Amazon EC2 Systems Manager
User Guide

Systems Manager Patch Management

Systems Manager Patch Manager automates the process of patching managed instances. You can scan instances to see a report of missing patches, or you can scan and automatically install all missing patches. Patch Manager uses patch baselines that include rules for auto-approving patches within days of their release, as well as a list of approved and rejected patches. You can install patches on a regular basis by scheduling patching to run as a Systems Manager Maintenance Window task. You can also install patches individually or to large groups of instances by using Amazon EC2 tags.

Patch Manager can patch the following operating systems:

Operating System Details


64-Bit and 32-Bit Systems

  • Amazon Linux 2012.03 - 2017.03

  • Ubuntu Server 14.04 LTS, or 16.04 LTS

  • Red Hat Enterprise Linux (RHEL) 6.5 - 6.9

64-Bit Systems Only

  • Amazon Linux 2015.03 - 2015.09

  • Red Hat Enterprise Linux (RHEL) 7.0 - 7.4


Windows Server 2008 through Windows Server 2016, including R2 versions. Patch Manager provides all patches for supported operating systems within hours of their being made available by Microsoft.


AWS does not test patches for Windows or Linux before making them available in Patch Manager.

Patch Manager integrates with AWS Identity and Access Management (IAM), AWS CloudTrail, and Amazon CloudWatch Events to provide a secure patching experience that includes event notifications and the ability to audit usage.

Getting Started with Patch Manager

To get started with Patch Manager, complete the following tasks.

Task For More Information

Verify Systems Manager prerequisites.

Systems Manager Prerequisites

Learn about how to set up and configure patching.

Working with Patch Manager

Configure permissions for Maintenance Windows

(Required if you intend to use this feature when patching.)

Controlling Access to Maintenance Windows

Create patch baselines, patch groups, and a Maintenance Window to execute patching in a test environment.

Systems Manager Patch Manager Walkthroughs