On-Demand Deployment (Application)

On-demand deployment for application updates is intended for the immediate rollout of specific application patches. Use it for urgent security fixes, critical vulnerabilities, or targeted updates without waiting for scheduled runs.

This section walks through how to create an on-demand deployment for application on targeted endpoints. For OS Patch, refer to our On-Demand Deployment (OS) guidelines.

Navigate to Patch Management > Deployments and select Create On-Demand Deployment. In the popup dialog, select For Application Patches to begin.

Deployment Information

Provide these details to identify and track the deployment.

  • Name: Enter a brief, memorable name.
  • Description: Specify the target, purpose, and expected outcomes.
  • Tags: Add tags for easy categorization and filtering.

Deployment Schedule

Define the start and end time for the deployment window.

  • Date: Select the run date (e.g., 3/11/2026).
  • Start time: Set the exact future start time.
  • End time (optional): The time deployment automatically stops. You can add an end time by clicking Add end time.
    • If no end time is specified, the deployment will only be marked as completed after all endpoints have finished their patching process and reported their results back to My OPSWAT Central Management.
    • Offline endpoints during the window are marked Unreachable.
  • Deployment Timezone
    • Fixed timezone: All endpoints begin the deployment at the exact same moment globally.
    • Local timezone: Each endpoint uses its own local timezone.

Update Notification

Configure how endpoints handle applications that need to be closed before performing an update.

  • Notify users to close or relaunch the applications in use, wait for end-users to close them, then proceed with the update.

    • You can set how often the endpoint prompts the user (e.g., every 30-60 minutes)
    • You can set the number of prompts a user can skip before the system triggers an automatic close/ relaunch to enforce the updates.
  • Force close or relaunch applications for updates: Applications in use will be closed immediately when the update begins

Note This behavior only applies for applications that require closing before performing the update.

Targeted Devices

Select the endpoints to receive this deployment.

Note Deployments support Windows devices only.

  • All Devices: Deployment will be performed on all devices.
  • Specific Groups: The deployment will be performed only on the selected groups.
  • Specific Devices: The deployment will be performed only on the selected devices.

Application Selection

Choose the applications you want to update.

  • Condition-Based Applications: Includes all applications that match conditions (e.g., "critical severity"). If you set multiple conditions, an application only needs to match one to be included.
  • Specific Applications: Manually select the exact applications you want to deploy in this on-demand deployment.

Note Rejected and unsupported applications are automatically excluded from the deployment, even if they match your selection criteria.

Report

Configure notifications for deployment completion.

Add one or more email addresses (e.g., admins, security teams). Recipients get a summary with per-device status: Success, Failure, or Unreachable.

Once a deployment is created, navigate to Patch Management > Deployments to monitor the update process. Refer to Deployment Management (Application) guideline for detailed instructions.

Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard