Monthly Windows Patching
Use this playbook to plan, execute, and validate a typical monthly Windows Server patch cycle using Cloudaware Patch Management.
Procedure
-
Prepare scope and baseline.
- Identify Windows hosts in scope using CMDB filters (for example, prod Windows servers for a given application or business unit).
- Review outstanding patches and associated vulnerabilities (see Vulnerability Management).
- Build or update a baseline that includes the monthly cumulative updates and any required prerequisites.
-
Plan maintenance windows and approvals.
- Coordinate with application owners to choose appropriate maintenance windows.
- Create or update change requests in your ITSM tool.
- Obtain approvals from change approvers or CAB where required.
-
Run a canary wave.
- Select a small group of representative servers (for example, non‑critical or lower‑tier instances).
- Contact Сloudaware to provide parameters for patching (baseline and the agreed window).
- Monitor job logs, host health, and application behavior after the canary completes.
-
Roll out to remaining servers.
- Increase the scope to remaining servers, using waves aligned with availability zones or roles.
- Contact Сloudaware to perform patching on a new set of servers.
- Monitor progress and address failures promptly.
- Use notifications to keep stakeholders informed.
-
Verify and close.
- Confirm hosts report the expected Windows patch levels.
- Check vulnerability scans to ensure critical issues are resolved.
- Update and close related change records, and capture any lessons learned for the next cycle.