Patching Approval Order
Recently, we had a meeting with our N-central Solutions Engineer to review our patching setup (as it's a mess so we are trying to bring in some standards), particularly around automatic patch approvals
I raised a support ticket some time ago to check what a previous colleague had set up which for arguments sake was
Definition
Critical
Security
Approved and then a decline rule below those (so the order is approve rules above the decline, everything else)
Support reviewed it and said it was correct, but in the recent meeting with our N-central solutions engineer, he said that was wrong and that the order should be Decline above all the approve rules.
So order wise
Decline All
Approve the following
Does anyone know which is correct?
I can't find the article, but I've tried reading the order of operations article and to be honest, I just find it too confusing XD so just wondering what others have done.
Thanks