[GH-ISSUE #396] Patch Management - cannot disable schedules #2187

Closed
opened 2026-03-14 02:55:09 +03:00 by kerem · 9 comments
Owner

Originally created by @frankemann on GitHub (Apr 15, 2021).
Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/396

Originally assigned to: @sadnub on GitHub.

  • OS: Ubuntu 20.04
  • Browser: Multiple browsers incl. Chrome, Edge, Firefox
  • RMM Version 0.5.3

Installation Method:

  • Standard

Agent Info (please complete the following information):

  • Agent version (as shown in the 'Summary' tab of the agent from web UI): 1.4.14
  • Agent OS: [e.g. Win 10 v2004, Server 2012 R2]: Windows 10 20H2

Describe the bug
We want to disable using the patch management automatically as we are using Intune for patching.
It seems like every device in TRMM gets an automatic Inherit on all patches and a schedule installation at Fridays and Saturdays. We have tried to create an Automation Manager including some test Clients, Sites where the Patch management polic is to Ignore all patches and none days are selected for scheduled installation.
But if we access the devices in the clients, sites and right click to edit, we can see the devices still are using the Inherit and are scheduled for patching Fridays And Saturdays.

Expected behavior
To be able to disable Patch Management Globally as default, or that the Patch management policies we apply in automation manager actually gets down to the devices/agents in the specified client, sites.

Screenshots
image
image

Additional context
Add any other context about the problem here.

Originally created by @frankemann on GitHub (Apr 15, 2021). Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/396 Originally assigned to: @sadnub on GitHub. - OS: Ubuntu 20.04 - Browser: Multiple browsers incl. Chrome, Edge, Firefox - RMM Version 0.5.3 **Installation Method:** - [ ] Standard **Agent Info (please complete the following information):** - Agent version (as shown in the 'Summary' tab of the agent from web UI): 1.4.14 - Agent OS: [e.g. Win 10 v2004, Server 2012 R2]: Windows 10 20H2 **Describe the bug** We want to disable using the patch management automatically as we are using Intune for patching. It seems like every device in TRMM gets an automatic Inherit on all patches and a schedule installation at Fridays and Saturdays. We have tried to create an Automation Manager including some test Clients, Sites where the Patch management polic is to Ignore all patches and none days are selected for scheduled installation. But if we access the devices in the clients, sites and right click to edit, we can see the devices still are using the Inherit and are scheduled for patching Fridays And Saturdays. **Expected behavior** To be able to disable Patch Management Globally as default, or that the Patch management policies we apply in automation manager actually gets down to the devices/agents in the specified client, sites. **Screenshots** ![image](https://user-images.githubusercontent.com/82226898/114834195-9d22e400-9dd0-11eb-9151-7171f6cd29e4.png) ![image](https://user-images.githubusercontent.com/82226898/114834275-b166e100-9dd0-11eb-8fc9-30ac64413760.png) **Additional context** Add any other context about the problem here.
kerem closed this issue 2026-03-14 02:55:15 +03:00
Author
Owner

@sadnub commented on GitHub (Apr 15, 2021):

@frankemann The patches won't be applied unless it is set to auto approve. The inherit means that, if configured, it will pull from a patch policy configured on automation policy.

<!-- gh-comment-id:820394914 --> @sadnub commented on GitHub (Apr 15, 2021): @frankemann The patches won't be applied unless it is set to auto approve. The inherit means that, if configured, it will pull from a patch policy configured on automation policy.
Author
Owner

@frankemann commented on GitHub (Apr 15, 2021):

Ok,thanks for fast feedback

But since the device in the screenshot has a patch policy configured through automation policy; shouldn't the Scheduled Time also says Inherit? For me it now seems that this device will eventually try to do some patch Friday, Saturdag 3 AM?
But you are saying that will now happen, since I have set the patch policy to Ignore on all settings, correct?

In that matter a feature reqeust could be to also show the Schedule Time to Inherit and now show the weekdays on the device itself, since it will show in the patch policy. Or that the weekdays show the same as the days in the patch policy. That is not the case right now.

<!-- gh-comment-id:820459932 --> @frankemann commented on GitHub (Apr 15, 2021): Ok,thanks for fast feedback But since the device in the screenshot has a patch policy configured through automation policy; shouldn't the Scheduled Time also says Inherit? For me it now seems that this device will eventually try to do some patch Friday, Saturdag 3 AM? But you are saying that will now happen, since I have set the patch policy to Ignore on all settings, correct? In that matter a feature reqeust could be to also show the Schedule Time to Inherit and now show the weekdays on the device itself, since it will show in the patch policy. Or that the weekdays show the same as the days in the patch policy. That is not the case right now.
Author
Owner

@sadnub commented on GitHub (Apr 15, 2021):

The schedule time is controlled by the schedule frequency. By default, the agent inherits all patch settings from an automation policy

<!-- gh-comment-id:820570056 --> @sadnub commented on GitHub (Apr 15, 2021): The schedule time is controlled by the schedule frequency. By default, the agent inherits all patch settings from an automation policy
Author
Owner

@sadnub commented on GitHub (Apr 15, 2021):

I mean I suppose I could hide the disabled controls when the dropdowns are set to inherit

<!-- gh-comment-id:820571730 --> @sadnub commented on GitHub (Apr 15, 2021): I mean I suppose I could hide the disabled controls when the dropdowns are set to inherit
Author
Owner

@frankemann commented on GitHub (Apr 15, 2021):

Would be nice to see something in the GUI which shows that there is no schedule to install patches when it inherits an automation policy which doesn't approve patches and have no schedule to install.

For now, all of our technicans has the impression that the device actually will boot Friday and Saturdat, as it really shows that on the device (as the screenshot show) Schduled time coulde f.ex show "None" which would indicate that " nothing gonna happen for patching on this computer, that's for sure :) "

<!-- gh-comment-id:820599984 --> @frankemann commented on GitHub (Apr 15, 2021): Would be nice to see something in the GUI which shows that there is no schedule to install patches when it inherits an automation policy which doesn't approve patches and have no schedule to install. For now, all of our technicans has the impression that the device actually will boot Friday and Saturdat, as it really shows that on the device (as the screenshot show) Schduled time coulde f.ex show "None" which would indicate that " nothing gonna happen for patching on this computer, that's for sure :) "
Author
Owner

@sadnub commented on GitHub (Apr 15, 2021):

I just fixed this and will be in the next release!

image

<!-- gh-comment-id:820611585 --> @sadnub commented on GitHub (Apr 15, 2021): I just fixed this and will be in the next release! ![image](https://user-images.githubusercontent.com/20450757/114914270-1847c280-9df0-11eb-956b-086685d50eb3.png)
Author
Owner

@frankemann commented on GitHub (Apr 15, 2021):

Wow, that was fast! Excellent!

Last question: If a Client, Site does not have any Patch Policy attached to their automation policy.
Is the default that pathces is auto approve and patching Friday, Saturdat at 3.AM? Or won't it patch, since it anyways says Inherit as default (and there is nothing to Inherit..? Unless the hidden default global setting is Friday, Saturday)

<!-- gh-comment-id:820613633 --> @frankemann commented on GitHub (Apr 15, 2021): Wow, that was fast! Excellent! Last question: If a Client, Site does not have any Patch Policy attached to their automation policy. Is the default that pathces is auto approve and patching Friday, Saturdat at 3.AM? Or won't it patch, since it anyways says Inherit as default (and there is nothing to Inherit..? Unless the hidden default global setting is Friday, Saturday)
Author
Owner

@sadnub commented on GitHub (Apr 15, 2021):

That value is just populated into the DB on creation. Doesn't do anything until you setup auto approval or start approving patches

<!-- gh-comment-id:820616455 --> @sadnub commented on GitHub (Apr 15, 2021): That value is just populated into the DB on creation. Doesn't do anything until you setup auto approval or start approving patches
Author
Owner

@frankemann commented on GitHub (Apr 15, 2021):

Thanks!

<!-- gh-comment-id:820618180 --> @frankemann commented on GitHub (Apr 15, 2021): Thanks!
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/tacticalrmm#2187
No description provided.