To add a Dynamic scope to an existing configuration, follow these steps:
Sign in to the Azure portal and navigate to Azure Update Manager.
Select Machines > Maintenance configurations.
In the Maintenance configurations page, select the name of the maintenance configuration for which you want to add a Dynamic scope.
In the given maintenance configuration page > select Dynamic scopes > Add a dynamic scope.
In the Add a dynamic scope page, select subscriptions (mandatory).
In Filter by, choose Select and in the Select Filter by, specify the Resource group, Resource type, Location, Tags and OS type and then select Ok. These filters are optional fields.
In the Preview of machines based on above scope, you can view the list of machines for the selected criteria and then select Save.
Note
The list of machines may be different at run time.
In the Configure Azure VMs for schedule updates page, select any one of the following options to provide your consent:
Change the required options to ensure schedule supportability ensures that the machines are patched as per schedule and not autopatched. By selecting this option, you are confirming that you want to update the patch orchestration to Customer Managed Schedules: This updates the following two properties on your behalf:
Patch mode = AutomaticByPlatform
Set the BypassPlatformSafetyChecksOnUserSchedule = True.
Continue with supported machines only - this option confirms that you want to proceed with only the machines that already have patch orchestration set to Customer Managed Schedules.
Note
In the Preview of machines based on above scope page, you can view only the machines that don't have patch orchestration set to Customer Managed Schedules.
Select Save. Notification confirms that the Dynamic scopes are successfully applied.
In the Maintenance configuration | Dynamic scopes page, you can view and edit the Dynamic scopes that were created.
View Dynamic scope
To view the list of Dynamic scopes associated to a given maintenance configuration, follow these steps:
Sign in to the Azure portal and navigate to Azure Update Manager.
Select Machines > Maintenance configurations.
In the Maintenance configurations page, select the name of the maintenance configuration for which you want to view the Dynamic scope.
In the given maintenance configuration page, select Dynamic scopes to view all the Dynamic scopes that are associated with the maintenance configuration.
The schedules associated to dynamic scopes are displayed in the following two areas:
In the Maintenance configurations page, select the name of the maintenance configuration for which you want to edit an existing Dynamic scope.
In the given maintenance configuration page > select Dynamic scopes and select the scope you want to delete. Select Remove dynamic scope and then select Ok.
View patch history of a Dynamic scope
Sign in to the Azure portal and navigate to Azure Update Manager.
Select History to view the patch history of a dynamic scope.
Provide consent to apply updates
Obtaining consent to apply updates is an important step in the workflow of dynamic scoping and listed are the various ways to provide consent.
In Azure portal, go to +Create a resource > Virtual machine > Create.
In Create a virtual machine, select Management tab and under the Guest OS Updates, in Patch orchestration options, select Azure-orchestrated. It sets the following properties:
Patch mode is set to AutomaticByPlatform
Set the BypassPlatformSafetyChecksOnUserSchedule = True
Complete the details under Monitoring, Advanced and Tags tabs.
Select Review + Create and under the Management you can view the values as Periodic assessment - Off and Patch orchestration options - Azure-orchestrated.
In Configure Azure VMs for schedule updates, page select Change the required options to ensure schedule supportability option to confirm that patch orchestration is set as Customer Managed Schedules. It sets the following properties:
Patch mode is set to AutomaticByPlatform
Set the BypassPlatformSafetyChecksOnUserSchedule = True.
The selection allows you to provide consent to apply the update settings, ensures that auto patching isn't applied and that patching on the VM(s) runs as per the schedule you've defined.
Select Save.
In Azure Update Manager, go to Overview > Settings > Update settings.
In Change Update settings, select +Add machine to add the machines.
In the list of machines sorted as per the operating system, go to the Patch orchestration option and select Customer Managed Schedules. It sets the following properties:
Patch mode is set to AutomaticByPlatform
Set the BypassPlatformSafetyChecksOnUserSchedule = True
Select Save.
The selection made in this workflow automatically applies the update settings and no consent is explicitly obtained.
Update Manager is a unified service that helps manage and govern updates for all your machines. It allows you to monitor Windows and Linux update compliance across Azure and on-premises from a single dashboard.
Improve business processes for customer service functions, such as automatic case creation and queue management with Microsoft Dynamics 365 Customer Service.