Introduction and Supported Architecture
Ceburu Patch Manager helps administrators manage operating system and application patches, monitor endpoint status, install applications, and track patch compliance for MSP and Enterprise environments.
After login, the portal opens the Patch Manager Dashboard, where users can review companies, hosts, endpoints, missing patches, patch status, and application information according to their assigned permissions.
Current Platform Support:
Platform | Supported Use |
Windows | Windows operating system patching, application patching, host services, client services, and Middle Agent deployment. |
Ubuntu | Linux operating system and application patching through the supported Linux agent and SSH connectivity. |
Oracle Linux | Linux operating system and application patching through the supported Linux agent and SSH connectivity. |
Ceburu initially creates and provisions both MSP and Enterprise companies. After the parent MSP company is active, an MSP administrator can create and manage customer subcompanies. Enterprise administrators manage only their own provisioned company and cannot create additional companies.
2. Login to the Portal:
1. Open the Patch Manager portal: Go to https://patchmanager.ceburu.com from a supported web browser.
2. Enter your credentials : Use the username and password provided for your MSP or Enterprise account.
3. Open the Dashboard: After successful authentication, the system directs you to the Patch Manager Dashboard.
Company Registration and Provisioning:
Company registration begins with Ceburu. Ceburu creates and provisions the initial company account for both MSP and Enterprise customers.
Initial Registration Performed by Ceburu:
1. Ceburu receives the required MSP or Enterprise company details.
2. Ceburu creates the parent company in the Patch Manager platform.
3. Ceburu configures the initial administrator account and required access.
4. Ceburu assigns or prepares the appropriate licensing and product access.
5. The customer administrator receives login credentials or an account activation invitation.
Company Type Comparison
Capability | MSP | Enterprise |
Initial company creation | Created and provisioned by Ceburu | Created and provisioned by Ceburu |
Create additional companies | Yes. The MSP administrator can create customer subcompanies after the parent MSP company is active. | No. The Enterprise administrator manages only the provisioned Enterprise company. |
Manage users | Parent MSP users and permitted subcompany users | Users within the Enterprise company |
Manage endpoints | Endpoints across permitted subcompanies | Endpoints within the Enterprise company |
Company visibility | Parent MSP and authorized subcompanies | Enterprise company only |

Introduction:
The Patch Manager in Ceburu helps administrators manage software patches, monitor client systems, and track update statuses for enterprises and MSPs. When you log in to the portal, the system automatically takes you to the Dashboard view of Patch Manager.


MSP Administration Workflow:
The MSP workflow uses a parent company and one or more customer subcompanies. The parent MSP company must first be created by Ceburu.
Creating an MSP Subcompany:
1. Navigate to Companies from the left menu.
2. Click Create Company.
3. Enter the subcompany name, valid company email address, and contact phone number.
4. Add the required host name, public IP address, and private IP address information.
5. Use the plus control to add additional IP entries. Use the remove control to delete an unnecessary entry.
6. Confirm that the subcompany is being created under the correct parent MSP company.
7. Click Create to save the subcompany, or click Cancel to exit without saving.
Editing an MSP Subcompany:
1. Open Companies from the left menu.
2. Select the required customer subcompany.
3. Update the permitted company, contact, host, or IP information.
4. Click Save or Update to apply the changes.


Enterprise Administration Workflow:
The Enterprise workflow is designed for a single organization. Ceburu creates and provisions the Enterprise company and its initial administrator account.
Enterprise Company Restrictions:
- Enterprise administrators cannot create additional companies or customer subcompanies.
- Company level changes that are not available in the Enterprise portal must be requested from Ceburu.
- Enterprise users can manage authorized users, hosts, agents, applications, and patches within their own company.

Company Users and Billing Licenses:
Managing Company Users:
1. Open Companies from the left menu.
2. Locate the parent company or subcompany that requires user management.
3. Click the View icon to open the Company Users page.
4. Select Create User to add a new user with name, email, phone number, and role.
5. Select an existing user to edit contact information, role, or access permissions.



Creating Billing Licenses for a Company:
Once users are created under a company, you can assign billing licenses.
- Navigate to the Billing tab from the left-hand menu.
- Click on the Create button.
- Provide the required Billing License details, such as:
- License Type (e.g., Standard, Enterprise, MSP).
- Number of Licenses to allocate.
- Duration/Validity (e.g., monthly, yearly).
- Assigned Company/User.
- Review the information entered.
- Click Save/Create to generate the billing license.


Windows Middle Agent and Patching Architecture:
The Windows Middle Agent provides centralized communication and patching services for Windows and supported Linux endpoints. It should be installed on a Windows system that has reliable network access to the endpoints it manages.
Windows Endpoint Patching:
- The Middle Agent communicates with Windows endpoints to validate systems, collect patch information, deploy operating system and application patches, and execute approved remote actions.
- Windows remote management and required firewall rules must be configured before remote patching begins.
- The endpoint must be assigned to the correct company and visible in the portal.
Linux Endpoint Patching:
- Linux patching currently supports Ubuntu and Oracle Linux.
- The Middle Agent connects to Linux machines through SSH.
- SSH can be configured for a subnet level connection or for an individual machine.
- The configured SSH port, normally port 22, must be reachable from the Windows Middle Agent.
- The Linux credentials or SSH key must have sufficient permission to inspect packages and install approved updates.
Recommended Deployment Models:
Environment | Recommended Model |
Small environment | One Windows Middle Agent can manage reachable Windows and Linux endpoints when routing and firewall access are available. |
Multiple subnets | Deploy or assign Middle Agent coverage by subnet so each network segment has reliable endpoint connectivity. |
Restricted Linux environment | Configure Linux SSH access per individual machine when subnet wide access is not permitted. |
MSP environment | Use company and subcompany boundaries so endpoints and patch actions remain associated with the correct customer tenant. |

Installing Windows Host and Client Applications:
Prerequisites:
- The company or MSP subcompany has been created.
- Required users have been added.
- Billing licenses have been generated and assigned.
- Firewall, proxy, endpoint security, and application patch download URL whitelisting are complete.
Download and Install:
1. Log in to the Ceburu Patch Manager portal from the Windows machine.
2. Select the download icon in the upper right area of the portal.
3. Choose Windows and select the required Host or Client package.
4. Download host.exe for the Windows host or Middle Agent system, or client.exe for a managed Windows endpoint.
5. Run the installer with the permissions required by the organization.
6. Follow the installer prompts and complete the company assignment or registration information.
7. Confirm that the installed system appears under Host Assigned or the appropriate agent view.
Installing the Linux Agent:
The Linux agent installation applies to currently supported Ubuntu and Oracle Linux machines. The exact package name may vary by Ceburu release, so use the package downloaded from the Patch Manager portal.
Linux Agent Prerequisites:
- The target company or MSP subcompany exists in the portal.
- A valid billing license is available and assigned.
- The Linux machine runs a supported Ubuntu or Oracle Linux release.
- The Windows Middle Agent can reach the Linux machine through the configured SSH port.
- Required Linux repositories and application patch download URLs are whitelisted and reachable.
- The installation account has sudo or equivalent administrative permission.
Download the Linux Agent:
1. Log in to the Ceburu Patch Manager portal.
2. Select the download icon.
3. Choose Linux and download the agent package that matches Ubuntu or Oracle Linux.
4. Transfer the package to the target Linux machine when the download was performed from another system.
5. Use this command to install : sudo ./CeburuPatchClient --install
Register and Verify the Linux Agent:
1. Complete the company, subcompany, registration token, or connection information requested by the installer.
2. Confirm that the agent service is running by using the service name provided with the Ceburu installation package.
3. Verify SSH connectivity from the Windows Middle Agent to the Linux endpoint.
4. Open the portal and confirm that the Linux machine appears under the expected company with the correct platform, IP address, and computer name.
5. Run an inventory or patch scan and confirm that package and patch information is returned.
Verify Host Assignment:
- Navigate to Host Assigned in the portal.
- Ensure the machine details (Company Name, MAC Address, Private/Public IP, Platform, Computer Name) appear in the list.

In the Host Assigned section of Patch Manager, administrators can define and manage subnets for better organization and network-based grouping of machines. This feature allows mapping hosts into specific subnets such as workstations, servers, or VDI environments.
Adding Subnets:
- Navigate to Host Assigned from the left-hand menu.
- Select the Company (e.g., Acordis Corp).
- Under the list of assigned hosts, click on the Subnet (Edit) icon for the desired machine.
- The Update Subnet dialog will appear.
- Fill in the details:
- Company Name – Auto-filled based on selection.
- Private IP – Pre-filled with host’s private IP.
- Subnet Type – Choose between Single Subnet or Multiple Subnets.
- IP Ranges – Add subnet ranges (e.g., 172.16.10.0/24).
- Subnet Name – Provide a descriptive name (e.g., Workstations).
- To add more subnets, click the “+” button.
- To remove an entry, click the “-” button.
- Click Submit to save changes.

Viewing Missing Patches:
- Navigate to Patches from the left-hand menu.
- The Missing Patches list will display:
- App Name – Application requiring updates.
- Missing Systems – Number of systems missing the patch.
- Latest Version – Available updated version.
- Company Name – Company associated with the missing patch.
- You can sort or filter patches by company, app name, or system count.
- Viewing Application Details
- Click on the Eye icon under the Action column.
- You will be redirected to the Agents → Applications page.
- Here, details for the specific application are displayed, including:
- Company name
- App name
- MAC address
- Local IP
- Platform
- Current version
- Latest version
Patch Actions Available:
From the Applications view, you can perform:
- Install/Publish Patch – Deploy the patch to target systems.
- Uninstall Patch – Remove the patch from selected systems.
- Decline Patch – Exclude a patch if not needed for a specific environment.
- Schedule Patch – Set a time for patch installation.
- Restart Agent – Restart the patch agent service if required.

How to View Declined Patches:
- Navigate to Decline Patches from the left-hand menu.
- Select the Company Name from the dropdown (e.g., Acordis Corp).
- The Decline Patches table will display:
- Patch Name – The declined application or update.
- Missing Systems – Number of systems where this patch is missing.
- Latest Version – Version of the declined patch.
- Company Name – Associated company.
- Action – Options to manage or export declined patches.

Host Client Applications:
The Host Client Applications section provides visibility into all client machines connected to a host. It shows patch compliance by listing the number of missing patches for each machine and allows administrators to drill down into specific details.
Viewing Host Client Applications
- Navigate to Host Client Applications from the left-hand menu.
- The table displays key details such as:
- Host Computer Name
- Host MAC Address
- Company
- Agent Computer (client machine name)
- Agent IP Address
- Agent Platform
- Agent Missing Patches
- The Agent Missing Patches column shows the total number of patches missing on that particular client machine.
Viewing Application Details
- Click on the Eye icon under the Action column for a specific machine.
- You will be redirected to the Host Client Applications Details page.
Here you can view:
- Computer Name & MAC Address
- Application Name installed on the machine
- Current Version
- Latest Available Version
This helps administrators identify which applications are outdated and require patching.


Application Uploader:
The Application Uploader feature allows administrators to upload, manage, and version custom applications for deployment across client machines. This is useful for distributing third-party or in-house applications that may not be part of standard patch repositories.

Creating a New Application:
- Navigate to Application Uploader from the left-hand menu.
- Click Create.
- Fill in the required details:
- Company Name – Select the company for which the application is being uploaded.
- Application Name – Provide the application name (e.g., ImageGlass).
- Version Number – Enter the version (e.g., 1.8.3).
- Platform – Choose the target platform (Limited to Windows).
- Application File – Upload the installer file (e.g., .exe, .msi).
- Click Create to save the application entry.
- The uploaded application will appear in the Application Uploader list with details such as Company, App Name, Version, Platform, and File Name.

Editing or Delete Applications:
- Edit – Update application details such as version number or file.
- Delete – Remove an uploaded application if no longer needed.
- Export / Email / Email Time – Share application upload data with teams.
Application Installer:
The Application Installer allows administrators to deploy uploaded applications directly onto selected systems within a company. This ensures centralized and consistent application installation across all endpoints.
Installing an application
- Navigate to Application Installer from the left-hand menu.
- Select the Company Name from the dropdown.
- Select the Application Name you want to install (applications are pulled from the Application Uploader list).
- Select the desired machine(s) by checking the boxes.
- Click Install Application.

Application Release Notes with AI
The former AI Reports section is renamed Application Release Notes with AI. This module uses AI assisted analysis to help administrators identify the latest available application version and understand the changes included in a release.
Information Provided
- Latest known application version
- Release date and release summary
- Security fixes and referenced CVEs when available
- Important bug fixes, improvements, or compatibility changes
- Comparison between the endpoint current version and the latest available version
- AI generated patch recommendations and audit findings
Viewing Application Release Notes
1. Navigate to Application Release Notes with AI from the left menu.
2. Review the notification list containing company, platform, current version, latest version, and application name.
3. Click the View icon for the required application.
4. Review the AI generated release information, security details, version comparison, and recommended patch action.

AI Chat Assistant:
Ceburu Patch Manager helps you view the latest patches for applications across systems. You can check them directly in the Patches tab or use the AI Chat Assistant for quick help.
AI Chat Assistant is the fastest way to locate and check the latest patches without manual navigation.

Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article