# Patch Scanning Cloud Vulnerabilities are increasing at an alarming rate. To mitigate risks effectively, it is imperative to maintain accurate and up-to-date patch scans. This proactive approach enables the identification of systems with missing critical patches, allowing for timely remediation and reducing the organization's overall security posture. ## Pre-Requisites of Patch Scanning 1. ### Patch Database Settings You can select the patches and updates that you wish to manage using Vulnerability Manager Plus in **Patch Database Settings** page. Once configured, this process will not demand any further involvement from you, the new patches will get automatically displayed post scanning based on your preferences that you select in this page. To lean more about Patch Database Settings refer to [this page.](https://www.manageengine.com/vulnerability-management/help/vulnerability-management/vulnerability_db_synchronization.html) 2. ### Agent Onboarding The agent has to be installed in the endpoint and onboarded. A patch scan can be initiated after the agent installation. This patch scan occurs only if the **Perform Patch Scanning** checkbox has been enabled. To enable this checkbox, navigate to **Admin -> Agent settings -> General Settings** tab. Under Actions to be performed after agent installation, enable the checkbox "Perform Patch Scanning". ## Validate Patch Scan Status A 20-minute wait period is required for the patch scan to complete. Subsequently, verify the scan's successful execution by navigating to **Systems -> Scan Systems** under the **Threats & Patches** tab. ![Validate Patch Scan Status](https://www.manageengine.com/products/desktop-central/help/images/patch-scan.png) ## Patch Scan Scenarios A patch scan is triggered under the following conditions: - **Patch Installation**: Following patch installation via **Install Patch Configuration**, **APD Deployment** or **Test and Approve**. - **System Reboot**: Post-reboot of systems that required a reboot after patch installation. - **APD/Test Group Actions**: When patches within an APD task or Test Group are approved, not approved, or declined. - **Manual Scan**: Initiated manually through the console or Agent Tray icon. ## On-Demand Patch Scan The patch scan can also be implemented manually through the console or the Agent Tray icon. Choose Initiate Patch Scan option by right-clicking on the Agent Tray icon -> Scan -> Initiate Patch Scan. To initiate patch scan manually through the console, follow the steps below: 1. Open Vulnerability Manager Plus console and navigate to **Threats & Patches -> Systems -> Scan Systems**. 2. Choose the computers to be scanned for patches and click **Scan Systems**. **Limitation** On Cloud, an on-demand scan of all systems is not supported. Choose the required computers and click **Scan Systems**, or wait for the automatic patch scan to complete. An out-of-band patch that is already supported can be searched under **Supported Patches**. It appears under **Missing Patches** after a patch scan completes on the managed computers. After synchronization with the patch database, Vulnerability Manager Plus will collect details of the latest patches released. In the next refresh policy, Vulnerability Manager Plus agents will automatically scan the computers to check if the newly available patches are missing. The scan happens right after the database is synced. The end-user can go to the patch DB settings to change the sync timings. Following the first successful scan after agent installation or onboarding, the product identifies the applications installed on the managed endpoint where vulnerabilities are detected or patches are missing. You can view these applications by navigating to **Systems -> Scan Systems**, clicking on your computer name, and selecting **Installed Software**. After that, every time when the scan happens, the latest missing patches are detected. The agents will scan only in their subsequent refresh cycle, post which the latest scan data (about detected vulnerabilities and missing patches) is updated in the product. The network traffic is distributed in the refresh interval, and hence, the server remains undisturbed. The user can get reports of missing patches after the scan is completed. Navigate to **Reports -> Schedule Reports -> Scan Report**. You can get it easily by scheduling the reports to be emailed 2 hours from the database sync. Also, you can configure it at any frequency you wish. **Note** Patch scan cannot be restricted to certain machines—once the agent establishes contact with the server, the scan takes place automatically during the refresh cycle. There's no option to schedule scan as the Vulnerability Manager Plus automatically scans your endpoints during the mentioned scenarios. Vulnerability and patch scans are not separate processes; they occur simultaneously as part of the same scan. ## Related - [Patch Database Settings](https://www.manageengine.com/vulnerability-management/help/vulnerability-management/vulnerability_db_synchronization.html)