ITSM

ManageEngine Endpoint Central -
patch management step by step

How to automate patch management in your company? ManageEngine Endpoint Central - configuration, policies, reporting for IT administrators.

← Back to Blog
ITSM
Jakub Roszkiewicz · May 2026 · 10 min read

Many companies still do not have fully automated patch management - they install patches manually, without a schedule, or wait for "someone to do it". Every unpatched machine is a potential entry path for an attacker. On top of that, in September 2024 Microsoft announced that WSUS - the traditional update distribution tool - is a deprecated product: it still works and is supported but no longer receives new features. That pushes companies to consider more modern solutions. ManageEngine Endpoint Central automates patch management - downloading, testing, deploying and reporting patches on 50-5000+ computers. In this article I show how to configure it from scratch.

patch
automation - download, test, deploy, report
WSUS
deprecated since 2024 - no new features
50-5000+
computers covered by one Endpoint Central instance

What is ManageEngine Endpoint Central?

Endpoint Central is a system for managing computers on a network (Endpoint Management) - with a focus on patch management. It is not the same as Intune - Endpoint Central is on-premise (on your server) or cloud, but more configurable than Microsoft's cloud solutions.

Main capabilities:

Free consultation

ITSM implementation for your company - start with needs analysis.

Endpoint Central setup with no commitment - 30 minutes online.

Book 30 min →

How automatic patch management works in Endpoint Central

The process looks like this:

  1. An agent is installed on the machine - a simple MSI that talks to the Endpoint Central server every 1-4 hours.
  2. The server fetches patches from the Microsoft source - not from WSUS, directly from the vendor (or from an offline copy if your machines have no internet access).
  3. Patches are verified and categorized - Security (critical), Updates (regular), Preview (test). The administrator decides which categories to roll out.
  4. Scheduling policy - for example "Security patches every other Tuesday at 23:00, with a 30-minute window; if not installed, retry at 2:00".
  5. Rollback-aware rollout - if the machine fails to start after patching, it can roll back automatically.
  6. Reporting - the dashboard shows: how many machines patched, how many in the queue, how many errors. Detailed logs per machine.

The result: instead of running WSUS manually every month and hoping everything installs, you have full automation.

Configuring patching policies - step by step

Practical setup for a company of 200 machines:

Step 1: Log in to Endpoint Central → Admin → Patch Management → Patch Policies
Click "Add Patch Policy" and the wizard appears.

Step 2: Name the policy and pick patch categories
Example: "Security & Critical Patches"
Categories: Security Updates, Critical Updates. Leave the regular Updates for a second policy.

Step 3: Set the deployment schedule
Frequency: Every 2 weeks
Day: Tuesday (because Microsoft releases patches on Tuesday UTC)
Time: 23:00 (evening, to avoid disrupting work)
Installation window: 30 minutes (the machine has 30 minutes to install, otherwise it times out)
Reboot behavior: "Allow reboot if required" - if the patch requires a reboot, the machine restarts automatically after a 15-minute warning.

Step 4: Assign machines to the policy
You can pick individual computers, Active Directory groups (for example OU=Office, OU=Production), or all machines. If you have critical machines (servers), you can exclude them from automation - patch manually.

Step 5: Testing
Before you push the policy to all machines, run it on a test group (for example 10 machines). Monitor the report for 2 weeks - did all the machines install without errors? Did any "break"? If OK, push to the whole network.

Inventory and compliance: what Endpoint Central sees on the network

Once the Endpoint Central agent is installed, the server automatically collects from each machine:

The Compliance Report dashboard shows: how many machines have current patches, how many have unlicensed software installed, how many have antivirus disabled. Very valuable for audits and NIS2 compliance.

Endpoint Central vs WSUS vs Microsoft Intune - table

CriterionEndpoint CentralWSUS (EOL)Microsoft Intune
Deployment modelOn-Premise or CloudOn-Premise onlyCloud SaaS (Microsoft Azure)
Vendor supportActive (Zoho)Deprecated since 2024 - works, no new featuresActive (Microsoft)
Patch ManagementAdvanced, schedulesBasic, limitedAdvanced + mobile
Software DeploymentMSI, EXE, scripts, AppXNoneLimited (LOB apps)
Hardware inventoryDetailed (CPU, RAM, disk, MAC)BasicDetailed + mobile devices
Compliance ReportingPCI-DSS, HIPAA, SOC2, GDPRNoneAdvanced, Defender integration
Pricing modelAnnual or perpetual license - quote based on machine countRole built into Windows Server (no separate fee)Part of Microsoft 365 / Intune subscription
IntuitivenessModern UI, simple setupOld UI, hardIntuitive (Microsoft 365 admin center)
Offline supportPossible (offline repo)Online onlyNo (cloud only)
Recommendation for 50-500 machinesGood choice - advanced patch managementWorks, but plan a successorSensible if you already have M365 E3+

FAQ - ManageEngine Endpoint Central

What is ManageEngine Endpoint Central used for?

Endpoint Central is a system for managing updates (patch management), software deployment, configuration and security on all computers on the network. It automates Windows patch rollout, manages Windows on 50-5000+ machines, oversees compliance, reports vulnerabilities.

Does Endpoint Central replace WSUS?

Endpoint Central can serve as a more modern alternative to WSUS. Both manage Windows patches, but Endpoint Central offers a richer interface, schedules, support for third-party applications and compliance reporting. Microsoft announced WSUS as a deprecated product in September 2024 - WSUS still works and is supported but does not receive new features, so it is worth planning a move to Endpoint Central or Microsoft Intune.

How do I configure a patch management policy in Endpoint Central?

In Endpoint Central: Admin > Patch Management > Patch Policies. Define a policy (for example Security & Critical: every 2 weeks on Sunday 23:00 with a 24h rollback window). Attach computers to the policy (via OU, AD groups or manual tags). Endpoint Central automatically fetches patches from the Microsoft source, verifies them and deploys them on schedule. The dashboard shows % of machines patched, install queue, errors.

What is a Patch Deployment Schedule in Endpoint Central?

A Patch Deployment Schedule is a deployment timetable for a group of computers. Example: security patches every 2 weeks in a 23:00-23:30 window (because vendors release patches on Tuesday, American time). You can set a roll-out: 10% of machines on Monday, 50% on Wednesday, 100% on Friday - to reduce risk across the whole infrastructure.

JR
Jakub Roszkiewicz
CTO · Rotech Group · specialist in ManageEngine Endpoint Central and patch management
Free patch management audit

Is your network up to date?

Rotech Group will scan your infrastructure and check how many machines have current patches. Report + Endpoint Central implementation quote - no commitment.

Book a free consultation →