
Ivanti EPM can scan client machines and install missing patches. As a rule, patches are for a subset of operating systems (Affected Platforms) and product versions (Affected Products).

If you need to exclude certain machines from the installation of patches, Query Filter can help with this[1]. Some of the fixes apply depending on conditions related to the registry or file system:

The most flexible solution for a complex set of conditions is to use a script. This is used by many vendors to condition the installation of a patch. The Visual Basic script (VBS) should return one of the predefined values as a result of its operation[2] (Detected, Reason, Expected, Found).

Many patch installation tools hide patch applicability detection logic ("detection logic") making it difficult to deal with patch malfunctions. The EPM administrator can analyze the script when a patch does not work as expected.
[1] https://forums.ivanti.com/s/article/How-to-exclude-a-managed-device-from-applying-patches
- Support and development of Microsoft and Nintex based applications
- Application design and development including digital processes
- Invoice management
- Requisition management
- Contract management
- Modern Intranet
ISCG sp. z o.o.
Al. Jerozolimskie 178, 02-486 Warsaw
NIP: 5262798378
KRS: 0000220621
Phone