Jump to content

Important update for WSUS 4.0 (KB3095113)


Recommended Posts

Posted (edited)

Source: WSUS Product Team Blog

 

Some of you may know that we are releasing the Windows 10 1511 feature upgrade, which is the firstin-place upgradefor Windows 10, to WSUS in the next couple weeks. To fully enable this deployment scenario, we shipped a patch to WSUS for WS12 and WS12R2 (KB 3095113). Following this release, we received some questions regarding the applicability of this update. Such questions included:

 

    [*]Is this patch required to support Windows 10?

    [*]What happens if I don’t install it?

    [*]Should I wait for the DLC or other non-Hotfix release?

    [*]Are there any known issues with the release?

    The simple translation of"Support Windows 10"

    You might be asking whether WSUS can recognise, sync/import, and distribute Windows 10 updates without having to receive a patch itself to enable this functionality. If this is your concern, then you will not need any patches to enable this behaviour. While Windows 10 is indeed a monumental release in our history, from the WSUS perspective it's just another product in the list, and there's nothing new to Windows 10 updates (including security updates) that requires WSUS to be modified in order to handle them. Administrators of WSUS 3.0 SP2 (including SBS 2011) and unpatched WSUS 4.0 will be able to deploy Windows 10 updates, but not feature upgrades.

     

    Our preferred translation of "Support Windows 10"

    One feature that makes Windows 10 special is delivering Windows as a service. For the WSUS or SCCM administrator, this means enabling feature upgrades to a new build of Windows. These upgrades will be processed just like the usual updates, except that once they are approved for installation on WSUS/SCCM-managed machines, they upgrade the entire build, not just some of its binaries. If you're a member of the Windows Insider Program, then you've already been using this technology for a while (though not via WSUS). Wiping and loading images in order to refresh your Windows builds can be nothing but a memory, and that's what is offered here. It's especially useful because new Windows 10 builds will be released much more frequently than the one-to-three-year release cycle to which you might be accustomed. In order for WSUS to support these feature upgrades, it needs to install a patch. Feature upgrades introduce a new update content file type (and classification, called Upgrades) that will likely only be apparent to the WSUS admin: we've done our best to abstract the details from non-enterprise users.

     

    As for the quality

    Some folks are cautious about updates like KB3095113 being released with boilerplate text that include verbiage such as “do not install unless you are experiencing this issue.” Hotfix is our most expedient release vehicle, and we wanted to provide as much time to deploy this ahead of the Windows 10 1511 feature upgrade release to WSUS as possible. We have tested it the same as we would any Windows Update release, so there is no reason to wait to install the update on your WSUS 4.0 servers. For your convenience, we’ll be releasing the update more broadly to DLC and Catalog, as well as to WSUS itself, in the first quarter of 2016. If you prefer to wait for those releases, then please review the caution described next.

     

    Important caution

    WSUS may be able to see the Windows 10 1511 feature upgrade even if it can’t properly download and deploy the associated packages. The feature upgrades will become visible as soon as the “Upgrades” classification is checked in the WSUS options for Products and Classifications. If you attempt to sync any Upgrades without having first installed the recent patch, then you will populate the SUSDB with unusable data that must be cleared before Upgrades can be properly distributed. This situation is recoverable, but the process is nontrivial and can be avoided altogether if you make sure to install the update before enabling sync of Upgrades.

     

    What this means for you

    If you are content to wipe and load images for Windows 10 in order to stay on a current build, then simply do not enable sync of Upgrades in your WSUS, and do what you usually do to upgrade your Windows builds. However, if you ever intend to deploy Windows 10 and fully enable Windows as a service for your enterprise, then you'll want to deploy the recent patch. Furthermore, the safest route is to enable sync of Upgrades in your WSUS only after you have installed this patch on all WSUS 4.0 servers that service Windows 10 machine in your environment.

     

    Your 1511 upgrade experience

    The Windows 10 1511 feature upgrade will be available via WSUS in the next 1-2 weeks (which is when you’ll see the new Upgrades classification), and it will apply to Windows 10 RTM as well as Windows 7 and Windows 8.1 machines. If you are upgrading from Windows 10 RTM, then the process is highly automated: it will skip the application provisioning stage and all setup steps that require user interaction, and will preserve file associations and other settings by default. Upgrading from Windows 7 and Windows 8.1 via WSUS will require some end user interaction because the entire platform is changing, not just a build.

Edited by Arthur
Posted

The Windows 10 1511 feature upgrade will be available via WSUS in the next 1-2 weeks (which is when you’ll see the new Upgrades classification), and it will apply to Windows 10 RTM as well as Windows 7 and Windows 8.1 machines

 

I'll er.. pass

Posted
The Windows 10 1511 feature upgrade will be available via WSUS in the next 1-2 weeks (which is when you’ll see the new Upgrades classification)

 

The Upgrade category is already there, at least for me it is, (Windows Server 2012 R2 with WSUS and KB3095113 installed).

Posted
The Upgrade category is already there, at least for me it is, (Windows Server 2012 R2 with WSUS and KB3095113 installed).

 

Word of warning, the updates (or should I say upgrades) for Windows 10 that appear here in this category, seem to target Windows 7 and Windows 8 as well.

 

I would also assume that not everyone wants to roll this out to older clients, and if you do it would be wise to check if there are any license implications with upgrading older Volume Licensed versions of Windows first! As always, proceed with caution :).

Posted

FYI, A new bunch of upgrades have been release for en-gb and en-us, the update names are in the following format:

 

Windows 10 Pro/Education/Enterprise( N), version 1511, 10586 - en-gb/en-us, Retail/Volume

 

According to WSUS, these updates supersede the previous update.

Posted
Sadly there's no free upgrade to Enterprise versions, at some point I'll reinstall the OSes the machines came with and upgrade them to 10 to enable the free licence for 10 Pro, then put them back to 7 for a while
Posted
FYI, A new bunch of upgrades have been release for en-gb and en-us, the update names are in the following format:

 

Windows 10 Pro/Education/Enterprise( N), version 1511, 10586 - en-gb/en-us, Retail/Volume

 

According to WSUS, these updates supersede the previous update.

 

I just tried to push this to a test machine running Windows 10 Education and got the error: Installation Failure: Windows failed to install the following update with error 0x8024200d: Upgrade to Windows 10 Education, version 1511, 10586 - en-us, Volume

 

investigating now

  • 2 months later...
Posted

How to delete upgrades in WSUS

 

This applies to anyone who missed KB3095113 when it was offered as a hotfix, and subsequently enabled syncing of Upgrades in their environment. The upgrades that were downloaded happen to be from the Windows 10 1511 feature upgrade, but these steps could be modified to suit a similar purpose for a different set of content).

 

In this scenario, WSUS has downloaded content that it cannot use. Because parsing only happens once, and WSUS does not know what “Upgrades” are without having installed KB3095113, it incorrectly identifies the upgrade as a regular update and saves it to the SUSDB as such. In order to remedy this, you must perform the following sequence of steps on the WSUS servers as specified in the table below

 

Some workarounds propose that you delete these entries from the SUSDB via SQL queries, but we do not recommend directly modifying database content. The supported way to remove update content is with PowerShell commands [from an elevated session] as described below. Again, be sure that you perform the deletion step on the WSUS server that is highest in your hierarchy first, and then work your way down; otherwise, your deletions may be replaced by the USS on the next sync attempt.

 

# Disable Upgrades classification on local WSUS server
Get-WsusClassification | Where-Object -FilterScript {$_.Classification.Title -Eq “Upgrades”} | Set-WsusClassification -Disable  

# Delete all update content on the current server belonging to the 1511 release
$s = Get-WsusServer
$s.SearchUpdates(“version 1511, 10586”) | foreach { $s.DeleteUpdate($_.Id.UpdateId) } 

# Enable Upgrades classification
Get-WsusClassification | Where-Object -FilterScript {$_.Classification.Title -Eq “Upgrades”} | Set-WsusClassification 

# Perform full sync
$sub = $s.GetSubscription()
$sub.StartSynchronization()

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...