Jump to content


volk1234

Manage Windows Updates in work environment whith SCCM 2012

Recommended Posts

HI,

 

Can anybody tell properly how to manage Windows Updates whith SCCM in real world? not in LAB. What is the Best practice to organize update groups? And how to maintain previously created packages - how to automate deletion of not required updates from update group?

Share this post


Link to post
Share on other sites

Like Niall said, it's different for every company...

 

I have found that, for my organization, the following works well:

 

1. Create a Software Update Group for the updates that you will be deploying this month along with a Deployment Package. The naming convention should have the month and year so it's easy to keep track of.

2. Create a Software Update Group named All Software Updates and a Deployment Package with the same name.

3. Deploy the Software Update Group for the current month as a WOL enabled required deployment.

4. Once the current months updates have been successfully deployed. Move the current months patches to the All Software Updates group.

5. Delete the current months Software Update Group and Deployment package.

6. Deploy the All Software Updates group to All Systems as Available with WOL disabled.

 

So, basically what we do is deploy the current months updates, then roll them up into another Software Update Group that is always set to Available just in case some machines missed the deployment. This way the users that missed the deployments can install them on their own leisure due to politics...

I hope this gives you some ideas so that you can come up with a process that works well for your organization.

  • Like 1

Share this post


Link to post
Share on other sites

For example: i have all my servers in Windwos 2008R2 collection. I had deploy windows updates whith criterias Product,Buleten ID

I had deploy Office updates to all servers- but there onle 2 servers have Office installed.

But there are still many updates needet to aplay- Report Viewer for only one server, and so on. How i must to deploy them ??

Share this post


Link to post
Share on other sites

I acutually like to bump this subject as I find myself struggling to come up with a normal or typical deployment.

 

First Question I have is for JOSH. I like the idea of pushing your updates up to all software updates group to protect you from a security hole, but what happens when you reach 500 updates. I thought there was a limit to the amount updates you could store in a group.

 

How do you deal with the managment of updates groups....i.e. dropping the expired updates form the group?

 

I think the site would benefit as a whole with a recommended procedures guide for this. In your guide on setup and setting up SCCM 2012 with Software Updates you only cover MS or security updates, it suttle but I think some people would miss it. Coming from a WSUS deployment to this is extremly frustrating because there seems like there is so much more work to do and more to think about.. I would love to see a guide that kinda gives the "best practices" for this type of user.

 

I just want to say that I think that this website is by far the best resource on the web for SCCM 2012. KUDOS.

  • Like 1

Share this post


Link to post
Share on other sites

The problem with solutions mentioned in this blog post on technet is that it seems MS thinks anyone who is an SCCM admin has only SCCM as a responsibility. Also, it mentions creating huge compliance-only update groups (not deployed) that you can check to make sure your machines are patched, but it never mentions how to patch just the ones that need it. Do I have to check this compliance and then create collections with potentially hundreds of machines that missed an update 6 months ago? Doesn't really do a great job explaining, IMHO.

 

I also found this which is an interesting read.

 

http://blogs.technet...nager-2012.aspx

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.