Just taken on extra responsibilities, one being WSUS. In the past it has been managed poorly.<\/p>\n
Advertisement
Going forward, im just working out the best way to manage the updates. There are a lot of updates sitting in my WSUS server with release dates from as far back as 2011 < wtf ?. Im presuming later updates will supersede these. Drive space is an issue, so ive just removed ‘drivers’ from the classifications options - hoping this will help.<\/p>\n
How do you go about approving/declining updates. How often do you do this? Once a month? How do you manage really old updates ?How do you go about testing updates if you are not 100% if they will have an adverse affect on your clients ?<\/p>\n
Im thinking of a monthly process, which looks like the below<\/p>\n
\n
\n
Once a month, review updates in WSUS<\/p>\n<\/li>\n
\n
approve / decline updates as required.<\/p>\n<\/li>\n<\/ol>\n
Just taken on extra responsibilities, one being WSUS. In the past it has been managed poorly.<\/p>\n
Going forward, im just working out the best way to manage the updates. There are a lot of updates sitting in my WSUS server with release dates from as far back as 2011 < wtf ?. Im presuming later updates will supersede these. Drive space is an issue, so ive just removed ‘drivers’ from the classifications options - hoping this will help.<\/p>\n
How do you go about approving/declining updates. How often do you do this? Once a month? How do you manage really old updates ?How do you go about testing updates if you are not 100% if they will have an adverse affect on your clients ?<\/p>\n
Im thinking of a monthly process, which looks like the below<\/p>\n
\n
\n
Once a month, review updates in WSUS<\/p>\n<\/li>\n
\n
approve / decline updates as required.<\/p>\n<\/li>\n<\/ol>\n
I got rid of WSUS. It’s a lot of work to manage if you want to manage it correctly. If all you want to do is apply updates, create a group policy to update from Microsoft. Have the updates happen automatically and reboot at like 3am.<\/p>\n
To do WSUS correctly, you need to review the updates as they come in. Test the updates in a test environment (for each OS you have in production at a minimum), then if the updates pass the testing phase, you approve the updates to be rolled out to your production machines. Even at that, I would roll the updates out to a group of power users first (ones that will give you feedback about problems). Then you need to keep up on maintaining the database. Remove updates that have been superceded, ensure that all updates have been pushed out to all machines. etc.<\/p>\n
Most people don’t use WSUS this way, they just auto approve critical and important updates, which is just easier with a group policy.<\/p>\n
My $.02<\/p>","upvoteCount":0,"datePublished":"2018-07-20T10:14:02.000Z","url":"https://community.spiceworks.com/t/wsus-best-practice/663104/2","author":{"@type":"Person","name":"jeffbuffington","url":"https://community.spiceworks.com/u/jeffbuffington"}},{"@type":"Answer","text":"
There is a script on here somewhere to help with it, I’m sure someone has the link handy.<\/p>","upvoteCount":0,"datePublished":"2018-07-20T10:20:29.000Z","url":"https://community.spiceworks.com/t/wsus-best-practice/663104/3","author":{"@type":"Person","name":"mhunt","url":"https://community.spiceworks.com/u/mhunt"}},{"@type":"Answer","text":"
It is only a lot of work, if you procrastinate. If you have WSUS, continue using it. Yes, it will be a chore to get up-to-date, but after that, it should only involve you say, once a month or so, for no more than 15 min. Hardly a PITA. What is a PITA is a stupid patch getting into your systems that screws up your accounting system (they won’t notice when payroll is late) or forbid one that blue screens half your company’s PCs.<\/p>\n
So yes, use a test group as that is best practice and make sure you have it resemble a cross-section of your environment. Make sure the folks in the test group understand why they are there and perhaps get them on board.<\/p>\n
Cause we all know that MS released patches are generally flawless.<\/p>","upvoteCount":3,"datePublished":"2018-07-20T10:22:52.000Z","url":"https://community.spiceworks.com/t/wsus-best-practice/663104/4","author":{"@type":"Person","name":"Denis-Kelley","url":"https://community.spiceworks.com/u/Denis-Kelley"}},{"@type":"Answer","text":"