Zero Touch Patch Automation: Tanium Tech Talks #172
How do you patch faster - all while honoring your patching policies and *not* breaking things?
Attackers are using AI to find and exploit vulnerabilities faster, and vendors are shipping patches faster too. Your patching processes need to keep up!
In this episode we show how to automate patching on a monthly cadence, roll it out in rings, and keep control of the process the whole way through. zero-touch, ring-based patch automation with Tanium deployment plans, in Atlas or the classic console.
In this episode we cover:
🔄 Using an Automatic Deployment Plan to implement zero-touch, ring-based patch automation
🎯 Using deployment plans to create ring-based rollouts
🛡️ How to account for sensitive endpoints so they're patched last
🚨 How to build accelerated plans and override rules for zero-day response
📊 How to measure and report patch compliance over time
RESOURCES:
Patch deployment automation article: https://help.tanium.com/bundle/PatchZeroTouchRunbook/page/Runbooks/PatchZeroTouchRunbook/Patch_Deployment_Automation.htm
Docs: https://help.tanium.com/bundle/ug_patch_cloud/page/patch/deploying_patches_automatically.html
Converge promo code (free tickets, in-person or virtual, labs included): TechTalks2026
CHAPTERS:
0:00 Intros
1:54 Why we have to patch faster
4:49 Patch deployment automation overview
8:07 DEMO: Starting from the Atlas Patch Tuesday prompt
9:35 DEMO: A ring-based deployment in the console
10:58 Dynamic vs. custom deployment plans
16:23 Accelerated plans for zero-days
18:34 DEMO: Building an automatic deployment configuration
27:17 Pausing and advancing - and blocking bad patches
31:20 Proving it: Patch compliance dashboards
33:41 Wrap-up