Approving Microsoft Patches for Installation
By default, patches are set to beย Notย Approved. If you don't approve a patch, it remains asย Notย Approved, which means it is effectively put on hold or ignored. In this case, the update will remain in the default list of available updates, but will not be installed.
You can approve the installation of updates for all the computers in your network or for different approval groups.
In the patches list, you can research what new Microsoft updates are available and approve them for use at your customer sites.
To see a description of the patch approval statuses that you can search on, see Viewing an Overview of Microsoft Patch Management.
In Service Center, clickย Patch Managementย >ย Patchย Approval.
To filter the patch list to display the patches you want to see, click theย Advanced Filteringย iconย
and do any of the following:
Choose an option inย Products andย Classifications.
Choose an option inย Patchย Supersedence.
Choose an option inย Releaseย Date.
Type a patch name or part of a patch name inย Titleย Contains.
Choose a patch status inย Status.
Choose an approval status inย Approval.
Choose a group inย Approvalย Group.
You can combine these filters to focus the list of patches. For example, if you choose a group in Approval Group and the status of Not Approved in Approval, you see a list of patches that have not been approved for that Approval Group. Or, if you choose the group All Computers in Approval Group and the status Needed in Approval, you see all the patches that are needed for a certain approval group.
Clickย Apply.
Do one of the following:
To select one patch at a time, select the check box of each patch for which you want to change the default approval setting.
To select all patches, select the check box in the column header.
Clickย Changeย Approvals.
Do one of the following:
To approve the update for all computers, from theย Approvalย list selectย Install.
To approve the update for a specific approval group, in theย Approvalย column, click the link and selectย Installย from the list.
Do one of the following to set when the patch should be installed (Install has been selected from the Approval list):
To not set a deadline, ensureย Noneย is showing besideย Deadline.
Depending on how often the agent policy is set to check for updates (the default is every 22 hours), the device will install a patch when it checks into update services and gets the instruction to do so. The deadline is used to force the patch to be installed by a certain time in the event that theย Notify for Download and Notify for Installย or theย Auto Download and Notify for Installย option button is selected in the patch policy and the local user on the box delays the operation when the notification pops up.To set a deadline but let users determine patch installation time, clickย Noneย and ensure theย Use client settings to determine patch installation timeย is selected and clickย OK.
To set a deadline but specify a patch installation time, clickย Noneย and select theย Installย patchย byย theย selectedย dateย andย time. Then select the date and time and clickย OK.
You can set a deadline in the past to force immediate installs.
Clickย OK.
The patches are dealt with in the order that they appear on theย Patch Approvalsย page. If any patches require you to accept or decline an End User License Agreement (EULA), you will be prompted before the patch is approved for installation. For example, you want to approve these patches:ย 7548456
ย 7589456 (EULA)
ย 7656585
ย 7636958 (EULA)
ย 7785483
If these patches are all selected and set for approved, then a, c and e would get approved, and then you would be prompted to accept the EULA for b and then d. If you decline the EULA for a patch, the patch is ignored in this round and put back in the "Not Approved" list. You will be re- prompted to accept or decline the EULA if you want to approve the patch at another time.