Jump to content

Recommended Posts

Posted

I'm not even seeing the November Security Only Quality Update in SCCM--only the Security Monthly Quality Rollup (and the Preview updates, which I'm ignoring; I don't trust MS updates at the moment, too many foul ups this year. I'll wait till full release, thanks).

 

I saw the October Security Only update, so no idea why I'm not seeing the November one.

Posted

These ones?

 

November, 2016 Security Monthly Quality Rollup for Windows 7 (KB3197868)

November, 2016 Preview of Monthly Quality Rollup for Windows 7 (KB3197869)

 

They're all there in SCCM for us, they seem to keep renaming them though as before it was Security Only as you said :p

 

Steve

Posted

I do wish they'd come up with a more intelligible naming convention..... Security Monthly Quarterly Rollup Rolldown Ruby Tuesday Quality Monthly Security Updates!!!

 

Seriously guys - Full update, or security only. That's all it is.

Posted
These ones?

November, 2016 Security Monthly Quality Rollup for Windows 7 (KB3197868)

November, 2016 Preview of Monthly Quality Rollup for Windows 7 (KB3197869)

They're all there in SCCM for us, they seem to keep renaming them though as before it was Security Only as you said :p

Steve

Yeah, I have those two, but I don't have the November 2016 Security Only Rollup (KB3197867) that @DaveAshworth listed above. 3197868 is the one that supersedes it, and I'm deploying that in lieu of 3197867, but I'd rather the former, as it's the smaller package to deploy. I'm not touching 3197869 as that's essentially "December 2016 but only half-baked and poorly tested". I'll wait until it's actually ready next month :)

Posted
Yeah, I have those two, but I don't have the November 2016 Security Only Rollup (KB3197867) that @DaveAshworth listed above. 3197868 is the one that supersedes it, and I'm deploying that in lieu of 3197867, but I'd rather the former, as it's the smaller package to deploy. I'm not touching 3197869 as that's essentially "December 2016 but only half-baked and poorly tested". I'll wait until it's actually ready next month :)

 

You can re-enable it if you turn off the auto-decline due to supercedence in your sync rules :p

 

Steve

Posted
You can re-enable it if you turn off the auto-decline due to supercedence in your sync rules :p

 

Steve

 

It's not that; All Software Updates still shows expired updates there (there's 3 or 4 for SCEP in any given day, after all). And it pulled through October's update. It's not being filtered out or not being ignored by the ADR; it's not showing it at all after syncing :confused:

Posted
It's not that; All Software Updates still shows expired updates there (there's 3 or 4 for SCEP in any given day, after all). And it pulled through October's update. It's not being filtered out or not being ignored by the ADR; it's not showing it at all after syncing :confused:

 

There's an auto cleanup built into SCCM that basis on it whether it's installed/assigned/required etc, as well as the top level sync one.

 

I bet you if you open WSUS console (as in real WSUS console) and look for the update its there :p It's only SCCM that's declining it

 

Steve

Posted

Whys are updates causing issues for people?

 

Mine are set to install at 3pm every day. if the computer is in use it won't restart, if it's not logged on it will restart.

 

As for the WSUS space, never had any issues. Network bandwidth - never known it to have any impact.

 

If there are big updates I just WOL the pcs and let them install over the weekend so staff don't get frustrated waiting.

Posted
Just progressively got worse here, for no reason it can take days before reporting (I've left PC's on checking for updates and it's took 3 days to report..) for no rhyme or reason - it all used to work perfectly.
Posted

Oh for f... so yes, under Administration > Site Configuration > Sites > [site server] > Configure Site Components > Software Update Point > Supersedence Rules, the Supersedence Behaviour ("immediately expire a superseded software update") does not act in the way it does elsewhere, which is to say that usually expired updates are simply marked as expired but still listed, and it's just one more field to search on. No, expired here means "I'll not bother getting it at all" :doh:

 

So having changed this setting that has not been any trouble whatsoever for 5 bloomin' years, including month 1 of this ridiculous new update scheme, I can now see both flavours of rollup. I'll leave this month's as is--gives me a baseline, I suppose--and go back to excluding "Quality Rollup" from my ADR for next month.

 

Whole thing is bloody ridiculous, especially off the back of a year of regularly broken updates. What were they thinking?

Posted
Whole thing is bloody ridiculous, especially off the back of a year of regularly broken updates. What were they thinking?

 

That's how it's always been :p If it's superseeded "and not assigned elsewhere" it gets tombstoned instantly and wiped off after 7 days.

 

The one you're talking about is expiring an active/assigned update within the deployment packages :D But as this update hasn't been deployed/assigned it gets hit before it even gets out.

 

Steve

  • 4 weeks later...
Posted

Update on this one that I've just seen in another thread - Microsoft have changed supersedence for December rollups - https://blogs.technet.microsoft.com/...ollup-updates/ (cheers @psydii for that).

 

It looks like Quality Rollup no longer supersedes Security Only, it only supersedes the previous Quality Rollup... I just checked on my workstations and they're now doubling up and installing both! (I have auto approve enabled for security updates)

 

Does anyone have any ideas for how to exclude Security Only from an automatic WSUS deployment? It's not the end of the world but it is stupid having such large updates duplicating.

  • 3 weeks later...
Posted

I don't get this update stuff.

 

As I look in the updates to install on my 2012r2 print server I see:

 

1. December, 2016 Security and Quality Rollup for .net etc etc etc#

2. December, 2016 Security Monthly Quality Rollup for Windows Server 2012 R2

3. December, 2016 Security Only Quality Update for Windows Server 2012 R2

 

There is also one for Flash and MSRT

 

Out of Numbers 2 and 3 - they sound the same. Do I assume that 2 has more updates in it than 3 (which is security only?)

 

Have I missed a message somewhere explaining all of this?

 

Any issues with December updates before I roll them out?

 

Cheers

 

Gareth

Posted
If it wants to put them all on, why not let it?

Bandwidth, install time, hard disk space, failure risks..... that and the fact doubling up is just plain unnecessary!

 

That being said, most of mine are currently installing both as there's no way to choose between full feature and security only updates via WSUS without manual intervention :/

Posted
Clear as mud - so which one do I put on? LOL

Gareth

@garethedmondson - that's something only you can choose I'm afraid!

 

Security Monthly Quality Rollup will give you ALL MS fixes for the month, security and feature, but take a bit longer.

 

Security Only Quality Update will just give you essential security fixes, but not feature and functionality fixes. Quicker and lighter.

Posted
Windows Update tends to offer you everything and then work selectively in terms of update dependency, obsolescence or incongruity the next time you check. I've often see it offer several security patches along with a cumulative security update that supersedes individual packages. Those packages are then reported as Failed but mysteriously don't reappear if you reboot and then check for updates again.
Posted
@garethedmondson - that's something only you can choose I'm afraid!

 

Security Monthly Quality Rollup will give you ALL MS fixes for the month, security and feature, but take a bit longer.

 

Security Only Quality Update will just give you essential security fixes, but not feature and functionality fixes. Quicker and lighter.

Although as per latest Microsoft changes / blog that I referenced, if you have previously only applied Security Quality updates if, or when you decide in the future to apply a future Security Monthly Quality Rollup the security elements are not updated (although the Rollup contains them). This (change) was introduced November. So for those computers, you would still have to (also) apply the Security Quality Updates for the security updates to apply.

 

:/

Posted

I have been following this but am still a bit confused, sorry.

 

So if until now I have been installing both Security Monthly Quality Rollup and the Security Only Quality Update, I can forget about the Security Only Quality Update, and from now on just install Security Monthly Quality Rollup.

 

Is that correct?

Posted
@garethedmondson - that's something only you can choose I'm afraid!

 

Security Monthly Quality Rollup will give you ALL MS fixes for the month, security and feature, but take a bit longer.

 

Security Only Quality Update will just give you essential security fixes, but not feature and functionality fixes. Quicker and lighter.

 

I don't think that's true--they contain the same patches, but the Monthly Quality Rollup also includes all the previous months' Security Only Quality updates. So if you install Oct, Nov and Dec Security Only, you have the same patches installed as if you installed the Dec Monthly Quality Rollup. (It doesn't help that the names are a jumble of buzzwords and almost impossibly to delineate mentally.)

 

I'm just deploying the security only each month, because that should result in a smaller footprint; deploying all the rollups would end up with a lot of server space taken up by obsolescent data. But arguably it'd be more efficient for the clients, who would only have to install the latest update. So I dunno which is the better strategy, long term.

Posted
I don't think that's true--they contain the same patches, but the Monthly Quality Rollup also includes all the previous months' Security Only Quality updates. So if you install Oct, Nov and Dec Security Only, you have the same patches installed as if you installed the Dec Monthly Quality Rollup. (It doesn't help that the names are a jumble of buzzwords and almost impossibly to delineate mentally.)

 

Apologies, yes, you're right there @sonofsanta. Monthly Quality Rollup is cumulative for all previous months, security is just that months.

 

Such a shame really, a wonderful opportunity to simplify Windows Updates, but ballsed up once again.

Posted
Such a shame really, a wonderful opportunity to simplify Windows Updates, but ballsed up once again.

 

Agreed there. Especially off the back of a year of crap updates, where something has been broken and there's been updates that have needed to be declined, I am not thrilled about rolling it all up so I either have to have all the fixes (including a broken one) or none of them at all. What a brilliant plan.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...