arh1a Posted January 9, 2017 Posted January 9, 2017 So just to confirm is it ok to tick the box Download express installation files in WSUS? We have plenty of hard drive space and run only one OS onsite (Windows 10.0.14393). I like the sound of the updates getting download/installed quicker on the clients.
DavR Posted January 9, 2017 Posted January 9, 2017 So just to confirm is it ok to tick the box Download express installation files in WSUS? We have plenty of hard drive space and run only one OS onsite (Windows 10.0.14393). I like the sound of the updates getting download/installed quicker on the clients. Be sure you mean it when you say plenty of disk space - even with just one OS you could be looking at several hundred GB. I maxed out a 100GB partition doing that for Windows 7 and had to go back... 1
arh1a Posted January 9, 2017 Posted January 9, 2017 Be sure you mean it when you say plenty of disk space - even with just one OS you could be looking at several hundred GB. I maxed out a 100GB partition doing that for Windows 7 and had to go back... Thank you I will bear that in mind. I have 400GB available to WSUS so hopefully that will be enough.
Arthur Posted January 9, 2017 Posted January 9, 2017 So just to confirm is it ok to tick the box Download express installation files in WSUS? We have plenty of hard drive space and run only one OS onsite (Windows 10.0.14393). Yes, although they are six times the size of the non-express files. 1
arh1a Posted January 10, 2017 Posted January 10, 2017 (edited) Yes, although they are six times the size of the non-express files. It definitely seem that way, the WSUS folder has grown from 12.9GB to 41.7GB Worth it in my eyes for the quicker download/install of updates to clients. Edited January 10, 2017 by arh1a
arh1a Posted January 11, 2017 Posted January 11, 2017 (edited) It definitely seem that way, the WSUS folder has grown from 12.9GB to 41.7GB Worth it in my eyes for the quicker download/install of updates to clients. Must be still growing as its on 69.1GB today! Worth running Server Cleanup Wizard regularly though as just ran it and its back down to 42GB. I also decline superseded updates manually which might help abit. Edited January 11, 2017 by arh1a Update
arh1a Posted January 12, 2017 Posted January 12, 2017 Not sure if I'm missing something like maybe I should be manually declining Cumulative updates now but WSUS is showing up an error trying to install Cumulative Update KB3213986? All other updates are still applying no problemm
Arthur Posted January 15, 2017 Posted January 15, 2017 Latest, revised changes (again!) are detailed here: https://blogs.technet.microsoft.com/configmgrdogs/2016/12/07/update-to-supersedence-behaviour-for-security-only-and-security-monthly-quality-rollup-updates/ New blog post detailing latest changes... Simplified servicing for Windows 7 and Windows 8.1: the latest improvements For the last four months this new servicing approach has provided customers on Windows 7, Windows 8.1, Windows Server 2008, Windows Server 2012 and Windows Server 2012 with a consistent model for staying current and secure. When there have been new fixes, a Monthly Rollup and a Security Only update have been released on Update Tuesday, and a Preview Rollup on the following Tuesday*. In this time, we have also been listening to you, our customers, for opportunities to fine tune the model and further simplify the update deployment scenarios. We are happy to announce the following changes: Deploying both the Security Only update and Monthly Rollup Both the Monthly Rollups and Security Only updates are available on WSUS and the Microsoft Update Catalog, and both are published with the “Security updates” classification, enabling enterprise customers using WSUS or other update management tools to sync and deploy both updates, depending on their settings. To further simply installation and deployment in this scenario, the servicing model was updated in December 2016 to better handle the Security Only update installation applicability. As of December 2016, a Security Only update will not be offered on a PC where a Monthly Rollup (from the same or later month) is already installed. This is accomplished through an applicability definition on the Security Only update, which checks for the installation of a Monthly Rollup (from the same or later month) to determine if it applicable on the PC. For example, if a PC attempts to install the February 2017 Security Only update, and the February 2017 (or later) Monthly Rollup is already installed, the Windows Update client will now report the Security Only update as not applicable. In addition to simplifying the installation scenario, tools that leverage such applicability for deployment reporting would see the Security Only update as not needed on the PC. Additionally, as of December 2016, Security Only updates from earlier months (October and November 2016) were revised to leverage this applicability check, so it now applies to all Security Only updates released in the new servicing model. Finally, this applicability definition also checks for the installation of a Preview Rollup from the same or later month, which also includes the security fixes for that month. See our earlier servicing model post for more information on update strategy choices and expected behaviors when deploying both updates. Reducing the package size of the Security Only update The Security Only update contains new security fixes for the Windows operating system, which includes Internet Explorer. Before October 2016, updates for the latest supported version of Internet Explorer (IE11 for Windows 7 SP1, Windows 8.1, Windows Server 2008 R2 and Windows Server 2012 R2; IE10 for Windows Server 2012) were provided in a separate monthly update. From October 2016 to January 2017 we included any Internet Explorer fixes for that month in the Security Only update to allow you to also remain secure for the latest supported Internet Explorer version for your operating system, all by installing the single Security Only update. This inclusion enabled a simplified update installation process, though the Internet Explorer updates constituted a significant percentage of the total Security Only update package size. Given that package size is one of the primary reasons some enterprise customers choose to leverage the Security Only update (to optimize for smaller download in limited bandwidth scenarios), these customers have requested increased flexibility for deploying the Security Only updates for Windows independently of the fixes for Internet Explorer. Starting with February 2017, the Security Only update will not include updates for Internet Explorer, and the Internet Explorer update will again be available as a separate update for the operating systems listed above. With this separation, the Security Only update package size will be significantly reduced, but you will need to deploy and install the Internet Explorer update to remain secure for the latest supported version of the browser. [Note that the Internet Explorer update will not install or upgrade to the latest supported version of Internet Explorer if not already present.] The Monthly Rollup will continue to include updates for Internet Explorer, as a single additive update that provides all security and reliability fixes since the beginning of the new servicing model in October 2016. Users of the Monthly Rollup will not need to install the separate Internet Explorer update. To simplify installation for Monthly Rollup users, the new Internet Explorer update will leverage the same installation applicability definition as the Security Only update (explained above), meaning that it will not install on a PC that has already installed the Monthly Rollup (or Preview Rollup) from the same or later month. The following table highlights the inclusion and applicability for these updates. 2
sonofsanta Posted January 16, 2017 Posted January 16, 2017 /looks back at repeated blog posts from Microsoft discussing changes, and changes to changes, and changes to changes to changes /looks at "simplified" in all the titles 3
DavR Posted January 16, 2017 Posted January 16, 2017 (edited) I'm not going down the Security Only route myself, but that just sounds like another unnecessary complication. Are there that many people out there who have stripped IE out of their Windows builds to justify changing the update mechanism (again) for everyone else? And they still haven't made the ONE common sense change that this method needs - make Monthly Quality and Security Only rollups different classifications in WSUS, to allow sys admins who use auto approvals a simple method of choosing which route to approve! Edited January 16, 2017 by DavR
arh1a Posted January 17, 2017 Posted January 17, 2017 Not sure if I'm missing something like maybe I should be manually declining Cumulative updates now but WSUS is showing up an error trying to install Cumulative Update KB3213986? All other updates are still applying no problem Anyone know why the above is happening? Its the same in two different sites and all I have done is enable Download express installation files in WSUS. All other updates are installing now problem.
arh1a Posted January 17, 2017 Posted January 17, 2017 Not sure if I'm missing something like maybe I should be manually declining Cumulative updates now but WSUS is showing up an error trying to install Cumulative Update KB3213986? All other updates are still applying no problem Anyone know why the above is happening? Its the same in two different sites and all I have done is enable Download express installation files in WSUS. All other updates are installing now problem.
Zourous Posted January 25, 2017 Posted January 25, 2017 Originally Posted by arh1a Not sure if I'm missing something like maybe I should be manually declining Cumulative updates now but WSUS is showing up an error trying to install Cumulative Update KB3213986? All other updates are still applying no problem We've got the same on our main student image. Update will just not install whatever you do. The event log shows error 0x800f0922 after the failure. I've tried all the usual fixes like the one's mentioned below: If you have error 0x800f0922, this is an ongoing systemic issue that has affected numerous people since at least October. Microsoft has offered nothing but the same solutions that don't work. Never been an Insider, which everyone seems to think causes this problem, and it is a new laptop that came with Win10AE. Any solution people offer will involve something along the lines: restart service, troubleshooter, delete folders, install manually, sfc /scannow, DISM, wumt, upload your data to MSFT, etc, etc. NOTHING WORKS. They just keep suggesting the same fixes for every cumulative update, but ignore the fact the entire process is broken. I've gone through all these things at least 5 times and am still unable to install the last 5 cumulative updates. The only thing to do is disable updates entirely or use WUMT to hide all the cumulative updates. For the moment, it doesn't look good. My laptop (separate build) has taken it, but not our student laptops. Apparently a new ISO will be on VLSC tomorrow with this update included, but of course that will require installing everything again from scratch.
gshaw Posted May 2, 2017 Posted May 2, 2017 (edited) Just noticed a couple of our machines haven't checked for updates in some time and are showing in WSUS with failures on some of the Rollup Updates e.g. KB3197868 (apparently pulled and reissued due to bugs). Has anyone else had similar and how are you fixing up these failed machines, we've got 2500+ endpoints here and cleaning up the mess manually each time a poor quality rollup fails doesn't sound much fun Edited May 2, 2017 by gshaw
DavR Posted May 2, 2017 Posted May 2, 2017 Just noticed a couple of our machines haven't checked for updates in some time and are showing in WSUS with failures on some of the Rollup Updates e.g. KB3197868 (apparently pulled and reissued due to bugs). Has anyone else had similar and how are you fixing up these failed machines, we've got 2500+ endpoints here and cleaning up the mess manually each time a poor quality rollup fails doesn't sound much fun I'm not sure there really is a way to manage this en masse tbh. At the moment, I'm wait until WSUS reports a machine as being below 95% compliant and then intervening manually. The biggest problem I'm seeing is with the older laptops, as the rollups take so long on them that people don't bother.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now