Javik Posted March 3, 2016 Posted March 3, 2016 Who has the time to mess around every Patch Tuesday to review Microsoft's update releases? The most that I would really want out of WSUS is the ability to delay all updates by 2 weeks so when Microsoft releases a fatal upgrade wrecking millions of desktops, at least we won't get it until after the fallout and emergency revision is available. And it's not like WSUS is a very reliable release mechanism either. Does anyone recall the first release of Windows 7 SP1? The one that randomly killed large numbers of desktops? Windows 7 computer won’t start after installing Service Pack 1. - Microsoft Community I very nearly deployed that to an entire district overnight, but then thought eh, maybe I should wait. And then once the news hit about SP1 breaking machines, I was afraid to even attempt applying it. Ultimately I ended up deploying SP1 the old fashioned way, as a new image to each computer via WDS rather than risking using WSUS and breaking everything. So it became.... um..... why am I even bothering with WSUS? It just more make-work that doesn't really benefit me. And so WSUS went bye bye, and all machines in the domain are set to Automatic install all Windows and Microsoft updates. If Microsoft screws that up it's on their head, not mine.
Michael Posted March 3, 2016 Posted March 3, 2016 WSUS when configured correctly is always recommended. The default configuration should be to disallow all Updates/Upgrades and only allow the ones you specify. This also manages bandwidth levels, as 100 workstations all downloading the latest Microsoft Upgrade wouldn't be a good idea.
rich_tech Posted March 3, 2016 Posted March 3, 2016 I wouldnt have that be the case there for anything I managed getting them straight off the web, given that WSUS is a free tool to control what installs or not, it can be very painful when it goes wrong and WSUS at least allows you to specify updates for Automatic Removal which can help with recovery of broken machines, as well as the scheduling and bandwidth control. WSUS also allows you to see if machines are not picking up the updates through its reporting. That being said, I would be looking to switch off any in-line upgrades on ours to different OS versions, we would want to control when people migrate and get our ADMX files in places and policies first off. Also with 10 the start menu seems to be a sticking point to going across, but its coming along slowly.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now