How do you handle windows updates on your servers?<\/p>\n
For work stations :- Automatic update and install
\nFor server :- download & Manual install
\n“Mission Critical” server are on no download, we update them manually.<\/p>\n
This is all handled by WSUS.<\/p>\n
The servers have to be done outside of work time, and this can be from 06:00 to 00:00.<\/p>\n
I don’t want to put the servers onto automatic download and install, because of rouge patches.<\/p>\n
So what do you all do?
\nIf you had the money what would you like to do?<\/p>\n
P.S. Absolutely no cloud solutions as some of my customers have stated that as soon as we use cloud then they will say good buy.<\/p>","upvoteCount":5,"answerCount":9,"datePublished":"2018-07-26T11:50:21.000Z","author":{"@type":"Person","name":"davidelliott6117","url":"https://community.spiceworks.com/u/davidelliott6117"},"acceptedAnswer":{"@type":"Answer","text":"
We got a little fed up of Windows Updates and patches screwing up systems.<\/p>\n
All our servers run Windows Server 2016 and our workstations Windows 10. All machines pull their updates from our internal WSUS server.
\nSo i implemented 2 test machines that download and apply the updates 1st. If the update does not destroy the machine then i roll it out to our live servers and workstations around a week later.
\nThe only ones i allow straight through are critical security updates.<\/p>\n
Its a little time consuming, but less time consuming than rolling back updates that have screwed up our systems and the added headache of multiple support calls claiming the updates that “ICT” applied yesterday broke everything.<\/p>","upvoteCount":0,"datePublished":"2018-08-08T10:38:21.000Z","url":"https://community.spiceworks.com/t/how-do-you-handle-windows-updates-on-your-servers/664286/8","author":{"@type":"Person","name":"ryantill","url":"https://community.spiceworks.com/u/ryantill"}},"suggestedAnswer":[{"@type":"Answer","text":"
How do you handle windows updates on your servers?<\/p>\n
For work stations :- Automatic update and install
\nFor server :- download & Manual install
\n“Mission Critical” server are on no download, we update them manually.<\/p>\n
This is all handled by WSUS.<\/p>\n
The servers have to be done outside of work time, and this can be from 06:00 to 00:00.<\/p>\n
I don’t want to put the servers onto automatic download and install, because of rouge patches.<\/p>\n
So what do you all do?
\nIf you had the money what would you like to do?<\/p>\n
P.S. Absolutely no cloud solutions as some of my customers have stated that as soon as we use cloud then they will say good buy.<\/p>","upvoteCount":5,"datePublished":"2018-07-26T11:50:21.000Z","url":"https://community.spiceworks.com/t/how-do-you-handle-windows-updates-on-your-servers/664286/1","author":{"@type":"Person","name":"davidelliott6117","url":"https://community.spiceworks.com/u/davidelliott6117"}},{"@type":"Answer","text":"
Servers are set to download automatically, but not install. We run 24x5 and many weeks are 24x7, so we have a limited install window.<\/p>","upvoteCount":0,"datePublished":"2018-07-26T12:17:31.000Z","url":"https://community.spiceworks.com/t/how-do-you-handle-windows-updates-on-your-servers/664286/2","author":{"@type":"Person","name":"big-green-man","url":"https://community.spiceworks.com/u/big-green-man"}},{"@type":"Answer","text":"
We use System Center for patch management. Push out updates to test servers the weekend after patch Tuesday and if no issues, prod follows about a week behind.<\/p>\n
The same for our desktops<\/p>","upvoteCount":0,"datePublished":"2018-07-26T12:18:29.000Z","url":"https://community.spiceworks.com/t/how-do-you-handle-windows-updates-on-your-servers/664286/3","author":{"@type":"Person","name":"chuckdruery","url":"https://community.spiceworks.com/u/chuckdruery"}},{"@type":"Answer","text":"
We have them set to download but not install. I’ll usually schedule them to install when someone (if not myself) is around to check if it runs well afterwards. If it doesn’t we just roll it back and investigate. Luckily the servers generally don’t have this issue but we have Rollback Rx Server these just in case there is an issue as well as a few readily available Veeam disk images.<\/p>\n
So we essentially install at a time when server won’t affect anyone if it’s down. If there is an issue we roll it back or re-image.<\/p>","upvoteCount":0,"datePublished":"2018-07-26T13:08:15.000Z","url":"https://community.spiceworks.com/t/how-do-you-handle-windows-updates-on-your-servers/664286/4","author":{"@type":"Person","name":"JohnFreeman","url":"https://community.spiceworks.com/u/JohnFreeman"}},{"@type":"Answer","text":"
Download only and manual install.<\/p>","upvoteCount":0,"datePublished":"2018-07-26T13:24:08.000Z","url":"https://community.spiceworks.com/t/how-do-you-handle-windows-updates-on-your-servers/664286/5","author":{"@type":"Person","name":"James404d","url":"https://community.spiceworks.com/u/James404d"}},{"@type":"Answer","text":"
I’m interested to know, what is your customers objection to a cloud based patch updates system? Cloud base storage or email I could understand if they are sensitive about where their data is, but a patch update system stores no data except the patch level of your PCs/servers.<\/p>","upvoteCount":0,"datePublished":"2018-07-26T14:05:20.000Z","url":"https://community.spiceworks.com/t/how-do-you-handle-windows-updates-on-your-servers/664286/6","author":{"@type":"Person","name":"simon-marden","url":"https://community.spiceworks.com/u/simon-marden"}},{"@type":"Answer","text":"
I follow the following plan:<\/p>\n
For workstations - Automatic update and install
\nFor servers - download & manual install outside of business hours (usually on a weekend)
\nThis is all handled by WSUS.<\/p>\n
All other patches are done through PDQ Deploy which works well for our SMB.<\/p>","upvoteCount":0,"datePublished":"2018-07-26T21:06:56.000Z","url":"https://community.spiceworks.com/t/how-do-you-handle-windows-updates-on-your-servers/664286/7","author":{"@type":"Person","name":"kas2021","url":"https://community.spiceworks.com/u/kas2021"}},{"@type":"Answer","text":"
we use PDQ inventory and PDQ deployment<\/p>","upvoteCount":0,"datePublished":"2018-08-24T17:37:11.000Z","url":"https://community.spiceworks.com/t/how-do-you-handle-windows-updates-on-your-servers/664286/9","author":{"@type":"Person","name":"kalvinlo7493","url":"https://community.spiceworks.com/u/kalvinlo7493"}}]}}