# Patch Management FAQ Last Updated On: 14 Jul 2026 71 minutes read ## Patch Detection and Deployment ### How can we perform patch deployment using Endpoint Central MSP? You can deploy a patch either [manually](https://www.manageengine.com/desktop-management-msp/help/patch-management/manual-deployment.html) or using an [automated patch deployment task](https://www.manageengine.com/desktop-management-msp/help/patch-management/apd.html). ### What happens if Microsoft releases a faulty patch in the new distributed model? How can Endpoint Central MSP remove it? It is recommended to use the "Test and Approve" feature, which can test the patches on lab machines and then approve them automatically before deployment. We also have the patch removal/roll back option, which can be used to handle these situations. ### How can I add patches for applications that aren't supported by the product? To add patches for applications that aren't supported by the product, please fill out the [feature request form](https://www.manageengine.com/products/desktop-central/need-features.html). This will allow us to understand your needs and potentially incorporate support for those applications in future updates. Your feedback is valuable in helping us enhance our offerings to better serve your needs. ### Is it possible to target specific device types, like laptops or desktops, for patch deployment? Yes, the target machines can be defined based on system type, such as laptops and desktops. A custom group can also be created with system type as criteria. ### Can I schedule reboots for servers and desktops after patch installation? We do support reboot scheduling in deployment policy with "Reboot Window/ Specify Reboot Time" for Force Reboot. ### Can we create a restore point before deploying a Windows update? Yes. It is possible by configuring a pre-deployment script in the deployment policy to create a restore point before deploying the Windows update. - Create a script that generates a system restore point on the target Windows device. - Add that script to the product and select it under the Deployment Policy as a pre-deployment script. - Test the policy on a pilot group first, verify restore point creation, and then roll it out to the wider environment. ### How can I be notified about zero-day patches availability for download to ensure timely deployment instead of having to wait for the scheduled policy? You can create an Automated Patch Deployment task to deploy patches with critical severity, including zero-day patches. Set the deployment policy timeframe to "as soon as possible". ### How does the patch scan process work? Does it scan all computers simultaneously or one at a time? Scanning will be initiated incrementally in order to avoid bandwidth bottlenecks. ### Will an automatic scan overburden the server with multiple requests? Will it choke the network traffic? Definitely not. The scan happens right after the database is synced. Every time the scan happens, the latest missing patches are detected and downloaded onto the server. We employ this effective mechanism of posting only the diff scan data (difference in the scan data between two consecutive scans), so it will not overburden the server. Also, it will not affect network traffic, since we don't initiate an on-demand scan from the server. ### Does the computer need to be logged into an admin account for patch deployment? No, as the agent installed in the managed computers would have the privilege to install the patches, the regular user account can be used for patch deployment. ### How to specify languages for patches? Endpoint Central MSP will automatically detect the language based on the operating system. ### What happens if a user accidentally turns off the computer while patches are being installed? Endpoint Central MSP will retry to install the patch during the subsequent deployment window, and the installation status will be updated. ### Is it possible to schedule patch installations followed by automatic reboot and shutdown? You can configure the Deployment Policy to schedule patch installation, as well as reboot or shutdown tasks, within pre- or post-deployment activities. ### How can we switch from WSUS to Endpoint Central MSP for MS patch management? You can disable auto-updates from WSUS and install Endpoint Central MSP agent on the computers to be managed, scan the computers and start deploying the patches. To know how to disable automatic updates, refer to [this page](https://www.manageengine.com/desktop-management-msp/how-to/patch-management/disable-automatic-updates.html). ### How can I selectively deploy Mozilla updates to specific computers while excluding others? You can create a custom group with the computers that you wanted to exclude. Decline the application by navigating to Threats & Patches → Settings → Decline Patch → Decline Patch for Group and specifying the application. ### How can I prevent individual computers from downloading patches directly from the internet, ensuring that all updates are sourced from the centralized patch management system? You can see the "Installed Time", against the patch, if it is installed using Endpoint Central MSP. If you do not find the "Installed Time", then it could be patched using automatic updates. In such cases, you will have to disable auto-updates from Configurations → Script Repository → Templates tab → Search for AutomaticUpdates.exe → add to repository. Create a configuration, select the target computers, and deploy it. To know how to disable automatic updates, refer to [this page](https://www.manageengine.com/desktop-management-msp/how-to/patch-management/disable-automatic-updates.html). ### Is there a way to configure the lists of computers, etc., to permanently display more than 25 at a time? You can customize the count of computers displayed. The changes you make will persist only for the technician and the view. ### If I want to schedule patches to run in the next 20 minutes, is there a way to force the Endpoint Central MSP agent on client machines to talk to the server? You can achieve this by using the "Deploy Immediately" option when you deploy a patch configuration. This will wake up the target computer on-demand to perform the task initiated by Endpoint Central MSP. ### Is it possible to allow a Java update for compatibility with an application and preserve the legacy version for compatibility with another application? You can create a dynamic custom group and choose to decline the patches for the specific application like JRE. By doing this, you can maintain multiple versions of the JRE in your network. ### What changes should I make in my firewall and proxy to patch computers? [Refer to this article](https://www.manageengine.com/desktop-management-msp/help/patch-management/patch-download-failure-error-403.html) to find the list of domains which need to be excluded. ### How do you make a separate policy that is specifically for server OSs and does not automatically restart the server? This can be achieved by configuring the deployment policy and excluding servers from reboot. Navigate to Threats & Patches → Deployment → Deployment Policies → Create Policy → Deployment Window → Reboot Policy → Exclude Servers from Reboot. ### How does the "wake and deploy" feature work for patching offline computers? You can wake up the computers and deploy the patches by configuring Threats & Patches → Deployment → Deployment Policies → Create Policy → Pre-deployment Activities → Wake-on LAN. ### How to identify servers from the Endpoint Central MSP web console? Navigate to Agent → Computers in the console interface. Create a filter for Operating System with tags "server" and "Oracle". The Red Hat Enterprise Linux OS server machines cannot be identified using the web console as its subscription has to be checked. ![identify servers](https://cdn.manageengine.com/manageengine/products/desktop-central/images/identify-servers.png) ## Automatic Patch Deployment ### How does Endpoint Central MSP handle automated download and cleanup of patches? Endpoint Central MSP will allow you to automate the complete process. You can create an APD task, which will automatically scan computers, detect missing patches, automatically download the required patches and deploy it to the target computers. You can configure the "Cleanup Settings" to delete the unwanted patches automatically. ### Is there a feature for creating a test group of several computers to pilot patch deployments? Yes, you can use the Test & Approve feature to create a test group of computers and pilot patch deployments before rolling them out to the entire organization. This allows you to test the patches for compatibility and performance issues. You can configure automatic approval after a specified period if no issues are detected, or manually approve the patches based on test results. ### Will the APD task retry in subsequent deployments? If patches are missing and not already installed, the Automatic Patch Deployment (APD) task will attempt to deploy them again. In cases where there is an installation error at the machine level, the APD task will halt after two unsuccessful attempts to deploy the patches. However, if the issue is network-related, the APD will continue retrying until the patches are successfully deployed. ## BIOS and Driver Updates ### Are Lenovo BIOS updates available for patching? No. Only the mentioned Drivers and BIOS in [this page](https://www.manageengine.com/desktop-management-msp/help/patch-management/biosdriverupdates.html#sdb) are supported by Endpoint Central MSP for patching. ## Microsoft 365 Deployment ### Where do the Office patches get downloaded, once the Click-to-Run settings are enabled? Once the Click-to-Run Settings have been enabled, the Office patches will be downloaded in the server's patch store (Patch Repository Location), as specified in the server. In the case of a Distribution Server, the Office patches will be downloaded in the specified patch repository location of both the Central Server and the Distribution Server. ## Linux Patch Management ### Does Endpoint Central MSP now patch Linux? Yes, refer to [this page](https://www.manageengine.com/desktop-management-msp/help/patch-management/linux-patch-management.html) to see supported Linux flavors. ## Patch Audit & Reports ### Is there a feature to pull local logs of failed deployments from Endpoint Central MSP? Yes, you can pull local agent logs from remote computers and upload them to support for analysis from Support → Create Support File. ## Integrations ### Can I integrate Endpoint Central MSP with Nessus? Since Nessus does not support APIs for integration, it is not possible to integrate it with Endpoint Central MSP. ## Miscellaneous ### How do I schedule a free demo for patch management? You can schedule a free demo for patch management by visiting the [request demo page](https://www.manageengine.com/products/desktop-central/free-trial.html) and filling out the form. ### Can I deploy/uninstall applications using the Patch Management module? No, the Patch Management module is specifically designed for managing and deploying patches to operating systems and third-party applications that are installed in your endpoints. For application deployment and uninstallation, refer to the [Software Deployment](https://www.manageengine.com/desktop-management-msp/help/software-deployment/software_deployment_setup.html) module. Kindly contact [msp-endpointcentral-support@manageengine.com](mailto:msp-endpointcentral-support@manageengine.com) for any queries.