Configure devices for security scanning and remediation

Use Distribution and Patch settings in the agent settings to determine what gets scanned, what the end user sees for a scan, device reboot behavior, and the level of interaction the end user is allowed when the security scanner runs on devices. For example, depending on the purpose or scheduled time of a scan, you may want to show the end user scanner progress and give them the opportunity to cancel or defer a scan or patch application.

A device's default scan and repair settings are deployed as part of the initial agent configuration. When a task has different scan and repair settings associated or assigned to it, the default settings are overridden. You can also choose to use the device's default settings by selecting them when you create a task.

Linux devices use Ivanti's contentless patching method, which is different from the content-based patching that macOS and Windows devices require. For more information, see the brief video below describing the differences.

Ivanti Patch - contentless and content-based patching compared (2:43)