# Patch Management with Hexnode UEM

What Hexnode Patch Management Does
----------------------------------

 [Patch management in Hexnode UEM](https://www.hexnode.com/mobile-device-management/help/patches-and-updates/) helps administrators identify, approve, deploy, and track operating system and application updates from a centralized console. The feature is designed to reduce security exposure from missing patches while giving IT teams control over when updates are installed and how restarts are handled.

 For Windows and macOS devices, Hexnode provides advanced patch-management capabilities that include OS update visibility, application patching, manual and automated deployment options, approval workflows, patch reports, and compliance-focused tracking. Windows patch management also includes a third-party application patch catalog maintained through the Hexnode Store.

- **OS updates:** Manage operating system patches and updates for supported Windows and macOS devices.
- **Application patches:** Deploy app updates where supported by the platform and Hexnode patch workflow.
- **Third-party patching:** Use Hexnode’s [curated patch catalog](https://www.hexnode.com/mobile-device-management/help/patch-catalog-curation-validation/) for supported third-party Windows applications.
- **Approval workflows:** Review and approve updates before deployment when approval is required.
- **Automation:** Configure [automated deployment rules](https://www.hexnode.com/mobile-device-management/help/patches-and-updates-deployment/) for recurring patch operations.
- **Reporting:** Use [patch reports](https://www.hexnode.com/mobile-device-management/help/patch-and-update-reports-in-hexnode-uem/) and [dashboard metrics](https://www.hexnode.com/mobile-device-management/help/patch-management-metrics/) to review missing updates, patch status, severity, and compliance posture.

How the Patch Lifecycle Works
-----------------------------

 Hexnode patch management follows a lifecycle that moves from discovery to compliance verification. This helps IT teams understand not only which updates are available, but also which devices need action, which updates are approved, and whether deployment succeeded.

Lifecycle StageWhat HappensAdmin OutcomeScanHexnode collects update-related information from enrolled devices and supported update sources.Admins gain visibility into available OS and app updates.Discover[Available patches](https://www.hexnode.com/mobile-device-management/help/viewing-available-patches/) are listed in the Patches and Updates section.Admins can review updates before deployment.ClassifyUpdates can be reviewed by attributes such as platform, severity, type, release date, approval status, KB number, CVSS data, and reboot requirement where available.Admins can prioritize critical or security-related patches.ApproveWhen update approval is required, admins approve selected patches before they are deployed.Only approved patches are deployed through approval-based automations.DeployAdmins deploy patches manually or through automated patch rules.Devices receive selected updates based on the configured deployment method.RebootRestart behavior can be controlled based on available platform and automation settings.Admins can reduce disruption by aligning restarts with maintenance windows where supported.ValidateAdmins review device status, patch status, and update activity after deployment.Failed, pending, or reboot-required devices can be identified for follow-up.ReportPatch reports and metrics provide compliance evidence.Security, IT operations, and audit teams can track patch posture across the fleet.Platform Support Matrix
-----------------------

 Hexnode patch and update capabilities vary by platform. Windows and macOS use Hexnode’s advanced patch-management engine. Other supported platforms use platform-native update controls and remote actions, so the level of patch automation, third-party patching, approval, rollback, and compliance reporting may differ. For a detailed capability-by-platform view, see the [Platform Support Matrix for Patch Management](https://www.hexnode.com/mobile-device-management/help/platform-support-matrix-for-patch-management/).

PlatformPatch Management ApproachWhat to Document or Validate Before DeploymentWindowsAdvanced patch engine for OS and supported app patching.Confirm update categories, app patch scope, maintenance windows, approval rules, restart behavior, and reporting requirements.macOSAdvanced patch engine for supported macOS patch workflows.Confirm OS update behavior, app patch scope, automation rules, technician notifications, restart behavior, and maintenance-window settings.LinuxPlatform-native update management rather than the Windows/macOS advanced patch engine.Validate available update actions, supported distributions, reporting scope, and whether the workflow meets internal compliance requirements.iOS and iPadOSNative Apple MDM software-update mechanisms.Validate supervision, ADE requirements, OS update deferral or scheduling settings, and user impact.AndroidNative Android Enterprise or OEM-supported OS update controls.Validate Device Owner requirements, OEM behavior, custom ROM or system-agent requirements where applicable, and OS update scheduling support.ChromeOSNative ChromeOS update controls.Validate ChromeOS policy behavior, update timing, and admin reporting requirements.Apple TV, tvOS, and visionOSNative Apple update-management behavior.Validate supported software-update actions, device supervision requirements, and available reporting fields.Manual vs Automated Patching
----------------------------

 Hexnode supports both manual and automated patch deployment for Windows and macOS. Manual deployment gives administrators direct control over which updates are installed and when. Automated deployment is better suited for recurring patch cycles, defined patch rules, and large-scale enforcement.

Deployment MethodBest ForAdmin ControlRecommended UseManual patchingTargeted updates, emergency fixes, pilot groups, and sensitive systems.High. Admins select updates and deployment targets directly.Use when testing patches, deploying to a small set of devices, or handling critical updates that need direct oversight. See [Manual Patch Deployment for Windows](https://www.hexnode.com/mobile-device-management/help/manual-patch-deployment-windows/) and [Deploy patches manually to macOS devices](https://www.hexnode.com/mobile-device-management/help/deploy-patches-manually-macos/).Automated patchingRecurring patch cycles, standard baselines, and large fleets.Rule-based. Admins configure automation criteria, schedules, target filters, and approval behavior.Use when the organization needs consistent patch enforcement with reduced manual effort. See [Automated Patch Management for Windows](https://www.hexnode.com/mobile-device-management/help/automated-patch-management-windows/) and [Automate Patch Deployment for Mac](https://www.hexnode.com/mobile-device-management/help/automate-patch-deployment-mac/).Approval-based automationSecurity-reviewed deployments and compliance-sensitive environments.Moderate to high. Updates must be approved before deployment when approval is required.Use when security or change-management teams must review updates before IT operations deploy them.Maintenance-window-based patchingDevices used during business hours or environments with strict uptime needs.Schedule-driven. Deployment and restart behavior can be aligned with defined windows where supported.Use to reduce user disruption and avoid patching during business-critical periods.Patch Approval and Role-Based Access
------------------------------------

 Patch approval helps organizations control which updates are allowed to deploy. In Hexnode, admins can approve updates individually or in bulk from the Patches and Updates section. If the **Require update approval** option is enabled in patch automation, only approved updates are deployed to devices under that automation.

 For enterprise environments, patch operations should be aligned with role-based responsibilities. A recommended operating model separates patch review, deployment, and reporting responsibilities among security, IT operations, and audit teams. Before publishing a role-based workflow internally, validate the exact technician role permissions available in your Hexnode tenant.

RoleTypical ResponsibilityRecommended Access PatternSecurity or vulnerability managementReview severity, CVE relevance, and business risk before approval.Access to review available patches and approve or revoke approval where permitted.IT operationsDeploy approved patches, configure schedules, and monitor installation status.Access to deployment workflows, automation configuration, device targeting, and rollback/remediation actions where permitted.Audit or complianceReview patch status, compliance posture, and historical evidence.Read-only or report-focused access where available.Maintenance Windows and Reboot Control
--------------------------------------

 Maintenance windows help administrators control when patch installation and related maintenance activities occur. This is important for reducing disruption, especially for users working during business hours or for devices used in operational environments.

 For supported Windows app update policies, Hexnode allows admins to update apps outside the device’s active hours or set a defined maintenance window. The minimum maintenance window for this workflow is four hours. Automated Windows patching also includes options related to update downloads and restarts, including overrides that can apply outside configured maintenance windows when enabled. For app-specific maintenance-window behavior, see [Configure app patches for Windows devices using Hexnode UEM](https://www.hexnode.com/mobile-device-management/help/configure-app-patches-for-windows-devices-using-hexnode-uem/).

ControlPurposeAdmin ConsiderationActive HoursHelps avoid update activity during user-active periods.Use for productivity-sensitive endpoints.Set maintenance windowDefines a specific time range for update activity.Use for planned patch cycles, off-hours maintenance, or scheduled fleet operations.Restart behaviorControls how and when devices restart after updates where supported.Review reboot options carefully to avoid disrupting users or business-critical workflows.Override settingsAllows selected update or restart behavior to bypass maintenance-window constraints where configured.Use only when the risk of delaying the update is greater than the disruption caused by immediate action.Patch Compliance and SLA Reporting
----------------------------------

 Hexnode provides [patch reports](https://www.hexnode.com/mobile-device-management/help/patch-and-update-reports-in-hexnode-uem/) and [dashboard metrics](https://www.hexnode.com/mobile-device-management/help/patch-management-metrics/) to help IT and security teams measure patch status across the managed fleet. These reports can support vulnerability management, operational reviews, and audit preparation by showing which devices are missing updates, which patches are installed, and which updates still require action.

 Hexnode’s patch and update reports include detailed patch attributes such as name, description, product, missing devices, installed devices, platform, severity, release date, KB number, update classification, identifier, type, vendor, approval status, reboot requirement, uninstallation support, CVSS v3.1, applicable devices, and patch compliance percentage where available.

Reporting AreaWhat It Helps AnswerMissing updatesWhich devices or products still require patches?Installed updatesWhich devices have already received the update?SeverityWhich updates should be prioritized based on severity?Approval statusWhich updates are approved, pending approval, or revoked?Reboot statusWhich updates require device restart or follow-up?CVSS and vulnerability contextWhich updates are associated with higher vulnerability risk where CVSS data is available?Patch compliance percentageHow close is the fleet to the organization’s patch baseline or SLA target? For SLA-based tracking, see [Enterprise Patch Compliance: Using Hexnode Metrics for SLA Enforcement](https://www.hexnode.com/mobile-device-management/help/auditing-patch-compliance/).

Third-Party Patch Catalog
-------------------------

 Hexnode’s Windows patch-management has a dual-layer approach for Windows endpoints: OS-level updates and a third-party application catalog. The Hexnode Store maintains a catalog of more than 1,300 applications for third-party patching.

 The [Hexnode Patch Catalog](https://www.hexnode.com/mobile-device-management/help/patch-catalog-curation-validation/) is the content layer behind app patch management. It describes how application titles enter the catalog, how new versions are detected, and how validated packages become available for deployment. Hexnode’s catalog process monitors supported vendors’ release channels, such as official update feeds, release notes, and published manifests.

 Not every application or update type should be assumed to be covered. Admins should verify whether a required application is present in the catalog, whether the patch is supported for the target platform, and whether internal testing is required before broad deployment.

Catalog AreaWhat to VerifySupported applicationsConfirm whether the required third-party application is available in the Hexnode Store or patch catalog.Version availabilityConfirm that the required version or patch has been validated and is available for deployment.Platform supportConfirm whether the catalog-based patch workflow applies to the target OS and app type.Deployment scopeDecide whether to update all supported apps or only targeted applications.ExclusionsIdentify apps that require manual handling, vendor-specific tools, custom packaging, or additional validation.Common Deployment Scenarios
---------------------------

 Hexnode patch management can support different rollout strategies depending on risk, urgency, and fleet size. The right workflow depends on whether the organization needs tight manual control, automated baseline enforcement, phased testing, or emergency remediation.

ScenarioRecommended Hexnode ApproachWhy It HelpsPilot group deploymentDeploy patches manually or through a limited automation target group first.Helps validate update behavior before broad rollout.Phased rolloutUse [deployment rings](https://www.hexnode.com/mobile-device-management/help/deployment-rings-hexnode-uem/) or staged targets to roll out patches in controlled waves.Reduces risk by expanding deployment only after earlier groups succeed.Emergency CVE remediationPrioritize patches by severity, CVE relevance, or critical update classification where available. See [Patch by CVE: CVE-Driven Patch Automation](https://www.hexnode.com/mobile-device-management/help/patch-by-cve-automating-vulnerability-remediation-across-enterprise-fleets/).Helps address high-risk vulnerabilities faster than a normal patch cycle.Monthly patch cycleUse automated patching with approval and maintenance windows.Creates a repeatable operating model for regular patch deployment.App-only patchingConfigure app update policies for supported applications and define whether to update all apps or targeted apps only.Keeps business-critical apps current without changing OS update behavior.Compliance audit preparationUse patch reports, dashboard metrics, and missing-update views to collect evidence.Helps demonstrate patch status and remediation progress to auditors or internal stakeholders.Limitations and Validation Notes
--------------------------------

 Patch behavior depends on platform capabilities, enrollment state, update source, device connectivity, and the type of patch being deployed. Before publishing internal deployment standards, validate the exact behavior in a pilot environment.

- Do not assume that every platform supports the same advanced patch-management workflow as Windows and macOS.
- Do not assume every third-party application is available in the Hexnode patch catalog.
- Do not assume every patch can be rolled back. Some updates cannot be reversed if the operating system or vendor does not provide a rollback path. See [Patch Rollback and Failed-Update Remediation](https://www.hexnode.com/mobile-device-management/help/patch-rollback/).
- Do not assume offline devices will update during a missed maintenance window. Validate how the next available window behaves for the relevant policy.
- Do not deploy critical patches broadly without testing when business-critical applications or production devices may be affected.