Edit

Share via


Tutorial: Schedule updates on dynamic scopes

Applies to: ✔️ Windows VMs ✔️ Linux VMs ✔️ On-premises environment ✔️ Azure VMs ✔️ Azure Arc-enabled servers.

This tutorial explains how you can create a dynamic scope and apply patches based on the criteria.

In this tutorial, you:

  • Create and edit groups.
  • Associate a schedule.

If you don't have an Azure subscription, create a free account before you begin.

Prerequisites

Patch Orchestration must be set to Customer Managed Schedules.

Create a dynamic scope

A dynamic scope exists within the context of a schedule only. You can use one schedule to link to a machine, a dynamic scope, or both. One dynamic scope can't have more than one schedule.

To create a dynamic scope, follow these steps:

  1. Sign in to the Azure portal and go to Azure Update Manager.

  2. Select Overview > Schedule updates > Create a maintenance configuration.

  3. On the Create a maintenance configuration pane, enter the details on the Basics tab. For Maintenance scope, select Guest (Azure VM, Arc-enabled VMs/servers).

  4. On the Dynamic scopes tab, follow the steps to add a dynamic scope.

  5. On the Machines tab, select Add machines to add any individual machines to the maintenance configuration.

  6. On the Updates tab, select the patch classification that you want to include or exclude. Then select Tags.

  7. On the Tags tab, provide the tags.

  8. On the Review + Create tab, review your configuration and then select Create.

Providing consent to apply updates is an important step in the workflow of scheduled patching. For steps that cover the various ways to provide consent, see Provide consent to apply updates.