Bedders Posted November 17, 2017 Posted November 17, 2017 Hi all, First off - Yes I'm a bad person for still running old systems. Secondly, 2012 R2 rather than 2016 because we have licenses for it already. I'm working on deploying Windows 10 Pro x64 within our business (about 100 computers in all) and as part of this I'm separating out the roles on our oldest server running 2003 R2. It's currently a secondary Domain Controller (our primary is on 2008 R2 and a 2008 level forest), our print server (causing me no end of headaches!), our primary file server (including shared drives and staff work areas & profiles), and our WSUS server. Oh, and our only DHCP server, and primary DNS server (backup DNS also on the 2008 R2). This was apparently commissioned over a decade ago and was simply migrated from physical to virtual when we moved to Hyper-V. So I've created my new virtual 2012 R2 server, and will install the Print Server and WSUS roles. I am only planning on moving these for now as they will allow me to move ahead with my Windows 10 deployment before Christmas. Since I have never set up a WSUS server before, I thought it prudent to enquire with the fantastic knowledge and experience all of you wonderful people have - Are there any considerations I should be aware of when setting up a second WSUS server within the same environment (not one downstream of the first)? I'm only selecting 'Windows 10' on the new WSUS server. - We use Item Level Targeting in Group Policy to apply the WSUS settings (server, group etc.). Is it simply a case of creating a new GPO with the new server for the Windows 10 machines? - Has anyone come across any issues with Windows 10 and WSUS i.e. updates deploying, anything that needs to be blocked, etc? I guess most here will probably be using Windows 10 Edu rather than Pro. Many thanks everyone. I'm sorry for the amateur sounding questions, I'm trying to pre-empt anything I could **** up break.
Michael Posted November 17, 2017 Posted November 17, 2017 Given you're going to re-image all machines, I'd leave all existing devices pointing to your old WSUS instance and anything imaged to your new WSUS instance. Setting up WSUS is very easy - on 2012/2016 it's a built in role and all wizard based. Just select a volume with a healthy amount of space (100GB minimum). You can select just Windows 10 as an option, but there are loads to consider such as MS Office too. You can use Item Level Targeting, this hasn't changed one bit. In the context of Windows 10 there's Feature and Quality upgrades - I'd focus on Quality upgrades as a starting point. You also need to enable a range of GPOs to give you more control. You can view that here. 1
minimoo Posted November 17, 2017 Posted November 17, 2017 And as i just said in another post - probably worht seeing https://blogs.technet.microsoft.com/configurationmgr/2017/08/18/high-cpuhigh-memory-in-wsus-following-update-tuesdays/ regarding wsus settings. 1
Bedders Posted November 22, 2017 Author Posted November 22, 2017 Thanks for the advice @minimoo and @Michael, great stuff!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now