Skip to content
Open app
Open app

Policies, groups and maintenance windows

How to group devices and decide when updates or reboots are allowed.

RMM → Policies (Policy center) covers overview, maintenance windows, device groups and hardware policies (monitoring thresholds). Set fleet rules here instead of clicking every PC.

  1. Open RMM → Policies.
  2. Review the overview tab to see what is already configured.
  3. Then create groups and windows — that order stays cleaner.
  • Maintenance windows = WHEN the window is open and WHICH checked actions it governs (unchecked follow their own schedules).
  • Groups = WHICH devices share the same rules.
  • Hardware policies = thresholds (e.g. temperature, disk) for monitoring.

A window defines when it is open (days/hours) and which actions it governs (updates, restart from console, backup, scripts). Unchecked actions follow their own schedules (e.g. backup job cron). Scope can be the whole company, a location, a group or a single device.

  1. In Policies open Maintenance windows.
  2. Create a window: name, days/hours, actions governed by the window.
  3. Set scope (e.g. “Servers” group) and save.
  4. Verify on 1–2 devices that outside the window the checked actions (e.g. console restart / install) are blocked as expected.
  • Common pattern: endpoints — patches in the evening; servers — weekend only + manual reboot; backups without the Backups checkbox — nightly on the job cron.
  • The “Restart from console” action = when the Restart button in the console is allowed. Auto-reboot after an OS patch is set on the group (“Manual restart only”), not in this checkbox. In a window with the Updates action, the cron reboots a PC that is already waiting for reboot (unless the group is manual-restart-only).
  • If the PC was off during the window, auto-install and auto-reboot do not run at first login — they wait for the next window (typical commercial RMM). Manual Restart / Install from the console still run immediately.
  • A window with no scope does nothing — always attach a group or devices.

Group devices by role (servers, endpoints, sensitive). On a group you can enable “Manual restart only” so updates do not reboot by themselves — you reboot on purpose.

  1. Policies → Device groups (or bulk from Endpoints: Add to group / Remove from group).
  2. Create groups: e.g. Servers, Endpoints, Sensitive.
  3. For servers enable manual-restart-only if required.
  4. Assign devices and optionally attach a maintenance window.
  • Groups describe the segment; windows enforce the schedule — use both.
  • A device can belong to several groups. “Add to group” attaches another group — it does not move the device. To drop one: workbench → Access → × on the tag, or bulk Remove from group.
  • After changing a group, refresh Devices — group tags should show next to the name.