Category filter
Patch Management with Hexnode UEM
What Hexnode Patch Management Does
Patch management in Hexnode UEM helps administrators identify, approve, deploy, and track operating system and application updates from a centralized console. The feature is designed to reduce security exposure from missing patches while giving IT teams control over when updates are installed and how restarts are handled.
For Windows and macOS devices, Hexnode provides advanced patch-management capabilities that include OS update visibility, application patching, manual and automated deployment options, approval workflows, patch reports, and compliance-focused tracking. Windows patch management also includes a third-party application patch catalog maintained through the Hexnode Store.
- OS updates: Manage operating system patches and updates for supported Windows and macOS devices.
- Application patches: Deploy app updates where supported by the platform and Hexnode patch workflow.
- Third-party patching: Use Hexnode’s curated patch catalog for supported third-party Windows applications.
- Approval workflows: Review and approve updates before deployment when approval is required.
- Automation: Configure automated deployment rules for recurring patch operations.
- Reporting: Use patch reports and dashboard metrics to review missing updates, patch status, severity, and compliance posture.
How the Patch Lifecycle Works
Hexnode patch management follows a lifecycle that moves from discovery to compliance verification. This helps IT teams understand not only which updates are available, but also which devices need action, which updates are approved, and whether deployment succeeded.
| Lifecycle Stage | What Happens | Admin Outcome |
|---|---|---|
| Scan | Hexnode collects update-related information from enrolled devices and supported update sources. | Admins gain visibility into available OS and app updates. |
| Discover | Available patches are listed in the Patches and Updates section. | Admins can review updates before deployment. |
| Classify | Updates can be reviewed by attributes such as platform, severity, type, release date, approval status, KB number, CVSS data, and reboot requirement where available. | Admins can prioritize critical or security-related patches. |
| Approve | When update approval is required, admins approve selected patches before they are deployed. | Only approved patches are deployed through approval-based automations. |
| Deploy | Admins deploy patches manually or through automated patch rules. | Devices receive selected updates based on the configured deployment method. |
| Reboot | Restart behavior can be controlled based on available platform and automation settings. | Admins can reduce disruption by aligning restarts with maintenance windows where supported. |
| Validate | Admins review device status, patch status, and update activity after deployment. | Failed, pending, or reboot-required devices can be identified for follow-up. |
| Report | Patch reports and metrics provide compliance evidence. | Security, IT operations, and audit teams can track patch posture across the fleet. |
Platform Support Matrix
Hexnode patch and update capabilities vary by platform. Windows and macOS use Hexnode’s advanced patch-management engine. Other supported platforms use platform-native update controls and remote actions, so the level of patch automation, third-party patching, approval, rollback, and compliance reporting may differ. For a detailed capability-by-platform view, see the Platform Support Matrix for Patch Management.
| Platform | Patch Management Approach | What to Document or Validate Before Deployment |
|---|---|---|
| Windows | Advanced patch engine for OS and supported app patching. | Confirm update categories, app patch scope, maintenance windows, approval rules, restart behavior, and reporting requirements. |
| macOS | Advanced patch engine for supported macOS patch workflows. | Confirm OS update behavior, app patch scope, automation rules, technician notifications, restart behavior, and maintenance-window settings. |
| Linux | Platform-native update management rather than the Windows/macOS advanced patch engine. | Validate available update actions, supported distributions, reporting scope, and whether the workflow meets internal compliance requirements. |
| iOS and iPadOS | Native Apple MDM software-update mechanisms. | Validate supervision, ADE requirements, OS update deferral or scheduling settings, and user impact. |
| Android | Native Android Enterprise or OEM-supported OS update controls. | Validate Device Owner requirements, OEM behavior, custom ROM or system-agent requirements where applicable, and OS update scheduling support. |
| ChromeOS | Native ChromeOS update controls. | Validate ChromeOS policy behavior, update timing, and admin reporting requirements. |
| Apple TV, tvOS, and visionOS | Native Apple update-management behavior. | Validate supported software-update actions, device supervision requirements, and available reporting fields. |
Manual vs Automated Patching
Hexnode supports both manual and automated patch deployment for Windows and macOS. Manual deployment gives administrators direct control over which updates are installed and when. Automated deployment is better suited for recurring patch cycles, defined patch rules, and large-scale enforcement.
| Deployment Method | Best For | Admin Control | Recommended Use |
|---|---|---|---|
| Manual patching | Targeted updates, emergency fixes, pilot groups, and sensitive systems. | High. Admins select updates and deployment targets directly. | Use when testing patches, deploying to a small set of devices, or handling critical updates that need direct oversight. See Manual Patch Deployment for Windows and Deploy patches manually to macOS devices. |
| Automated patching | Recurring patch cycles, standard baselines, and large fleets. | Rule-based. Admins configure automation criteria, schedules, target filters, and approval behavior. | Use when the organization needs consistent patch enforcement with reduced manual effort. See Automated Patch Management for Windows and Automate Patch Deployment for Mac. |
| Approval-based automation | Security-reviewed deployments and compliance-sensitive environments. | Moderate to high. Updates must be approved before deployment when approval is required. | Use when security or change-management teams must review updates before IT operations deploy them. |
| Maintenance-window-based patching | Devices used during business hours or environments with strict uptime needs. | Schedule-driven. Deployment and restart behavior can be aligned with defined windows where supported. | Use to reduce user disruption and avoid patching during business-critical periods. |
Patch Approval and Role-Based Access
Patch approval helps organizations control which updates are allowed to deploy. In Hexnode, admins can approve updates individually or in bulk from the Patches and Updates section. If the Require update approval option is enabled in patch automation, only approved updates are deployed to devices under that automation.
For enterprise environments, patch operations should be aligned with role-based responsibilities. A recommended operating model separates patch review, deployment, and reporting responsibilities among security, IT operations, and audit teams. Before publishing a role-based workflow internally, validate the exact technician role permissions available in your Hexnode tenant.
| Role | Typical Responsibility | Recommended Access Pattern |
|---|---|---|
| Security or vulnerability management | Review severity, CVE relevance, and business risk before approval. | Access to review available patches and approve or revoke approval where permitted. |
| IT operations | Deploy approved patches, configure schedules, and monitor installation status. | Access to deployment workflows, automation configuration, device targeting, and rollback/remediation actions where permitted. |
| Audit or compliance | Review patch status, compliance posture, and historical evidence. | Read-only or report-focused access where available. |
Maintenance Windows and Reboot Control
Maintenance windows help administrators control when patch installation and related maintenance activities occur. This is important for reducing disruption, especially for users working during business hours or for devices used in operational environments.
For supported Windows app update policies, Hexnode allows admins to update apps outside the device’s active hours or set a defined maintenance window. The minimum maintenance window for this workflow is four hours. Automated Windows patching also includes options related to update downloads and restarts, including overrides that can apply outside configured maintenance windows when enabled. For app-specific maintenance-window behavior, see Configure app patches for Windows devices using Hexnode UEM.
| Control | Purpose | Admin Consideration |
|---|---|---|
| Active Hours | Helps avoid update activity during user-active periods. | Use for productivity-sensitive endpoints. |
| Set maintenance window | Defines a specific time range for update activity. | Use for planned patch cycles, off-hours maintenance, or scheduled fleet operations. |
| Restart behavior | Controls how and when devices restart after updates where supported. | Review reboot options carefully to avoid disrupting users or business-critical workflows. |
| Override settings | Allows selected update or restart behavior to bypass maintenance-window constraints where configured. | Use only when the risk of delaying the update is greater than the disruption caused by immediate action. |
Patch Compliance and SLA Reporting
Hexnode provides patch reports and dashboard metrics to help IT and security teams measure patch status across the managed fleet. These reports can support vulnerability management, operational reviews, and audit preparation by showing which devices are missing updates, which patches are installed, and which updates still require action.
Hexnode’s patch and update reports include detailed patch attributes such as name, description, product, missing devices, installed devices, platform, severity, release date, KB number, update classification, identifier, type, vendor, approval status, reboot requirement, uninstallation support, CVSS v3.1, applicable devices, and patch compliance percentage where available.
| Reporting Area | What It Helps Answer |
|---|---|
| Missing updates | Which devices or products still require patches? |
| Installed updates | Which devices have already received the update? |
| Severity | Which updates should be prioritized based on severity? |
| Approval status | Which updates are approved, pending approval, or revoked? |
| Reboot status | Which updates require device restart or follow-up? |
| CVSS and vulnerability context | Which updates are associated with higher vulnerability risk where CVSS data is available? |
| Patch compliance percentage | How close is the fleet to the organization’s patch baseline or SLA target? |
For SLA-based tracking, see Enterprise Patch Compliance: Using Hexnode Metrics for SLA Enforcement.
Third-Party Patch Catalog
Hexnode’s Windows patch-management has a dual-layer approach for Windows endpoints: OS-level updates and a third-party application catalog. The Hexnode Store maintains a catalog of more than 1,300 applications for third-party patching.
The Hexnode Patch Catalog is the content layer behind app patch management. It describes how application titles enter the catalog, how new versions are detected, and how validated packages become available for deployment. Hexnode’s catalog process monitors supported vendors’ release channels, such as official update feeds, release notes, and published manifests.
Not every application or update type should be assumed to be covered. Admins should verify whether a required application is present in the catalog, whether the patch is supported for the target platform, and whether internal testing is required before broad deployment.
| Catalog Area | What to Verify |
|---|---|
| Supported applications | Confirm whether the required third-party application is available in the Hexnode Store or patch catalog. |
| Version availability | Confirm that the required version or patch has been validated and is available for deployment. |
| Platform support | Confirm whether the catalog-based patch workflow applies to the target OS and app type. |
| Deployment scope | Decide whether to update all supported apps or only targeted applications. |
| Exclusions | Identify apps that require manual handling, vendor-specific tools, custom packaging, or additional validation. |
Common Deployment Scenarios
Hexnode patch management can support different rollout strategies depending on risk, urgency, and fleet size. The right workflow depends on whether the organization needs tight manual control, automated baseline enforcement, phased testing, or emergency remediation.
| Scenario | Recommended Hexnode Approach | Why It Helps |
|---|---|---|
| Pilot group deployment | Deploy patches manually or through a limited automation target group first. | Helps validate update behavior before broad rollout. |
| Phased rollout | Use deployment rings or staged targets to roll out patches in controlled waves. | Reduces risk by expanding deployment only after earlier groups succeed. |
| Emergency CVE remediation | Prioritize patches by severity, CVE relevance, or critical update classification where available. See Patch by CVE: CVE-Driven Patch Automation. | Helps address high-risk vulnerabilities faster than a normal patch cycle. |
| Monthly patch cycle | Use automated patching with approval and maintenance windows. | Creates a repeatable operating model for regular patch deployment. |
| App-only patching | Configure app update policies for supported applications and define whether to update all apps or targeted apps only. | Keeps business-critical apps current without changing OS update behavior. |
| Compliance audit preparation | Use patch reports, dashboard metrics, and missing-update views to collect evidence. | Helps demonstrate patch status and remediation progress to auditors or internal stakeholders. |
Limitations and Validation Notes
Patch behavior depends on platform capabilities, enrollment state, update source, device connectivity, and the type of patch being deployed. Before publishing internal deployment standards, validate the exact behavior in a pilot environment.
- Do not assume that every platform supports the same advanced patch-management workflow as Windows and macOS.
- Do not assume every third-party application is available in the Hexnode patch catalog.
- Do not assume every patch can be rolled back. Some updates cannot be reversed if the operating system or vendor does not provide a rollback path. See Patch Rollback and Failed-Update Remediation.
- Do not assume offline devices will update during a missed maintenance window. Validate how the next available window behaves for the relevant policy.
- Do not deploy critical patches broadly without testing when business-critical applications or production devices may be affected.
Frequently Asked Questions
Can Hexnode patch third-party applications?
Yes, Hexnode supports third-party application patching where the app and platform are supported by the Hexnode patch workflow. For Windows, Hexnode has a third-party application catalog maintained through the Hexnode Store with more than 1,300 applications. Admins should verify whether a specific application is available in the catalog before planning deployment.
Can Hexnode enforce maintenance windows for patch deployment?
Hexnode supports maintenance-window-based patch scheduling for supported Windows and macOS patch workflows. For Windows app updates, Hexnode provides options to update outside Active Hours or during a defined maintenance window, with a minimum window requirement for that workflow.
Can Hexnode report CVEs?
Hexnode patch reports include CVSS v3.1 and patch-related metadata where available. Hexnode also supports CVE-driven patch automation for supported Windows and macOS workflows. Admins should verify whether CVE data is available for the specific product, update, or catalog title being reviewed.
Does Hexnode support both manual and automated patching?
Yes. Hexnode supports manual and automated patch deployment for Windows and macOS. Manual patching is useful for selective deployment and testing, while automated patching is useful for recurring patch cycles and larger fleets.
Which platforms use Hexnode’s advanced patch engine?
Hexnode’s advanced patch engine exists for Windows and macOS currently. Other platforms, including Linux, iOS, iPadOS, tvOS, visionOS, Android, and ChromeOS, rely on native update-management mechanisms rather than the same advanced patch engine.
Can patches be approved before deployment?
Yes. Hexnode allows admins to approve updates individually or in bulk. If Require update approval is enabled in a patch automation, only approved updates are deployed through that automation.
Can Hexnode show patch compliance?
Yes. Hexnode provides patch reports and metrics that help admins review missing updates, installed updates, severity, approval status, reboot requirements, applicable devices, and patch compliance percentage where available.
Can every patch be rolled back?
No. Patch rollback depends on whether the operating system or vendor provides a supported removal path. Some update types cannot be reversed after installation. Admins should review rollback support and test critical updates before broad deployment.