Getting started
From sign-up to the first patched endpoint: agents, groups, approvals, automations, alerts.
Idolbe Patch is a cloud console that keeps Windows and Linux computers patched and shows you which vulnerabilities are present on them. A small agent on each computer talks to the console over HTTPS; nothing is installed on your network and no inbound port is opened.
This guide takes you from sign-up to a fleet that patches itself. Fifteen minutes is enough for the first computer.
1. Create your organization
Open the console and choose Create account. Use your work email address: the first user becomes the administrator of a new, isolated organization. Everything you see afterwards (endpoints, groups, reports, users, audit trail) belongs to that organization only.
You can create more organizations later (Organizations → New organization) and switch between them from the top bar. Managed-service providers use one organization per customer.
2. Install the first agent
Go to Getting started (the "+ Install Agent" button in the top bar).
- Windows: click Download Agent. The file already contains your organization's enrollment key. Run it on the computer, approve the security prompt, done: the agent installs itself as a service and enrolls the computer. See Install the Windows agent.
- Linux: copy the one-line command and run it as root on the server. See Install the Linux agent.
The page waits for the agent and shows Agent installed when the computer checks in, usually within a minute. From then on the endpoint reports its inventory every hour and picks up your commands within 30 seconds.
Deploying to many computers at once? Getting started → Other options has the silent install command for Group Policy, Intune, SCCM or your RMM tool, and Agent Deployment installs the agent on domain computers from an existing endpoint (Active Directory Deployer).
3. Look at what the agent found
- Endpoints lists every computer with its operating system, hardware, logged-on user, IP addresses, pending reboot flag and agent version. Click one for the full record: disks, installed software, missing updates, vulnerabilities, custom attributes and a Run Script / Deploy / Reboot toolbar.
- Update Approval shows every missing update across the fleet (Windows, Microsoft products, drivers, Linux packages and third-party applications detected through winget and the catalog). Approve, decline or leave them for your automations.
- Vulnerabilities correlates installed software and missing Windows updates with the NVD, CISA KEV and Microsoft advisories. Each CVE shows the affected endpoints and a remediation deadline computed from your SLA settings.
- Installed Software is the fleet-wide inventory, searchable and exportable.
4. Organize endpoints into groups
Endpoints → Manage groups creates static groups (pick the computers) or dynamic groups (rules on OS, name, domain, custom attributes, agent version, last seen). Groups drive everything else: automations target a group, alerts watch a group, reports can be limited to a group. Built-in groups such as All Endpoints, New Endpoints and per-platform groups exist from the start.
5. Patch automatically
Automations → New automation wizard:
- Action: Deploy Updates (or Run Script, Deploy Software, Reboot, Uninstall Software).
- What to deploy: all updates, all except drivers, only approved, only selected, or by severity.
- Targets: a group or a list of endpoints; optionally deployment rings (a pilot group first, then the rest after a delay).
- Schedule: run now, once at a date and time, or daily, weekly, monthly; rings add a delay between the pilot and the rest.
- Reboot policy: never, if required (with the branded end-user prompt and postpone options), or always.
Every execution appears under History with a per-endpoint log. You can also run any action immediately on selected endpoints from the Endpoints page.
6. Get told when something needs you
Alerts sends emails when an endpoint goes offline, a group's uptime drops, critical updates are missing, a critical CVE appears, a reboot is pending, or any built-in or custom report returns rows. Scheduled Reports emails any built-in or custom report as CSV or PDF on a schedule.
7. Invite your team
Users & API Credentials adds colleagues with a role: Viewer, Operator, Administrator, or a custom role with exactly the permissions you choose. The same page creates API credentials for integrations (REST API v1). Email-based multi-factor authentication is on by default; Microsoft and Google sign-in can be enabled under Advanced → Security.
What the dashboard checklist tracks
Until the basics are in place, the dashboard shows a six-step checklist: first agent, first group, a Deploy Updates automation, an email alert, a scheduled report and a second user or API credential. Hide it whenever you like.
Where to go next
- Security FAQ and trust model: what the console can do on your computers and how access is controlled.
- Troubleshooting agents: when an endpoint shows as disconnected.
- Data retention and account closure: what is stored, for how long, and how to leave.
- Availability commitment and support: how to reach us and what we promise.
