Maintenance windows
A maintenance window says when scheduled work may act on a computer. This page explains the two kinds of window, how windows set at different levels combine, and what a window never does.
What a maintenance window is
A maintenance window says when scheduled work may touch a computer. It exists so that recurring maintenance happens at times the client can live with, and never at times they cannot.
A window is a limit, not a trigger. It never starts anything. A schedule starts recurring work, and the window decides whether that work may act at that moment.
Allow and exclude
There are two kinds of window.
| Kind | What it means |
|---|---|
| Allow | Scheduled work acts only inside the window |
| Exclude | A blackout. No scheduled work runs during it, whatever else says otherwise |
Use an allow window to keep scheduled maintenance to the evening or the weekend. Use an exclude window to protect a period when nothing should change, such as a client's month-end.
Where a window applies
You declare a window at one of four levels:
- every client
- one client
- a tag
- one named computer
When more than one window covers a computer, the more specific one wins. A window on one computer beats a window on its tag, which beats one on its client, which beats one set for every client.
An exclude works differently. It is a veto at any level. A blackout on one computer stops scheduled work on that computer even when an allow window for every client says the time is fine.
A window is read in the tenant's time zone where one is set, and in your default time zone otherwise.
What a window does not do
- It does not schedule anything. A window limits when scheduled work may act. It never causes work to happen.
- It does not hold back a person. Run maintenance pressed by a person starts immediately, whether or not a window is open. Windows govern scheduled work only.
- It does not decide restarts. Whether a computer restarts after maintenance is a matter for the restart policy.
How windows fit with the other controls
Four separate controls shape unattended work. Each decides one thing.
| Control | What it decides |
|---|---|
| Schedule | When recurring detection and maintenance start |
| Maintenance window | When that scheduled work may act on a computer |
| Restart policy | What may happen about a restart |
| Standing authorisation | What Overseer may do on its own without asking |
Who can set a window
Setting a maintenance window requires the capability to act on computers. That is the same capability that covers deployments, schedules and restart policy, so grant it with care.