Getting Started - Links and Prerequisites
1. Lenovo Patch User Guide, Upgrade Guide, and Release Notes
- Lenovo Patch 2.5 User Guide
- Lenovo Patch 2.5 Upgrade Guide
- Lenovo Patch 2.5 Release Notes
- Lenovo Patch End-User License Agreement
- These release notes support the current version of Lenovo Patch plugin
- The installer can be downloaded from: Lenovo Patch 2.5.1298.0
- File Version is 2.5.1298.0
- Checksum:
- MD5: 5C00D8558FC3F8008455772C304E85CF
- SHA1: ED8396CE07ACADCF1E5BCAB2E8C7C567CB10A8F4
- SHA256: 8DEE041721AED0055CB5D1A865FD147C1FBF6298D7143A20922D3C9BA3585492
- If you have any questions, please contact our Technical Support Team via the Lenovo Patch help center.
- Documentation for Previous Versions
2. Installation Requirements
- Configuration Manager Requirements
- 2012 R2 SP1 through Current Branch
- Operating System Requirements
- The Configuration Manager console must be installed on a 64-bit version of one of the following Windows operating systems (excluding Server Core or Nano):
- Windows Server 2022
- Windows Server 2019
- Windows Server 2016
- Windows Server 2012 R2
- Windows 11, Pro or Enterprise Edition
- Windows 10, Pro or Enterprise Edition
- Microsoft Visual C++ 2015-2022Redistributable (x86 and x64) - Version 14.42.34433.0 or later
- If the console computer or server is missing either of these requirements, they will be installed on to the console computer or server during installation of Lenovo Patch.
- .NET Framework 4.8 or later
- If the console computer or server is missing the .NET requirement, .NET Framework 4.8 will be installed on the computer or server during the installation of Lenovo Patch. .NET 4.8 requires a reboot prior to installing Lenovo Patch.
- The device where the Configuration Manager console is installed must contain at least 4 GB of RAM.
3. Configuration Requirements
- Windows Server Update Services (WSUS) Requirements:
- If Lenovo Patch is installed on the primary Configuration Manager server and the server operating system is either Windows Server 2019, Windows Server 2016, Windows Server 2012 R2, then the WSUS API and the PowerShell cmdlets features must be enabled.
- If Lenovo Patch is installed on a remote Windows 10 the RSAT: Windows Server Update Services Tools Feature on Demand must be installed on the computer.
- SQL Server Requirements
- Every user requires access to a SQL Server database and must have read/write permissions to the database. Any version of Microsoft SQL Server supported by the currently installed Microsoft Endpoint Configuration Manager version is valid.
- The user installing the database must have db_create permissions on the SQL Server instance.
- Automation Scheduler Requirements
- If there is intention to automatically publish updates using a recurring scheduled tasks through the Automation Scheduler, then the Microsoft Task Scheduler service must be enabled.
- The user executing the scheduled task must be granted Log on as a batch job rights.
- Alerts Requirements
- If users intend to receive alert notifications via email, then Configuration Manager must be configured to allow email notifications. For more information, refer to the Managing Alerts section of the Lenovo Patch 2.5 User Guide at the beginning of this article.
- User Rights Requirements
- The user running Lenovo Patch must:
- Must not be a member of the Protected Users security group in Active Directory.
- Must have Read Access to Active Directory.
- Be a member of the WSUS Administrators group on the WSUS server.
- Must be assigned to one of the following Configuration Manager Security Roles:
- 3rd Party Patch Administrator *
- 3rd Party Patch Read Only User *
- Full Administrator
* The security role is created by the Data Migration Tool. For more information and the expanded list of permissions, refer to Appendix D: Permissions Assigned to Imported Security Roles in the Lenovo Patch 2.5 User Guide.
- Be assigned to the All instances of the objects that are related to the assigned security roles security scope in the Configuration Manager application.
- In addition, if the WSUS Server is remote, the user must be a member of the Administrators group local to the WSUS Server.
Note: If utilizing a service account when publishing updates, either manually or using the Automated Scheduler, that service account must meet the above requirements. To verify an account meets these requirements, use the Configuration Checker found on the General tab of the Lenovo Settings dialog.
- Firewall Requirements
- The firewall, proxy (if used), and web filter lists must contain a number of URLs. The URLs are used by Lenovo Patch to download updates from third-party vendors.
- For the complete list of URLs to add, refer to the Lenovo Patch: URL Exception List.
- Federal Information Processing Standard (FIPS) Requirements
- When operating in a FIPS environment, the console must be configured as a FIPS-compliant machine before Lenovo Patch is installed. If FIPS is enabled after the installation, Lenovo Patch must be reinstalled.
- Client Machine Requirements
- Each client computer must meet the following requirements to deploy non-Microsoft updates distributed by a WSUS server:Must contain a copy of the code signing certificate in the appropriate certificate stores.
- Must have enabled the Allow signed updates from an intranet Microsoft update service location policy setting.
- To deploy updates from the Lenovo Updates Catalog, the Lenovo devices must meet the 2 previous requirements, must also have the LUC Agent installed, and must be one of the supported Think branded product lines.
- For more information about the LUC Agent, refer to the Lenovo Patch: LUC Agent - Deploy Me First Knowledge Base Article.
- For more information about the supported Think branded product lines, refer to the Lenovo Patch: Supported Hardware Products List Knowledge Base Article.
- For more information about the supported 3rd Party Software Update content and Application Installers, refer to the Lenovo Patch: Supported Software Products Lists Knowledge Base Article.
- Supported Languages
- The following languages are supported for use with the Lenovo Patch interface:
- Chinese (Simplified and Traditional)
- English
- French
- German
- Italian
- Japanese
- Portuguese (Brazil)
- Russian
- Spanish
- Licensing Requirements
- Lenovo Patch can be activated using the following methods.
- Purchased Activation code
- Trial Activation code - Limited time frame and number of products
Related Articles
Getting Started with ThinkShield BuildAssure
ThinkShield BuildAssure Web Portal Home Page The ThinkShield BuildAssure Web Portal Home page provides users with the ability to download BuildAssure files for individual or multiple devices. Additionally, the Download Center on the portal enables ...
Upgrade Landing Page Redirects to Ivanti Website
Symptom When a new version of the Lenovo Patch product becomes available, the notification window is displayed including a link. When clicking on the link in the notification window from Lenovo Patch, the link takes you to an Ivanti webpage. Cause A ...
Installing the Plugin on Windows 10 1809 and Newer
Symptom When installing the Lenovo Patch plugin to a console installed on a Windows 10 1809 or newer operating system, the following error message may display on the screen: Solution The following process will ensure that the requirements for the ...
IT Assist Features & FAQ
About IT Assist Lenovo IT Assist is a cloud-based generative AI-powered assistant designed to help IT Admins efficiently find information, gain better visibility into their PC fleets and networks, and streamline device management. Lenovo IT Assist ...
Error: Cannot Connect to WSUS Server
Symptom Despite fulfilling all the prerequisites in the Lenovo Patch documentation, some users may still find themselves unable to connect the plug-in to their WSUS server. Cause This issue appears to be related to a User Account Control (UAC) issue. ...