SMA (K1000)

Please tell us how you’d like to see the Systems Management Appliance product improved!

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Suspend BitLocker as part of the Patch Detect & Deploy Jobs

    K1000 should (through inventory detection) be able to determine that the machine has BitLocker enabled and during a patch deployment of that machine, there should be an option to suspend BitLocker (manage-bde –protectors –disable c:) before the reboot so the patch job does not get stuck at waiting for a user to enter the BitLocker PIN. If multiple reboots are required the K1000 can continue to disable BitLocker in a Detect & Deploy job until all patches have been installed. After which BitLocker can be resumed. This would be a HUGE help if it can be added to the product.…

    309 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    14 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  2. Rerun patch schedules for only the devices that are offline or have errors

    instead of rerunning a patch schedule for all devices, just continue to run the patch schedule on devices that are not completed or have errored out. If you have two schedules one that has no reboots and and one patch schedule with a reboot option. it should reboot the machine instead of bypassing the pending reboot status inorder to patch the missing patch

    2 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  3. Patch Management Compliance

    Under Patch Management > Catalog you can see the compliance of a single patch. It shows you the number of computers that have a patch installed or missing but you can't click on the numbers and get a list of the computers. Being able to click on the numbers would be great. You could get an instant view of computers names that have a patch installed or missing.

    11 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  4. Firmware Patching

    Currently Kace patches Dell firmware. Surface Pro systems have several firmware updates in the windows updates.

    When can we get the Surface Pro (and others) to have firmware included in patching?

    34 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  5. Change Windows Update last check after patching

    Following the "Wannacrypt" panic in my company, an admin invited all users to "manually" update their computer. But many of them were angry against the admins team when they seen the last Windows Update check was one year ago.
    Actually, the K1000 appliance is patching the client computers daily, but the "Windows Update last check" date is not modified, so the users think updates are not applied.
    It could be appreciated if this "flag" can be upadted after patching through Kace.

    21 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  6. Security Patches should not be superseded by non security patches

    In our environment, we use Kace to deliver Microsoft security patches to our Windows Servers. We also use the setting to inactivate superseded patches to reduce patch installation redundancy.

    I found the July Windows Server 2016 cummulative update, KB4025339, was superseded a week later by KB4025334, which is a non-security update. This completely messes up my patching workflow.

    My current options, as I see it, are to either included non-security updates in my patching catalog and figure out which ones I am going to allow, or to allow superseded patches to remain active.

    Based on this, in my opinion, a…

    11 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  7. Fix the Patch Catalog

    Monthly Quality roll-ups do not supersede Monthly Security-only roll-ups as they should.

    10 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  8. Notification if patch subscription is expired

    It would be nice if you could set KACE to alert you with an email or otherwise if your patch subscription expires for one reason or another so you can take action immediately.

    10 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  9. Hard Drive Encryption

    Please see if we can inject a script before patching starts to turn off login for encryption (Symantec Endpoint Encryption) and a script to turn back on after patching is done.

    4 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  10. When patching fails with "error", tell us what the problem is!

    What a concept. It says "error" and error only. Tell us what the error is and why it's failing, maybe a solution??

    44 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  11. Add Publishers - Ability to add our own Publishers

    Ability to add publishers so we can add more software to be updated.

    21 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  12. Allow for Maintenance Windows for patch deployments

    With SCCM there is the option to allow a Maintenance window for a group of machines (collection). So i could have a single patch schedule which defines the group of patches to be deployed and assign it to all systems. The machines would ONLY be able to download and install the patches based on the defined maintenance window.

    Example:

    Server Group A - midnight to 2am
    Server Group B - 2am to 4am
    Server Group C - 4am to 6am

    Patch schedule includes all server groups. But based on the respective windows the times these servers will patch will be…

    11 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  13. Notifications for Patching

    It would be nice to have the ability to link one or more email addresses to a patch schedule kind of like in the reporting. When all the servers in the schedule are finished (completed, error, or reboot pending) an email is sent to notify someone.

    16 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  14. Pre-staging of patches

    To increase our patching run rates and to better manage network bandwidth, we’d like the ability to pre-stage required patches on systems and kick off the installation at a designated time; preferably, the appliance tells the agent to start its patching cycle at the designated time (especially for devices off-network like laptops).

    It's my understanding that staging doesn't occur with just a detect; the updates are only copied down during the deploy phase.

    171 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    5 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  15. Check all sessions before restarting the machine

    When a patch management deploy schedule has a reboot option enabled with the property "Automatically Reboot When No One Is Logged In" set to true, the Dell KACE agent should check all sessions on the system, not just the console session. If someone logs-in to their desktop via RDP and then disconnects, the agent (as it works now) will automatically restart the PC because it is only checking the console session.

    12 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  16. Patching - ability to display list of patches to be installed

    The option to display "details" of a patch job would be nice. A competitors product was nice in this regard. Key patch testers would know with no clicks just what was to be done to their systems.

    9 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  17. Add the ability to associate a script to a Patch Schedule

    I would love to have the ability to run a script as part of a patch schedule and have it run before the patching begins.

    The example I have in mind would be for patching BIOS on computers using Bitlocker. I could have a separate patch schedule for BIOS patching only and have a script set to run prior to patching that would suspend bitlocker and enable it after the next reboot. With it being integrated with the patch schedule, I would not have to worry about the bitlocker disable script running needlessly.

    I am doing something similar with scripts,…

    36 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    3 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  18. End-user ability to minimize the patching box that comes up.

    Currently, the user can drag the box off the screen to get rid of it, but it is still there if there are giving a presentation, for example. It should be fairly easy to make it so the end-user can minimize the box.

    12 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  19. "Lock" a patch label

    Our current patching procedure involves running a test job of newly released patches from our smart labels on the Wed. following Patch Tues. We run this test job on approx. 10 IT lab PC’s + the PC’s of users who use critical applications. Once the test job and application testing is complete, we would like a way to lock the patch job to prevent additional patches from being added to the Smart Labels. Currently, patches that are downloaded to the K1000 subsequent to our testing and prior to the scheduled company-wide patch deployment can be dynamically added to the Smart…

    16 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  20. Email notification upon Patch Schedule Completion

    As many users do, i assume that they have patch schedules set up.. Detect or Deploy only. or even full detect and deploy.. Set up to run at specific times.

    Currently, when you go into that patch schedule, you can see down at the bottom, the machines it will be doing (based on your selection), with Amount needing to be patching, that were patched, etc.. and the STATUS.

    Currently i have created a report, which i now manually run the next morning, to give me this information. I want to see WHAT was done automatically, without having to log into…

    27 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base