Jump to content

Recommended Posts

Posted

Morning all,

 

We are currently investigating and fine tuning our server patching procedure. Due to a problematic server patch recently we have decided to hold off on patches until we can deploy and test adequately (ie. Holidays & Half-Terms). How does it work in your various schools? Do you allow servers to automatically download the latest updates and install as necessary, or have a more manual approach to it?

 

Also, I have a question for anyone that runs SCCM. I am trying to get updates deployed instantly, with reboots held off until a scheduled maintenance window. I have setup an overnight maintenance window for the servers, deployed a Software Update Group to the servers and ticked to 'Allow Software Installation outside of Maintenance Window'. The patches install correctly and report back to SCCM that they are awaiting system reboot but the servers do not restart overnight as expected. Any idea's why this might be? For reboots to work correctly do they need to be run alongside the software installation (ie. during the maintenance window). Is there something else I am missing? I could remove the Maintenance Window all together and schedule reboots on servers out of hours if there is one pending, but would rather keep it all in SCCM if possible.

 

Thanks,

Michael

Posted
All my servers are set to notify me of updates. Every half term I install the latest updates and reboot manually at evenings or weekends. That way I can check everything is still working OK once the server has rebooted, rather than letting it reboot overnight (when backups take place) and finding it failed or something stopped working the next morning.
Posted
I'm going through all my servers at the minute, We don't set them to automatically update just notify when updates are ready. All point back to our WSUS server via group policy. Looking at restarting a few over the weekend to bring them up to speed.
Posted
My virtualised servers are set to automatically install, and if a reboot is required, then 3 am is when they should reboot. Updates get promptly installed, and users are not impacted by the server restart.
Posted
I manually approve updates monthly, the servers are set to install them the following weekend then reboot. My Hyper-V hosts require full manual install and reboot, they get done less frequently (usually half termly). Clients check daily and install at 4pm, restarting themselves at 5pm.
Posted
I manually approve and install update via wsus typically during the holiday. Always book 1 day maintenance of servers and network during each holiday. The only update that is auto approved are the defender/fronted protection updates.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...