I need to setup a group of clients so that they download their patches outside of production and only during maintenance. I understand the maintenance window being configured means the patches will install when the maintenance window opens. But I'd also like to suppress the download as well. The best idea I can come up with is to...
Windows Patch Remediation Settings - Patch Filter Update Interval - Change from every 30 minutes to daily at the same time our maintenance window opens. (Or every 30 minutes within our maintenance window).
That way when the patch filters are updated, the clients will then need to check in (currently hourly) and they'll get there policies applied and follow up with the package downloads. The thing is, I have agents around the globe and I can't have patch filter updates specific to a group of machines.
Is there a way to setup the package downloads for the patches to only run during the general agent maintenance window? Or any other way to assure the patch packages are only downloaded within a certain time period? I'd prefer not to do an agent blackout as there are times we need to run tasks and choose "override maintenance window". I could do throttling but the goal is for NO download traffic. If it where I software management policy I would have the ability to control this with the compliance check schedule.