Jump to content

Recommended Posts

Posted

https://blogs.technet.microsoft.com/configmgrdogs/2016/12/07/update-to-supersedence-behaviour-for-security-only-and-security-monthly-quality-rollup-updates/

 

Personally I preferred the update roll up superseding everything, though I can understand the reasoning behind it. However with the 'new' way it is unclear what rules the client will follow when both the "rollup" and "security only" updates are available but neither have yet been installed.

  • Thanks 2
  • 2 weeks later...
Posted

Just caught up on this one.... my clients are now installing both the Quality and Security rollup from WSUS :rolleyes:

 

Supersedence was working logically in my mind (Full Quality trumps Security only), and now they've broken it and clients are doubling up on what they install!!!!

  • 3 weeks later...
Posted (edited)

Just (finally!) got my head around all this new method of Windows updating... with Security Only Quality Update and Security Month Quality Rollup plus the .Net variants... and how they are (or now, were) applied and superceeded etc.

 

Then November came, and the the way the 2 updates applied changed!

 

Found this article, that eventually explained the current situation...https://blogs.technet.microsoft.com/configmgrdogs/2016/12/07/update-to-supersedence-behaviour-for-security-only-and-security-monthly-quality-rollup-updates/

 

The last section I would appreciate advice on, the article states:

 

Based on feedback, the team has updated the supersedence relationship of updates so that Security Only Quality Updates are not superseded. In addition, the logic of the updates has been modified so that if the Monthly Quality update is installed (which contains the security updates), the security update will not be applicable. This allows organisations managing updates via WSUS or Configuration Manager to:

 

Selectively install Security Only Quality Updates (bundled by Month) at any time

Periodically deploy the Security Monthly Quality Rollup and only deploy the Security Only Quality Updates since then, and;

More easily monitor software update compliance using Configuration Manager or WSUS.

 

Which makes sense, 'but' say initially you have been applying Security Only Quality Updates, does that mean you always have to continue to 'approve' and use them forever? Even if you get to a stage in the future whereby you'd want to just 'approve' and use the (combined) Security Monthly Quality Rollup? as 'technically' that includes the Security Only Quality updates too. But the section referenced above states it won't.

 

Hope that makes sense!

Edited by MYK-IT

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...