On-Demand Deployment (OS)

On-demand deployment is intended for immediate rollout of specific patches. Use it for urgent security fixes, critical bugs, or targeted updates without waiting for scheduled runs.

Note This section walks through how to create an on-demand deployment for OS patch. For On-Demand Deployment (Application), refer to our dedicated guideline.

Navigate to Patch Management > Jobs and select Create On-Demand Deployment. In the popup dialog, select For Window Patches to begin.


Deployment Information

Provide these details to identify and track the deployment.


  • Title: Enter a brief, memorable name.

  • Description: Specify the target, purpose, and expected outcomes.

  • Tags: Add tags for easy categorization and filtering.

Deployment Schedule

Define the start and end time for the patching window.


  • Date: Select the run date (e.g., 3/11/2026).

  • Start time: Set the exact future start time.

  • End time (optional): The time deployment automatically stops. You can add an end time by clicking Add end time.

    • If no end time is specified, the deployment will only be marked as completed after all endpoints have finished their patching process and reported their results back to My OPSWAT Central Management.

    • Offline endpoints during the window are marked Unreachable.


  • ** Deployment Timezone

      • Fixed timezone: All endpoints begin the deployment at the exact same moment globally.

      • Local timezone: Each endpoint uses its own local timezone.

Reboot Options

Customize reboot behavior to ensure patches are finalized with minimal disruption to users.


  • You can set how often the endpoint prompts the user to restart (e.g., every 1 or 2 hours).

  • You can set the number of prompts a user can skip before the system triggers an automatic reboot to enforce the updates.

Targeted Devices

Select the endpoints to receive this deployment.

Note Deployments support Windows devices only.


  • All Devices: Deployment will be performed on all devices.

  • Specific Groups: The deployment will be performed only on the selected groups.

  • Specific Devices: The deployment will be performed only on the selected devices.

Patch Selection

Choose the patches you want to install.

Note Deployment supports Windows patches only.


  • Condition-Based: Includes patches that match your criteria (e.g., "critical severity"). If you set multiple conditions, a patch only needs to match one to be included.

  • Specific Patches: Manually select the exact patches you want to deploy in this on-demand deployment.

  • Rejected and unsupported patches are automatically excluded from the deployment, even if they match your selection criteria.

Report

Configure notifications for deployment completion.


Add one or more email addresses (e.g., admins, security teams). Recipients get a summary with per-device status: Success, Failure, or Unreachable.

Once a deployment is created, navigate to Patch Management > Deployments to monitor patching process. Refer to Deployment Management (OS) guideline for detailed instructions.