Jump to content

Recommended Posts

Posted

I've just trashed and recreated my WSUS Server as the WsusContent folder was getting out of control! (Over 350 GB)

 

The reinstall has gone well, but I want to get my automatic approvals as tight as possible.

 

Can anyone share their setups?

Posted

There should be no automatic approvals, other than Windows Defender identity updates.

 

These smalls steps can help avoid issues when Microsoft inadvertently release a problematic update.

Posted
There should be no automatic approvals, other than Windows Defender identity updates.

 

These smalls steps can help avoid issues when Microsoft inadvertently release a problematic update.

 

So you then manually approve every update at some later point in time?

Posted

Automatic Approval for Critical Updates, Security Updates, Definition Updates

 

With the constant churn of security issues I remember reading guidance (possibly from MS themselves) to patch asap.

 

Also need to look at a reset of the WSUS cache soon as it's hit the same 350GB from years of XP updates, Office 2010 etc. no longer in use but eating up space. At some point will run wsusutil.exe reset and let it repopulate with the legacy items unticked.

Posted
So you then manually approve every update at some later point in time?

 

Correct - puts you in full control, plus you don't necessarily need or require every update.

 

You also have to consider you should have some managed firewall in your environment which reduces the surface area of attack, compared to a PC at home which is just behind a router. This generally buys you more time anyway, plus there's very few occasions I deploy an update immediately after it's released.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...