Suspending or stopping Software Management policies at the device level

You may need to temporarily pause or permanently stop Software Management activity on a specific device without affecting other machines assigned to the same profiles. This article explains how to suspend Software Management activity on a device, how to remove profile assignments entirely, and the caveats that apply to each approach.

Problem statement

You need to temporarily or permanently stop Software Management from performing scanning and deployment tasks on one or more devices without removing the Software Management module entirely. Software Management policies will continue to run on other devices.

Resolution

Two methods are available depending on whether you need a temporary pause or a permanent stop.

Method 1: Temporarily suspend Software Management activity

Use this method to pause Software Management scans and deployments on a device while keeping its profile assignments intact so activity can be resumed later.

To suspend Software Management activity on a device, complete the following steps:

  1. In VSA 9, navigate to Software Management > Management > Machines.
  2. Select the check box next to the machine you want to suspend.
  3. Click Suspend/Resume in the upper panel.
  4. Confirm the action when prompted.

The Status column for the machine updates to show the suspended icon, indicating that Software Management activity is paused. Scans and deployments will not run on the device until you resume it.

To resume Software Management activity, select the machine and click Suspend/Resume again.

NOTE  If Software Management attempts to run a task on a suspended machine, it logs the error "Error 4060: This machine is in a suspended state." This is expected behavior and does not indicate a separate underlying problem.

Method 2: Permanently stop Software Management activity by removing profiles

Use this method to stop Software Management activity on a device indefinitely. Removing all profile assignments prevents scans and deployments from running and removes the device from Software Management compliance reporting.

To remove profile assignments from a device, complete the following steps:

  1. Navigate to Software Management > Management > Machines.
  2. Select the check box next to the machine.
  3. Click Remove Profiles in the upper panel.
  4. Select the profiles to remove: Scan and Analysis, Deployment, 3rd-Party Software, or Override Profiles.
  5. Confirm the removal when prompted.

To restore Software Management management, reassign the appropriate profiles using Assign Profiles.

NOTE  If the device used an Only OS Updates Scan and Analysis profile, removing that profile resets all Windows Update group policies on the machine to Not Configured status, which is the default Windows configuration. The endpoint user can then modify Windows Update settings directly.

Caveats

Be aware of the following limitations and side effects before suspending or removing profiles.

  • Suspension does not remove profile assignments. A suspended machine retains all profile assignments. If you later resume the machine, Software Management will resume scans and deployments on its next scheduled run based on those profiles.
  • Removing a Deployment profile stops patch deployment but not scanning. A machine can still be scanned if a Scan and Analysis profile remains assigned. To stop all Software Management activity, remove all profile types.
  • A Deployment profile is required for Software Management to deploy patches. If you remove the Deployment profile but leave a Scan and Analysis profile using the Kaseya Update or Third-Party Software Updates + OS Updates patch strategy assigned, scans will continue but no patches will be deployed.
  • Patch Management conflict. If the Prevent an agent from running both Patch Management and Software Management at the same time option is enabled on Software Management > Configuration > Settings > Application Settings, Software Management will not run on any machine that has an active Patch Management scan schedule, policy, or update schedule. In this case, Software Management activity stops automatically for those machines, and suspending or removing profiles is unnecessary unless you want to prevent Software Management from running once the Patch Management association is removed.
  • Override profiles and precedence. If a machine has multiple Override profiles assigned, removing one override does not affect the others. Override profiles are evaluated from highest to lowest priority in the list shown on the Profiles tab for the machine. Run a scan after reassigning an override profile for the changes to take effect.
  • Windows group policies are not cleaned up on suspension. Suspension only pauses Software Management task execution. Any Windows Update group policies applied by an Only OS Updates or Third-Party Software Updates + OS Updates profile remain in effect on the endpoint until the profile is removed or the machine is unassigned from the profile.

Tips and tricks

If you need to stop activity on a large number of machines at once, select multiple machines in the Machines page grid before clicking Suspend/Resume or Remove Profiles. Both actions support multi-machine selection.

To confirm that a machine is suspended, check the Status column on the Machines page. A suspended machine displays the suspended status icon instead of the standard managed icon. You can also check the Errors tab in the lower panel for any machine is in a suspended state entries logged before you applied the suspension.

If a machine should not be suspended but the error This machine is in a suspended state appears in its task log, select the machine and click Suspend/Resume to restore active status.