ClioSport.net

Register a free account today to become a member!
Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

  • When you purchase through links on our site, we may earn an affiliate commission. Read more here.

WSUS - Anyone good with it



  E39 530i
Been trying to work out the best way to push the updates out to the clients wortkstations. At present I have setup a test deployment group, a couple of pc's from each department. I have setup automatic approval for security and critial updates, for the above group. All clients get their WSUS settings from group policy, to download and install the approved updates on a Saturday night - providing they leave there pc's turned on. We would then evaluate the updated for a week or so, address any issues which the new updates may cause, before pushing out to the rest of the orginaisation. Does this practice sound good enough.

Would you guys recommend anything else?

Cheers
 
  E39 530i
Ps how good is SCCM. Recommend it? never looked into this. Where do I start if I want to have a play, any advice on this as well....
 

ChrisR

ClioSport Club Member
SCCM is great, all the cool kids have it.

Patching is more of a manual process with to over WSUS as you don't have the auto approval of patches, you've got ot go in and grab them, assign them to your deployments etc. But it's much better for managing things.

Should be a trial available here http://www.microsoft.com/systemcenter/en/us/configuration-manager.aspx, the cal pricing can work out expensive though unless your on a good licensing plan that has the CAL bundles.
 

KDF

  Audi TT Stronic
Been trying to work out the best way to push the updates out to the clients wortkstations. At present I have setup a test deployment group, a couple of pc's from each department. I have setup automatic approval for security and critial updates, for the above group. All clients get their WSUS settings from group policy, to download and install the approved updates on a Saturday night - providing they leave there pc's turned on. We would then evaluate the updated for a week or so, address any issues which the new updates may cause, before pushing out to the rest of the orginaisation. Does this practice sound good enough.

Would you guys recommend anything else?

Cheers

Almost exactly what I do, except I have a small test lab that it goes to first, then a guinea pig group, then mass deployment.

Set up reports so you get weekly emails highlighting any systems that have had problems updating which you can then address on a system by system basis or if fix via some scripting.
 

ChrisR

ClioSport Club Member
Reporting on SCCM is good, I used to have some good little ones setup that gave some good lists of patch status' throughout the network.
 
  E39 530i
Will be looking into SCCM very shortly. Cheers guys sound mint

As for WSUS. Does anyone have any little handy scripts which will enable me to force a client to check in and download the necessary updates from the WSUS server. I have tried running the wuauclt /detectnow and also the wuauclt /resetauthorization /detectnow switches but no joy.Updates statusfor necessary critial updates are set to install but for some reason the updates are not downloading at the necessary group policy time. Any ideas :(
 
  1 Series Coupe
I have set ours up to not download any updates what so ever. Every once in a while i will allow updates through to a test OU. If all is ok, will then deploy to the 800 machines on site.
 
  E39 530i
Is there not a way to force a client machine to download the approved updates from the WSUS server, before the group policy setting take affect WITHOUT doing a maual windows update from Microsoft?
 
  1 Series Coupe
I have an GPO that is added to the OU's that force the machines to download and install the updates from WSUS.
 
  E39 530i
I've got that as well, but one pc is being stuburn. It's showing up within WSUS and is added to the group within WSUS which has been set for automatic approval. But it doesnt download and install the necessary updates at the specific day / time which is set by the GPO.
 
I've got that as well, but one pc is being stuburn. It's showing up within WSUS and is added to the group within WSUS which has been set for automatic approval. But it doesnt download and install the necessary updates at the specific day / time which is set by the GPO.
Check the log file to see why its not downloading.

1. wuauclt /detectnow
2. Open c:\windows\windowsupdate.log

Should start like:

2011-07-25 16:55:20:467 408 3228 AU Triggering AU detection through DetectNow API
2011-07-25 16:55:20:468 408 3228 AU Triggering Online detection (non-interactive)
2011-07-25 16:55:20:472 408 120c AU #############
2011-07-25 16:55:20:472 408 120c AU ## START ## AU: Search for updates
 


Top