Patch Authority Ultimate
Comprehensive Patch Management

Patch Authority Ultimate is a robust, multi-faceted patch management application that includes a robust patch detection engine for automating the patching of software on virtual and physical desktop machines and servers, minimizing the amount of time required for IT administrators to secure the network.
Patch Authority Ultimate features:
- Comprehensive Patching (Windows, Office, Exchange, IIS, SQL, Adobe, Winzip and more...)
- Automated Patch Management
- Virtual Machine Management
- Robust Reporting
- Ease of Use
Virtual Machine Management
Patch Authority Ultimate enables you to scan and patch online and offline virtual machines as well as VMware templates. A virtual machine that is online and running is treated by PAU exactly the same as a physical machine. Offline virtual machines are those that aren’t powered on when a patch scan is performed. It’s important to ensure that these systems are patched so that when they are brought online they don’t place your network at risk.
Fast Deployment
Scan your network and start patching machines in less than 30 minutes.
Scheduled Patch File Downloads
Automatically check for new patches on a recurring basis. The scheduled check and download function can occur hourly – even when the console is closed.
Automated Synchronisation of Distribution Servers
Define the interval when you’d like to sync your distribution servers with the PAU console or manually synchronize your distribution servers.
Flexible & Robust Scanning Options
PAU provides a number of ways to perform a scan. The home page provides simple one-click methods for beginning a scan. Or, you can begin scans from within a machine group or with a favorite group. Scans can also be performed by domain, organisational unit, machine name, IP address or IP range.
Automated Remote Machine Patching
PAU also allows you to schedule when a patch will be executed on each remote system. The deployment can be set for a specific date/time, immediately, at next reboot, or they can be copied to the machine but not installed. Reboots can occur immediately after the installation of patches, scheduled at the next occurrence of a specific time, or a specific date/time.
Precise Reboot
PAU provides pinpoint control over when systems are rebooted- during planned downtime. This is a critical difference, particularly on servers. PAU enables administrators to specify detailed, granular reboot instructions that allow for system restarting during scheduled windows. Remediation and reboots can be scheduled separately.
Automated Patch Deployment
By enabling the Auto Deploy option, you can automatically enforce patch policies by correcting any discrepancies found on the scanned machines. Any missing patches are automatically deployed immediately after the scan.
Custom Patch Management
PAU provides the ability to patch virtually any Windows application on your network, including custom applications and legacy applications. You can also scan for and deploy private patches from Microsoft Corporation. All of this is managed with the implementation of the Custom Patch File Editor. The editor’s wizard-like interface expertly guides you through the process of creating your own custom patch XML files. The program combines your custom XML files with the primary XML patch data file and uses that modified file when performing scans and deployments.
Comprehensive Reporting
More than 20 built-in reports ranging from Executive Dashboard to Patch Status Detail. Reports detail everything from Seat License Count to Patch Status. Advanced filtering allows you to obtain a very granular view all the way down to specific machines or specific patches. Reports can be exported in 9 different formats. Automatically email reports or notifications by defining the email recipients in scan template, deployment template, or machine group.
Multiple Console Configurations
For larger organisations there are many advantages to maintaining multiple consoles:
- The consoles can reside at physically distinct locations and be close to the machines they are managing
- You can distribute the workload across multiple consoles
- The scans, deployments, and remediations are performed much quicker
- You won't tie up your network trying to scan hundreds of geographically distinct machines from one location
- It cuts down on a lot of network traffic, especially over WANs
- The results from each console can be rolled up to and viewed from one central location
Agent-Based Patching
Keep remote employees who are not always connected to the network always up-to-date using agents. The Patch Authority Ultimate agent can be deployed to mobile devices and users and provides the ability to push patches when connected to the network. The PAU agent supports the patching of Service Packs as well as checkpoint or restarting of any patch deployments that were interrupted if network connection was lost.
Machine Groups
PAU uses machine groups to keep track of the machines that are included in a particular scan. The machine groups within PAU are flexible enough to allow you to organize and group machines based on OU, Domain or IP Ranges which will automatically identify new machines that are added to the network.
Machine View
PAU uses machine groups to keep track of the machines that are included in a particular scan. The machine groups within PAU are flexible enough to allow you to organize and group machines based on OU, Domain or IP Ranges which will automatically identify new machines that are added to the network.
- You are not restricted to viewing just those machines involved in a particular scan. You can view all the machines that have ever been scanned.
- You can quickly assess the status of all machines in your organisation
- You can filter the information and drill down into the table for a more detailed analysis
Role-based Administration
You can assign different roles to different users of PAU. This enables you to make the program available to a wide variety of people within your organisation while maintaining control over its use. The role assigned to a user determines what that particular user can do.
Includes Security Explorer
Enhance your security with central management of service status, configuration, logon accounts and scheduled task configuration.

