abaxter2 Posted October 4, 2016 Posted October 4, 2016 So here we are as Microsoft go full steam ahead with their monthly patch rollup including windows 7 8/8.1 server 2008 / 2012 and 2012 r2: https://blogs.technet.microsoft.com/windowsitpro/2016/08/15/further-simplifying-servicing-model-for-windows-7-and-windows-8-1/ Microsoft shifting to monthly patch update model for Windows 7 and 8.1 | Windows Central 1
Michael Posted October 4, 2016 Posted October 4, 2016 I'm on the fence with this one - Yes single Cumulative Updates are useful, but then each month it's getting progressively larger and takes more resources to deploy. If I have a machine that's already updated to September, I'd still prefer to have 12 separate updates per year, rather than download the same information 11 times prior - downloading/installing in order. It could mean the difference between installing a 50MB update and a 500MB update.
TwistedHelixis Posted October 4, 2016 Posted October 4, 2016 And if something is wrong with the update do we need to un-install the entire rollup rather than the faulty update?????
Michael Posted October 4, 2016 Posted October 4, 2016 Yes you have to uninstall the whole Cumulative Update, even though 95% could be OK, and was limited to a specific component. Evidently Microsoft have published the September Update twice for build 1507, once for 1511 and three times for 1607. Definitely not ideal when we're talking about update files which are hundreds of Megabytes or more in size!
TwistedHelixis Posted October 4, 2016 Posted October 4, 2016 I can't get my head round why MS think this is a good thing for a server.
sonofsanta Posted October 4, 2016 Posted October 4, 2016 Given how often there have been problematic patches in the last 12 months alone, I am firmly against this. We'll end up missing security patches to avoid show stoppers like KB3170455 and its printer nonsense.
gshaw Posted October 7, 2016 Posted October 7, 2016 (edited) Dumb question, how does this work with WSUS if half the updates in the rollup are "Security" \ "Critical" and others are just "Updates" Do we need to manually approve these as rollups now rather than just leaving the auto-approval rule for Security & Critical as we do at present? Edit: seen this at the tail-end of one article: Lastly, Microsoft says that it will also push a monthly "Security-only" update that will only contain security patches for that month. This will be released separately from Windows Update via WSUS, SCCM, and the Microsoft Update Catalog. So presumably the important stuff will be in the auto-approved category and the other where we approve manually. Being cumulative I guess each rollup will supersede the previous version? Edited October 7, 2016 by gshaw
DavR Posted October 12, 2016 Posted October 12, 2016 Single update my bottom. Patch Tuesday is here, and I have six... I can see that Silverlight and Office would have separate updates, they're separate optional products. I'm trying to work out the difference between the FOUR different rollup packages it's given me.... good thing I'm only subscribed to critical and security, who knows how many "single" rollups I'd have ended up with.
DavR Posted October 12, 2016 Posted October 12, 2016 (edited) Ok, so reading up a bit more here, there are security only updates and monthly rollup updates, which are this months updates only, and (eventually) cumulative update since last release version. To obfuscate the matter, they throw the words quality, security and rollup into the title of each one, in a different order. Unfortunately, with my WSUS set to pick up critical and security updates, I get both, which is duplication. That's pretty dumb, especially considering one of these will eventually be MASSIVE. Edited October 12, 2016 by DavR
Arthur Posted October 12, 2016 Posted October 12, 2016 @gshaw. The following link has more details. More on Windows 7 and Windows 8.1 servicing changes First, let’s review what we will release each month: A security-only quality update A single update containing all new security fixes for that month This will be published only to Windows Server Update Services (WSUS), where it can be consumed by other tools like ConfigMgr, and the Windows Update Catalog, where it can be downloaded for use with other tools or processes. You won’t see this package offered to PCs that talk to Windows Update. This will be published to WSUS using the “Security Updates” classification, with the severity set to the highest level of any of the security fixes included in the update. This (like all updates) will have a unique KB number. This security-only update will be released on Update Tuesday (commonly referred to as “Patch Tuesday”), the second Tuesday of the month. (This is also referred to as a “B week” update). A security monthly quality rollup A single update containing all new security fixes for that month (the same ones included in the security-only update released at the same time), as well as fixes from all previous monthly rollups. This can also be called the “monthly rollup.” This will be published to Windows Update (where all consumer PCs will install it), WSUS, and the Windows Update Catalog. The initial monthly rollup released in October will only have new security updates from October, as well as the non-security updates from September. This will be published to WSUS using the “Security Updates” classification. Since this monthly rollup will contain the same new security fixes as the security-only update, it will have the same severity as the security-only update for that month. With WSUS, you can enable support for “express installation files” to ensure that client PCs only download the pieces of a particular monthly rollup that they haven’t already installed, to minimize the network impact. This (like all updates) will have a unique KB number. This monthly rollup will be released on Update Tuesday (also known as “Patch Tuesday), the second Tuesday of the month. (This is also referred to as a “B week” update). A preview of the monthly quality rollup An additional monthly rollup containing a preview of new non-security fixes that will be included in the next monthly rollup, as well as fixes from all previous monthly rollup. This can also be called the “preview rollup.” This preview rollup will be released on the third Tuesday of the month (also referred to as the “C week”). This will be published to WSUS using the “Updates” classification as an optional update. It will also be available via Windows Update (where all consumer PCs will install it) and on the Windows Update Catalog. With WSUS, you can enable support for “express installation files” to ensure that client PCs only download the pieces of a particular monthly rollup that they haven’t already installed, to minimize the network impact. Starting in early 2017 and continuing for several months, older fixes will also be added to the preview rollup, so it will eventually become fully cumulative; installing the latest monthly rollup will then get your PC completely up to date. This (like all updates) will have a unique KB number. Each month there will be separate updates released for a variety of reasons (e.g. DST time zone changes, out-of-band security fixes). Many of these will be rolled into the next monthly rollup, although some will remain separate- including Office, Flash and Silverlight updates. 1
Arthur Posted October 12, 2016 Posted October 12, 2016 If I have a machine that's already updated to September, I'd still prefer to have 12 separate updates per year, rather than download the same information 11 times prior - downloading/installing in order. It could mean the difference between installing a 50MB update and a 500MB update. From the link above. With WSUS, you can enable support for “express installation files” to ensure that client PCs only download the pieces of a particular monthly rollup that they haven’t already installed, to minimize the network impact. While express installation files can help greatly reduce the amount of content needed to patch each PC, it is still useful to implement peer-to-peer sharing technologies like BranchCache or Delivery Optimization to reduce the overall impact on the network by allowing PCs to obtain the updates they need from other PCs on the network that have already obtained them from WSUS or ConfigMgr. 3
Michael Posted October 12, 2016 Posted October 12, 2016 Thanks Arthur - here's where Express Installation Files is located (for everyone's reference): I've already deployed the October 2016 update, but will certainly look at this next month. Not entirely sure why this shouldn't be enabled by default? I see no disadvantage! 1
DavR Posted October 12, 2016 Posted October 12, 2016 Thanks Arthur - here's where Express Installation Files is located (for everyone's reference): [ATTACH=CONFIG]39186[/ATTACH] I've already deployed the October 2016 update, but will certainly look at this next month. Not entirely sure why this shouldn't be enabled by default? I see no disadvantage! Oooh, thanks for that, will have a look tomorrow. I guess it's because the express download files will take up more server space - as if WSUS doesn't take enough already!
john Posted October 13, 2016 Posted October 13, 2016 Oooh, thanks for that, will have a look tomorrow. I guess it's because the express download files will take up more server space - as if WSUS doesn't take enough already! Be warned that option, if you have a lot of MS systems will take up a HUGE volume of space, we used to have it on and our WSUS was heading for 3/4TB (we use a LOT of MS stuff that is patched via WSUS) so Edu won't be as bad. Another 2 tips, remember to run the clean up wizard every month to clean up and also search for and decline (then clean up) the Itanium patches (unless you are running them obviously!) that will save you a shed load of space.
DavR Posted October 13, 2016 Posted October 13, 2016 Be warned that option, if you have a lot of MS systems will take up a HUGE volume of space, we used to have it on and our WSUS was heading for 3/4TB (we use a LOT of MS stuff that is patched via WSUS) so Edu won't be as bad. Another 2 tips, remember to run the clean up wizard every month to clean up and also search for and decline (then clean up) the Itanium patches (unless you are running them obviously!) that will save you a shed load of space. Thanks for the warning @john! I've enabled it, but I'm only running Win7 and Server 2012 r2 at the mo, so hopefully it won't hit my storage too badly. I always expect Server Cleanup Wizard to give more back than it does - I've just run it for the first time in 6-12 months, and it's saved me all of 26MB!
john Posted October 13, 2016 Posted October 13, 2016 Thanks for the warning @john! I've enabled it, but I'm only running Win7 and Server 2012 r2 at the mo, so hopefully it won't hit my storage too badly. I always expect Server Cleanup Wizard to give more back than it does - I've just run it for the first time in 6-12 months, and it's saved me all of 26MB! It could be broken then, if its too long before its run it can be broken as we've had that as it times out running the SQL Commands behind the scenes - Cleaning a Stuck WSUS Server: Too Many Unapproved Updates gives some pointers and links but you basically need SQL Manager on the host, connect to the DB and then run the stored procedures in SQL itself and it won't time out as easily so thenit will run and run and run and then keep on top of it 1
gshaw Posted October 14, 2016 Posted October 14, 2016 Yup I had to do the same on my WSUS VMs, cleanup wizard got stuck and timed out so now I have the SQL queries on weekly schedule to keep things tidy. I used this one which also does some work on the WSUS DB indexes https://community.spiceworks.com/how_to/103094-automate-wsus-cleanup
DavR Posted October 19, 2016 Posted October 19, 2016 (edited) Thanks for the warning @john! I've enabled it, but I'm only running Win7 and Server 2012 r2 at the mo, so hopefully it won't hit my storage too badly. I always expect Server Cleanup Wizard to give more back than it does - I've just run it for the first time in 6-12 months, and it's saved me all of 26MB! So, just a for info on enabling Express Installation Files. I did this last week, and my WSUS storage usage has rocketed from 40GB to 100Gb, ie 2.5 fold. It might've been more, except it's now used all the space on that drive. On further reading, this setting can cause a 3 or 4 fold increase in WSUS content size. USE WITH EXTREME CAUTION! Edited October 19, 2016 by DavR
john Posted October 25, 2016 Posted October 25, 2016 So, just a for info on enabling Express Installation Files. I did this last week, and my WSUS storage usage has rocketed from 40GB to 100Gb, ie 2.5 fold. It might've been more, except it's now used all the space on that drive. On further reading, this setting can cause a 3 or 4 fold increase in WSUS content size. USE WITH EXTREME CAUTION! If you have a good and stable LAN and you are not really needing to send many updated over VPN, to remote sites wtihout local WSUS then that setting isn't that helpful as you wont be on a metered LAN Connection so if its a good one just leave it off and save the disk
DavR Posted October 25, 2016 Posted October 25, 2016 If you have a good and stable LAN and you are not really needing to send many updated over VPN, to remote sites wtihout local WSUS then that setting isn't that helpful as you wont be on a metered LAN Connection so if its a good one just leave it off and save the disk Yeah, I've reverted now, although it did mean deleting the content and running the WSUS reset command to download everything again. Live and learn!
gshaw Posted November 22, 2016 Posted November 22, 2016 Bit of a thread resurrection but how are people managing this in practice now? As it stands my Approval rules will be causing duplication with the Security Updates \ Rollups, anyone found an easy way to automatically choose one or the other? As an aside I could really do with a Cumulative Rollup for Windows 8.1 right now, 276 updates to get the machine on my desk up to date Before anyone says it yes 10 would probably be better but they're my digital signage machines and I'd need to rebuild everything onto Win10 LTSB to get them all to match, a project for another day I think
DavR Posted November 22, 2016 Posted November 22, 2016 By duplication, do you mean have both the "Security only" and the "Security and Feature" update rollup approved? I'm using auto-approval, so both are approved, but only the security and feature rollup has installed on machines. As far as I can tell, if you have both approved in WSUS, the full one supersedes the security only one. 1
gshaw Posted November 22, 2016 Posted November 22, 2016 Yeah that's the rule I have on as well, good if it does work like that in practice as the MS article seemed to suggest it could be luck of the draw depending on which tries to install first.
DavR Posted November 22, 2016 Posted November 22, 2016 Surely not, that would be chaos! I've just checked on my WSUS server, and November Security Only Quality Update (KB3197867) is definitely superseded by November Security Monthly Quality Rollup (KB3197868). If you read the description of KB3197867 there is a heading for "Updates superseding this update" where it lists the full feature KB3197868. I'm not sure what you have to do if you want to enforce the Security Only, whether there are approval rules for that or if you have to run manual approvals. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now