# Patch Management FAQ **Last Updated On**: 14 Jul 2026 **71 minutes read** ## Patch Detection and Deployment ### How can we perform patch deployment using Endpoint Central? You can deploy a patch either [manually](https://www.manageengine.com/products/desktop-central/help/patch-management/manual-deployment.html) or using an [automated patch deployment task](https://www.manageengine.com/products/desktop-central/help/patch-management/apd.html). ### What happens if Microsoft releases a faulty patch in the new distributed model? How can Endpoint Central remove it? It is recommended to use the "Test and Approve" feature, which can test the patches on lab machines and then approve them automatically before deployment. We also have the patch removal/roll back option, which can be used to handle these situations. ### How can I add patches for applications that aren't supported by the product? To add patches for applications that aren't supported by the product, please fill out the [feature request form](https://www.manageengine.com/products/desktop-central/need-features.html). This will allow us to understand your needs and potentially incorporate support for those applications in future updates. ### Is it possible to target specific device types, like laptops or desktops, for patch deployment? Yes, the target machines can be defined based on system type, such as laptops and desktops. A custom group can also be created with system type as criteria. ### Can I schedule reboots for servers and desktops after patch installation? We do support reboot scheduling in deployment policy with "Reboot Window/ Specify Reboot Time" for Force Reboot. ### Can we create a restore point before deploying a Windows update? Yes. It is possible by configuring a pre-deployment script in the deployment policy to create a restore point before deploying the Windows update. - Create a script that generates a system restore point on the target Windows device. - Add that script to the product and select it under the Deployment Policy as a pre-deployment script. - Test the policy on a pilot group first, verify restore point creation, and then roll it out to the wider environment. ### How can I be notified about zero-day patches availability for download to ensure timely deployment instead of having to wait for the scheduled policy? You can create an Automated Patch Deployment task to deploy patches with critical severity, including zero-day patches. Set the deployment policy timeframe to "as soon as possible". ### How does the patch scan process work? Does it scan all computers simultaneously or one at a time? Scanning will be initiated incrementally in order to avoid bandwidth bottlenecks. ### Will an automatic scan overburden the server with multiple requests? Will it choke the network traffic? Definitely not. The scan happens right after the database is synced. Every time the scan happens, the latest missing patches are detected and downloaded onto the server. Only the diff scan data (difference in the scan data between two consecutive scans) is posted, so it will not overburden the server or affect network traffic. ### Does the computer need to be logged into an admin account for patch deployment? No. The agent installed in the managed computers would have the privilege to install the patches, so the regular user account can be used for patch deployment. ### How to specify languages for patches? Endpoint Central will automatically detect the language based on the operating system. ### What happens if a user accidentally turns off the computer while patches are being installed? Endpoint Central will retry installing the patch during the subsequent deployment window, and the installation status will be updated. ### Is it possible to schedule patch installations followed by automatic reboot and shutdown? You can configure the Deployment Policy to schedule patch installation, as well as reboot or shutdown tasks, within pre- or post-deployment activities. ### How can we switch from WSUS to Endpoint Central for MS patch management? You can disable auto-updates from WSUS and install the Endpoint Central agent on the computers to be managed, scan the computers and start deploying the patches. To know how to disable automatic updates, refer to [this page](https://www.manageengine.com/products/desktop-central/how-to/patch-management/disable-automatic-updates.html). ### How can I selectively deploy Mozilla updates to specific computers while excluding others? You can create a custom group with the computers that you want to exclude. Decline the application by navigating to Threats & Patches → Settings → Decline Patch → Decline Patch for Group and specifying the application. ### How can I prevent individual computers from downloading patches directly from the internet, ensuring that all updates are sourced from the centralized patch management system? You can see the "Installed Time", against the patch, if it is installed using Endpoint Central. If you do not find the "Installed Time", then it could be patched using automatic updates. In such cases, you will have to disable auto-updates from Configurations → Script Repository → Templates tab → Search for AutomaticUpdates.exe → add to repository. Create a configuration, select the target computers, and deploy it. Refer to [this page](https://www.manageengine.com/products/desktop-central/how-to/patch-management/disable-automatic-updates.html). ### Is there a way to configure the lists of computers, etc., to permanently display more than 25 at a time? You can customize the count of computers displayed. The changes you make will persist only for the technician and the view. ### If I want to schedule patches to run in the next 20 minutes, is there a way to force the Endpoint Central agent on client machines to talk to the server? You can achieve this by using the "Deploy Immediately" option when you deploy a patch configuration. This will wake up the target computer on-demand to perform the task initiated by Endpoint Central. ### Is it possible to allow a Java update for compatibility with one application and preserve the legacy version for another? You can create a dynamic custom group and choose to decline the patches for the specific application like JRE. This allows you to maintain multiple versions in your network. ### What changes should I make in my firewall and proxy to patch computers? Refer to [this article](https://www.manageengine.com/products/desktop-central/help/patch-management/patch-download-failure-error-403.html) to find the list of domains that need to be excluded. ### How to identify servers from the Endpoint Central web console? Navigate to Agent → Computers in the console interface. Create a filter for Operating System with tags "server" and "Oracle". The Red Hat Enterprise Linux OS server machines cannot be identified using the web console as its subscription has to be checked. ![identify servers](https://cdn.manageengine.com/manageengine/products/desktop-central/images/identify-servers.png) (Additional sections including **Automatic Patch Deployment**, **BIOS and Driver Updates**, **Microsoft 365 Deployment**, **Linux Patch Management**, **Patch Audit & Reports**, **Integrations**, and **Miscellaneous** continue with detailed FAQs covering deployment automation, Test & Approve workflows, BIOS/driver enablement and sync steps, Office Click-to-Run behavior and bandwidth optimization, Linux EOL handling, report scheduling, Tenable/Rapid7/Spotlight integrations, vulnerability correlation via CVE IDs, compliance visibility, supported applications, cleanup settings, and troubleshooting guidance as described in the full documentation.) For any queries, contact [endpointcentral-support@manageengine.com](mailto:endpointcentral-support@manageengine.com).