Patch Management for Small Business: A Practical Policy
A working patch policy for a small office: what to update, how fast, how to stage Windows updates with Intune rings, and how to handle apps and firmware.
Patch management is the routine of finding, installing, and confirming software updates on everything your business runs: computers, phones, applications, servers, and network equipment. A workable small-office policy fits on one page. Keep an inventory, let operating systems and browsers update automatically, stage Windows updates so a few machines get them first, set deadlines so restarts actually happen, check third-party apps and firmware on a calendar, and verify the results every month. The sections below give you each piece.
What needs patching?
It is easy to think of Windows and stop there. The full list is longer:
- Operating systems: Windows, macOS, iOS, Android, and any server OS.
- Browsers: Chrome, Edge, Firefox, Safari.
- Microsoft 365 apps. The Click-to-Run versions of Office update through their own channel. Microsoft notes they cannot be updated through Windows Update policies.
- Third-party apps: PDF readers, Zoom, accounting software, remote access tools, Java.
- Line-of-business software: practice management, point of sale, design or imaging tools. The vendor usually controls the schedule and the supported OS versions.
- Drivers and computer firmware (BIOS or UEFI).
- Network equipment firmware: firewall, router, switches, Wi-Fi access points, network storage, printers, cameras, and phone systems.
NIST defines enterprise patch management as “identifying, prioritizing, acquiring, installing, and verifying the installation of patches, updates, and upgrades” in SP 800-40 Rev. 4. The same five verbs work for an office of ten.
A simple patching policy you can adopt
Start with an inventory. For every device and application, record the owner, the version, who the vendor is, and whether it is reachable from the internet. You cannot patch what nobody has written down.
Then set target timelines. These are reasonable starting points that we suggest, not an external standard. Adjust them to your business.
| What | Target | How |
|---|---|---|
| A vulnerability listed in CISA’s Known Exploited Vulnerabilities Catalog, or anything on an internet-facing device | As soon as the fix is available, within days | Manual push or expedited update |
| Monthly Windows and macOS security updates | Pilot machines within a few days, everyone within two weeks | Update rings with deadlines |
| Browsers and Microsoft 365 apps | Automatic | Leave auto-update on and make sure people restart the apps |
| Other third-party apps | Monthly check | Management tool, or a calendar reminder |
| Firewall, router, and Wi-Fi firmware | Check quarterly, and immediately on a vendor security advisory | Scheduled window, with a configuration backup first |
| Feature upgrades (a new Windows version) | When the vendors of your key software confirm support | Planned project |
CISA recommends using the KEV catalog as an input when deciding what to fix first. It lists flaws that attackers are known to be using, which makes it a better urgency signal than a severity score alone. CISA’s #StopRansomware Guide also singles out timely patching of internet-facing systems.
How do Windows update rings work?
Microsoft releases Windows quality updates, which include security fixes, on the second Tuesday of each month. The risk with any update is that it breaks something, so the standard approach is to stage it. A “ring” is a group of devices that gets updates on the same schedule. A few pilot machines go first, and everyone else follows a few days later if nothing went wrong.
The tools Microsoft provides
- Windows Update client policies. This is the current name for what was called Windows Update for Business. Microsoft describes it as a free service for Windows Pro, Education, and Enterprise editions that lets you defer quality updates up to 30 days, defer feature updates up to 365 days, pause updates for 35 days, and set install deadlines. You configure it with Group Policy or a device management tool. Windows Home is not supported.
- Intune update rings. If you have Microsoft Intune (Plan 1 is included in Microsoft 365 Business Premium), the same policies are set from a web console and assigned to groups of devices.
- Windows Autopatch. Microsoft lists Business Premium among the licenses that include Autopatch, which can create and manage the rings for you and adds reporting on update status. Devices must be company-owned and enrolled in Intune.
A two-ring setup for a small office
In the Intune admin center, go to Devices, then By platform, then Windows, then Manage updates, then Windows updates. Open the Update rings tab and select Create profile.
- Pilot ring. Two or three computers that between them run all of your important software, used by people who will speak up if something breaks. Quality update deferral: 0 days.
- Everyone ring. All other computers. Quality update deferral: 5 to 7 days.
- On both rings, set a deadline (for example, 3 days after the update is offered) and a short grace period before a forced restart. Deadlines are what stop “remind me later” from running for months.
- Assign each ring to a device group, not a user group, so the policy applies before anyone signs in.
- If a bad update appears, use Pause on the Everyone ring. It holds updates for up to 35 days. Uninstall can roll back the latest quality update.
Microsoft also offers hotpatch updates, which install security fixes without a restart in most months. They require Windows 11 version 24H2 or later, Intune, and an eligible license, and Microsoft’s Autopatch FAQ lists Business Premium as eligible.
No Intune?
On Windows Pro you can set the same deferral and deadline policies with local Group Policy on each machine, which is fine for a handful of PCs. At minimum, leave automatic updates on, set active hours so restarts happen overnight, and ask staff to leave computers on and plugged in one night a week.
Macs, iPhones, and iPads update through Apple’s Software Update. Turn on automatic updates, and if the devices are enrolled in mobile device management, you can enforce a minimum OS version.
How do you keep third-party apps updated?
Windows Update does not touch most non-Microsoft software. Your options, from least to most effort saved:
- Built-in auto-updaters. Chrome, Edge, Firefox, Zoom, and many others update themselves. The fix often waits until the app restarts, so closing the browser fully now and then matters.
- A scheduled manual check. A monthly reminder to open each app on the inventory and look for updates. Tedious, but workable for five computers.
- Intune Enterprise App Management. Microsoft’s catalog of prepackaged apps can keep many common Windows apps updated automatically. It requires a paid add-on beyond Intune Plan 1.
- A third-party patching or remote management tool. Several products handle Windows and common apps together. Compare their app catalogs against your inventory before buying.
Remove software nobody uses. An app that is not installed needs no patches.
What about firmware and network equipment?
Firewalls, routers, and VPN appliances sit directly on the internet, which makes their firmware some of the most important patching you will do, and the easiest to forget because nothing prompts you.
- Sign up for each vendor’s security advisory emails.
- Export a configuration backup before every firmware update.
- Update in a maintenance window, and have someone on site or a way back in if the device does not return.
- Record the end-of-support date for each device. Hardware that no longer receives firmware should be scheduled for replacement. See our firewall guide.
- For computers, Windows Update can deliver many driver and firmware updates, and Dell, HP, and Lenovo each provide their own update utilities.
Software that cannot be updated on schedule
Some systems depend on a vendor: imaging software that supports only certain Windows versions, a payment terminal with its own release cycle, a machine controller. For these:
- Ask the vendor in writing which OS versions and updates they support.
- Put those computers in their own slower ring so they are not updated ahead of vendor approval.
- Reduce exposure in the meantime: no email or general web browsing on that machine, and its own network segment.
- Write down the exception, the reason, and a review date.
Windows 10 is the largest example. Support ended on October 14, 2025. Microsoft’s Extended Security Updates program for organizations costs $61 per device for year one through volume licensing, doubles each consecutive year, and runs for a maximum of three years. It buys time and nothing else. Our Windows 10 end-of-life guide covers the options.
How do you verify that patches installed?
“Downloaded” is not “installed.” Once a month, check:
- The installed OS build on each device against the current release.
- Devices showing a pending restart.
- Devices that have not checked in for two weeks or more. A laptop in a drawer is still a liability the day it comes back.
- Failed updates, and the error behind them. Rule out low disk space first: Microsoft recommends at least 10 GB free.
Intune and Autopatch provide update reports. Without them, Settings, then Windows Update, then Update history on each PC shows the same information one machine at a time. A vulnerability scan is an independent check that catches what the update tools miss. If you use Defender for Business, its vulnerability management view lists missing updates by device.
After any significant update, test the business task, not only the version number: open the practice software, print, scan, run a test transaction.
Common mistakes
- Deferring updates “until things calm down” and never setting a deadline.
- Patching Windows and ignoring the firewall.
- Leaving Windows Home on business computers, where update policies do not apply.
- Turning on automatic updates for a vendor-dependent system without asking the vendor.
- Reporting patching as complete without checking the devices that were offline.
- Having no way back. Know the rollback option before a significant update: an uninstall, a configuration backup, or a spare machine.
Common questions
Should we just turn on automatic updates everywhere?
For operating systems, browsers, and Microsoft 365 apps on ordinary office computers, yes. Automatic updates with a restart deadline are safer than manual habits. The exceptions are computers tied to vendor-certified software and network equipment, where a planned window and a backup are the better approach.
How long is it safe to delay a Windows update?
Windows allows quality updates to be deferred up to 30 days, but for most computers a delay of about a week gives time for widespread problems with an update to surface. Anything on CISA’s Known Exploited Vulnerabilities list, or affecting an internet-facing system, should not wait for the normal cycle.
What is Patch Tuesday?
It is the informal name for the second Tuesday of each month, when Microsoft typically releases its monthly Windows quality updates, including security fixes. Microsoft can also release urgent fixes at any other time. It is a convenient anchor for a monthly routine.
Do Macs and phones need patch management?
Yes. Apple and Google release security updates regularly, and phones often hold business email and files. Turn on automatic updates, and use device management to require a minimum OS version before a device can reach company data. A BYOD policy should state that expectation for personal phones.
How we can help
Coastal Growth Co. can build your inventory, set up Intune update rings or Autopatch, put third-party apps and firmware on a schedule, and send you a short monthly report of what was installed and what is still outstanding. This can be a one-time setup or part of ongoing managed IT support. Scope and price are agreed before paid work begins. Contact us to get started.
- patch management
- Windows Update
- Microsoft Intune
- cybersecurity
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward