Zero Touch Patch Automation: Tanium Tech Talks #172

Oct 7, 2026

How do you patch faster - all while honoring your patching policies and *not* breaking things?

Attackers are using AI to find and exploit vulnerabilities faster, and vendors are shipping patches faster too. Your patching processes need to keep up!

In this episode we show how to automate patching on a monthly cadence, roll it out in rings, and keep control of the process the whole way through. zero-touch, ring-based patch automation with Tanium deployment plans, in Atlas or the classic console.

In this episode we cover:
🔄 Using an Automatic Deployment Plan to implement zero-touch, ring-based patch automation
🎯 Using deployment plans to create ring-based rollouts
🛡️ How to account for sensitive endpoints so they're patched last
🚨 How to build accelerated plans and override rules for zero-day response
📊 How to measure and report patch compliance over time

RESOURCES:
Patch deployment automation article: https://help.tanium.com/bundle/PatchZeroTouchRunbook/page/Runbooks/PatchZeroTouchRunbook/Patch_Deployment_Automation.htm
Docs: https://help.tanium.com/bundle/ug_patch_cloud/page/patch/deploying_patches_automatically.html
Converge promo code (free tickets, in-person or virtual, labs included): TechTalks2026

CHAPTERS:

0:00 Intros

1:54 Why we have to patch faster

4:49 Patch deployment automation overview

8:07 DEMO: Starting from the Atlas Patch Tuesday prompt

9:35 DEMO: A ring-based deployment in the console

10:58 Dynamic vs. custom deployment plans

16:23 Accelerated plans for zero-days

18:34 DEMO: Building an automatic deployment configuration

27:17 Pausing and advancing - and blocking bad patches

31:20 Proving it: Patch compliance dashboards

33:41 Wrap-up