Patch governance that
actually runs itself.

OPUS turns Azure patching into a structured, governed process — from a guided monthly workflow to a fully autonomous mode. Audit-ready compliance evidence for frameworks including Cyber Essentials, on demand. No agents. No complex setup. From a single IT team to an MSP managing thousands of devices across multiple tenants.

90-day free trial. No payment details required.

OPUS Security Briefing

Monthly patching shouldn't
consume your week

Azure Update Manager is powerful — but managing it at scale, across multiple environments and tenants, without structure, is a grind.

Hours of portal work every month

Manually checking assessment results, managing maintenance windows, chasing non-compliant devices — repeated across every tenant, every cycle.

Guided workflow replaces the grind

No visibility until something breaks

Unmanaged devices, expired exemptions, and missed patch windows go unnoticed until an audit — or an incident — surfaces them.

Continuous audit and compliance dashboard

Scaling headcount with tenant count

Managing five client tenants with the same manual process as one means five times the work. There's no leverage without structure.

Consistent process across every tenant

The capabilities no other
patching tool gives you

OPUS isn't just a scheduler. It's a governance layer — with structured workflows, human-controlled curation, and compliance evidence built in from the start.


Know your compliance
posture at a glance

Real-time compliance status across every device in every tenant. Non-compliant devices are scored by CVE severity data from Microsoft — so you always know which gaps carry the most risk, not just how many there are.

  • Monthly snapshots captured automatically for trend reporting and audit evidence
  • PDF and Excel export — compliance evidence ready for auditors in 30 seconds
  • Cyber Essentials aligned — produce patch management evidence on demand
OPUS Compliance Dashboard

A structured process,
not just a scheduler

Every phase of the patch cycle — assessment, maintenance window creation, device management, compliance review — delivered as a step-by-step guided workflow. Nothing skipped, nothing forgotten, every action logged.

  • Phases adapt to your governance settings — SQL, remediation, and runbook phases appear when enabled
  • Full activity audit trail — every mutating operation logged per tenant, per month
  • Or go fully autonomous — set your governance rules once and let OPUS run the cycle unattended
OPUS Guided Patch Workflow

Human governance over
what gets deployed

Before a single patch runs, OPUS presents the full list of available updates for your review. Approve, defer, or exclude individual KBs — with risk context surfaced from Microsoft's security data — before committing to your maintenance window.

  • CVE severity context for every available patch — make informed decisions, not guesses
  • KB-level exclusions written back to Azure tags — auditable, reversible, never silent
  • No other patching tool gives you this step — most just deploy what's available
OPUS Patch Curation

Everything else
included as standard

No feature gating between tiers. Every customer gets every capability from day one.

Multi-Tenant Management

Unlimited tenants, each fully isolated with their own credentials, governance settings, and compliance history.

Autonomous Patching Mode

Configure your maintenance windows and governance rules once — OPUS handles the rest on schedule.

Device Tag Audit

Discover every VM across your subscriptions and validate patch governance tag coverage instantly.

Device Exemptions

Time-limited or permanent exemptions with full Azure tag write-back. Expired exemptions flag for action — never silently removed.

KB Operations

Install or uninstall specific KBs across your estate outside the regular schedule — for emergency patches or rollbacks.

Maintenance Config Management

Create, manage, and audit maintenance configurations across all environments with full confirmation before any Azure change.

SQL IaaS Support

OS and SQL Server patching governed from one interface, including SQL IaaS extension registration tooling.

Patch Intelligence

Pre-patch health checks — pending reboots, disk space, Windows Update service status. Surface blockers before they become failures.

Runbook Integration

Connect Azure Automation runbooks into your patch workflow for power management and pre/post-patch scripting.

Arc-Enabled Server Support

Full patch governance for Azure Arc-enabled servers alongside your Azure VMs — discovered automatically, no additional setup.

Activity Audit Log

Per-tenant, per-month log of every mutating operation. Exportable — a complete audit trail for any compliance review.

Prerequisite Checker

Validates resource provider registrations, SP permissions, VM patch modes, and Resource Graph accessibility before your first run.

Integration

Close the loop with
your ITSM platform

OPUS monitors compliance continuously and can notify your ITSM system the moment a non-compliance threshold is breached — no manual checking, no missed incidents.

  • Outbound webhook to any ITSM that accepts HTTP POST
  • Works with ServiceNow, Jira Service Management, and more
  • Configurable threshold — you decide when to fire
  • Per-tenant configuration — each client can have its own endpoint

Automated alerting

Scheduler runs in the background — incidents are raised without anyone having to check a dashboard.

Rich payload

Notification includes tenant name, device count, compliance percentage, and patch month — everything your team needs to act.

Scheduler-driven

Runs on OPUS's background heartbeat — no external dependencies, no cron jobs, nothing to configure outside of OPUS.

From setup to compliant
in the same afternoon

OPUS is self-hosted and clientless. There's nothing to install on your managed servers — just point it at your Azure tenant and go.

1

Install & configure

Deploy OPUS as a Windows Service on any server in your environment. Create a Service Principal in Azure, assign the Contributor role, and configure your first tenant in minutes.

2

Set governance

Define your environments, subscriptions, and patch schedule. OPUS builds your monthly workflow automatically — SQL, remediation, and runbook phases appear when you enable them.

3

Run your patch cycle

Follow the guided workflow each month, or switch to autonomous mode and let OPUS run it unattended. Either way, compliance history and reports are always current.

Your data, your infrastructure

OPUS is entirely self-hosted. No tenant data is ever transmitted to Cloudframe Solutions or any third party. Azure communication is directly between OPUS and Microsoft's APIs.

No IIS required

OPUS runs as a Windows Service using the built-in Kestrel web server. Administrators access it via browser — no additional web server infrastructure needed.

Free Azure tier

OPUS works exclusively on the free Azure Update Manager tier. No additional Microsoft licensing required — just an Azure subscription you already have.

Simple, device-based pricing.
No surprises.

Pay only for the devices you manage. Monthly billing with no lock-in — or save 20% with annual prepayment.

Starter
1 – 100 devices
£ 2.50
per device / month
Save 20% with annual billing
  • Full feature access
  • 100 devices = £250/month
  • Annual = £2,400/year (save £600)
  • Flexible monthly billing
Scale
251 – 1,000 devices
£ 1.50
per device / month
Save 20% with annual billing
  • Everything in Growth
  • 500 devices = £750/month
  • Annual = £7,200/year (save £1,800)
  • Priority onboarding support
  • Direct access to the team

1,000+ devices?

Custom pricing available. Get in touch for a tailored quote with hands-on onboarding.

Monthly or annual

Monthly billing suits MSPs with fluctuating device counts. Annual saves 20% and locks in your rate.

No Azure extras

OPUS works on the free Azure Update Manager tier. No additional Microsoft licensing required.

Three months free.
Three full Patch Tuesday cycles.

Most tools give you 14 days. OPUS gives you three months — enough time to embed it into your operational workflow, build up compliance history, and see exactly what it's worth before spending a penny.

No payment details required to start. If your trial ends mid-cycle, a 14-day read-only grace period ensures it completes. OPUS never leaves your estate semi-compliant.

3
months free
  • Full functionality
  • No device cap
  • No payment details
  • Data retained after trial
  • 14-day grace period on expiry
Start Free Trial

A question? A specific requirement?
We want to hear it.

OPUS is built by an infrastructure engineer who has run enterprise patching at scale. If your estate has a specific shape, get in touch — we'll tell you honestly whether OPUS is the right fit.

hello@opus-orchestrator.co.uk

Usually replied to within one business day.