HardenCoverage

Patch window coordination

Sequences reboots so the same host is patched once, in dependency order, without a maintenance page.

Tools

Microsoft Intune, Jamf, Qualys, ServiceNow Security Operations

Outcomes

Reboot backlog at zero each week • Dependency order respected in every window • Patch coverage reported per business unit

Documentation

Instruction-ready detail below

Patching is scheduled per team, so a server gets restarted twice in one night and a domain controller is patched after the machines that depend on it. The hosts that need a restart are the ones nobody owns, so they sit unpatched for weeks while the report still says the patch was deployed.

The workflow builds the window. It reads the list of hosts that are past their patch deadline, separates the ones that can patch while running from the ones that need a restart, and orders the rest by dependency rather than by whichever team replied first. Domain controllers and file servers go first, application servers next, workstations last. Each batch gets an owner, a time and a confirmation step, and a host already restarted that night is not queued again. The window closes with a coverage report by business unit instead of a percentage of the fleet, so the gap is named.

A human approves the window, the order, and any host that will be left out of it.

Automations

Choose the setup that matches your tools.

Problem this workflow solves

Patching is scheduled per team, so a server gets restarted twice in one night and a domain controller is patched after the machines that depend on it. The hosts that need a restart are the ones nobody owns, so they sit unpatched for weeks while the report still says the patch was deployed.

Download

Start with one instruction file.

Download the app and begin with drafts and checklists before you write anything back.

  • •Plain-language instructions
  • •Runs on your machine
  • •Works with your existing setup
  • •Reviewable activity history
Download