Jump to content


  • 0
wrayjl

transitioning from WSUS/GPO patching to SCCM

Question

we are moving looking to move away from WSUS/GPO windows patching to SCCM and i have read and bookmarked quite a bit on configuring windows patching in SCCM and have it setup and tested and it seems to be working as it should, however i have one sticking point that i could use some clarifying on. we have/had our WSUS patching broken down by AD security groups with pc's targeted in each group for instance WSUS_Servers and for that said policy we had it set via GPO where automatic updates were enabled and set to option 4 to download and install but to not reboot with a user logged on in which servers had to be manually rebooted when it wouldn't affect production... i.e... early AM hours or weekends for mailservers, fileservers, web servers, etc, etc. I would like to duplicate that scenario if possible IN SCCM so that an admin or on call technician reboots all critical servers after the patches have been installed, due to our environment and how it was setup(incorrectly i might add) which we are address as well. Currently have a deployment deadline for those critical servers to be no later than 2 weeks after they become availiable to install a 3AM in the morning and the suppress reboot option for servers is set is that the best way to approach this or to use maintenance windows for those collections

Share this post


Link to post
Share on other sites

3 answers to this question

Recommended Posts

  • 0

Hi,

I would use maintenance windows just to make sure that no installations are executed on a different time..

If for instance a server is down on 3AM or communicaiton is down, the server will install them as soon as it gets in contact with the SCCM server after the deadline. A maintenance windows will prevent such behaviour.

Regards;Jörgen

Share this post


Link to post
Share on other sites

  • 0

so just one last thing to clairify. If i set a maintenance window on this collection and in the deployment management if i have it set to suppress reboots on servers then it will not reboot correct after applying patches within that maintenance window correct?

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.