Compliance Scan Configuration for Delayed OS Updates but Latest AV Signatures
Hello Fortinet Community,
I’ve deployed the FortiNAC Persistent Agent and implemented compliance scans to ensure our systems are secure. Our policy is to delay operating system updates by one month, but we want antivirus signatures to always be up-to-date.
I understand it's possible to delay OS definitions downloads, but this also delays AV updates.
Is there a way to configure compliance scans to check that the OS has all critical updates with a one-month delay while ensuring AV signatures are always the latest?
Any guidance or best practices would be appreciated!
Thank you!
