Hi BigFix masters,
I am stuck in an very critical issue raised by our security Team.
Scenario -
Basically in BigFix platform, when you deploy a patch and if a restart is required for that patch we will be able to see the action status as “Pending Restart” which is the default behavior of the BigFix platform.
Our environment consists of servers and totally we have 2000 plus Windows servers.
Now after deploying the patches on the servers, we have a policy that the reboot of the servers will be taken when we get the approval from the application team (which is at the end of the month), thus patches are deployed in the 2nd week of the month but the reboot of servers are taken at the month end. My security team generates the patching compliance report in the middle of the month before taking the reboot of the servers as they have to submit the patch compliance report to our management.
Now the main issue comes -
When the security team generates the patch compliance report, the systems which are still under pending restart state in the report they show as remediated and 100% compliant even the restart of the server has not happened.
Sometime what happens is after rebooting the server the patch gets failed on the server and now there is difference in the compliance report, where our management gets pissed saying as why there is difference in the report.
Now my security team has started comparing BigFix tool with other tool, where in other tool after deploying the patches on the server until the server is rebooted the patch compliance of the system still shows as not compliant.
My management is demanding the same behavior from BigFix application.
To summaries the issue -
my management is saying that once you deploy the patch on any server and if the server is under pending restart state in the Patch compliance report it should not say as 100% remediated it should still show as applicable, and once the system is rebooted and the patch is applied successfully on the system then the patch compliance report should say as 100% remediated.
Can any one help me in achieving the same. I have tried applying the client setting _BESClient_WindowsOS_BypassPendingRestartRelevance on the server and have tested the same but it is not working properly.
Any help in achieving the same will be helpful,
Thanks in advance,
Regards,
kk