Update Management for Non-Domain Devices via Local Policy Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IT departments in corporate settings lack control over updating computing devices that are not joined to a domain, as they cannot test or manage updates for non-domain devices, leading to uncontrolled and potentially incompatible software updates.
Innovation Solution
A management agent on the device communicates with a management service to enroll and configure the device to use a specific update service, such as WSUS, without requiring domain membership, allowing IT to manage and control update installations for all devices, including those not connected to a directory service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If devices are joined to a domain to enable centralized update management, then update control and testing capability is improved, but device enrollment complexity and network configuration requirements worsen
Solution Approach 1:
The patent extracts the update management functionality from the domain joining requirement. Instead of requiring devices to be domain-joined to enable centralized update control, the solution allows standalone devices to be managed through local configuration files and automated update agents that can communicate with external update servers, thereby separating update management capability from domain membership
Solution Approach 2:
The patent introduces an intermediary configuration mechanism that bridges standalone devices and centralized update management. Configuration files stored locally on devices act as intermediaries, containing update policy information that enables the update agent to communicate with external update servers without requiring domain authentication or joining
2Ease of operation
If automatic update option is used from vendor servers, then update installation simplicity is improved, but IT department control and testing capability worsens
Solution Approach 1:
The patent implements dynamic update management where the update agent can adapt its behavior based on locally stored configuration files. The system dynamically switches between automatic updates from vendor servers and controlled updates through centralized repositories, allowing IT departments to enforce policies while maintaining automated operation without requiring manual intervention for each update
Solution Approach 2:
The patent implements feedback mechanisms where the update agent continuously checks for configuration file changes and updates its behavior accordingly. The system provides feedback loops that allow IT departments to push policy updates to configuration files, which the agent then detects and implements, enabling remote control while maintaining automated update operations
3Adaptability or versatility
If non-domain devices are excluded from centralized update management, then device enrollment simplicity is improved, but update security and compatibility control worsens
Solution Approach 1:
The patent implements preliminary configuration where update policies and server information are pre-configured in configuration files before updates are applied. This preliminary setup enables standalone devices to be pre-configured with trusted update sources and security policies, ensuring that even without domain joining, devices receive updates from controlled and tested sources, maintaining security and compatibility
Data Source
AI summary
Disclosed are approaches for enforcement of updates for devices unassociated with a directory service. An application executing on a computing device can determine, based on a policy received from a management service, that the computing device is to use an update service specified in the policy to receive updates. The application then modifies a setting of the computing device to specify the use of the update service by the computing device.


