TwistedHelixis Posted June 5, 2016 Posted June 5, 2016 Hello, I was informed that on a production server (main server for a primary school) you should not install all the Windows updates. I was told to un-tick recommended updates from the change settings page (See image below) Is that correct???? I am also getting optional updates listed on the main Windows update page just below the important updates, and wonder if I should be installing these??? (see image below) Thanks for the advice.
ellsandell Posted June 5, 2016 Posted June 5, 2016 Should really be running WSUS to filter out unnecessary/bad updates for both clients & servers. https://technet.microsoft.com/en-us/windowsserver/bb332157.aspx 1
TwistedHelixis Posted June 5, 2016 Author Posted June 5, 2016 This is a small primary with one server.
Oaktech Posted June 6, 2016 Posted June 6, 2016 This is a small primary with one server. And..? You should still be running WSUS to update all your clients as well, so you can filter out the bad updates before they come down from windows update and spanner your network!
TwistedHelixis Posted June 6, 2016 Author Posted June 6, 2016 If they wanted me more than 2 hours every week I might have the time to go through all the updates that MS release, but they do not have the money and I do not have the time. They also do not have enough space on the server for WSUS or any spare computers and even if they did I don't think they would pay out for a Windows server licence just for updates. I really need to keep the server updated with the core updates for the moment, hence my request.
woreilly Posted June 6, 2016 Posted June 6, 2016 In reality you should only need about 20GB of free space to manage WSUS efficiently - it can be set to only download and store the updates you approve. Unless you have a mixed network of 32-bit and 64-bit clients with different versions of office, 20GB should be enough! I can understand the time constraints though!
3s-gtech Posted June 6, 2016 Posted June 6, 2016 WSUS can also be set to not download any updates, just manage them. Clients then download them directly from MS. This loses the bandwidth saving features, but keeps the manageability.
Cazale Posted June 6, 2016 Posted June 6, 2016 If they wanted me more than 2 hours every week I might have the time to go through all the updates that MS release, but they do not have the money and I do not have the time. They also do not have enough space on the server for WSUS or any spare computers and even if they did I don't think they would pay out for a Windows server licence just for updates. I really need to keep the server updated with the core updates for the moment, hence my request. I'm the same (2 hours in each), and would definitely use WSUS. You don't need to read around each update, just delay releases slightly (you'll likely hear about any catastrophic updates through tech media such as The Register, or on here, or even in mainstream news these days). It gives you the ability to control when clients update, gives you a central hub for all reports and lets you plan/control when you fix update issues. It's probably even more important when you're time limited tbh. Not sure about 20gb though, ours (small primaries) run at about 150gb for Windows 7, server and a couple of Office versions!
woreilly Posted June 6, 2016 Posted June 6, 2016 Not sure about 20gb though, ours (small primaries) run at about 150gb for Windows 7, server and a couple of Office versions! I support a range of schools from Firsts to Middles. Generally we give their WSUS servers 80-127GB of maximum space but I like to keep it as low as I can. The 20gb was more my thinking of single client OS architecture, 1 version of office across the whole school and one server OS. If you keep on top of old updates and removed all your superseded updates you could quite easily have it down to 20-30GB.
TwistedHelixis Posted June 6, 2016 Author Posted June 6, 2016 They run mixed OS clients and mixed office etc and definitely would not have enough room on their old server. Another issue is MS say not to install WSUS on a DC server and this server is already running SQL, Sims, DHCP, Printers & data, and the last time I installed WSUS on my test DC server it crashed. If the school had another server or even a spare PC I would be looking at WSUS but at the moment they do not and I do not want to risk installing it on the main DC. @Cazale Do you also use WSUS for your server updates or just clients?
dry Posted June 6, 2016 Posted June 6, 2016 Sounds like perhaps there's a few more underlying jobs to think about as well as implementing WSUS (read: virtualisation and segregating server roles). I feel your pain though- there's only so much you can do when you're in for such a small amount of time each week.
DavR Posted June 6, 2016 Posted June 6, 2016 I've had WSUS running on a DC before, along with DHCP, DNS, Printers, SQL, the lot. I've never understood what the fuss about having it on a DC has been about, although it certainly is a pig for disk usage (the cleanup tool never gets you back anything like you were expecting) and it's nice to have it separated out. Personally, for the bandwidth usage alone, I'd never run a network without WSUS. In WSUS categories, I download Critical and Security updates. I run the automatic approval rule, because I don't have the time to do the whole delayed release thing (living on the edge!). If I were doing manual updates, I'd leave Recommended updates in there but not touch the Optional ones. If they're optional, not installing them is no threat to your security, so ignore them unless they add a feature you need. 1
LeMarchand Posted June 6, 2016 Posted June 6, 2016 (edited) I've had WSUS running on a DC before, along with DHCP, DNS, Printers, SQL, the lot. I still do at one site . Edited June 6, 2016 by LeMarchand
DavR Posted June 6, 2016 Posted June 6, 2016 I've had WSUS running on a DC before, along with DHCP, DNS, Printers, SQL, the lot./QUOTE] I still do at one site . Well, if it's a small network and budget doesn't really stretch beyond one physical server, I don't see a problem with that personally!
Cazale Posted June 7, 2016 Posted June 7, 2016 They run mixed OS clients and mixed office etc and definitely would not have enough room on their old server. Another issue is MS say not to install WSUS on a DC server and this server is already running SQL, Sims, DHCP, Printers & data, and the last time I installed WSUS on my test DC server it crashed. If the school had another server or even a spare PC I would be looking at WSUS but at the moment they do not and I do not want to risk installing it on the main DC. @Cazale Do you also use WSUS for your server updates or just clients? Clients and server, and it is running on a DC without issue. I guess that advice is so the DC doesn't take a performance hit, for a small school with a half-decent server it doesn't really matter, especially as you can schedule updates to run at the end of a day.
sniffingmoose Posted June 9, 2016 Posted June 9, 2016 I have never run WSUS and I let each of the 150 PCs automatic update themselves. I also do each server out of ours from home on remote so they don't need a reboot during working hours. So yes I am sure you don't have to set up WSUS. The company who set up the servers say they don't recommend WSUS as they are all DC's However I dont know how you are expected manage it all on 2 hours per week though. 1
dry Posted June 9, 2016 Posted June 9, 2016 I have never run WSUS and I let each of the 150 PCs automatic update themselves. I also do each server out of ours from home on remote so they don't need a reboot during working hours. So yes I am sure you don't have to set up WSUS. The company who set up the servers say they don't recommend WSUS as they are all DC's However I dont know how you are expected manage it all on 2 hours per week though. So you've got potentially 150 devices downloading the same update simultaneously on the same WAN connection? Hope your ISP doesn't mind! I'd strongly recommend implementing WSUS as it allows you to pre-vet updates before they break the same thing across 00s of devices. It's proactively making your life easier.
TwistedHelixis Posted June 9, 2016 Author Posted June 9, 2016 So you've got potentially 150 devices downloading the same update simultaneously on the same WAN connection? Hope your ISP doesn't mind! Don't think its such an issue with Windows 10 which can get it's updates from another Windows 10 machine that has already downloaded them. @sniffingmoose Seeing as you are doing the same as me would you mind answering my questions about the server updates from my initial post, Thanks.
TwistedHelixis Posted June 9, 2016 Author Posted June 9, 2016 This is interesting - If you un-tick recommended updates you still get them, it just they are listed in the optional updates rather than the important updates list apparently. What types of updates will I get?Windows Update categorizes software updates based on the update's importance. There are three categories for updates: important, recommended, and optional. Important updates. Important updates help keep your computer more secure and reliable, protecting your computer and your privacy. These updates include security and critical updates, as well as reliability improvements. Recommended updates. Recommended updates help keep your software up to date and your computer running at its best. If you selected Use recommended settings when you set up Windows Update, then recommended updates will be shown together with important updates. If you selected Install important updates only, recommended updates will be shown together with optional updates. Recommended updates include software updates and new or improved features. Optional updates. Optional updates include updates and software that you can install manually, such as new or trial Microsoft software or optional device drivers from Microsoft partners.
DavR Posted June 9, 2016 Posted June 9, 2016 Don't think its such an issue with Windows 10 which can get it's updates from another Windows 10 machine that has already downloaded them. Oh really? I hadn't heard of that one, it's a good trick if they have managed to do that! If so, they've pinched the logic behind Apple's caching server for that one, but done it in peer-to-peer rather than on a server.
DavR Posted June 9, 2016 Posted June 9, 2016 This is interesting - If you un-tick recommended updates you still get them, it just they are listed in the optional updates rather than the important updates list apparently. Well, they are still being offered, as you know, they are still updates that Microsoft recommends. It does means that if you just do a standard update, they won't be included though, you have to go in and pick them if you want them.
mikes Posted June 10, 2016 Posted June 10, 2016 well i thought the question wasn't "shall I use WSUS" but "should I deploy optional updates to servers" ? I have WSUS but this is the first I have heard about not deploying optional updates to servers? I deploy or decline them individually depending on what is in them
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now