Tefters Posted November 14, 2016 Posted November 14, 2016 So I recently deployed Win 10 1607 Edu x64 this summer via SCCM, nice and tidy image, fresh app installs up-to-date, couldn't be happier! Now comes the patching... I've been reluctant to setup patching til I have a decent strategy. Back in Windows 8.1 days I would simply every patch Tuesday -1 which worked out well and would set Office updates to go out weekly on Wednesdays, this is all done via SCCM APR's. Now running Windows 10 on my home and office machine I constantly see updates on my Shutdown and Restart option every week (which isn't a bad thing, patching is moving on and being more dynamic due to constant threats) however on both machines which are I7's with 8GB+ ram and decent Samsung Evo SSD's I face at least 1 patch a month which takes a good 20 minutes to apply on shutdown and then another 5 minutes to configure on start-up. These timings are rough but not far off the truth running on a nice beefy machine with decent SSD for IOPS. Now here's the big question - What the hell would these updates be like on a mechanical 7.2k rpm mechanical drive on I3 machines with 4GB of ram? I've just hit the sweet spot where Flash and Silverlight are fallen out of date so am going to push the latest KB's for those 2 tomorrow which I know are nice and small but i'm worried for 1. The back log of patches to be deployed and mainly 2. The state of patching moving forward. On desktop machines I can quite easily setup WOL on desktops (that support it) and configure SCCM to finally WOL when patching in order to patch out of hours fine... I had similar back in Windows 8.1 but without WOL and used 17:00 to 18:00 for patching before sending a shutdown script down to machines at 19:00. Laptops were always an issue though due to them being turned on for 30/40 minute spurts at a time possibly 3/4 times a day and in batches of 20+ in a room which didn't work out well against 1 AP, flooding the AP with traffic and the airways from the AP to the laptops therefore making patching on them a nightmare as they would never log on within a decent time and then spend their entire life corrupt due to people binning the lids closed while patches installed etc... I'm going to isolate laptops and manually get them out during half terms and then push updates to them when their wired in at an IT suite for a whole day or 2. How are people seeing / tackling the patches themselves? Whenever I build a custom image at the moment from the base 1607 ISO i'm seeing as of today a good 2 reboots full of patches for Windows and these are big downloads and then there's Office 2016! which is 1 whole reboot worth of patches but the downloads/installs are massive. I'm going to setup a test build with my image then package up all Windows 10 updates from build time til now that are needed and send them to the machine but I foresee a painful outcome. Another option I've thought of is to just run the Flash and Silverlight updates in and rebuild every summer with the latest ISO, custom build takes 2 days, 2 days to update all apps (which I do yearly anyway unless hand in forced for whatever reason) then rebuild all machines over the course of 2 weeks in between other tasks and lastly deploy SIMS where needed to machines. ------------------- After peoples true experiences patching Windows 10 at the moment, woes and successes. Thanks!
alfatec Posted November 15, 2016 Posted November 15, 2016 I run the Office updates as they come in. Cumulative updates every half term on everything. Use PDQ to deploy all Flash/Java/Silverlight/Adobe Reader/Chrome updates as they are updated. Stops the 'I am trying to shutdown the computer but it will not shutdown' from staff who then unplug it from the wall and crash it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now