DavR Posted September 14, 2017 Posted September 14, 2017 Over the summer I completed our Windows 10 update, and while it was a bit of a bumpy road to get there, it seems to be behaving and performing well. The only possibly snag that I'm worried about is Windows Updates, as we hit the September update cycle. I've just updated one laptop with this months update, and the install of updates took about 20 minutes, and the reboot to complete probably took another 20! Under Windows 7 I just let Windows Update get on with it and install patches at shutdown/reboot, but if we're talking these kind of times I might need to rethink. We have trolleys of laptops, I can't see class teachers being too pleased at having to wait that long to get a lesson started. What is the general consensus with Monthly Rollups on Windows 10? Are people letting them out and sucking up the delay caused, or are we holding off and doing manual patching during the holidays? I know some people have chosen LTSB to avoid this, but we wanted to have the full feature set and went for full Enterprise.
Michael Posted September 14, 2017 Posted September 14, 2017 You have two choices - Either deploy monthly Delta updates (for example): May, June, July, August, September - You couldn't do May, June, July, September. Alternatively deploy the full updates, so for example I deployed the full May 2017 update and recently the September 2017 update. If you read the notes, you can make a decision based on whether it's necessary to deploy an update or not. 1
mavhc Posted September 14, 2017 Posted September 14, 2017 Firstly why are they taking so long? Do you have SSDs? If not, get SSDs. Secondly why not schedule them to wake up and install at midnight, then reboot and go back to sleep?
DavR Posted September 14, 2017 Author Posted September 14, 2017 You have two choices - Either deploy monthly Delta updates (for example): May, June, July, August, September - You couldn't do May, June, July, September. Alternatively deploy the full updates, so for example I deployed the full May 2017 update and recently the September 2017 update. If you read the notes, you can make a decision based on whether it's necessary to deploy an update or not. Delta updates? Ok, that's a new one on me! So we went from batches of single updates monthly, to Cumulative Updates containing every update since release, back to single updates monthly (albeit rolled into one package). I do wish MS would make their minds up! Thank you for that though, I will need to read up on that. Looks like it only saves on the download rather than the install time though :/
DavR Posted September 14, 2017 Author Posted September 14, 2017 Firstly why are they taking so long? Do you have SSDs? If not, get SSDs. Secondly why not schedule them to wake up and install at midnight, then reboot and go back to sleep? Those weren't exact times, this was a laptop I set off updating and was chiefly concerned at the time it took on the reboot. It may not be representative, but there's certainly some delay here I may need to mitigate. Can you schedule a wakeup on laptops? I suppose you could, it's not something I've tried. Under Windows 7 I've always just let updates download and install at shutdown, which could cause a few minutes delay sometimes but otherwise worked well. I was rather hoping to get away with the same again for Windows 10, rather than having to configure out of hours maintenance windows or doing manual patching.
Michael Posted September 14, 2017 Posted September 14, 2017 Logically it should be faster - smaller download and consequently quicker install time. If there were no difference, they'd be no benefit. As I say, I don't see it necessary to deploy every update. I chose the September CU as it addresses a lot of vulnerabilities, including a zero day (included in the notes), but also the May CU update was of course 5 months ago, which is quite a long time in the context of IT.
mavhc Posted September 14, 2017 Posted September 14, 2017 I install every update as fast as possible, is there ever a month when there's not a critical security issue?
DavR Posted September 14, 2017 Author Posted September 14, 2017 @Michael is probably right, I doubt I need every update, but in all honesty I don't have time to review them. Updates are either on or off as far as I'm concerned, and to cover myself like @mavhc I want all the protection necessary! I'll have to time how long Windows Updates are currently taking on a test machine, and see if delta updates can improve on it any. As this is a new setup, I'm not entirely sure how Windows Updates are behaving under 10. As I say, my main worry is users being faced with a 10-20 minute startup because it's first boot after updates....
DavR Posted September 15, 2017 Author Posted September 15, 2017 I did a bit of testing on a my spare PC this afternoon. Full cumulative update installs from WSUS in the background quietly, which is good, but does then take 7 minutes on shutdown, and 6 minutes to start back up again. So not as bad as I'd worried, but in terms of switch-on usability still a bit naff. This is on a decent spec machine, though not SSD, so I will have some faster and plenty slower. Gonna have a bash with the Delta update on Monday, on the same machine for reference, hopefully it can do better than that.
DavR Posted September 18, 2017 Author Posted September 18, 2017 Update: so ignore my above comment on times in testing, that was for Sept CU from scratch, rather than just as an update. Starting with a base level of August CU, I installed the Sept CU and the Sept Delta update separately, and both had a reboot time of about 8 minutes. As WSUS installs updates in the background, it is mainly the shutdown or startup delays that concern me, as that's the actual disruption. The delta upgrades would be faster in terms of file copying and may install faster, but aren't cutting out the above delays, which would seem to be unavoidable. I guess I'll just stick with full CUs for now (these arrive in my WSUS and are approved automatically, the deltas I'd need to intervene) and see if anyone complains. As an aside, while reading up I found this article which states that the delta upgrades are an interim measure for 1607 and 1703 only, and won't be released for 1709. It looks like MS recommended best practice from this point forward is to use Express Update Files, which expand the files on the WSUS server, allowing delta updates on machines that way. The storage requirements for that though are phenomenal!
free780 Posted September 18, 2017 Posted September 18, 2017 I think this is why they want to use branch cache and WUDO.
Michael Posted September 19, 2017 Posted September 19, 2017 Express downloads still have full and delta (equivalent). I can't really understand the difference at this point.
DavR Posted September 19, 2017 Author Posted September 19, 2017 I think the logic behind having both is that anything more than a month out of date gets the full CU, but the more up to date ones just get delta patches. You're right though, it's really quite difficult keeping up with this. Anyone would think MS were making this up as they go along....
Squelch Posted September 20, 2017 Posted September 20, 2017 Our laptops wake for the 2am scheduled maintenance and I've set updates to install during that period. Those laptops that anyone bothered to plug in when they finished using them generally wake up and install the updates, I also schedule a wake up just before 7am and then a reboot at 7am to try and make sure everything has installed and if there are 20 minute reboot times they should happen then instead of when an impatient student is trying to login. It's not perfect, as any member of staff would tell you, but it's the best I can do.
DavR Posted September 20, 2017 Author Posted September 20, 2017 Sounds like overnight might be the way to go if the update reboots get in the way. What mechanism are you using to do these wakeups for update, WoL or something in Windows Update itself? I saw some wake up options in group policy, but they were all talking about wake from sleep or hibernate, we've disabled these and use proper shutdowns.
Squelch Posted September 20, 2017 Posted September 20, 2017 (edited) If anyone shuts down a laptop it will not wake up and nothing happens until someone switches it back on. Via GPO I've enabled wake timers, then with another GPO I've scheduled the wake/reboot times. It generally works well once you've drummed it into everyone to just sign out and not shutdown. The laptops go to sleep after a period of non use, I don't have hibernation enabled. Edited September 20, 2017 by Squelch
DavR Posted September 20, 2017 Author Posted September 20, 2017 Why disable hibernate and sleep? Why enable them? These are multi-user devices, they should be shut down properly after each use, not just close the lid and hibernate, saving the previous users session. I've always found the sleep function a hindrance in an enterprise environment, you sacrifice a bit of performance for faster startup. But that's a whole other thread.
DavR Posted September 20, 2017 Author Posted September 20, 2017 If anyone shuts down a laptop it will not wake up and nothing happens until someone switches it back on. Via GPO I've enabled wake timers, then with another GPO I've scheduled the wake/reboot times. It generally works well once you've drummed it into everyone to just sign out and not shutdown. The laptops go to sleep after a period of non use, I don't have hibernation enabled. Ah ok, so you're using sleep and those wake and install updates functions. Something to think about for future in our case as that's not our current power policy. Presumably you could replace shutdown with sleep on the start menu to push users towards sleep instead of shutdown? I'm sure I saw a policy along those lines somewhere.
Squelch Posted September 20, 2017 Posted September 20, 2017 Yes I think you are correct, it's on my list of things to do. Regarding power usage, yes to shutdown everything would use minimal power but then users get interrupted and hassled by updates which results in more frustrated pupils and staff. It's all a balancing act isn't it?
atcoates Posted September 20, 2017 Posted September 20, 2017 Years a go I would have left servers with pending updates for a few days or weeks! Now I'm always rebooting at the earliest opportunity and we mostly schedule reboots in the middle of the night or weekends etc. Same with PCs if we have staff that have pending updates but never log off their computer they'll receive a message from me. If they ignore I'll force a reboot on the machine.
DavR Posted September 20, 2017 Author Posted September 20, 2017 @atcoates, gone are the days when Anti Virus was all you needed to protect you from nasties eh! Not that it ever did a particularly good job. It's an ever more paranoid area since WannaCry. @Squelch, yes it is all a balancing act. Gone are the days when Windows Updates could just happen in the background it seems, they're now so big and frequent they need their own schedule. Thanks for sharing your solution!
Squelch Posted September 20, 2017 Posted September 20, 2017 I wouldn't call in a solution exactly, more of a fudge to try and get around Microsoft's fudge of windows updates
atcoates Posted September 20, 2017 Posted September 20, 2017 @DaveAshworth yes I remember those days...with fondness!
mavhc Posted September 20, 2017 Posted September 20, 2017 Of course on Windows 10 Shutdown = log everyone off and hibernate. But for people not logging off, a reboot at 3am can fix that, or something like https://github.com/lcoulet/windows_AutoLogoff
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now