dapaulio Posted November 1, 2019 Posted November 1, 2019 I have been tasked on a site to patch servers and workstations that hadn’t been patched for years. I found they had a wsus server which was misconfigured in wsus and in group policy targeting. Fine fixed that rebooted all machines and found they still weren’t checking in. I little digging uncovered that a group policy had specific settings to disable and stop the windows update service. Once removed all workstations and servers began checking in and updating successfully and the domain logins seem ok. This is obviously intentional and not a possible mistake unlike the first issue described. My suspicious brain is asking why??? Why would someone prevent windows from updating from a technical perspective. First thought sabotage but why it’s not causing great detriment to anyone really. The site clients is running Windows 10 edu 1709. I understand this is still supported until next April and we have plans to move them to sccm, but in the mean time I am trying to understand why someone would go to great lengths to stop devices updating themselves. Anyone with any technical experience explain this. Are there any glitches
BKGarry Posted November 1, 2019 Posted November 1, 2019 Was there not an update a few years ago which caused the windows update service to hog all the RAM? It could also be that the previous tech just had enough of people complaining about updates 1
3s-gtech Posted November 1, 2019 Posted November 1, 2019 Windows 10 updates are frequent, intrusive and take ages at times. They also often break more than they fix. That’s probably why - though they still need to be enabled and configured to cause the least possible disruption. 1
jthompson Posted November 1, 2019 Posted November 1, 2019 Windows 10 updates are frequent, intrusive and take ages at times. They also often break more than they fix. That’s probably why - though they still need to be enabled and configured to cause the least possible disruption. I think they're less of an annoyance than they were in Win7. In terms of breaking more than they fix, I've simply not found that to be the case with anything classified as critical or security. Given that the OP found WSUS to be misconfigured, I'd wager that the previous tech couldn't get things working properly and made the mistake of listening too much to users' complaints about updates, so turned them off. 1
bald_pig Posted November 1, 2019 Posted November 1, 2019 I think you're looking too far into this, always remember Hanlon's razor: "Never attribute to malice that which can be adequately explained by stupidity." 2
dapaulio Posted November 1, 2019 Author Posted November 1, 2019 Thanks all. To be honest I only considered malice or inability as that makes my life a lot easier. My worry was that if he knew of a technical issue that broke something. Didn’t fancy A phone call Monday morning after deploying the updates across the rest of the site over the weekend and it has bricked every computer. We will see [emoji848]
mavhc Posted November 2, 2019 Posted November 2, 2019 Updates are annoying, not updating and getting hacked, ransomware everywhere, more annoying. Update a few machines manually, check no problems, then email everyone saying there's a lot of security updates to do to protect the school, and to reboot asap when you're not using the machine for 2 hours. Update problems only affect a very small %age of people, if all 1 billion Windows computers failed, it would be global news
free780 Posted November 2, 2019 Posted November 2, 2019 Or get a maintaince windows working. Wake the PCs at night and trigger updates. I've also encountered the disable windows updates mantra. If you take GDPR and Cyber Essentials seriously you need to keep current. We are no longer in a world with a static IT environment for the academic year. Windows Updates need a fast ring and a slow ring. Also a medium ring for servers. I recommend going to 1809 not 1903 yet.
dapaulio Posted November 2, 2019 Author Posted November 2, 2019 Windows Updates need a fast ring and a slow ring. Also a medium ring for servers. I recommend going to 1809 not 1903 yet. Thanks for the tip. I have fully patched 1709 version which by the looks of it as I check in with the server all is ok. My view is to feature upgrade a couple computers or an ict suite to 1809 see if it breaks anything and then go from there. Thanks all for your valuable input
3s-gtech Posted November 2, 2019 Posted November 2, 2019 It has been pretty stable with 1607, 1703 and 1903 builds at ours, didn’t use 1709 or the 2018 builds. Generally 10 is fine - I always defer updates for a little while after release to catch any recalls/major bugs, but this carries a degree of risk for active exploits. You won’t go far wrong having them auto-approve.
mikeprice Posted November 2, 2019 Posted November 2, 2019 Sounds to me like this tech had a problem with WSUS and was having problem with updates as a result Maybe updates were disabled as a temporary measure until WSUS could be sorted - then they left before they could finish it???? I do remember when I left my last job I spent the last month or more running around trying to tie up things that were not completed fully - but still had a few things left that I had not had time to sort out 1
Norphy Posted November 2, 2019 Posted November 2, 2019 (edited) Another possibility is that he may have had SCCM in at some point and was using that to do updates. Although SCCM uses WSUS to do updating, you still have to disable the built mechanism for it to work. Either that or the guy was either fed up with complaints about updates and disabled them or he was a complete tool. Edited November 2, 2019 by Norphy 1
dapaulio Posted November 3, 2019 Author Posted November 3, 2019 Another possibility is that he may have had SCCM in at some point and was using that to do updates. Although SCCM uses WSUS to do updating, you still have to disable the built mechanism for it to work. Either that or the guy was either fed up with complaints about updates and disabled them or he was a complete tool. Yeah don’t get me started on sccm. I found a server with sccm and wsus on as well. Again non functioning services stopped and disabled. This lad must have had a right nightmare. That my intention to rebuild the sccm server then that will take over eventually.
Guest Guest Posted November 3, 2019 Posted November 3, 2019 If your using SCCM to manage software updates WSUS has to be installed on the server
pacapps Posted November 4, 2019 Posted November 4, 2019 Could it be that the Windows 10 computers had been set up update from other Windows 10 Computers? I had this at one school I used to support. https://www.digitalcitizen.life/how-set-windows-10-get-updates-local-network-internet
garethEds Posted November 4, 2019 Posted November 4, 2019 Could it be that the Windows 10 computers had been set up update from other Windows 10 Computers? I had this at one school I used to support. https://www.digitalcitizen.life/how-set-windows-10-get-updates-local-network-internet I read about doing this - is it considered bad? Gareth
elsiegee40 Posted November 4, 2019 Posted November 4, 2019 I read about doing this - is it considered bad? Gareth It’s what you might do at home to save bandwidth. Personally, I’d use WSUS in a work environment
mavhc Posted November 4, 2019 Posted November 4, 2019 I read about doing this - is it considered bad? Gareth I got rid of WSUS, as it broke yet again, and switched to http://www.edugeek.net/forums/windows-10/207846-update-compliance.html So I enable p2p lan sharing, saves a bit of bandwidth, 21.5% says MS, but most of my computers are laptops, if you have a few classrooms of desktops it'll work much better.
free780 Posted November 4, 2019 Posted November 4, 2019 If you have the bandwidth WUfB will work. If you don't WSUS is better but you do need to maintain it like any other server.
dapaulio Posted November 4, 2019 Author Posted November 4, 2019 Wsus is so easy when it is used and maintained properly. Maintaining wsus always has been regular routine maintenance for me when I was in my own school. Now I work for a private company supporting schools I am going out fixing problems due to technicians lack of routine maintenance.
mavhc Posted November 4, 2019 Posted November 4, 2019 Wsus is so easy when it is used and maintained properly. Maintaining wsus always has been regular routine maintenance for me when I was in my own school. Now I work for a private company supporting schools I am going out fixing problems due to technicians lack of routine maintenance. Was always grinding to a halt, plus taking up 500GBs of storage, causing WU to fail on one site completely, those cleanup scripts helped a bit, but eventually it always died, and then reinstalling it from scratch was another pita. Plus that whole esd debacle, WUfB is much nicer, and obviously how MS wants everyone to head, plus it works when laptops are at home. Not even noticed the bandwidth hit, but I do have 2Mb/client
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now