← SOP Library

Technical SOPs

RMM Policy Set (Syncro) — Windows + Mac

Updated 2026-06-06 For Internal — engineering

RMM Policy Set (Syncro) — Windows + Mac

The standard Syncro RMM policy applied to every customer org at onboarding (Syncro SOP Part A step 6 / Engineer Runbook step 1). Two policies, assigned by OS: one Windows (PC), one Mac. Grounded in what Syncro actually automates — Syncro’s native patch manager patches Windows only; the Mac Agent does fleet management, monitoring, and macOS update enforcement plus scripted updates.

Patch SLA (both platforms — approved 2026-06-06)

SeverityDeploy within
Critical7 days
High30 days
Standard / optional60 days

This is the same bar the Readiness Report recommends to firms (C-09) — we hold ourselves to what we sell. Patch compliance is a monthly-report posture chip and feeds the compliance evidence.

Maintenance / reboot window (both)

Install in an after-hours window, notify the user, allow short deferral, then force a reboot once a patch has been pending 7 days. The window is set per customer from the Deployment Questionnaire (their stated maintenance window / change-control constraints).


🖥️ Windows (PC) policy

Patching — native Syncro patch policy

Monitors → ticket

MonitorThresholdSeverity
Offline> 30 min (business hours)alert
Disk free< 10% / < 5%alert / critical
RAM> 90% sustained 15 minalert
CPU> 90% sustained 15 minalert
Defender / Huntress healthnot reporting / disabledcritical
Pending reboot> 7 daysalert
Backup agentfailed jobalert
Disk SMARTfailure predictedcritical

Automation


🍎 Mac policy

Patching

Monitors → ticket

MonitorThresholdSeverity
Offline> 30 minalert
Disk free< 10%alert
FileVault encryptionOFFcritical (the Mac encryption control)
Huntress healthnot reportingcritical
macOS updateoverdue vs SLAalert
Backup statusfailedalert

Automation


Honest limits (state these; don’t overclaim)

Where this applies

”Done” means