Skip to content

Responder Updates

AIR Responders installed on your assets must stay compatible with the Console. Responder Updates control how and when those Responders receive the current Responder version packaged with your Console.

You can:

  • Update Responders manually by assigning an Update Responder Version task
  • Update Responders automatically using a Default policy and optional custom policies
  • Exclude groups of assets from automatic updates with exclusion policies
  • Manually exclude individual assets from updates
  • See why a specific asset is or is not eligible for automatic updates on the asset detail page

Automatic updates always target the Responder version that matches your Console. There is no per-policy target version selector.


ModeWhat happens
Manual UpdatesResponders update only when an administrator assigns an Update Responder Version task. Saved automatic policies remain stored but are not enforced.
Automatic UpdatesManaged assets update according to the Default policy and any matching custom policies, when they next check in with the Console and are eligible.

You select the mode under Settings → Assets → Responder Updates.

Responder Updates: Manual and automatic update mode options
  1. Open Settings.
  2. Go to Assets.
  3. Find the Responder Updates section.

Changes on this page are kept in a draft until you click Save. Leaving the page with unsaved changes shows a confirmation prompt.

Responder Updates: Unsaved changes confirmation prompt
  1. Select Update asset Responders automatically.
  2. Confirm when prompted (type Enable when asked).
  3. Review the summary of enabled and disabled custom policies, and the Default policy schedule.
  4. Click Save.
Responder Updates: Enable automatic updates confirmation
  1. Select Update asset Responders manually (by assigning an upgrade task).
  2. Confirm when prompted (type Manual when asked).
  3. Click Save.

Automatic configuration (Default policy and custom policies) remains stored but inactive.

Responder Updates: Switch to manual updates confirmation

Choose what happens when an update conflicts with running tasks

Section titled “Choose what happens when an update conflicts with running tasks”

An update restarts the Responder, so it cannot run at the same time as an acquisition, Hunt/Triage, or other task. Under When an update conflicts with running tasks, choose which takes priority:

OptionBehaviour
Wait for running tasks to finishThe update starts automatically once every running task completes, provided the update window is still open. Otherwise it moves to the next window.
Stop running tasks and update immediatelyRunning tasks are cancelled so the update can start. They must be started again manually.

Responder Updates: Choosing what happens when an update conflicts with running tasks

This setting governs automatic updates. When you assign a manual update to an asset that has running tasks, AIR asks you to confirm first and tells you how many tasks would be stopped.

Responder Updates: Confirmation shown before a manual update stops running tasks


When Automatic Updates are enabled, the Default policy applies to managed assets that do not match any enabled custom policy.

  • Behaviour: Update automatically
  • Target: Managed assets that do not match any custom policy
  • You can edit the schedule only
  • The Default policy cannot be deleted or disabled
  1. Under Default policy, click Edit schedule.
  2. Choose either:
    • Update at any time, or
    • A recurring time window (days of the week, start and end time, and timezone)
  3. Apply the drawer changes, then click Save on the settings page.
Responder Updates: Default policy with Edit schedule action

Timezone options:

  • Use each asset’s local timezone, or
  • A specific timezone you select
Responder Updates: Edit default policy schedule drawer

Custom update policies refine Automatic Updates for filtered groups of managed assets. Each update policy can use its own schedule and timezone.

Typical uses:

  • Update Windows workstations only during a maintenance window
  • Use a different schedule for a production organization or tag
  • Roll updates for one platform earlier than another
FieldDescription
Policy nameUnique name shown in Settings and on asset status
BehaviourUpdate automatically
FilterAsset conditions that must match
EnabledDisabled policies are ignored
ScheduleAny time, or a day/time window with timezone

Update policies do not set a specific Responder version. Matching eligible assets receive the Console’s current Responder version.

Responder Updates: Custom update policy card

An exclusion policy uses the same filter model as an update policy, but its behaviour is Exclude from automatic updates.

Matching managed assets never update automatically, even when the Default policy would update them.

Exclusion policies:

  • Do not use a schedule
  • Do not block manually assigned Update Responder Version tasks
  • Can be enabled or disabled like update policies
Responder Updates: Exclusion policy drawer

You can exclude a specific asset from Responder updates without creating a policy.

From the asset list (bulk actions) or asset actions, choose the exclude-from-updates action and confirm.

Responder Updates: Exclude assets from updates via bulk actions

While an asset is manually excluded:

  • It does not receive automatic Responder updates
  • Queued update tasks are not delivered until the asset is included again
  • The asset detail Responder Update Status shows Manually excluded from updates

Use Include in updates from the asset detail status card, asset actions, or bulk actions, then confirm.

Responder Updates: Asset manually excluded from updates

Custom policies have no priority order. AIR evaluates matching as follows when Automatic Updates are enabled:

1. Is the asset manually excluded?
→ Yes: do not update automatically (and do not deliver update tasks until included)
2. Is global mode Manual Updates?
→ Yes: policies are inactive; update only via assigned tasks
3. Does any enabled exclusion policy match?
→ Yes: do not update automatically
4. Does any enabled update policy match?
→ Yes: update only if at least one matching update policy's schedule window is open
(if all matching update windows are closed, the Default policy is NOT used)
5. No custom policy matches?
→ Use the Default policy schedule

Disabled policies are ignored.

SituationResult
Global Manual UpdatesNo automatic updates; assign tasks manually
Manually excluded, matches an update policyRemains excluded until included again
Matches an exclusion policy and an update policyExcluded (exclusion wins)
Matches two update policies; either window is openEligible during an open matching window
Matches an update policy; all matching windows are closedNot eligible; Default schedule does not apply
Matches no custom policyFollows the Default policy
Policy disabledTreated as if the policy does not exist

Create, edit, enable, disable, and delete policies

Section titled “Create, edit, enable, disable, and delete policies”
  1. Under Custom policies, click Add policy.
  2. Enter a unique Policy name.
  3. Choose Behaviour:
    • Update automatically, or
    • Exclude from automatic updates
  4. Add at least one filter condition.
  5. For update policies, configure the schedule if needed.
  6. Click Apply changes in the drawer.
  7. Click Save on the settings page.
Responder Updates: Add policy drawer filter step

Open the policy from the custom policy list, change fields, apply drawer changes, then Save.

Use the enable/disable control on the policy card, then Save.

  • Active: Automatic Updates are on and the policy is enabled
  • Inactive: Manual Updates are on (policy stored but not enforced), or the policy itself is disabled
Responder Updates: Enable or disable a custom policy
  1. Delete the policy and confirm.
  2. Save the settings page.

Deleting an update policy may cause matching assets to follow another matching policy or the Default policy. Deleting an exclusion policy may make matching assets eligible for automatic updates again.


Filters select which managed assets a custom policy applies to. The UI always scopes policies to managed assets.

Supported filter fields include:

FieldTypical use
OrganizationLimit to one or more organizations
IP addressMatch management or interface addresses
Device nameHostname patterns
LabelAsset label text
Group pathAsset group location
Operating systemOS string (for example, Windows, Ubuntu)
Responder versionCurrent Responder version on the asset
TagsOne or more tags
PlatformWindows, Linux, macOS, and other supported platforms
ServerWhether the asset is classified as a server

Combine conditions with the filter builder (AND/OR groups) using operators such as equals, contains, matches, in, and all/not-all for tags.


On a policy card:

  • Review the matching asset count
  • Click View matches to open Matching Responders
  • Search by device name and page through results
Responder Updates: Matching Responders list

Counts reflect filter matches for managed assets. They do not by themselves prove that an asset is currently inside an update window or free of manual exclusion.


Identify why an asset is or is not updating

Section titled “Identify why an asset is or is not updating”

The asset detail page answers this in two places.

Open the asset → General (or asset overview) and find Responder Update Status. It summarises the asset’s eligibility under your policies.

StatusMeaning
Manually excluded from updatesAsset-level exclusion is active
Automatic updates are disabledGlobal Manual Updates mode
Excluded from automatic updatesAn exclusion policy matches
Automatic updates enabledEligible via a matching update policy or the Default policy

It may also show:

  • The matching policy name (when applicable)
  • The effective schedule summary
  • Shortcuts to Include in updates, Assign an update task manually, or Manage Responder update settings
Responder Updates: Asset with automatic updates enabled

Higher up the same page, the Version update card reports what is happening right now rather than what your configuration allows. It shows the current and target versions, the lifecycle status, and the specific reason an update is waiting, scheduled, or failed — plus Update now and View update history.

Use Responder Update Status to check whether your policies make an asset eligible, and the Version update card to find out why an eligible asset has not updated yet.

For the full status reference — the nine statuses, the distinct waiting reasons, retry timing, and the at-a-glance view in the Assets list — see Responder Update Status.


Use this when you need an immediate or scheduled update outside (or in addition to) automatic policy behaviour.

High-level steps:

  1. Open the asset.
  2. For an immediate install, expand Version update and choose Update now.
  3. To schedule, or to use the full drawer, start Update Responder Version (from asset actions or Responder Update Status → Assign an update task manually).
  4. Configure the task in the drawer (now or later), then assign it.

For detailed drawer steps and screenshots, see How do I update Responders on assets?.


  1. In the asset list, select the assets (or use a filter and bulk selection).
  2. From the bulk actions bar, choose Update Responder Version.
  3. Complete the Update Responder Version drawer.

If some selected assets are already current, the drawer limits selection to assets that require an update.

See the FAQ for the full drawer workflow.


The Update Responder Version drawer supports:

OptionBehaviour
NowAssign the update task immediately
Schedule for laterChoose timezone (asset timezone or a selected timezone) and start time

Scheduling a new update for an asset replaces any previously scheduled Responder update for that asset.

Full steps: How do I update Responders on assets?


Version update statuses vs Assets Summary labels

Section titled “Version update statuses vs Assets Summary labels”

Two Console surfaces use similar wording for different jobs. Do not treat them as the same label set.

Version update card and Assets list Version column

Section titled “Version update card and Assets list Version column”

These report the live Responder update lifecycle. Common idle or behind-target states include:

StatusMeaning
Update requiredThe Responder is older than a release Binalyze has marked as mandatory and must be updated (for example, to accept tasks)
Update availableA newer Responder version can be installed; automatic updating is not applying it for this asset (for example, global Manual Updates)
Up to dateThe asset runs the target version; automatic update is not issued and manual update selection is unavailable

The full set of nine statuses, waiting reasons, and retry rules is in Responder Update Status.

The Assets Summary widget still uses endpoint issue labels for fleet counts and filters:

LabelMeaning
Update RequiredSame urgency class as the Version update Update required status — the Responder must be updated for compatibility
Update AdvisedThe Responder is on an older version and an update is recommended (OldVersion issue). This Home label is not the Version update card’s Update available status

Automatic updates run when the asset checks in, is eligible under precedence and schedule rules, and is behind the Console Responder version. AIR also limits how many Responder updates run at the same time across the environment; see Concurrent update limit.


  1. Start in Manual Updates while you design filters and schedules, then switch to Automatic after reviewing Matching Responders.
  2. Keep the Default policy conservative (for example, a maintenance window) if most assets should wait for off-hours updates.
  3. Use update policies for clear cohorts (platform, organization, tags).
  4. Use exclusion policies for groups that must never auto-update.
  5. Use manual exclusion for individual critical servers.
  6. After changing policies, open a representative asset’s Responder Update Status and Version update card to verify eligibility and live state.
  7. Remember that enabling Automatic Updates clears outstanding scheduled/assigned manual update tasks.

Automatically update Windows assets during a maintenance window

Section titled “Automatically update Windows assets during a maintenance window”
  1. Enable Automatic Updates and save.
  2. Add an update policy named for example Windows maintenance.
  3. Filter: Platform is Windows (add other conditions as needed).
  4. Schedule: your maintenance days and hours; choose asset timezone or a fixed timezone.
  5. Apply and Save.
  6. Use View matches to confirm the cohort.

Assets that match this policy follow its window. They do not fall back to the Default policy if that window is closed.

Exclude Linux servers from automatic updates

Section titled “Exclude Linux servers from automatic updates”
  1. Add an exclusion policy.
  2. Filter: Platform is Linux (optionally Server is true).
  3. Apply and Save.

Matching Linux servers skip automatic updates. You can still assign Update Responder Version tasks to them when needed.

  1. Create an update policy filtered by Tag (for example tier-1) with an earlier window.
  2. Create another update policy filtered by Organization or Tag tier-2 with a later window.
  3. Leave remaining assets on the Default policy.

If an asset matches both an exclusion policy and an update policy, it is excluded.

Manually exclude a critical server that matches an update policy

Section titled “Manually exclude a critical server that matches an update policy”
  1. Open the critical asset.
  2. Exclude it from updates and confirm.
  3. Confirm Responder Update Status shows Manually excluded from updates.

The asset stays excluded even if it still matches an update policy. Include it again when you are ready to update.

Determine why an asset is not receiving automatic updates

Section titled “Determine why an asset is not receiving automatic updates”

Start on the asset detail page, then fall back to policy checks:

  1. Open the Version update card — the status badge and explanation name the current blocker (window, maintenance, running tasks, capacity, failure, and so on). See Responder Update Status.
  2. Open View update history (or the Version Updates tab) if the card shows Failed or repeated retries. See Responder Update History.
  3. Check Responder Update Status for eligibility: manually excluded, global Manual Updates, or an exclusion policy.
  4. If an update policy matches with a closed window, the Default schedule does not apply for that asset.
  5. Confirm the asset is not already Up to date, and that it is managed and checking in.

ProblemWhat to check
No assets update automaticallyConfirm Automatic Updates is selected and saved; confirm assets are managed and online/checking in
Asset matches my update policy but never updatesOpen the Version update card first; then check manual exclusion, exclusion policies, and whether the policy schedule window is open — closed grant windows do not use Default
Asset still follows Default after I created a policyConfirm the policy is enabled, saved, and that the asset appears under Matching Responders
I assigned an update but nothing happensIf the asset is manually excluded, include it first; confirm the asset needs an update; confirm the task was not cleared by enabling Automatic Updates; check history for a failed or cancelled attempt
Enabling Automatic cleared my scheduled updatesExpected behaviour — scheduled/assigned Version Update tasks are removed when Automatic Updates is enabled
Unexpected policy name on the status cardMultiple policies may match; verify all matching update and exclusion policies, not only the displayed name
Changes in the policy drawer did not applyClick Save on the main settings page after applying drawer changes

ActionTypical privilege requirement
Change Responder Updates settings and policiesSettings save permission
Exclude or include assets; assign Update Responder VersionAssign version update task permission
View asset Responder Update StatusEndpoint / asset view permission

Exact role names depend on your configured roles.