STEPS FOR WINDOWS PATCHING THROGH SSM

 

  • Start the Instances

 

  1. Create 2 roles: (a) EC2 full access   (b) SSM full access 

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

  1. Go to portol.azure.com and then search for Enterprise Application.

A screenshot of a computer

Description automatically generated

 

  1. Search for Team CVoter and then go to user and group.

A screenshot of a computer

Description automatically generated

  1. Select the user and assign the role that you have created in step 1.
  2. Now in AWS console search for SSM.

A screenshot of a computer

Description automatically generated

  1. Now go to the Maintenance Windows Section and enable it from action menu.

A screenshot of a computer

Description automatically generated

  1. Select the windows ID and go to the targets. You can choose the particular instance manually, you want to update.

A screenshot of a computer screen

Description automatically generated

 

  1. Edit the Description Section to Schedule the Scan Process.

A screenshot of a computer

Description automatically generated

  1. Now give the name: cvotermw01, and in schedule section select the CRON/Rate Expression.

 

 

A screenshot of a computer

Description automatically generated

 

 

 

 

  1.  Give the time in UTC (in cron expression) and give the 2 hours duration in maintenance windows duration.

 

A screenshot of a computer

Description automatically generated

 

  1. Save the Changes.

 

  1. Now go to the Task Section.

A screenshot of a computer

Description automatically generated

 

 

  1. Now select the Window task ID and edit it.

 

 

A screenshot of a computer

Description automatically generated

 

 

 

  1. In Parameter Section Choose the Scan Option and leave other as default

A screenshot of a computer

Description automatically generated

 

  1.  Now run the edit run command task.

 

  1. After the Scanning process you can see the available patches or updates in view details -History section.

 

  1.  Mail the client and give the information about the available patches.

 

  1. Have to follow the same procedure for the installation of the patches, Only you have to change the   parameters action to install in Task section.

 

A screenshot of a computer

Description automatically generated

 

  1.  In History you can see the status Change to SUCCESS from PENDING.

A screenshot of a computer

Description automatically generated

 

  1.  Select the ID and View the details, Download the patches that has been installed and mail the client.

 

  1. Finally stop the Instances.