All baseline controls
Endpointmedium priority

Managed endpoints are patch-compliant

Patch compliance reported by the management tool. Part of the standard Alignr Baseline library for proactive technical alignment.

Join Waitlist for Early Access
WHAT THIS CONTROL CHECKS

Patch compliance reported by the management tool

An RMM-managed endpoint should report a compliant patch status, not a backlog of pending updates — unpatched endpoints are the most common way a known vulnerability turns into an incident.

Interpret the result in context

This check uses the source tool’s compliance verdict. The meaning of compliant depends on that tool’s policy and does not replace a separate review of scanner findings.

YOUR STANDARD

Configure the expectation.

Use this baseline as a starting point. You can also build your own controls and standards from integration data, with client-specific requirements and documented exceptions.

A fixed baseline expectation

This shipped control has no adjustable numerical threshold. Review its applicability and record approved exclusions for the client.

FROM FINDING TO ACTION

Review. Remediate. Verify.

Use one-click remediation where the integration and action support it, or the evidence to guide the technician’s next step.

  1. 01

    Review the patch policy and updates causing non-compliance.

  2. 02

    Schedule approved updates and required restarts with the device owner.

  3. 03

    Refresh patch status and confirm the source tool reports compliance.

A completed action is only part of the record. Refresh the supporting evidence to establish whether the finding has cleared.

Make your baseline part of every client review.

Connect checks, findings and remediation to the same client record.

Join Waitlist for Early Access