<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/08218a407ae648709c9c75f1b9db1708&quot; frameborder=&quot;0&quot; width=&quot;1920&quot; height=&quot;1440&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>1440</height><width>1920</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>1440</thumbnail_height><thumbnail_width>1920</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/08218a407ae648709c9c75f1b9db1708-ea92fb1f685d6624.gif</thumbnail_url><duration>584.522</duration><title>Building Azure Update Manager Patch Lab</title><description>This Loom explains how Elijah built an Azure Update Manager patch management lab using Terraform, including the architecture, security choices, deployment, and compliance validation. He set up a small Windows domain with a domain controller and two workstations and used four Terraform modules for networking, key vault secret storage, compute (domain promotion and joining VMs), and update manager configuration with per-VM assignments, with remote state stored in an Azure storage account. He highlights real deployment blockers including a CPU quota limit (region allowed 4 vCPUs vs an original 6), a public IP limit (max 3 per region), capacity-restricted VM size requiring a different SKU, and two configuration bugs involving a required managed identity for the assessment policy and correct patch orchestration mode before linking to maintenance. The final result shows all three machines enrolled and passing validation with zero missing critical or security patches, and it generates a JACE JSON compliance report for auditing.</description></oembed>