Configuring update installation

To configure the update installation:

  1. Open Kaspersky Endpoint Security Cloud Management Console.
  2. Select the Security managementVulnerability Assessment and Patch Management section.
  3. Under Patches and updates, click the Installation settings button.

    The Update installation settings window opens.

  4. In the Installation mode list, select the required value:
    • Install approved updates only (by default).

      You can approve updates that must be installed and skip updates that must not be installed.

      For example, you first may want to check the installation of updates in a test environment and make sure that they do not interfere with the operation of devices, and only then approve the installation of these updates on managed devices.

    • Install all updates

      All updates are installed as soon as they are detected, according to other installation settings.

  5. In the Installation scope list, select the devices on which you want to install updates:
    • All devices
    • Workstations only
    • Servers only
    • Specific devices

      Select this value if you want to test installation of updates on a small amount of devices, or to exclude certain devices from the installation scope.

      In this case, do the following:

      1. Click the Modify button.

        The Installation scope window opens.

      2. Select the check boxes next to the devices on which you want to install updates, and clear the check boxes next to the devices that you want to exclude from the installation scope.

        To select or deselect all devices, select or clear the check box in the table heading.

      3. Click the Save button to save the changes.
  6. In the Installation schedule list, select the required value:
    • Disabled (by default)—The update installation never runs.
    • Every week—Specify the day of week and the time (with the time zone) when the update installation must run.

      If a protected device is offline at the scheduled time, the task will run as soon as the device goes online.

    • Every day—Specify the time (with the time zone) when the update installation must run.

      If a protected device is offline at the scheduled time, the task will run as soon as the device goes online.

  7. If the Start installation at device restart or shutdown option is enabled, updates are installed when the device is restarted or shut down. Otherwise, updates are installed according to the schedule.

    Use this option if installing updates might affect the device performance.

  8. Under Operating system restart option, select what to do if the update installation requires the restart of the device operating system:
    • Do not restart the device

      Managed devices are not restarted automatically after the operation. To complete the operation, users must restart their devices. This option is suitable for servers and other devices where continuous operation is critical.

    • Restart the device

      Managed devices are always restarted automatically if a restart is required for completion of the operation. This option is useful for devices for which regular pauses in their operation (shutdown or restart) are acceptable.

    • Prompt the user for action

      The restart reminder is displayed on the screen of the managed device, prompting the user to restart it manually. You can change the text of the message for the user. This option is most suitable for workstations where users must be able to select the most convenient time for a restart.

      If the Restart the device after option is enabled, after prompting the user, the application forces a restart of the operating system upon expiration of the specified time interval. Otherwise, users must restart their devices manually. If necessary, change the default value of the time interval (30 minutes).

  9. Click the OK button to save the changes.

The update installation is configured.

You can also run the installation of all planned updates at any time by clicking the Settings button, and then selecting the Unscheduled parameter. Installation of the updates will be started at the optimal time estimated by the security application.

Page top