Jump to content

Recommended Posts

Posted

We have WSUS and SCCM installed on the same server, both of which were installed by a third party contractor at the same time when we upgraded our server infrastructure. The reason we were told why WSUS was used to manage updates, despite the fact that SCCM can manage updates, was because apparently SCCM's update management was problematic. I have recently updated SCCM to 1610 in order to effectively test, deploy and manage Windows 10 and Server 2016. I'm now wondering if it is worth switching to SCCM's update management now?

 

1) Has SCCM's update management improved and worth using instead of WSUS, or is worth sticking with just WSUS?

2) If I'm to use SCCM, how do I switch from WSUS if its located on the same server?

3) For those using SCCM, what are your experiences compared to using WSUS?

 

Are there any other considerations I need to make?

Posted

WSUS is required for SCCM, SCCM talks to WSUS for you.

SCCM gives you the ability to schedule updates and set deadlines

WSUS would just download and install after approval.

Sometimes computers would just reboot, SCCM has maintenance windows.

If WSUS and SCCM are on the same server you should be able to stop approving updates in WSUS and just downloading them in SCCM.

depending on what you contractor did you may need to remove readd or reconfigure the software update point in SCCM.

Do you have recent updates listed in SCCM?

  • Thanks 2
Posted (edited)
WSUS is required for SCCM, SCCM talks to WSUS for you.

SCCM gives you the ability to schedule updates and set deadlines

WSUS would just download and install after approval.

Sometimes computers would just reboot, SCCM has maintenance windows.

If WSUS and SCCM are on the same server you should be able to stop approving updates in WSUS and just downloading them in SCCM.

depending on what you contractor did you may need to remove readd or reconfigure the software update point in SCCM.

Do you have recent updates listed in SCCM?

Cheers for the info. I can see all the recent updates listed in SCCM, for all the products that we need. However despite having no issues with WSUS, the updates in SCCM are showing as not downloaded, despite they should have been by WSUS prior to me enabling it in SCCM. Is this normal?

 

I have followed this guide: https://4sysops.com/archives/unifying-sccm-and-wsus-part-2-baselines-and-automatic-deployment-rules/

However, if my WSUS was configured to download updates to the F:\ drive and SCCM is also downloading the updates, but to the distribution point on E:\ drive...does that mean I'm going to have both WSUS and SCCM downloading updates, so I'm duplicating the data/download?

Edited by CHiLL
Posted

I use SCCM for updates. It was all set up before I got here so I'm unsure as to how they both integrate and don't know much on WSUS since I don't use it. I've had a few issues with SCCM but they're more errors made by myself or my predecessor, things such as updates installing during the day or showing that updates need to be installed, but that's down to how they've been scheduled and is an easy fix.

 

I download the updates through SCCM from the internet, but you can point to a location on your network if WSUS has already downloaded them. If you have created a custom search to search all the updates (eg just search for relevant updates to your network), when you highlight them all, right click > Download > Select deployment package > Download location. Here you have the option to download from the internet or a location on your network.

 

For us, SCCM is the main management tool for software, updates, Endpoint protection. If you use SCCM often, it makes sense to just use the updates in their rather than using another tool to do the same job.

 

Only thing I don't trust it for is updating Servers. Mainly because as we all know updates can cause issues. So I do these manually through windows update so I can keep an eye on them and make sure the server doesn't hang after/before a reboot and it's left sitting their for a day/night before we realise. It's time consuming, but I've had an important server hang after installing updates from SCCM (installing them in the middle of the night seems like a good idea until this happens and you get in to tons of missed calls because the server didn't reboot correctly).

 

- - - Updated - - -

 

I use SCCM for updates. It was all set up before I got here so I'm unsure as to how they both integrate and don't know much on WSUS since I don't use it. I've had a few issues with SCCM but they're more errors made by myself or my predecessor, things such as updates installing during the day or showing that updates need to be installed, but that's down to how they've been scheduled and is an easy fix.

 

I download the updates through SCCM from the internet, but you can point to a location on your network if WSUS has already downloaded them. If you have created a custom search to search all the updates (eg just search for relevant updates to your network), when you highlight them all, right click > Download > Select deployment package > Download location. Here you have the option to download from the internet or a location on your network.

 

For us, SCCM is the main management tool for software, updates, Endpoint protection. If you use SCCM often, it makes sense to just use the updates in their rather than using another tool to do the same job.

 

Only thing I don't trust it for is updating Servers. Mainly because as we all know updates can cause issues. So I do these manually through windows update so I can keep an eye on them and make sure the server doesn't hang after/before a reboot and it's left sitting their for a day/night before we realise. It's time consuming, but I've had an important server hang after installing updates from SCCM (installing them in the middle of the night seems like a good idea until this happens and you get in to tons of missed calls because the server didn't reboot correctly).

Posted

If you have WSUS automatically downloading and approving updates you will want to stop that.

That article talks about ADRs which does everything for you once you set the rules. You may want to do it manually a few times to understand what is happening and it gives greater control. I have an ADR for the daily definitions, but do the monthly stuff by hand.

 

You have 3 groups to consider

Update packages are where you will download the updates to, I just create a new one every year so they don't get too large.

Software update groups, I have 3+ These are where you add updates to be deployed to the clients. I have one for definitions, one for the current month and one for each year.

Everything in the years deployment is set to install and reboot if needed, updates in the current month get a 2 week deadline and do not force a reboot. However the next month I move those updates to the year group. This gives the users a month to six weeks before updates force a reboot on them.

Collections are what you deploy the updates to, collections can be either devices or users, but for updates we want devices. You can deploy to workstations with different settings then servers.

 

You can create searches and save them, so software updates required equal to or greater then one and not expired and not superseded and not deployed are all the updates needed by your clients.

 

So the monthly process is this;

Run your saved needed updates search

Select all, right click and download

Go through the wizard and select or create this years updates package, and I download them from the internet.

Select the updates you want to deploy, right click and either choose create software update group or edit membership, depending on if you have already created the current months update group.

Once you have added the updates you want to the group, go to the software update groups right click and deploy to a collection, setting deadlines as desired.

 

I prefer to do it by hand so I can pick and choose if there is a bad update that month, but with the monthly roll ups I may got back to ADRs.

 

I feel I've wrote you a mini novel so I hope its not too confusing.

Posted
One of the warnings during the setup of sccm software updates is to install *but not configure* wsus on your server. Therefore I think a prudent course of action would be to remove the sccm software update role and the wsus role, so hopefully you are starting fresh, then add the wsus role and then the sccm software update role and configure sccm from there.
Posted

Thanks for the updates so far!

 

If you have WSUS automatically downloading and approving updates you will want to stop that.

That article talks about ADRs which does everything for you once you set the rules. You may want to do it manually a few times to understand what is happening and it gives greater control. I have an ADR for the daily definitions, but do the monthly stuff by hand.

 

You have 3 groups to consider

Update packages are where you will download the updates to, I just create a new one every year so they don't get too large.

Software update groups, I have 3+ These are where you add updates to be deployed to the clients. I have one for definitions, one for the current month and one for each year.

Everything in the years deployment is set to install and reboot if needed, updates in the current month get a 2 week deadline and do not force a reboot. However the next month I move those updates to the year group. This gives the users a month to six weeks before updates force a reboot on them.

Collections are what you deploy the updates to, collections can be either devices or users, but for updates we want devices. You can deploy to workstations with different settings then servers.

 

You can create searches and save them, so software updates required equal to or greater then one and not expired and not superseded and not deployed are all the updates needed by your clients.

 

So the monthly process is this;

Run your saved needed updates search

Select all, right click and download

Go through the wizard and select or create this years updates package, and I download them from the internet.

Select the updates you want to deploy, right click and either choose create software update group or edit membership, depending on if you have already created the current months update group.

Once you have added the updates you want to the group, go to the software update groups right click and deploy to a collection, setting deadlines as desired.

 

I prefer to do it by hand so I can pick and choose if there is a bad update that month, but with the monthly roll ups I may got back to ADRs.

 

I feel I've wrote you a mini novel so I hope its not too confusing.

This is what I've gathered so far, it's just implementing that.

 

So far, I've:

Disabled automatic downloads in WSUS

Created Software Update Groups for each of my products to include; Expired - No, Superceeded - No, Product - Windows 8.1, Update Classification - Critical, OR Update Classification - Security.

Created a deployment to test groups for each product and downloaded the updates into specifically named folders on a shared folder on one of the drives available on the SCCM server.

Created an ADR for monthly update checks to merge them into the existing package.

Enabled Software Updates within the SCCM client.

 

Testing so far has been successful.

 

Question: When the ADR triggers and the package is updated - does that updated package automatically send the updates to the client, or do I have to manually deploy the package again?

Posted
Here are the GP settings you need for clients to use the sccm update point: https://technet.microsoft.com/en-us/library/gg712312.aspx#BKMK_AssociatedSettings

 

( I would remove the old one and create a new one with those settings above).

From what I can tell from that article, I need to enable the following in Computer Configuration > Policies > Administrative Policies > Windows Components > Windows Updates:

1) Allow signed updates from an internet Microsoft update service location > Enabled

2) Automatic Updates detection frequency > Enabled and set to custom interval

3) Specify intranet Microsoft update service location > Enabled and define the server in both boxes (http://sccm:8530)

 

When it mentions about Self Update, I'm not sure what that is on about or if it is referring to a specific setting.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...