← SOP Library

Technical SOPs

RMM Policy Set (Action1) — Windows + Mac

Updated 2026-06-18 For Internal — engineering

RMM Policy Set (Action1) — Windows + Mac

The standard Action1 RMM policy applied to every customer group at onboarding (Action1 SOP Part C / Engineer Runbook step 1). Two policies, assigned by OS: one Windows (PC), one Mac. Grounded in what Action1 actually automates — Action1 does app + minor-OS patching on both platforms via patch policies, runs scripts for security configuration, and raises alerts/automations; it is not an MDM (enforced config-profiles = Intune) and not the EDR (detection = Huntress).

Replaces the Syncro policy set. This SOP replaces the retired rmm-syncro/policy-set.md. The RMM leg moved to Action1 per operations-only/strategy/syncro-decommission-and-function-map.md. The patch SLA, maintenance window, and the FileVault-OFF / BitLocker-OFF critical alert carry over unchanged; the mechanism (native patch manager + script-driven Mac) is now Action1.

Patch SLA (both platforms — unchanged from the prior policy)

SeverityDeploy within
Critical7 days
High30 days
Standard / optional60 days

This is the same bar the Readiness Report recommends to firms (C-09) — we hold ourselves to what we sell. Patch compliance is a monthly-report posture chip and feeds the compliance evidence.

Maintenance / reboot window (both)

Install in an after-hours window, notify the user, allow short deferral, then force a reboot once a patch has been pending 7 days. Set the window per customer from the Deployment Questionnaire (their stated maintenance window / change-control constraints), configured on the Action1 patch automation for the group.


🖥️ Windows (PC) policy

Patching — Action1 patch policy / automation

Monitors / alerts → notification

Action1 raises these via alerts/automations (notification to the shared inbox / engineer — there is no PSA ticket queue in Action1; ticketing is the shared-inbox interim model). EDR-health alerting is Huntress’s job, surfaced from the Huntress portal — Action1 confirms the agent’s presence, Huntress confirms detection health.

MonitorThresholdSeverity
Offline> 30 min (business hours)alert
Disk free< 10% / < 5%alert / critical
RAM> 90% sustained 15 minalert
CPU> 90% sustained 15 minalert
BitLocker encryptionOFF / no escrowed keycritical (the Windows encryption control — mirrors the Mac FileVault monitor; see C-10 SOP)
Huntress agent presentagent missing on a managed endpointcritical (detection health itself = Huntress portal)
Pending reboot> 7 daysalert
Backup agentfailed jobalert (backup vendor is an open item — see Honest limits)
Disk SMARTfailure predictedcritical

Automation


🍎 Mac policy

Patching

Monitors / alerts → notification

MonitorThresholdSeverity
Offline> 30 minalert
Disk free< 10%alert
FileVault encryptionOFF / no escrowed keycritical (the Mac encryption control — see C-10 SOP)
Huntress agent presentagent missingcritical (detection health = Huntress portal)
macOS updateoverdue vs SLA (app/minor only)alert
Backup statusfailedalert (backup vendor is an open item)

Automation


Honest limits (state these; don’t overclaim)

Where this applies

”Done” means