System Maintainence
Android
iOS
Linux
macOS
Windows
We leverage Maintainence Groups and Maintenence Windows to define patching processes which are configured and maintained by Enterprise Operations.
Maintainence Group
Maintenence Groups (TAMU_MG) set the delay after Patch Tuesday occurs each month.
- TEST (2 days after Patch Tuesday), only IT systems are part of this Maintainence Group.
- PROD (10 days after Patch Tuesday), all other computers are added to this Maintenence Group.

Maintenence Window
Maintainence Windows (TAMU_MW) define the timeframes that patching can occur. PVFA has set the following windows as our approved windows:
- Sun8p6a (Sunday 8pm-6am)
- Mon8p6a (Monday 8pm-6am)
- Tue8p6a (Tuesday 8pm-6am)
- Wed8p6a (Wednesday 8pm-6am)
- Thu8p6a (Thursday 8pm-6am)
- Fri8p6a (Friday 8pm-6am)
- Sat8p6a (Saturday 8pm-6am)
- WeekdayLunch (Monday-Friday 11am-1pm)
Environment Variables
We set both the Maintainence Group and Window by utilizing Environment Variables, enforced by Configuration Items as part of a Baseline.
We chose this mechanism over GPO's because baselines can evaulate over the internet (do not need to be on campus like GPO) and baselines will continue to re-evaluate if there is compliance drift and set back to our designated settings.
The two baselines we use are PVFA - CB - SetEnvironmentVariableforProdUpdateSchedule (this is set for the majority of computers) and PVFA - CB - SetEnvironmentVariableforTestUpdateSchedule (only on testing computers)
Restart Proceess
After patching has completed we have the following restart settings in place to control how long the computer waits before presenting a restart banner screen to the user to complete the patching process and the deferral period that the user can delay the restart.
We will NOT force a restart without notifying you and/or giving you the ability to defer the update for approximately 5 days after windows patches install.
