difference between Endpoint Central MSP and Endpoint Central MSP? Endpoint Central MSP is a full endpoint management solution including patching and additional features. Endpoint Central MSP (standalone) focuses primarily on patch management. ### Can I deploy/uninstall applications using Patch Management? No. Use the [Software Deployment](https://www.manageengine.com/products/desktop-central/help/software-deployment/software_deployment_setup.html) module. ### Can the Patch Management module upgrade third-party applications? No. Use the [Software Deployment](https://www.manageengine.com/products/desktop-central/help/software-deployment/software_deployment_setup.html) module for upgrades. ### Why is the Threats & Patches section not visible? It is available only with the Vulnerability Management add-on or Security Edition. Refer to [this page](https://www.manageengine.com/products/desktop-central/edition-comparison-matrix.html). For any queries, contact [msp-endpointcentral-support@manageengine.com](mailto:msp-endpointcentral-support@manageengine.com).