Categories

Windows Update Patch Policies and Schedules

You are here:

This document outlines BRITECITY’s default patching categories, schedules, and approval policies for all managed Windows Workstations and Servers. The patching strategy balances proactive security with operational stability, using severity- and classification-based rules for deployment.

See also: Daytime Patching

Patch Policy Overview

Patching policies are tailored to device type and structured to control:

  • When and how updates are installed
  • Reboot logic and whether user interaction is required
  • Severity-based installation logic
  • Classification-specific rules (e.g., Drivers, Feature Packs)
  • Deferred feature and quality updates based on ConnectWise NOC release timing

 

Windows Update Schedules & Policies

Machine CategoryDownload & Install ScheduleReboot WindowUser NotificationUpdate Assistant ModeCreate Restore PointBaseline Patch EnforcementFeature/Quality Update Deferment
WorkstationsNightly, 12–4 AMSundays 8 PM–12 AMAsk > 24hr wait → Auto-allow (max 4×4hr snoozes)Managed – UI DisabledYesYesDeferred until released by ConnectWise NOC
Server HostsSaturdays, 12–4 AMSaturdays, 5–6 AMNo user notificationManagedYesYesDeferred until released by ConnectWise NOC
Servers (VMs / Bare Metal)Sundays, 12–4 AMSundays, 5–6 AMNo user notificationManagedYesYesDeferred until released by ConnectWise NOC

Windows Update Approval Matrix

Patch CategoryWorkstationsServers
Security UpdatesDeploy (NOC Approved)Deploy (NOC Approved)
Critical UpdatesDeploy AllDeploy Al
UpdatesDeploy AllDeploy All
Feature UpdatesDeploy AllDeploy All
DriversDo Not DeployDo Not Deploy
Feature PacksDeploy AllDo Not Deploy
Update RollupsDeploy AllDeploy All
ToolsDeploy AllDeploy All
OS UpgradeOffOff
Active Directory Rights Management ClientDenySeverity-based
ASP.Net Web FrameworksApproveSeverity-based
Bing Bar / Desktop / IMEDenyDeny
CAPICOMDenyApprove
Definition UpdatesApproveApprove
Exchange ServerDenyApprove
Microsoft Dynamics / Lync ServerDenySeverity-based
Microsoft SQL Server / WorksDenyApprove
Microsoft Office / Report ViewerApproveApprove
Silverlight / Service PacksApproveSeverity-based
Skype for WindowsApproveDeny
System CenterDenySeverity-based

Severity-Based Settings

Severity RatingWorkstationsServers
UnspecifiedApproveApprove
LowApproveApprove
ModerateApproveApprove
ImportantApproveApprove
CriticalApproveApprove
CVSS Score > 1ApproveApprove
Jump to...