Skip to main content

Monthly Windows Patching

Use this playbook to plan, execute, and validate a typical monthly Windows Server patch cycle using Cloudaware Patch Management.

Procedure

  1. Prepare scope and baseline.

    • Identify Windows hosts in scope using CMDB filters (for example, prod Windows servers for a given application or business unit).
    • Review outstanding patches and associated vulnerabilities (see Vulnerability Management).
    • Build or update a baseline that includes the monthly cumulative updates and any required prerequisites.
  2. Plan maintenance windows and approvals.

    • Coordinate with application owners to choose appropriate maintenance windows.
    • Create or update change requests in your ITSM tool.
    • Obtain approvals from change approvers or CAB where required.
  3. Run a canary wave.

    • Select a small group of representative servers (for example, non‑critical or lower‑tier instances).
    • Contact Сloudaware to provide parameters for patching (baseline and the agreed window).
    • Monitor job logs, host health, and application behavior after the canary completes.
  4. Roll out to remaining servers.

    • Increase the scope to remaining servers, using waves aligned with availability zones or roles.
    • Contact Сloudaware to perform patching on a new set of servers.
    • Monitor progress and address failures promptly.
    • Use notifications to keep stakeholders informed.
  5. Verify and close.

    • Confirm hosts report the expected Windows patch levels.
    • Check vulnerability scans to ensure critical issues are resolved.
    • Update and close related change records, and capture any lessons learned for the next cycle.