University of Wisconsin-Eau Claire utilizes multiple applications to patch Windows and many 3rd party applications in our managed Windows fleet. This document provides an overview of what those tools are, the most important details about them, the schedules followed, as well as other information notes of importance.
This document is intended to maintain compliance required by Universities of Wisconsin Information Security Policy 1042.6.C.
Table of Contents
LTS – Learning and Technology Services: The central IT unit for the University of Wisconsin-Eau Claire (UWEC).
CSS – Client Support Services: A sub-unit of LTS.
SMC – Systems Management & Configuration: The team within CSS that handles the system administration of managed Windows and Apple devices for UWEC
SCCM - System Center Configuration Manager: On premise tool provided by Microsoft to manage Windows devices. We still refer to our management system by SCCM throughout this document.
MCEM - Microsoft Endpoint Configuration Manager: The rebranded name of SCCM.
WSUS – This is a built-in role that can be configured on a Windows Server for Windows Server Update Services that allows IT administrators to centrally manage and distribute some Microsoft product updates and security patches they manage.
Software Center - An application within Windows that works with SCCM for making available updates and software titles to be installed without administrator rights by end users. It also shows the progress of installs.
General Access Computer Lab - Also known as a GA lab is a computer lab open to use by the campus community at large, but intended for student use the most.
LTSLNR – This is the computer naming prefix use for LTS’ dedicated loaner pool of laptops to loan out while a user’s primary work computer is in for repair.
PMPC – Patch My PC: A service used that pushes other non-Microsoft application updates through WSUS that automates the packaging and deployment.
Maintenance Window - This is from midnight to 6AM every day and it is when most applications and the Windows operating system are allowed to freely update themselves.
CCTK Dell Client Command Toolkit - This is an administrative utility used to manage and configure BIOS settings on Dell computers.
Dell Command | Configure - The rebranded name of Dell CCTK.
Dell Command Update - This application delivers Dell issued drives and bios updates for their hardware. This can be run by the client, but not all updates are allowed to be installed without additional rights or knowledge.
InTune - Microsoft’s cloud-based Windows management platform.
AutoPatch - A tool within InTune used to deliver software and driver updates to managed Windows devices.
AD – Active Directory: A Microsoft Server service that Windows computers and other operating systems can be bound to that assists with the management and application of group policy settings, user rights, and other functionality.
CVE – Common Vulnerabilities and Exposures: This is a library of cybersecurity security flaws in products where each is given a unique ID and then also has a variety of other information associated with it about that issue.
CVSS – Common Vulnerability Scoring Systems: One of the fields that can be associated with a CVE is a CVSS score that is a scale from 0-10, with 10 being the worst score. The higher the score, typically the sooner you should remediate the CVE with an update if it is available.
‘Microsoft Patch Tuesday’ is the second Tuesday of each month when Microsoft generally releases updates for Microsoft products. Those updates are automatically imported into our WSUS, then pulled into SCCM. Automated rules configured in SCCM automatically approve the proper updates on a schedule. Patches are then made available in software center and to the local SCCM client on the computer.
Distribution of the updates follows the groups and schedules listed further down. Updates will install themselves during the maintenance window if the computer is powered on and on the network.
When an update hits the deadline that it must be installed by it then becomes a “forced install”. At this point updates will install at will, even during standard business hours of Monday through Friday from 7:30AM to 4:30PM. This process will force the install of the patch during business hours, but the computer will not reboot until the next maintenance window. We have found that if we do not eventually force install, even during standard business hours, patch compliance will not get to an acceptable level before the next month’s patch cycle starts.
Clients have been told they need to routinely check for updates to install and restart their computers at a time of their choosing roughly every two weeks minimum to avoid unwanted restarts and performance hits when updates install themselves after reaching forced install date.
Alpha Test Group - 75 computers, mix of SMC computers, a handful of office computers in various departments, and a high use general access computer lab
Beta Test Group - 325 computers, All LTS and LTSLNR named computers, ARCC department, 4 GA Labs
All Campus - All offices/labs
Cumulative and Rollup Patches - These are deployed monthly and contain most critical security updates and patches
Alpha - Available on patch Tuesday and forced install 2 days later
Beta - Available on patch Tuesday and forced install 8 days later
All Campus - Available on patch Tuesday and forced install 12 days later
Windows Client Updates - Basically any patch that is not a "cumulative or rollup patch". This can include patches for other products such as Office 365
Alpha - Available on patch Tuesday and forced install 1 day later
Beta - Available on patch Tuesday and forced install 4 days later
All Campus - Available on patch Tuesday and forced install 9 days later
Critical/Out of Band updates - Highest Priority patches that are deemed extremely critical to patch. Usually patches like this are released outside of Patch Tuesday by Microsoft
All computers - available when pushed and forced install 1 day later
Some updates can fully install without need to reboot the computer, but others do require a reboot to complete the install. For those updates that require a reboot, if the install has completed its pre-stage and is waiting for the that reboot, it will not be reported as installed to SCCM until the reboot has occurred and the install finishes successfully.
Windows 11 “H2” fall releases are supported for 36 months. The naming on these major updates contains the last two digits of the year that update was released. The H2 update from fall of 2025 was named “25H2” as an example.
Windows 11 updates are released once a year and supported for 36 months. Newest builds are deployed within a month of release by Microsoft (after testing).
Every 180 days we will email users about out-of-date Windows 11 major builds that SCCM could not update. We will then troubleshoot update issues and get the computer updated to the newest supported build. If users do not respond we temporarily disable computer in AD until we can get computer to be compliant.
UWEC has recently bound our managed Windows computers to InTune management, putting our fleet into a hybrid management configuration between on premises and cloud. We will slowly work towards moving the slider of how much is managed by SCCM vs towards InTune over time.
SMC is currently testing the use of AutoPatch as the new mechanism for delivery of Microsoft updates. The updates included cover Windows Cumulative/Rollup/Non-Cumulative updates, Microsoft .NET updates, drivers, and Office 365 updates. We are hopeful this new method will deliver more available updates more reliably. This solution also has bands of computers set for testing of updates before they go out to the entire fleet. It is more complicated in this tool to establish and maintain a specific list of machines for the different bands and so the targets are randomly chosen by InTune for each update.
Alpha – 5% of all lab/office computers, installs 2 days after patch Tuesday
Beta – 15% of all lab/office computers, installs 8 days after patch Tuesday
All – 80% of all lab/office computers, installs 12 days after patch Tuesday
Critical/Out of band – would be set to install within 48 hours
PMPC compatible apps are automatically added to PMPC =< 7 days after they are released by the product’s software development company. If the product has been packaged in the past, PMPC will automatically swap the updated package in SCCM and it will go out to existing deployments.
Non-CVE apps – Updated as requested by clients or as we are notified about security/bugfix updates. Many apps in academia are less used/known apps that are used infrequently, not updated by the developer frequently, or don’t make it onto CVE lists.
CVE apps - If we get an alert about a high CVE product that is not covered by PMPC, SMC will manually create a package immediately, typically within 1-2 business days, but no later than 1 week depending upon the severity of the CVSS rating.
Runs overnight every 7 days. Installs drivers and BIOS updates from Dell. Most updates can be run by the client with this tool, but not all.
Some applications can be a standalone executable that can function on its own without registering with Windows. Unless other tools we use for security are able to find these executables, or we’re told to look specifically for them, they may not be patched.
Some products are not able to be automated for install through our management tools. Either the client or LTS staff have to manually go through the install process. If we get an alert about a high CVE for one of these products, LTS staff would ensure the impacted application’s update is installed within 7 days or less based on any assigned CVSS rating.
When a computer is imaged with a new install of Windows, the Dell CCTK sets all computers to wake every night at midnight. In the case of portable computers, we also check that it is plugged into a power source to prevent them from powering on while in some type of storage.
This is a group of managed Windows computers that are in a special group that ignores all requirements that it must reboot to finish installing updates. These machines are typically used to run long-term experiments that can’t be interrupted to prevent research data loss. We are working on the best way to automate a report for SMC to follow-up weekly with computers that have not reboot in the last 14 days. It is our intent to also run managed Windows computers through an eForm approval process so it is tracked and reviewed on an annual basis like other information security items.
This is a group of Windows computers that no longer have our Windows management agent on it and are no longer bound to Active Directory. These Windows computers are removed from the campus network and are often connected to research equipment that frequently is too expensive for campus to replace the hardware and/or software, or there is no equivalent replacement available. This typically happens when the vendor does not provide versions of software that will operate on the latest supported version of Windows or the vendor states our management tools will interfere with the operation of their product even if on a supported version of Windows.
LTS continues to identify computers in these situations within our IT asset management system with several attributes:
Assigned the asset form “Unmanaged Computer”
Special Inventory field set to “Yes”
Off Network field set to “Yes”
With how our current solutions are configured on-premises and in the cloud, as long as the managed device has access to the public internet, they will be able to receive patching resources as if they were on the campus network.
Note: This automated process was piloted on the smaller Apple device fleet with success and will be implemented for the Windows fleet fall of 2026.
For managed Windows computers that have been powered off, have a broken SCCM client or a variety of other issues, and have not communicated with the SCCM management server:
At 45 days of no talk, an email is sent directly to the client listed as the owner in our IT asset management system to have them power on and update the device
At 60 days of no talk, a ticket for the client and device is automatically created and SMC follows up with the client or takes direct action to get the device powered on and updated
The goal of this process is to help ensure devices remain updated. It also helps identify computers that may no longer be needed and can be either surplus or redeployed later for another purpose. Departments are encouraged to have CSS store unused computers with us to also avoid no talk state.
Any computer that is returned to CSS for us to store in either of these statuses, have their data wiped before going into storage offline. Before they are returned to service they receive a new image of Windows. If some type of critical BIOS update releases while in storage, they are put on our bench and patched. If nothing critical comes while stored to prompt that update, Dell Command Update runs during the imaging sequence regardless.