Koldov Posted April 25, 2019 Posted April 25, 2019 Looking through my WSUS server today after the holidays just to make sure everyone is up to date and being quite pleased that everyone is at 99% or 100% with just a couple needing to be reminded to reboot and finish the updates installation. Then I have a returned laptop which I am repurposing, so took it off the Domain and removed from the WSUS server etc... I just thought I would check for updates and suddenly loads started coming through (this laptop was supposedly at 100% according to WSUS). These are the updates that it needed: The drivers are understandable (I don't have that enabled), the ones like Silverlight I'm not sure if I have the classifications right for those, but the other Cumulative/Malicious Software Removal/Servicing Stack/Security Update for Adobe Flash ones...? Taking just one of the updates and searching through WSUS, it appears that although it is aware of the update and the approval is for 'Install', the status is 'Not Applicable'.... Strange as when a computer is taken off the Domain, it suddenly appears as though it IS applicable! But going through the others: KB4346087 - Not on WSUS KB4493470 - Installed/Not Applicable KB4493478 - Installed/Not Applicable KB890830 - Installed/Not Applicable KB4485447 - Installed/Not Applicable And so on.... However, checking through a Domain joined machine they have definitely NOT been installed... I have the following classifications ticked in WSUS: I have the Default Automatic Approval rule set for Critical and Security updates and everything ticked in the Adavanced tab to approve revisions and decline expired updates.
Koldov Posted April 26, 2019 Author Posted April 26, 2019 Does anybody have any ides? Just took another machine off Domain to test and checked for updates, it required the following: Why aren't these appearing as required in WSUS when they are joined to the Domain?! There's no point in using WSUS if it isn't keeping machines up to date! I wonder if there's anyway to go back to using Windows Update, but track them somehow in WSUS? What does this mean?
DJ-1701 Posted April 26, 2019 Posted April 26, 2019 What have you got set under Products? The highlighted section is to make the machines download the updates from the net, but still be managed by WSUS to check which updates they should get. 1
Koldov Posted April 26, 2019 Author Posted April 26, 2019 What have you got set under Products? We have: Forefront Endpoint Protection (couldn't find Defender). Office 2016 Windows 10 LTSB
Koldov Posted April 26, 2019 Author Posted April 26, 2019 (edited) It just hit me scrolling through, that maybe I should have this generic 'Windows 10' classification ticked as well...? Edit: Although some of the updates that come through AFTER removing from the Domain/WSUS, specify they are for 1607 (I presume = LTSB, though I could be wrong), only I can't find 1607 as a 'Product' in WSUS... Edited April 26, 2019 by Koldov
DJ-1701 Posted April 26, 2019 Posted April 26, 2019 (edited) I thought 1607 was a CB (current branch) only, not a SB (service branch), I though the LTSBs were based on year, so LTSB 2015, etc. 1607 is no longer receiving updates as it is End of Life. https://support.microsoft.com/en-gb/help/13853/windows-lifecycle-fact-sheet Edited April 26, 2019 by DJ-1701 1
Koldov Posted April 26, 2019 Author Posted April 26, 2019 I thought 1607 was a CB (current branch) only, not a SB (service branch), I though the LTSBs were based on year, so LTSB 2015, etc. 1607 is no longer receiving updates as it is End of Life. https://support.microsoft.com/en-gb/help/13853/windows-lifecycle-fact-sheet Yes, true... My fault! Windows 10 Enterprise 2016 LTSB (the version we are using) was based on the mid-2016 Windows 10 1607. So, I was presuming updates aimed at 1607 would apply to LTSB 2016 (which seems to tally if you look at the screenshots of the updates the machine gets once it is off Domain). Not sure if I've got the latest info, but as it's an LTSB we should be good for a while as far as upates go, with extended support for Windows 10 Enterprise 2016 LTSB until October 13, 2026. Still, none of this explains why my WSUS won't see that my machines obviously need these updates... What am I missing?!
Koldov Posted April 29, 2019 Author Posted April 29, 2019 Well, unfortunately I have decided to remove all clients from WSUS today... Over the weekend I thought I would remote in and tick that generic box for 'Windows 10' whilst nobody was on the network. Once synchronised it showed about an extra 100GB of space used on the server and a lot of clients at 73%, so I was hopeful some of the missing updates would come through. Sadly as they all connected this morning they all shot up to 100% again, with nothing extra installed. I removed another spare laptop and my own machine from the Domain (both showing 100% on WSUS) and sure enough the updates started appearing... The security of clients obviously being compromised without the latest updates takes priority over me being able to approve and keep tabs on client updating I guess, so I think it's best until I can resolve it to go back to Windows Updates... There are some GPOs I think that were set back in the day (apart from the 'look at WSUS for updates' one) to stop clients updating from Microsoft directly, if anyone has a list of those I would be grateful as I obviously need to check and remove those as well. WHOLE THREAD TL;DR Windows 10 Enterprise 2016 LTSB - Clients not getting Windows Updates (WSUS) Products ticked in WSUS: Windows 10 LTSB Windows 10 Office 2016 (updating fine) Forefront Endpoint Protection Classifications ticked in WSUS: Critical Updates Definition Updates Security Updates Service Packs Update Rollups Updates Updates that appear once the machine is removed from Domain/WSUS -
free780 Posted April 29, 2019 Posted April 29, 2019 You can use the Windows Update for Business group policy settings to delay updates. You can have AD Groups of PCs to have a fast ring and a slow ring. Bandwidth may be the issue though which MS claim Delivery Optimization can help with. I'm not convinced. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now