Jump to content

To use WSUS or Not  

26 members have voted

  1. 1. To use WSUS or Not

    • WSUS (2008 r2)
      2
    • WSUS (2012r2)
      15
    • WSUS (2016)
      7
    • No WSUS - Internet updates
      2
    • Other software
      0


Recommended Posts

Posted (edited)

Trying to set up WSUS on Server 2016 and its not finding any updates after 2015.... (wtf??)

 

So my question to you.

 

WSUS or Not?

 

(If other please post below what you using)

Edited by newpersn
Posted (edited)

WSUS, I know it can be buggy to setup.

 

With so many options when it comes to installing updates on Domain machines with GPO why bother with anything else.

 

Even though I have no WSUS at home I have the GPO setup so at least I can choose when the PC updates.

Edited by Davit2005
  • Thanks 1
Posted
WSUS lets us enforce deadlines for updates to ensure that they get applied and not perpetually postponed by end users. It also let's us turn that off when machines are being used for exams. I'm not sure that's possible without WSUS.
  • Thanks 1
Posted
Without WSUS, our internet connection would frequently max out (which happens to all of the schools on our WAN who don't use WSUS, which then affects us anyway).
  • Thanks 1
  • 2 weeks later...
Posted

How would you setup WSUS in virtual environment please? We have very limited amount of Windows 7 and 10 machines but when it comes to updates it drags the entire network down. We are already using Mac Caching server for iOS and Mac updates and I'd like to do the same for Windows. Will be using Windows server 2016 in virtual environment.

 

Any guidance will be highly appreciated.

 

Kindest regards

 

J.

Posted

Easy enough.

 

Install 2016 >domain join

Add wsus role.

Set path during install.

Once roll installed configure what products you need updates for (windows 7, 10 server 2012 etc....)

Let the server sync (will take up to an hour to sync depending on how much you selected)

 

Change your Group Poilcy windows update location to point at your new server.

 

(Posted via app)

  • Thanks 1
Posted
Forgot to add: once updates have sync you can approve updates to send to the computers to update. Once updates have been approved it will download the update to the sever.
Posted
Digging deeper you can create a test and production target group. This can be pushed out via group policy. Test new updates to the Test target group first then to the production target group. Make sure your servers only reboot at night.
Posted

I've just this week been building a new WSUS installation after the existing one completely broke on me.

 

On the first attempt at building a new WSUS server I made the mistake of approvaling all critical and security updates after the initial sync. It was then wanting to download 279GB of updates, which would have taken more than a month at the rate it was going.

 

I scrapped that and started again, this time only approving updates with a status of 'Needed' by clients. Only about 30GB of updates now needed to be downloaded, which it managed in about a day. I'm going to wait for 30 days or more and then run the cleanup wizard to decline all those unneeded updates, before going anywhere near automatic approval rules (which is the ultimate aim).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...