Needless to say, take a look at ahead of and immediately after patching. You need to be inside the practice of checking the login/logout moments of end users. Commonly a location Verify will do. Personally, I just check for just about anything out with the standard. For example, a VPN user logging in at two PM from unrecognized IP address must be a