Help Center/Statuses & glossary

Statuses & glossary

Every status vocabulary used across Patch Console, in one place, plus the terms the rest of the documentation leans on.

Deploy states

The lifecycle of a patch group's deployment, from creation to cleanup:

StateMeaning
newNewGroup created; no installer validated yet.
validatedValidatedInstaller passed SHA-256 and signature checks.
approvedApprovedIntune artifacts or signed agent scripts created; rollout in motion.
deployedDeployedThe rollout reached its devices; verification is tracking results.
retiredRetiredFinished; artifacts cleaned up.

Fleet statuses

The per-group rollup of how the member devices stand against the fix target:

StatusMeaning
OpenOpenDevices remain below the fix target and unaddressed.
PartialPartialSome devices are verified at target; others are still pending or failing.
DoneDoneEvery member device is verified at or above the fix target (or the product was removed).
Not DeployedNot DeployedThe group has no active deployment yet.

Finding statuses

StatusSet byMeaning
openengineVulnerable version present, no deployment covering it.
patch_availableengineA fixed version exists; the finding is actionable.
remediation_scheduledengineAn approved deployment targets this device and product.
remediation_attemptedengineThe install ran; inventory has not yet proven the fix.
reboot_requiredengineThe update landed but needs a restart to take effect.
remediation_failedengineThe deployment ran and the device is still vulnerable.
resolvedengineInventory proved the fixed version, or the software was removed.
mitigatedadminAddressed by a compensating control; audited.
accepted_riskadminDeliberately accepted, on record; audited.
false_positiveadminThe match is wrong for this device; audited.

Grade bands

BandReading
A / BHealthyStrong severity-weighted coverage, no open caps.
CNeeds attentionCoverage slipping or a cap in effect.
D / FCriticalSignificant unremediated exposure.

Terms

TermMeaning
Patch groupThe unit of work: one product, a fix target version, and every device below it.
Fix targetThe version at or above which the group's vulnerabilities are fixed; everything measures against it.
Pilot ringThe small set of devices a deployment reaches first, before the rest of the group.
Version gateThe post-install check that reads the real installed version and refuses success if it did not move.
Hybrid groupA patch group containing both Intune-managed and agent-only devices; each device uses its own channel.
Self-servicing productA product only its own vendor updater can update (Defender platform, Microsoft 365 Apps). See Self-servicing products.
Auto-haltThe safety rail that stops a deployment after 3 device failures or 10% of the group failing.
Four-eyes approvalThe second-administrator sign-off required for agent-channel deployments above 25 devices.
KEVCISA's Known Exploited Vulnerabilities catalog; open KEV findings cap the Remediation Grade.
EPSSExploit Prediction Scoring System, the probability a CVE will be exploited in the wild.
OSVThe open-source vulnerability feed used for npm, PyPI, and NuGet developer packages.
EOLEnd-of-life software that will never receive a patch; its presence caps the Remediation Grade.