ACCOUNT LOGIN
Automating New Machine Provisioning: Applications, Updates, and Configuration in One Workflow

Automating New Machine Provisioning: Applications, Updates, and Configuration in One Workflow

Setting up a new machine involves several separate tasks, often handled by different people at different times. Each step is straightforward in isolation, but the effort compounds across many machines—no two machines end up quite the same. 

This article examines how imaging, application installation, update policies and configuration can be combined into a single sequence, and what remains under administrator control at each stage.

 

Why Manual Provisioning Breaks Down at Scale

Manual provisioning doesn’t fail due to the difficulty of any individual step, but because those steps are repeated across every machine in the fleet. Each machine receives whatever installer version was current at the time it was built, so a fleet assembled over six months may end up running three or four versions of the same application. Manually applied settings vary by technician (one may configure the time zone; another may not). 

Updates land whenever a machine happens to be switched on, so patch levels drift apart across identical hardware. The cost shows up later, in support. When no two endpoints match, you can’t reproduce a fault on a second machine, and a fix that works on one doesn’t reliably transfer to the rest.

 

Combining Applications, Updates and Configuration Into One Automated Workflow

Faronics Deploy approaches provisioning as a single, coordinated process. A deployment package handles imaging and application installs together, and a policy takes over from there—governing how those applications update and how the machine stays configured going forward.

The platform runs from the cloud, with policies assigned per group so different fleets can follow different rules from the same console. What follows is a look at three specific capabilities within Deploy that make this unified workflow possible.

  • Application Update Rules

A policy sets one update mode for every managed application, then lets you override individual apps in the grid. There are four:

  • Automatic: The app updates whenever a new version reaches the Faronics Deploy library.
  • Manual: Nothing updates until you trigger it from the Applications grid.
  • Scheduled: Updates run only inside the window set in the policy’s general settings.
  • Version freeze: Updates for that app are blocked.

On a newly imaged machine, the timing of the maintenance window determines when updates are applied. Maintenance can run at a fixed time—1 a.m. daily, for example—or once per day, a set number of minutes after the machine boots.

The second option accommodates fleets without a reliable overnight window, where machines are typically powered off. Users can be notified before maintenance begins and given a snooze option of one to 12 hours, preventing updates from interrupting active work.

  • Windows Update Rules

Windows Updates are governed by category. For each one (critical, security, definition, rollup, drivers and the rest), a Faronics Deploy policy holds one of three states:

  • Automatic install: Patches in that category go out as they release.
  • Denied: Patches in that category don’t install at all.
  • Neither box checked: Approval falls to you, done per patch from the Windows Updates grid by name or KB number.

Automatic install also accepts a deferral period, set in days. Setting security updates to a 20-day deferral means a patch reaches your machines 20 days after release, allowing time for problems to appear elsewhere first. Feature updates can be deferred up to 365 days, quality updates up to 30.

Deferral functions as a lightweight form of patch testing. A more thorough approach uses two policies: a small test group with the category set to automatic install, and a production group with the same category left unmarked. Approval there stays manual until the patch has run successfully in the test group.

  • Application Version Freezing and Shortcuts

Two per-application controls in the Faronics Deploy policy grid address cases where an application should remain at a fixed version or be less visible to users. Version freeze holds an application at its installed version and blocks further updates. The policy’s update mode can be set to version freeze to apply this to all applications, or left on automatic, scheduled, or manual with the version freeze box checked beside specific applications.

Freezing individual applications keeps the rest of the build current. This is useful when only a small number of applications need to remain fixed. Examples include the browser version a testing tool was certified against, or the runtime a line-of-business application depends on.

Disable shortcuts is narrower than it sounds. It makes an application’s shortcuts unusable, but the application itself remains accessible through the Start menu and File Explorer. Use it to discourage use of an application on a shared build, not to restrict access entirely.

 

Discover Faronics Deploy

Faronics Deploy handles imaging, application installs, update rules and machine configuration from one cloud console, across Windows and macOS. New machines pick up their software through a post-imaging app preset and their update behavior through the policy attached to their group. This moves most of the repetitive setup work off the technician and into the package.

You can start with one group and one policy, then extend the same package to the rest of the fleet.

See how Faronics Deploy handles new machine provisioning.

 

FAQs

 

Can Different Groups of Computers Run Different Update Rules?

Yes. Policies are assigned per group, so a lab and an office fleet can run different update modes and maintenance schedules from the same console.

 

What Happens When a Machine Is Off During Its Update Window?

Nothing installs. Setting maintenance to run a set number of minutes after boot covers machines that aren’t left on overnight.

 

Does Version Freezing Block Security Patches?

It blocks updates for the frozen application only. Windows Updates are governed separately, by category.

 

Can Users Delay a Reboot?

Up to five times, if the policy allows it. Maintenance itself can be snoozed for one to 12 hours.

 

How Often Are Missing Patches Detected?

Patch scans run every six, 12, or 24 hours, depending on the policy setting.

About The Author

Matt Williams

A self-proclaimed ‘tech geek’, Matt has worked in technology for a decade and divides his time between blogging and working in IT. A huge New York Giants fan, expert on Reboot Restore Technology when not watching football Matt gets his game on playing Call of Duty with his friends and other tech bloggers.

Sign Up For A 30-Day Trial

BOXAE

Deep Freeze Enterprise

Centralized deployment and management as well as a host of configuration options for the Enterprise.

  • This field is for validation purposes and should be left unchanged.

Ready to find out more about Faronics? Let us know how to reach you.

We're here to help you in any way possible.