Hello everyone,
I’m new to BigFix and would like to consult with you about the logic of my patching policy. Before I start, please take into consideration that a work week in my country is Sunday-Thursday
So I have 2 policies:
-
Monthly policy that refreshes every 2nd Thursday - So the logic here is that I give BigFix a couple of days to implement patches because they’re probably not available as soon as Microsoft releases new patches on the 2nd Tuesday. 2 days after Patch Tuesday should be enough I hope.
1.1. The first schedule I put in this policy is “validation group” which consists of test hosts. The schedule is set for the 2nd Thursday (just like the refresh). So the logic here again is that after the refresh, those patches will be deployed on the same day. If it matters, the refresh is at 5AM and the deployment is at 5PM.
1.2. The second schedule is the “production group”. It’s set to the 3rd Monday which should give me enough time to notice if anything breaks in the test group. -
The other policy I have is the “Validation policy”. It refreshes on a daily.
2.1. The first schedule is deployed to a test group every Monday.
2.2. The other schedule is deployed to a test group every Wednesday.
The logic behind this policy is that some updates are becoming available outside of the “patch Tuesday” and I would like to test those “surprise updates” almost on a daily basis.
With all that being said, I have a few questions:
- What about “patch duration”? How long should I give it and what does it depend on?
- How do I handle reboots? I set the schedules to not reboot.
- Anything else I missed? I’ll be glad to receive tips and tricks on this subject. Please assume I know practically nothing about BigFix although I did go through the entire patching docs.
Thank you