Idolbe Patch

Getting started

From sign-up to the first patched endpoint: agents, groups, approvals, automations, alerts.

Idolbe Patch is a cloud console that keeps Windows and Linux computers patched and shows you which vulnerabilities are present on them. A small agent on each computer talks to the console over HTTPS; nothing is installed on your network and no inbound port is opened.

This guide takes you from sign-up to a fleet that patches itself. Fifteen minutes is enough for the first computer.

1. Create your organization

Open the console and choose Create account. Use your work email address: the first user becomes the administrator of a new, isolated organization. Everything you see afterwards (endpoints, groups, reports, users, audit trail) belongs to that organization only.

You can create more organizations later (Organizations → New organization) and switch between them from the top bar. Managed-service providers use one organization per customer.

2. Install the first agent

Go to Getting started (the "+ Install Agent" button in the top bar).

  • Windows: click Download Agent. The file already contains your organization's enrollment key. Run it on the computer, approve the security prompt, done: the agent installs itself as a service and enrolls the computer. See Install the Windows agent.
  • Linux: copy the one-line command and run it as root on the server. See Install the Linux agent.

The page waits for the agent and shows Agent installed when the computer checks in, usually within a minute. From then on the endpoint reports its inventory every hour and picks up your commands within 30 seconds.

Deploying to many computers at once? Getting started → Other options has the silent install command for Group Policy, Intune, SCCM or your RMM tool, and Agent Deployment installs the agent on domain computers from an existing endpoint (Active Directory Deployer).

3. Look at what the agent found

  • Endpoints lists every computer with its operating system, hardware, logged-on user, IP addresses, pending reboot flag and agent version. Click one for the full record: disks, installed software, missing updates, vulnerabilities, custom attributes and a Run Script / Deploy / Reboot toolbar.
  • Update Approval shows every missing update across the fleet (Windows, Microsoft products, drivers, Linux packages and third-party applications detected through winget and the catalog). Approve, decline or leave them for your automations.
  • Vulnerabilities correlates installed software and missing Windows updates with the NVD, CISA KEV and Microsoft advisories. Each CVE shows the affected endpoints and a remediation deadline computed from your SLA settings.
  • Installed Software is the fleet-wide inventory, searchable and exportable.

4. Organize endpoints into groups

Endpoints → Manage groups creates static groups (pick the computers) or dynamic groups (rules on OS, name, domain, custom attributes, agent version, last seen). Groups drive everything else: automations target a group, alerts watch a group, reports can be limited to a group. Built-in groups such as All Endpoints, New Endpoints and per-platform groups exist from the start.

5. Patch automatically

Automations → New automation wizard:

  1. Action: Deploy Updates (or Run Script, Deploy Software, Reboot, Uninstall Software).
  2. What to deploy: all updates, all except drivers, only approved, only selected, or by severity.
  3. Targets: a group or a list of endpoints; optionally deployment rings (a pilot group first, then the rest after a delay).
  4. Schedule: run now, once at a date and time, or daily, weekly, monthly; rings add a delay between the pilot and the rest.
  5. Reboot policy: never, if required (with the branded end-user prompt and postpone options), or always.

Every execution appears under History with a per-endpoint log. You can also run any action immediately on selected endpoints from the Endpoints page.

6. Get told when something needs you

Alerts sends emails when an endpoint goes offline, a group's uptime drops, critical updates are missing, a critical CVE appears, a reboot is pending, or any built-in or custom report returns rows. Scheduled Reports emails any built-in or custom report as CSV or PDF on a schedule.

7. Invite your team

Users & API Credentials adds colleagues with a role: Viewer, Operator, Administrator, or a custom role with exactly the permissions you choose. The same page creates API credentials for integrations (REST API v1). Email-based multi-factor authentication is on by default; Microsoft and Google sign-in can be enabled under Advanced → Security.

What the dashboard checklist tracks

Until the basics are in place, the dashboard shows a six-step checklist: first agent, first group, a Deploy Updates automation, an email alert, a scheduled report and a second user or API credential. Hide it whenever you like.

Where to go next