Windows Patch Management: Difference between revisions
No edit summary |
No edit summary |
||
(18 intermediate revisions by 2 users not shown) | |||
Line 1: | Line 1: | ||
In order to combat the ever increasing number of third-party security vulnerabilities on Windows machines, UMIACS staff has deployed Ivanti Endpoint Manager. As security threats have evolved from the operating system to applications we have had to take this step in order to maintain operational security for the Institute. Currently the updates are focused on applications that are exposed to the internet such as web browsers, teleconferencing solutions, Google Drive, Java, etc. | |||
The Ivanti Endpoint Manager agent software is currently deployed on all UMIACS-supported [[Windows]] desktops as well as [[Windows/LaptopSupport#UMIACS_Enterprise_Laptop_Support | Enterprise supported]] Windows laptops and home machines. | |||
==Automated Scanning== | |||
Patches are deployed during the week leading up to the [[MonthlyMaintenanceWindow|maintenance window]]. Specifically, they will always be deployed on the Wednesday that occurs between the 9th and the 15th (inclusive) of each month, and typically in the morning. | |||
*'''Desktops''' will scan for updates to be installed every night sometime between 7pm and 9pm. If you are not logged in during those times, the system will automatically install the patches and reboot if necessary. If you remain active on your system during those times, you will see a popup with the scan beginning and (once patches are downloaded) a prompt from Ivanti asking to begin installing patches. | |||
*'''Laptops''' will scan for updates to be installed at least once every day (assuming the laptop is powered on). This will only occur when the laptop has an active Internet connection (wired or wireless). You will see a popup with the scan beginning and (once patches are downloaded) a prompt from Ivanti asking to begin installing patches. | |||
Installation can be deferred until lock/logoff if desired. If you do not respond to the prompt within a given amount of time, installation will automatically proceed: | |||
*'''Desktops''': 24 hours | |||
*'''Desktops''' | *'''Laptops''': 3 hours | ||
*'''Laptops''' | |||
If a reboot is required after installation finishes, you will receive another pop up. It is highly suggested to reboot right away due to system instability and vulnerability. However, reboot can be deferred for up to 6 days if desired. If you do not respond to the prompt within a given amount of time, the machine will automatically reboot: | |||
*'''Desktops''': 24 hours | |||
*'''Laptops''': 9 hours | |||
If you interrupt the installation process between when the first patch begins installing and when the last patch finishes installing, Ivanti may ask to reboot before continuing to install the remaining patches next time it pops up. This is by design. If you would like to avoid multiple reboots on a machine that is used intermittently (such as a laptop), we would recommend starting a manual scan just before you stop using the machine for the night and then letting the machine download and apply all patches overnight. See below section for how to do this. | |||
==Manual Scanning== | ==Manual Scanning== | ||
This should only need to be done on laptops or home machines in the event that | This should only <b>need</b> to be done on laptops or home machines in the event that Ivanti has not had a large enough time window to scan your computer recently, but can be optionally done if you see fit. '''Please note you will need an active Internet connection for this to work, however you do not need to be on the UMIACS [[VPN]].''' | ||
# Search for "Security Scan" from the Start menu and click | # Search for "Security Scan" from the Start menu and click the result that shows up (should show a shield icon). The scan will begin. Patches will be detected and downloaded. | ||
#* '''Note''': The scan may fail on the "Checking for other running scanners" step if | #* '''Note''': The scan may fail on the "Checking for other running scanners" step if Ivanti is already running an invisible scan in the background. If this occurs, wait 10-15 minutes and then retry the scan. | ||
# | #: [[File:Landesk1.png]][[File:Landesk2.png]] | ||
# After all patches have been downloaded, you will be prompted to allow the install to begin. | # After all patches have been downloaded, you will be prompted to allow the install to begin. | ||
# | #: [[File:Landesk3.png]] | ||
# After all patches have been installed, you may be prompted to reboot. | # After all patches have been installed, you may be prompted to reboot. | ||
# | #: [[File:Landesk4.png]] | ||
# If you do not want to reboot immediately, you can click on the 'Remind me in:' drop down menu and click 'More options...' | |||
#: [[File:Landesk5.png]] | |||
# Click the 'Remind me on' radio button and choose a date and time before the deadline (it will tell you what the deadline is). Then click 'Remind me later'. | |||
#: [[File:Landesk6.png]] | |||
# After reboot, run another scan and verify no patches are detected. If a patch is continually failing, please [[HelpDesk | contact staff]]. |
Latest revision as of 19:52, 28 October 2024
In order to combat the ever increasing number of third-party security vulnerabilities on Windows machines, UMIACS staff has deployed Ivanti Endpoint Manager. As security threats have evolved from the operating system to applications we have had to take this step in order to maintain operational security for the Institute. Currently the updates are focused on applications that are exposed to the internet such as web browsers, teleconferencing solutions, Google Drive, Java, etc.
The Ivanti Endpoint Manager agent software is currently deployed on all UMIACS-supported Windows desktops as well as Enterprise supported Windows laptops and home machines.
Automated Scanning
Patches are deployed during the week leading up to the maintenance window. Specifically, they will always be deployed on the Wednesday that occurs between the 9th and the 15th (inclusive) of each month, and typically in the morning.
- Desktops will scan for updates to be installed every night sometime between 7pm and 9pm. If you are not logged in during those times, the system will automatically install the patches and reboot if necessary. If you remain active on your system during those times, you will see a popup with the scan beginning and (once patches are downloaded) a prompt from Ivanti asking to begin installing patches.
- Laptops will scan for updates to be installed at least once every day (assuming the laptop is powered on). This will only occur when the laptop has an active Internet connection (wired or wireless). You will see a popup with the scan beginning and (once patches are downloaded) a prompt from Ivanti asking to begin installing patches.
Installation can be deferred until lock/logoff if desired. If you do not respond to the prompt within a given amount of time, installation will automatically proceed:
- Desktops: 24 hours
- Laptops: 3 hours
If a reboot is required after installation finishes, you will receive another pop up. It is highly suggested to reboot right away due to system instability and vulnerability. However, reboot can be deferred for up to 6 days if desired. If you do not respond to the prompt within a given amount of time, the machine will automatically reboot:
- Desktops: 24 hours
- Laptops: 9 hours
If you interrupt the installation process between when the first patch begins installing and when the last patch finishes installing, Ivanti may ask to reboot before continuing to install the remaining patches next time it pops up. This is by design. If you would like to avoid multiple reboots on a machine that is used intermittently (such as a laptop), we would recommend starting a manual scan just before you stop using the machine for the night and then letting the machine download and apply all patches overnight. See below section for how to do this.
Manual Scanning
This should only need to be done on laptops or home machines in the event that Ivanti has not had a large enough time window to scan your computer recently, but can be optionally done if you see fit. Please note you will need an active Internet connection for this to work, however you do not need to be on the UMIACS VPN.
- Search for "Security Scan" from the Start menu and click the result that shows up (should show a shield icon). The scan will begin. Patches will be detected and downloaded.
- Note: The scan may fail on the "Checking for other running scanners" step if Ivanti is already running an invisible scan in the background. If this occurs, wait 10-15 minutes and then retry the scan.
- After all patches have been downloaded, you will be prompted to allow the install to begin.
- After all patches have been installed, you may be prompted to reboot.
- If you do not want to reboot immediately, you can click on the 'Remind me in:' drop down menu and click 'More options...'
- Click the 'Remind me on' radio button and choose a date and time before the deadline (it will tell you what the deadline is). Then click 'Remind me later'.
- After reboot, run another scan and verify no patches are detected. If a patch is continually failing, please contact staff.