CyBeRkId2002 Posted May 19, 2017 Posted May 19, 2017 Morning all, We are currently investigating and fine tuning our server patching procedure. Due to a problematic server patch recently we have decided to hold off on patches until we can deploy and test adequately (ie. Holidays & Half-Terms). How does it work in your various schools? Do you allow servers to automatically download the latest updates and install as necessary, or have a more manual approach to it? Also, I have a question for anyone that runs SCCM. I am trying to get updates deployed instantly, with reboots held off until a scheduled maintenance window. I have setup an overnight maintenance window for the servers, deployed a Software Update Group to the servers and ticked to 'Allow Software Installation outside of Maintenance Window'. The patches install correctly and report back to SCCM that they are awaiting system reboot but the servers do not restart overnight as expected. Any idea's why this might be? For reboots to work correctly do they need to be run alongside the software installation (ie. during the maintenance window). Is there something else I am missing? I could remove the Maintenance Window all together and schedule reboots on servers out of hours if there is one pending, but would rather keep it all in SCCM if possible. Thanks, Michael
ITGURU Posted May 19, 2017 Posted May 19, 2017 All my servers are set to notify me of updates. Every half term I install the latest updates and reboot manually at evenings or weekends. That way I can check everything is still working OK once the server has rebooted, rather than letting it reboot overnight (when backups take place) and finding it failed or something stopped working the next morning.
CyBeRkId2002 Posted May 19, 2017 Author Posted May 19, 2017 thanks both... that's what we are looking to do. Cheers.
RobD Posted May 19, 2017 Posted May 19, 2017 We patch most of our servers (few hundred) using a similar method to this: WSUS – Auto Patching Servers | Tech Blog
jonnykewell1 Posted May 19, 2017 Posted May 19, 2017 I'm going through all my servers at the minute, We don't set them to automatically update just notify when updates are ready. All point back to our WSUS server via group policy. Looking at restarting a few over the weekend to bring them up to speed.
Julian Posted May 19, 2017 Posted May 19, 2017 My virtualised servers are set to automatically install, and if a reboot is required, then 3 am is when they should reboot. Updates get promptly installed, and users are not impacted by the server restart.
MrFrostmaul Posted May 19, 2017 Posted May 19, 2017 Auto install via WSUS, schedule install and reboot every Saturday at 3am if they need to.
3s-gtech Posted May 19, 2017 Posted May 19, 2017 I manually approve updates monthly, the servers are set to install them the following weekend then reboot. My Hyper-V hosts require full manual install and reboot, they get done less frequently (usually half termly). Clients check daily and install at 4pm, restarting themselves at 5pm.
dapaulio Posted May 21, 2017 Posted May 21, 2017 I manually approve and install update via wsus typically during the holiday. Always book 1 day maintenance of servers and network during each holiday. The only update that is auto approved are the defender/fronted protection updates.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now