Jump to content

Recommended Posts

Posted

I'm on the fence with this one -

 

Yes single Cumulative Updates are useful, but then each month it's getting progressively larger and takes more resources to deploy.

 

If I have a machine that's already updated to September, I'd still prefer to have 12 separate updates per year, rather than download the same information 11 times prior - downloading/installing in order. It could mean the difference between installing a 50MB update and a 500MB update.

Posted

Yes you have to uninstall the whole Cumulative Update, even though 95% could be OK, and was limited to a specific component.

 

Evidently Microsoft have published the September Update twice for build 1507, once for 1511 and three times for 1607. Definitely not ideal when we're talking about update files which are hundreds of Megabytes or more in size!

Posted
Given how often there have been problematic patches in the last 12 months alone, I am firmly against this. We'll end up missing security patches to avoid show stoppers like KB3170455 and its printer nonsense.
Posted (edited)

Dumb question, how does this work with WSUS if half the updates in the rollup are "Security" \ "Critical" and others are just "Updates"

 

Do we need to manually approve these as rollups now rather than just leaving the auto-approval rule for Security & Critical as we do at present?

 

Edit: seen this at the tail-end of one article:

 

Lastly, Microsoft says that it will also push a monthly "Security-only" update that will only contain security patches for that month. This will be released separately from Windows Update via WSUS, SCCM, and the Microsoft Update Catalog.

 

So presumably the important stuff will be in the auto-approved category and the other where we approve manually. Being cumulative I guess each rollup will supersede the previous version?

Edited by gshaw
Posted

Single update my bottom. Patch Tuesday is here, and I have six...

 

Windows Updates.jpg

 

I can see that Silverlight and Office would have separate updates, they're separate optional products. I'm trying to work out the difference between the FOUR different rollup packages it's given me.... good thing I'm only subscribed to critical and security, who knows how many "single" rollups I'd have ended up with.

Posted (edited)

Ok, so reading up a bit more here, there are security only updates and monthly rollup updates, which are this months updates only, and (eventually) cumulative update since last release version. To obfuscate the matter, they throw the words quality, security and rollup into the title of each one, in a different order.

 

Unfortunately, with my WSUS set to pick up critical and security updates, I get both, which is duplication. That's pretty dumb, especially considering one of these will eventually be MASSIVE.

Edited by DavR
Posted

@gshaw. The following link has more details.

 

More on Windows 7 and Windows 8.1 servicing changes

 

First, let’s review what we will release each month:

 

A security-only quality update

  • A single update containing all new security fixes for that month
  • This will be published only to Windows Server Update Services (WSUS), where it can be consumed by other tools like ConfigMgr, and the Windows Update Catalog, where it can be downloaded for use with other tools or processes. You won’t see this package offered to PCs that talk to Windows Update.
  • This will be published to WSUS using the “Security Updates” classification, with the severity set to the highest level of any of the security fixes included in the update.
  • This (like all updates) will have a unique KB number.
  • This security-only update will be released on Update Tuesday (commonly referred to as “Patch Tuesday”), the second Tuesday of the month. (This is also referred to as a “B week” update).

A security monthly quality rollup

  • A single update containing all new security fixes for that month (the same ones included in the security-only update released at the same time), as well as fixes from all previous monthly rollups. This can also be called the “monthly rollup.”
  • This will be published to Windows Update (where all consumer PCs will install it), WSUS, and the Windows Update Catalog. The initial monthly rollup released in October will only have new security updates from October, as well as the non-security updates from September.
  • This will be published to WSUS using the “Security Updates” classification. Since this monthly rollup will contain the same new security fixes as the security-only update, it will have the same severity as the security-only update for that month.
  • With WSUS, you can enable support for “express installation files” to ensure that client PCs only download the pieces of a particular monthly rollup that they haven’t already installed, to minimize the network impact.
  • This (like all updates) will have a unique KB number.
  • This monthly rollup will be released on Update Tuesday (also known as “Patch Tuesday), the second Tuesday of the month. (This is also referred to as a “B week” update).

A preview of the monthly quality rollup

  • An additional monthly rollup containing a preview of new non-security fixes that will be included in the next monthly rollup, as well as fixes from all previous monthly rollup. This can also be called the “preview rollup.”
  • This preview rollup will be released on the third Tuesday of the month (also referred to as the “C week”).
  • This will be published to WSUS using the “Updates” classification as an optional update. It will also be available via Windows Update (where all consumer PCs will install it) and on the Windows Update Catalog.
  • With WSUS, you can enable support for “express installation files” to ensure that client PCs only download the pieces of a particular monthly rollup that they haven’t already installed, to minimize the network impact.
  • Starting in early 2017 and continuing for several months, older fixes will also be added to the preview rollup, so it will eventually become fully cumulative; installing the latest monthly rollup will then get your PC completely up to date.
  • This (like all updates) will have a unique KB number.

Each month there will be separate updates released for a variety of reasons (e.g. DST time zone changes, out-of-band security fixes). Many of these will be rolled into the next monthly rollup, although some will remain separate- including Office, Flash and Silverlight updates.

 

100616_2357_1.png

  • Thanks 1
Posted
If I have a machine that's already updated to September, I'd still prefer to have 12 separate updates per year, rather than download the same information 11 times prior - downloading/installing in order. It could mean the difference between installing a 50MB update and a 500MB update.

From the link above.

 

With WSUS, you can enable support for “express installation files” to ensure that client PCs only download the pieces of a particular monthly rollup that they haven’t already installed, to minimize the network impact.

 

While express installation files can help greatly reduce the amount of content needed to patch each PC, it is still useful to implement peer-to-peer sharing technologies like BranchCache or Delivery Optimization to reduce the overall impact on the network by allowing PCs to obtain the updates they need from other PCs on the network that have already obtained them from WSUS or ConfigMgr.
  • Thanks 3
Posted

Thanks Arthur - here's where Express Installation Files is located (for everyone's reference):

 

Express.png

 

I've already deployed the October 2016 update, but will certainly look at this next month. Not entirely sure why this shouldn't be enabled by default? I see no disadvantage!

  • Thanks 1
Posted
Thanks Arthur - here's where Express Installation Files is located (for everyone's reference):

 

[ATTACH=CONFIG]39186[/ATTACH]

 

I've already deployed the October 2016 update, but will certainly look at this next month. Not entirely sure why this shouldn't be enabled by default? I see no disadvantage!

 

Oooh, thanks for that, will have a look tomorrow.

 

I guess it's because the express download files will take up more server space - as if WSUS doesn't take enough already!

Posted
Oooh, thanks for that, will have a look tomorrow.

 

I guess it's because the express download files will take up more server space - as if WSUS doesn't take enough already!

 

Be warned that option, if you have a lot of MS systems will take up a HUGE volume of space, we used to have it on and our WSUS was heading for 3/4TB (we use a LOT of MS stuff that is patched via WSUS) so Edu won't be as bad.

 

Another 2 tips, remember to run the clean up wizard every month to clean up and also search for and decline (then clean up) the Itanium patches (unless you are running them obviously!) that will save you a shed load of space.

Posted
Be warned that option, if you have a lot of MS systems will take up a HUGE volume of space, we used to have it on and our WSUS was heading for 3/4TB (we use a LOT of MS stuff that is patched via WSUS) so Edu won't be as bad.

 

Another 2 tips, remember to run the clean up wizard every month to clean up and also search for and decline (then clean up) the Itanium patches (unless you are running them obviously!) that will save you a shed load of space.

 

Thanks for the warning @john! I've enabled it, but I'm only running Win7 and Server 2012 r2 at the mo, so hopefully it won't hit my storage too badly.

 

I always expect Server Cleanup Wizard to give more back than it does - I've just run it for the first time in 6-12 months, and it's saved me all of 26MB!

Posted
Thanks for the warning @john! I've enabled it, but I'm only running Win7 and Server 2012 r2 at the mo, so hopefully it won't hit my storage too badly.

 

I always expect Server Cleanup Wizard to give more back than it does - I've just run it for the first time in 6-12 months, and it's saved me all of 26MB!

 

It could be broken then, if its too long before its run it can be broken as we've had that as it times out running the SQL Commands behind the scenes - Cleaning a Stuck WSUS Server: Too Many Unapproved Updates gives some pointers and links but you basically need SQL Manager on the host, connect to the DB and then run the stored procedures in SQL itself and it won't time out as easily so thenit will run and run and run and then keep on top of it

  • Thanks 1
Posted (edited)
Thanks for the warning @john! I've enabled it, but I'm only running Win7 and Server 2012 r2 at the mo, so hopefully it won't hit my storage too badly.

 

I always expect Server Cleanup Wizard to give more back than it does - I've just run it for the first time in 6-12 months, and it's saved me all of 26MB!

 

:doh: So, just a for info on enabling Express Installation Files.

 

I did this last week, and my WSUS storage usage has rocketed from 40GB to 100Gb, ie 2.5 fold. It might've been more, except it's now used all the space on that drive.

 

On further reading, this setting can cause a 3 or 4 fold increase in WSUS content size.

 

USE WITH EXTREME CAUTION!

Edited by DavR
Posted
:doh: So, just a for info on enabling Express Installation Files.

 

I did this last week, and my WSUS storage usage has rocketed from 40GB to 100Gb, ie 2.5 fold. It might've been more, except it's now used all the space on that drive.

 

On further reading, this setting can cause a 3 or 4 fold increase in WSUS content size.

 

USE WITH EXTREME CAUTION!

 

If you have a good and stable LAN and you are not really needing to send many updated over VPN, to remote sites wtihout local WSUS then that setting isn't that helpful as you wont be on a metered LAN Connection so if its a good one just leave it off and save the disk

Posted
If you have a good and stable LAN and you are not really needing to send many updated over VPN, to remote sites wtihout local WSUS then that setting isn't that helpful as you wont be on a metered LAN Connection so if its a good one just leave it off and save the disk

 

Yeah, I've reverted now, although it did mean deleting the content and running the WSUS reset command to download everything again.

 

Live and learn!

  • 4 weeks later...
Posted

Bit of a thread resurrection but how are people managing this in practice now? As it stands my Approval rules will be causing duplication with the Security Updates \ Rollups, anyone found an easy way to automatically choose one or the other?

 

As an aside I could really do with a Cumulative Rollup for Windows 8.1 right now, 276 updates to get the machine on my desk up to date :o Before anyone says it yes 10 would probably be better but they're my digital signage machines and I'd need to rebuild everything onto Win10 LTSB to get them all to match, a project for another day I think :p

Posted

By duplication, do you mean have both the "Security only" and the "Security and Feature" update rollup approved?

 

I'm using auto-approval, so both are approved, but only the security and feature rollup has installed on machines. As far as I can tell, if you have both approved in WSUS, the full one supersedes the security only one.

  • Thanks 1
Posted
Yeah that's the rule I have on as well, good if it does work like that in practice as the MS article seemed to suggest it could be luck of the draw depending on which tries to install first.
Posted

Surely not, that would be chaos!

 

I've just checked on my WSUS server, and November Security Only Quality Update (KB3197867) is definitely superseded by November Security Monthly Quality Rollup (KB3197868). If you read the description of KB3197867 there is a heading for "Updates superseding this update" where it lists the full feature KB3197868.

 

I'm not sure what you have to do if you want to enforce the Security Only, whether there are approval rules for that or if you have to run manual approvals.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...