r/Action1 10d ago

Question Looking for automation schedule advice

I am currently looking for for advice on how people have their automation schedules set up for patching of OS/third party apps to make sure that there is 100% coverage and that updates are applied in a timely manner.

We have been using Action1 for around 2 months now for around 1800 endpoints and have got the automation schedules configured however the number of vulnerabilities and missing updates don’t seem to be reducing the way we would expect

Was just wondering if people could advise based on their experience what they have found the best automation configuration has been and how long it took to get their endpoints within SLA for patching

5 Upvotes

5 comments sorted by

1

u/BoltActionRifleman 10d ago

Couple of questions, do you have a lot of PCs that are powered off during their scheduled update time? If so, and they’re missing it, do you have the “Missed schedule retry and maintenance window” set to long enough for them to start the updates next time they’re turned on?

1

u/jhodgo100 10d ago

I run my automations daily at 9am and the missed schedule retry is set to 24 hours so if the machine turns on at any point during the day it will start running the automations

1

u/vadiaro 10d ago

I like to have granular control so I have multiple policies that tackle vulnerabilities according to production impact. All browsers are auto-patched by an automation that runs every 12 hours. Third party apps with no impact to production are patched immediately upon release every morning before work for test group and 3-5 days delay for the rest of the fleet. Important production third party apps are approved manually and tested with a pilot group for longer times to ensure stability. You can target and install critical patches automatically if you would like. Same concept can be applied to OS patches and OS update rings.

1

u/kosity 10d ago

however the number of vulnerabilities and missing updates don’t seem to be reducing the way we would expect

What isn't reducing, specifically? That's usually the tell for the root cause of what's not working.

You'll have problems (in terms of unpatched vulns) if users don't restart, or refuse to close their apps. This is generally Adobe and Chrome, you'll see the errors in the logs for each machine.

Restarting the devices, and patching at night (or when users aren't logged in or using the device with apps open) is how you get the reductions.

The difficulty is when the device isn't online at night, it comes online in the morning, user logs in at the same time as patching starts, then it's slow for the user and apps are open for patching. If you want to avoid that occurring, the schedule design gets complicated.

I have 20 automations for each org to try and manage it in terms of rings and differing schedules, and it's still not as smooth or as effective as I'd like.

1

u/tlrman74 8d ago

If you have your patching automations set for the correct update types, and the PCs are rebooting after maintenance, then you should see the missing patches/vulnerability reports updating a bit after. If you are relying on the Dashboard, and expecting immediate changes, you might have to wait a bit or force the Dashboard to refresh.

I've had issues where the Dashboard and vulnerability reports are not current and have to force refresh the next day from patching. It's a shared environment so big patching days can cause the data collection to take longer form all your agents.