Already a NinjaOne customer? Log in to view more guides and the latest updates.

Windows Patch Management: Approving, Rejecting, Uninstalling, and Updating Software

Topic

This article describes the process for patching Windows endpoints via NinjaOne's patch management features.

For general details about leveraging patch management in NinjaOne, refer to our Patching Resource Catalogue.

Environment

NinjaOne patch management

Description

In NinjaOne's Windows patch management, you can use the Control mode to either approve or reject patches before a scan detects them. If you prefer, you can also manually approve or reject patches by Knowledge Base (KB) number or patch ID after the scan identifies them. Depending on your policy settings, NinjaOne will categorize the patch as Approved, Rejected, or Pending.

Select a topic to continue.

How NinjaOne Prioritizes Approvals and Rejections at Different Levels

There are four different levels at which NinjaOne could approve or reject a patch:

  • Device-level overrides
  • Policy-level overrides
  • Global preemptive approvals/rejections
  • Policy-level automated approvals/rejections

NinjaOne prioritizes the closest level to the device in the patch approval process. Device-level overrides take precedence, followed by policy-level overrides, global approvals or rejections, and automated approvals or rejections at the policy level.

When there are clashes between the Knowledge Base (KB) and the Patch ID at the same level (device, policy, or global), NinjaOne prioritizes patch rejections above all else. If the KB rejects a patch but the Patch ID approves it, NinjaOne will reject the patch. Similarly, if the Patch ID rejects a patch but the KB approves it, NinjaOne will also reject the patch.

For an overview of various avenues in the patch approval process, refer to the following diagram.

Figure 1: Patch approval scenarios (click to enlarge)

Preemptively Approving or Rejecting Patches

Only system administrators can preemptively approve or reject patches at the global level.

You can only preemptively approve or reject patches by KB. You cannot preemptively approve or reject a patch without an associated KB (such as a driver).

Preemptively Approving or Rejecting OS Patches at the Global Level

To approve or reject a patch at the global level:

  1. Navigate to the NinjaOne Patching App at AdministrationAppsInstalledNinjaOne Patching.
Figure 2: NinjaOne Apps Administration (click to enlarge)
  1. Click the Global OS approve/reject tab, then click Add.
Figure 3: Patching App → Global OS approve/reject → Add (click to enlarge)
  1. Enter the KB number for the patch and select Approve or Reject. Refer to Automate Patching Approval / Rejection for more information about patching options.

Preemptively Approving or Rejecting OS Patches at the Policy Level

You can approve or reject a patch at the policy level by using the following workflow.

  1. In NinjaOne, navigate to Administration → Policies and select a Windows policy.
  2. The policy's configuration options will open. Click OS Patching and ensure that Enable OS patching is active.
Figure 5: The Enable Policy slider (click to enlarge)
  1. Scroll to the Approval overrides card and click Add.
  2. Click the link listing the current number of approved and rejected patches, as shown in the following screenshot.
Figure 6: Approved and rejected patch overrides (click to enlarge)
  1. The Edit patching custom approvals window will appear. Use the search field to search for the patch, or enter its KB number, then use the Status menu to select Auto approve or reject.
Figure 7: Adding an override (click to enlarge)

Automatically Approving Patches Based on a Designated Number of Days

In the NinjaOne Policy Editor, you can automatically approve Windows patches after a specific number of days. You can set a limit of up to 30 days for all updates. You can also approve feature updates for up to 365 days. This delayed approval helps reduce the risk of potentially faulty patches. You can configure each patch type with its own unique delay period.

When you set a patch to Approve After X Day(s), the countdown starts from the release date, not from when NinjaOne identifies the patch.

Follow these instructions to automatically approve patches after a specified number of days.

  1. In NinjaOne, navigate to Administration → Policies and select a Windows policy.
  2. The policy's configuration options will open. Click OS Patching and ensure that Enable OS patching is active. Scroll to the Approvals section and click Edit. NinjaOne segments these sections into Security update approvals, General approvals, and Advanced approvals. Refer to NinjaOne Patching: Windows OS Patch Management to learn more about patch approval categories.
Figure 9: Update approval sections (click to enlarge)

Manually Approving or Rejecting Patches

You can manually approve or reject patches via the dashboard. To learn more, refer to our Dashboards: Patch Management article. The following approval and rejection options are available.

Approval/Rejection OptionsDescription
Approve/Reject for this deviceSelect this category to create a device-level override for a single device using the Patch ID to target the correct path. You can access this option when you view a pending, approved, or rejected patch from the device level.
Approve/Reject for this device by KBSelect this category to create a device-level override for a single device. You can access this option when you view a pending, approved, or rejected patch from the device level.
Approve/Reject This option uses the Patch ID to target the correct path. You might find multiple patches with the same KB number, but each will have its own unique Patch ID. 
Approve/Reject by KBKB labels on Microsoft patches indicate a specific update. Multiple patches can share the same KB label. If you approve or reject a patch based on its KB, you automatically approve or reject all patches associated with that KB.
Approve/Reject for policy/policiesThis option creates a policy-level override for the policies linked to the devices with a pending, approved, or rejected patch. You can choose this workflow when viewing a patch on the system dashboard, the organization dashboard, or at the device level.

Manually Rejecting or Approving Patches in the Pending State

If a patch is waiting for approval or rejection, decide whether to approve or reject it. Determine if the patch logic should use the KB number or Patch ID, and specify whether it applies to the device or the policy:

  1. In NinjaOne, navigate to the Dashboard page.
  2. Move your mouse over the Devices tab.
  3. Select Approvals → Pending.
  4. Click the device name you'd like to manage.
  5. On the device's Overview page, scroll to the Health section.
  6. Click the downward-pointing chevron next to the patch to be approved or rejected.
  7. In the menu, select whether you want to reject or approve the patch and whether to do so by KB or Patch ID for the device or the policy.
Figure 11: Approving or rejecting a patch (click to enlarge)

Manually Scanning for or Applying Updates

NinjaOne can initiate an on-demand patch scan and update cycle on any endpoint. NinjaOne installs all available updates and will reboot the device if necessary. If a device hasn't received a patch update in over 60 days, it might need several reboots to apply all updates because some updates depend on NinjaOne installing others first.

To manually scan for or apply updates to a single device:

  1. In NinjaOne, navigate to the Devices page.
  2. Click the device name you'd like to manage.
  3. Move your mouse over the Run option in the menu at the top of the list.
  4. Select Patching, then click OS scan to scan for new patches or OS update to apply existing patches.
Figure 12: Scanning or updating an individual device (click to enlarge)

To run an ad-hoc scan or update on multiple devices:

  1. In NinjaOne, navigate to the Devices page.
  2. Select the checkboxes next to the devices you'd like to include in the scan or update cycle.
  3. Move your mouse over the Run option in the menu at the top of the list.
  4. Select Patching, then click OS scan to scan for new patches or OS update to apply existing patches.
Figure 13: Scanning or updating multiple devices (click to enlarge)
  1. Ensure that Windows patch management is active for the policy applicable to your devices and verify that they are online. The Additional Filters option lets you quickly locate these devices.
Figure 14: Additional Filters (click to enlarge)

You can also see the Windows patch status at the device level. If you have patches set to manual approval or rejection, you can take those actions from the Overview tab on the device dashboard.

Figure 15: OS Patch Management status (click to enlarge)

Uninstalling Patches

You can uninstall individual patches from the device detail page. To do so, perform the following steps.

  1. In NinjaOne, navigate to the Devices page.
  2. Click the device name you'd like to manage.
  3. On the device's Overview page, move your cursor over the Patching menu.
  4. Select OS patches. Then, click Installed.
Figure 16: Patching → OS patches → Installed (click to enlarge)
  1. Move your cursor over the patch row and click the actions menu.
  2. Click Uninstall.
Figure 17: Uninstall a patch (click to enlarge)
Some patches do not support uninstallation. You can verify whether a patch supports uninstallation by checking the corresponding Uninstall Supported column for a value of Yes.
Figure 18: Uninstall supported (click to enlarge)

FAQ

Next Steps