Manual Patch Deployment

⌘K

Overview

Manual Deployment lets you install or uninstall specific patches on chosen devices or groups, on your own schedule, instead of waiting for an automatic rollout. Each deployment is saved as a profile you can track, re-run, or review later.

What is Manual Deployment?

Manual Deployment, found under Secure → Deployment, is used to deploy specific patches to selected devices or groups. It is useful for one time fixes, urgent patches, or controlled rollouts where you need direct control over the deployment timing and target devices.

Every deployment you create appears in the profile list with its own status, so you can track whether it succeeded, is still running, or needs attention.

Step 1: Navigate to Manual Deployment

  1. Log in to the Zecurit portal.
  2. Go to Endpoint Manager → Secure → Deployment → Manual Deployment.
  3. Click Install / Uninstall Patch.

Step 2: Configure the Deployment

Configure the Policy Details, Deployment Handling Rules, Schedule, and Scope of Target sections.

Policy Details

FieldRequiredDescription
Policy NameYesA descriptive name for the deployment (e.g., “Patch deployment policy”). Shown in the profile list to identify it later. An Add Description link sits next to the field, letting you attach an optional, longer description of the deployment’s purpose.
Operation TypeYesWhether this deployment installs or uninstalls the selected patches. Choose Install or Uninstall. Install is selected by default.
PatchesYesThe specific patches to deploy or uninstall.

Adding and managing patches:

  1. Click Add Patch to open the patch picker and select one or more patches.
  1. Selected patches appear in a table below a Total Selected Patches counter (e.g., “Total Selected Patches: 1”), which updates as you add or remove patches.
  1. The table has the following columns:
ColumnDescription
(checkbox)Select one or more rows before using Remove Patch.
Patch IDThe internal identifier for the patch, for example 51871.
TitleThe patch name and version, for example “Git – 2.50.1.” If the title is truncated, hover over it to see the full name in a tooltip.
SeverityA badge showing the patch’s severity rating, for example “Unknown,” Critical, High, or Low, depending on how the patch is classified.
  1. Remove Patch is disabled (greyed out) until at least one patch row’s checkbox is selected. Check a row first, then click Remove Patch to remove it from the deployment.

Deployment Handling Rules

FieldDescription
Network ConditionsChoose Any Network to deploy regardless of connection, or Lan Only to deploy only while the device is on the local network.
Retry on Failed TargetsWhen turned on, automatically retries the deployment on any device where it failed.
Retry CountHow many times to retry a failed deployment before giving up.
Retry IntervalHow long to wait, in minutes, between retry attempts.
Retry After RebootWhen turned on, retries the deployment after the device restarts, in case the failure was reboot-related.

Schedule

OptionEffect
Deploy ImmediatelyThe deployment starts automatically as soon as the device contacts the Zecurit Server.
Schedule DeploymentThe deployment begins at a chosen Start Date and Time Zone. If a device is offline at that time, it starts when the device next contacts the Zecurit Server.

Scope of Target

Targets are configured one row at a time, and each row is numbered as you add it the first is labeled Target 1, the next Target 2, and so on.

For each target row:

  1. Use the type dropdown on the left (e.g., “Devices”) to choose whether this target row applies to Devices or Groups.
  2. Use the search field next to the dropdown to find and select the specific devices or groups. Each selection appears as a removable chip inside the field (for example, campbell ). You can select multiple devices or groups within the same target row.
  3. To add another target, click the + icon at the end of the row. This creates a new numbered target row (Target 2, Target 3, …), which can use a different type (Devices or Groups) and its own selections.
  4. To exclude specific devices from the overall scope, use Exclude Target and select the devices to leave out of the deployment, even if they belong to a selected group.

Note: Confirm the Exclude Target control’s exact location in your environment before publishing this section it may only appear after at least one target has been configured, rather than being visible from the start.

Step 3: Publish or Save as Draft

Click Publish to run the deployment according to the configured schedule, or click Save as Draft to complete the deployment later.

OptionEffect
PublishActivates the deployment according to the chosen schedule.
Save as DraftStores the deployment configuration without activating it, so it can be reviewed or completed later.
CancelDiscards changes and exits without saving.

Understanding the Profile List

ColumnDescription
Profile NameThe name given to the deployment when it was created.
PlatformThe operating system the deployment targets.
Created ByThe user who created the deployment.
Created TimeThe date and time the deployment was created.
VersionThe current version number of the deployment profile.
Associated DevicesHow many individual devices the deployment targets.
Associated GroupsHow many device groups the deployment targets.
Profile StatusThe current outcome of the deployment.

Profile Status Values

StatusMeaning
In ProgressThe deployment is currently running on its targeted devices or groups.
ExecutedThe deployment completed successfully.
FailedThe deployment did not complete successfully on one or more targets. Check the target devices for connectivity or agent issues.

Best Practices

  • Name deployments clearly enough that they’re identifiable later in the profile list without opening them.
  • Turn on Retry on Failed Targets for unattended deployments, so temporary connectivity issues don’t require manual follow-up.
  • Use Lan Only for large patches where you want to avoid consuming bandwidth on remote or metered connections.
  • Review Failed deployments promptly rather than assuming a retry will resolve the issue on its own.
  • Use Schedule Deployment for planned maintenance windows instead of deploying immediately during business hours.

Troubleshooting Tips

IssueResolution
Publish button is disabledConfirm a Policy Name is entered and at least one patch has been added.
Profile Status shows FailedCheck the target device’s connectivity and agent status; enable Retry on Failed Targets if not already on.
Profile Status stuck on In ProgressConfirm the target devices are online; offline devices only pick up the deployment once they reconnect.
Deployment didn’t run at the scheduled timeConfirm the Start Date and Time Zone were set correctly, and that the profile was Published, not left as a draft.

How can we help?