{"id":3452,"date":"2026-08-21T07:38:26","date_gmt":"2026-08-21T07:38:26","guid":{"rendered":"https:\/\/zecurit.com\/help\/?post_type=docs&#038;p=3452"},"modified":"2026-08-21T07:38:27","modified_gmt":"2026-08-21T07:38:27","slug":"manual-patch-deployment","status":"publish","type":"docs","link":"https:\/\/zecurit.com\/help\/endpoint-management\/patch-management\/manual-patch-deployment\/","title":{"rendered":"Manual Patch Deployment"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p>Manual Deployment lets you install or uninstall specific patches on chosen devices or groups, on your own schedule, instead of waiting for an automatic rollout. Each deployment is saved as a profile you can track, re-run, or review later.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is Manual Deployment?<\/h2>\n\n\n\n<p>Manual Deployment, found under <strong>Secure \u2192 Deployment<\/strong>, is used to deploy specific patches to selected devices or groups. It is useful for one time fixes, urgent patches, or controlled rollouts where you need direct control over the deployment timing and target devices.<\/p>\n\n\n\n<p>Every deployment you create appears in the profile list with its own status, so you can track whether it succeeded, is still running, or needs attention.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"963\" src=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Manaual-Patch-Deployment-2-1024x963.webp\" alt=\"\" class=\"wp-image-3560\" srcset=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Manaual-Patch-Deployment-2-1024x963.webp 1024w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Manaual-Patch-Deployment-2-300x282.webp 300w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Manaual-Patch-Deployment-2-768x722.webp 768w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Manaual-Patch-Deployment-2-1536x1444.webp 1536w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Manaual-Patch-Deployment-2-2048x1925.webp 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Step 1: Navigate to Manual Deployment<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Log in to the Zecurit portal.<\/li>\n\n\n\n<li>Go to <strong>Endpoint Manager \u2192 Secure \u2192 Deployment \u2192 Manual Deployment<\/strong>.<\/li>\n\n\n\n<li>Click <strong>Install \/ Uninstall Patch<\/strong>.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Step 2: Configure the Deployment<\/h2>\n\n\n\n<p>Configure the Policy Details, Deployment Handling Rules, Schedule, and Scope of Target sections.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Policy Details<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Field<\/strong><\/th><th><strong>Required<\/strong><\/th><th><strong>Description<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Policy Name<\/td><td>Yes<\/td><td>A descriptive name for the deployment (e.g., &#8220;Patch deployment policy&#8221;). Shown in the profile list to identify it later. An <strong>Add Description<\/strong> link sits next to the field, letting you attach an optional, longer description of the deployment&#8217;s purpose.<\/td><\/tr><tr><td>Operation Type<\/td><td>Yes<\/td><td>Whether this deployment installs or uninstalls the selected patches. Choose <strong>Install<\/strong> or <strong>Uninstall<\/strong>. Install is selected by default.<\/td><\/tr><tr><td>Patches<\/td><td>Yes<\/td><td>The specific patches to deploy or uninstall.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Adding and managing patches:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Click <strong>Add Patch<\/strong> to open the patch picker and select one or more patches.<\/li>\n<\/ol>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li>Selected patches appear in a table below a <strong>Total Selected Patches<\/strong> counter (e.g., &#8220;Total Selected Patches: 1&#8221;), which updates as you add or remove patches.<\/li>\n<\/ol>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li>The table has the following columns:<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Column<\/strong><\/th><th><strong>Description<\/strong><\/th><\/tr><\/thead><tbody><tr><td>(checkbox)<\/td><td>Select one or more rows before using Remove Patch.<\/td><\/tr><tr><td>Patch ID<\/td><td>The internal identifier for the patch, for example 51871.<\/td><\/tr><tr><td>Title<\/td><td>The patch name and version, for example &#8220;Git &#8211; 2.50.1.&#8221; If the title is truncated, hover over it to see the full name in a tooltip.<\/td><\/tr><tr><td>Severity<\/td><td>A badge showing the patch&#8217;s severity rating, for example &#8220;Unknown,&#8221; Critical, High, or Low, depending on how the patch is classified.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li><strong>Remove Patch<\/strong> is disabled (greyed out) until at least one patch row&#8217;s checkbox is selected. Check a row first, then click Remove Patch to remove it from the deployment.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Deployment Handling Rules<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Field<\/strong><\/th><th><strong>Description<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Network Conditions<\/td><td>Choose <strong>Any Network<\/strong> to deploy regardless of connection, or <strong>Lan Only<\/strong> to deploy only while the device is on the local network.<\/td><\/tr><tr><td>Retry on Failed Targets<\/td><td>When turned on, automatically retries the deployment on any device where it failed.<\/td><\/tr><tr><td>Retry Count<\/td><td>How many times to retry a failed deployment before giving up.<\/td><\/tr><tr><td>Retry Interval<\/td><td>How long to wait, in minutes, between retry attempts.<\/td><\/tr><tr><td>Retry After Reboot<\/td><td>When turned on, retries the deployment after the device restarts, in case the failure was reboot-related.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Schedule<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Option<\/strong><\/th><th><strong>Effect<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Deploy Immediately<\/td><td>The deployment starts automatically as soon as the device contacts the Zecurit Server.<\/td><\/tr><tr><td>Schedule Deployment<\/td><td>The deployment begins at a chosen Start Date and Time Zone. If a device is offline at that time, it starts when the device next contacts the Zecurit Server.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Scope of Target<\/h3>\n\n\n\n<p>Targets are configured one row at a time, and each row is numbered as you add it the first is labeled <strong>Target 1<\/strong>, the next <strong>Target 2<\/strong>, and so on.<\/p>\n\n\n\n<p><strong>For each target row:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Use the <strong>type dropdown<\/strong> on the left (e.g., &#8220;Devices&#8221;) to choose whether this target row applies to <strong>Devices<\/strong> or <strong>Groups<\/strong>.<\/li>\n\n\n\n<li>Use the <strong>search field<\/strong> next to the dropdown to find and select the specific devices or groups. Each selection appears as a removable chip inside the field (for example, campbell ). You can select multiple devices or groups within the same target row.<\/li>\n\n\n\n<li>To add another target, click the <strong>+<\/strong> icon at the end of the row. This creates a new numbered target row (Target 2, Target 3, &#8230;), which can use a different type (Devices or Groups) and its own selections.<\/li>\n\n\n\n<li>To exclude specific devices from the overall scope, use <strong>Exclude Target<\/strong> and select the devices to leave out of the deployment, even if they belong to a selected group.<\/li>\n<\/ol>\n\n\n\n<p><strong>Note:<\/strong> Confirm the Exclude Target control&#8217;s exact location in your environment before publishing this section it may only appear after at least one target has been configured, rather than being visible from the start.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 3: Publish or Save as Draft<\/h2>\n\n\n\n<p>Click <strong>Publish<\/strong> to run the deployment according to the configured schedule, or click <strong>Save as Draft<\/strong> to complete the deployment later.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Option<\/strong><\/th><th><strong>Effect<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Publish<\/td><td>Activates the deployment according to the chosen schedule.<\/td><\/tr><tr><td>Save as Draft<\/td><td>Stores the deployment configuration without activating it, so it can be reviewed or completed later.<\/td><\/tr><tr><td>Cancel<\/td><td>Discards changes and exits without saving.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Understanding the Profile List<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Column<\/strong><\/th><th><strong>Description<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Profile Name<\/td><td>The name given to the deployment when it was created.<\/td><\/tr><tr><td>Platform<\/td><td>The operating system the deployment targets.<\/td><\/tr><tr><td>Created By<\/td><td>The user who created the deployment.<\/td><\/tr><tr><td>Created Time<\/td><td>The date and time the deployment was created.<\/td><\/tr><tr><td>Version<\/td><td>The current version number of the deployment profile.<\/td><\/tr><tr><td>Associated Devices<\/td><td>How many individual devices the deployment targets.<\/td><\/tr><tr><td>Associated Groups<\/td><td>How many device groups the deployment targets.<\/td><\/tr><tr><td>Profile Status<\/td><td>The current outcome of the deployment.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Profile Status Values<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Status<\/strong><\/th><th><strong>Meaning<\/strong><\/th><\/tr><\/thead><tbody><tr><td>In Progress<\/td><td>The deployment is currently running on its targeted devices or groups.<\/td><\/tr><tr><td>Executed<\/td><td>The deployment completed successfully.<\/td><\/tr><tr><td>Failed<\/td><td>The deployment did not complete successfully on one or more targets. Check the target devices for connectivity or agent issues.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Best Practices<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Name deployments clearly enough that they&#8217;re identifiable later in the profile list without opening them.<\/li>\n\n\n\n<li>Turn on Retry on Failed Targets for unattended deployments, so temporary connectivity issues don&#8217;t require manual follow-up.<\/li>\n\n\n\n<li>Use Lan Only for large patches where you want to avoid consuming bandwidth on remote or metered connections.<\/li>\n\n\n\n<li>Review Failed deployments promptly rather than assuming a retry will resolve the issue on its own.<\/li>\n\n\n\n<li>Use Schedule Deployment for planned maintenance windows instead of deploying immediately during business hours.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting Tips<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Issue<\/strong><\/th><th><strong>Resolution<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Publish button is disabled<\/td><td>Confirm a Policy Name is entered and at least one patch has been added.<\/td><\/tr><tr><td>Profile Status shows Failed<\/td><td>Check the target device&#8217;s connectivity and agent status; enable Retry on Failed Targets if not already on.<\/td><\/tr><tr><td>Profile Status stuck on In Progress<\/td><td>Confirm the target devices are online; offline devices only pick up the deployment once they reconnect.<\/td><\/tr><tr><td>Deployment didn&#8217;t run at the scheduled time<\/td><td>Confirm the Start Date and Time Zone were set correctly, and that the profile was Published, not left as a draft.<\/td><\/tr><\/tbody><\/table><\/figure>\n","protected":false},"featured_media":0,"parent":3147,"menu_order":8,"comment_status":"open","ping_status":"closed","template":"","meta":{"_is_vendor_doc":"0","footnotes":""},"doc_tag":[],"class_list":["post-3452","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3452","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/comments?post=3452"}],"version-history":[{"count":18,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3452\/revisions"}],"predecessor-version":[{"id":3564,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3452\/revisions\/3564"}],"up":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3147"}],"prev":[{"title":"Patch Scan","link":"https:\/\/zecurit.com\/help\/endpoint-management\/patch-management\/patch-scan\/","href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3427"}],"wp:attachment":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/media?parent=3452"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/doc_tag?post=3452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}