Patch window coordination
Sequences reboots so the same host is patched once, in dependency order, without a maintenance page.
Tools
Microsoft Intune, Jamf, Qualys, ServiceNow Security Operations
Outcomes
Reboot backlog at zero each week • Dependency order respected in every window • Patch coverage reported per business unit
Documentation
Instruction-ready detail below
Patching is scheduled per team, so a server gets restarted twice in one night and a domain controller is patched after the machines that depend on it. The hosts that need a restart are the ones nobody owns, so they sit unpatched for weeks while the report still says the patch was deployed.
The workflow builds the window. It reads the list of hosts that are past their patch deadline, separates the ones that can patch while running from the ones that need a restart, and orders the rest by dependency rather than by whichever team replied first. Domain controllers and file servers go first, application servers next, workstations last. Each batch gets an owner, a time and a confirmation step, and a host already restarted that night is not queued again. The window closes with a coverage report by business unit instead of a percentage of the fleet, so the gap is named.
A human approves the window, the order, and any host that will be left out of it.