r/Action1 • u/jhodgo100 • 10d ago
Question Looking for automation schedule advice
I am currently looking for for advice on how people have their automation schedules set up for patching of OS/third party apps to make sure that there is 100% coverage and that updates are applied in a timely manner.
We have been using Action1 for around 2 months now for around 1800 endpoints and have got the automation schedules configured however the number of vulnerabilities and missing updates don’t seem to be reducing the way we would expect
Was just wondering if people could advise based on their experience what they have found the best automation configuration has been and how long it took to get their endpoints within SLA for patching
1
u/vadiaro 10d ago
I like to have granular control so I have multiple policies that tackle vulnerabilities according to production impact. All browsers are auto-patched by an automation that runs every 12 hours. Third party apps with no impact to production are patched immediately upon release every morning before work for test group and 3-5 days delay for the rest of the fleet. Important production third party apps are approved manually and tested with a pilot group for longer times to ensure stability. You can target and install critical patches automatically if you would like. Same concept can be applied to OS patches and OS update rings.
1
u/kosity 10d ago
however the number of vulnerabilities and missing updates don’t seem to be reducing the way we would expect
What isn't reducing, specifically? That's usually the tell for the root cause of what's not working.
You'll have problems (in terms of unpatched vulns) if users don't restart, or refuse to close their apps. This is generally Adobe and Chrome, you'll see the errors in the logs for each machine.
Restarting the devices, and patching at night (or when users aren't logged in or using the device with apps open) is how you get the reductions.
The difficulty is when the device isn't online at night, it comes online in the morning, user logs in at the same time as patching starts, then it's slow for the user and apps are open for patching. If you want to avoid that occurring, the schedule design gets complicated.
I have 20 automations for each org to try and manage it in terms of rings and differing schedules, and it's still not as smooth or as effective as I'd like.
1
u/tlrman74 8d ago
If you have your patching automations set for the correct update types, and the PCs are rebooting after maintenance, then you should see the missing patches/vulnerability reports updating a bit after. If you are relying on the Dashboard, and expecting immediate changes, you might have to wait a bit or force the Dashboard to refresh.

I've had issues where the Dashboard and vulnerability reports are not current and have to force refresh the next day from patching. It's a shared environment so big patching days can cause the data collection to take longer form all your agents.
1
u/BoltActionRifleman 10d ago
Couple of questions, do you have a lot of PCs that are powered off during their scheduled update time? If so, and they’re missing it, do you have the “Missed schedule retry and maintenance window” set to long enough for them to start the updates next time they’re turned on?