Setting maintenance windows

Maintenance windows control when patches can be applied to a computer group. A maintenance window is separate from the deployment start and end time. After a maintenance window is applied to a computer, that endpoint does not install patches or restart to complete patch installation, unless it is currently in an open maintenance window. To install a patch, the maintenance window must be open during the configured deployment time.

Ensure that maintenance windows are at least four hours long, repeat at least once each month, and properly overlap with deployment times and change control process timelines.

A maintenance window is different from a scan window. For more information about limiting scan activity to a designated scan window, see Scan windows.

Maintenance window options

You can configure maintenance windows for the times that are best for your environment. Apply maintenance windows by enforcing them against computer groups. Multiple maintenance windows can affect a computer group, creating several times that patch activity is permitted.

If you want . . . After the date and time, select . . .
A one-time window Does Not Repeat
A window that repeats every few days Daily and the number of days between windows
A window that repeats on the same days of the week Weekly, the number of weeks between windows, and which days of the week it opens on
A window that repeats on the same date each month Monthly, the number of months between windows, and Day of the Month
A window that repeats on the same day each month Monthly, the number of months between windows, and Day of the Week
A window that repeats on the same day of the year Yearly and the number of years between windows

If a maintenance window does not repeat and it is the only one enforced against a computer group, patches cannot be applied after the window closes.

Create a maintenance window

You can open multiple maintenance windows to customize when patches are applied to your endpoints. For example, you can create windows that allow deployments to install patches during periods of low network activity or outside of core working hours.

  1. From the Patch menu, go to Maintenance Windows and then click Create Window.
  2. Name the window and select an operating system.
  3. Configure the window options.
    1. (Optional) Select the recurrence time frame.
      If you chose to repeat the window, set additional options, such as how often the window repeats, day of the week, or day of the month.
    2. Choose from the local time on the endpoint or UTC time.
    3. Use the date and time pickers to set the start and end time of the window.

      If a maintenance window repeats, it does not have an end date. You must remove the enforcement against the target computer groups to stop the maintenance window.

    4. If you chose to repeat the window, set the duration of the window.

    For example, to account for Patch Tuesday, you could use these settings for the Wednesday a week after patch updates are typically released by Microsoft.

  4. Click Create Window and then add one or more target computer groups.

    Maintenance window computer groups must be assigned RBAC permissions for the user or group to appear in the list. For more information, see Tanium Console User Guide: RBAC overview.

Edit a maintenance window

  1. From the Patch menu, go to Maintenance Windows.
  2. Click the name of a window and click Edit.

    You cannot edit a maintenance window if the Allow Maintenance Window Editing option is disabled in the Patch settings.

  3. Make your changes and click Update Window.

Override a maintenance window

You can apply a patch outside of a maintenance window by configuring the Override Maintenance Windows option during a patch deployment. For more information, see Deploying patches. Note that if you also choose to restart the endpoint in the deployment options, the endpoint restarts immediately after the patch is installed.

Delete a maintenance window

After the enforcements have been removed, you can delete a maintenance window.

  1. From the Patch menu, go to Maintenance Windows.
  2. Click the name of a window.
  3. If the window is enforced against computer groups, remove all groups.
  4. Click Delete .