Concorbit HelpAll guides →

Patches

Patches

Patch management keeps your fleet up to date with operating system and third-party updates. concorbit RMM detects available patches, lets you approve them individually or in bulk, and deploys them with staged rollout to minimise risk.

Patch management requires a paid plan.

Patch compliance dashboard

The main Patches page shows fleet-wide compliance:

  • Overall compliance percentage

  • Breakdown by severity (critical, important, moderate, low)

  • Per-site compliance table with missing and installed counts

  • Devices needing attention

Patch lifecycle

Patches move through these stages:

  1. Missing: the agent detected an available update

  2. Approved: an administrator has cleared it for installation

  3. Deploying: the install command has been sent to the agent

  4. Installed: the patch was applied successfully

  5. Failed: the installation failed (check the device timeline for details)

  6. Blocked: manually blocked from deployment

Approving patches

From a device's Patches tab or the fleet Patches page:

  • Select individual patches and click Approve

  • Or click Approve all missing to approve everything in one action

Approval defaults can be set per site: manual (default), auto-approve, or staged.

Deploying patches

Once approved, select patches and click Deploy. A confirmation dialog shows what will be installed and on which devices.

Staged rollout

For large fleets, staged rollout deploys patches in waves. A percentage of devices receive the update first. If no failures are detected after a defined pause, the next wave proceeds. This catches regressions before they affect your entire fleet.

Maintenance windows

Define blackout periods when patches will not deploy. Go to Settings > Maintenance windows to create one:

  • Name the window

  • Set the scope (organisation, site, or device)

  • Define the schedule (one-time or recurring)

  • Set the start and end time

Patches queued during a maintenance window deploy when the window closes.

Per-device patches

Each device's Patches tab shows its individual patch status. Filter by status, approve or block patches, and schedule deployments for a specific date and time.