Jump to content

Recommended Posts

Posted

I have been tasked on a site to patch servers and workstations that hadn’t been patched for years.

 

I found they had a wsus server which was misconfigured in wsus and in group policy targeting. Fine fixed that rebooted all machines and found they still weren’t checking in.

 

I little digging uncovered that a group policy had specific settings to disable and stop the windows update service. Once removed all workstations and servers began checking in and updating successfully and the domain logins seem ok.

 

This is obviously intentional and not a possible mistake unlike the first issue described.

 

My suspicious brain is asking why??? Why would someone prevent windows from updating from a technical perspective.

 

First thought sabotage but why it’s not causing great detriment to anyone really.

 

The site clients is running Windows 10 edu 1709. I understand this is still supported until next April and we have plans to move them to sccm, but in the mean time I am trying to understand why someone would go to great lengths to stop devices updating themselves.

 

Anyone with any technical experience explain this. Are there any glitches

Posted

Was there not an update a few years ago which caused the windows update service to hog all the RAM?

 

It could also be that the previous tech just had enough of people complaining about updates

  • Thanks 1
Posted
Windows 10 updates are frequent, intrusive and take ages at times. They also often break more than they fix. That’s probably why - though they still need to be enabled and configured to cause the least possible disruption.
  • Thanks 1
Posted
Windows 10 updates are frequent, intrusive and take ages at times. They also often break more than they fix. That’s probably why - though they still need to be enabled and configured to cause the least possible disruption.

 

I think they're less of an annoyance than they were in Win7. In terms of breaking more than they fix, I've simply not found that to be the case with anything classified as critical or security.

 

Given that the OP found WSUS to be misconfigured, I'd wager that the previous tech couldn't get things working properly and made the mistake of listening too much to users' complaints about updates, so turned them off.

  • Thanks 1
Posted

I think you're looking too far into this, always remember Hanlon's razor:

 

"Never attribute to malice that which can be adequately explained by stupidity."

  • Thanks 2
Posted

Thanks all. To be honest I only considered malice or inability as that makes my life a lot easier.

 

My worry was that if he knew of a technical issue that broke something.

 

Didn’t fancy A phone call Monday morning after deploying the updates across the rest of the site over the weekend and it has bricked every computer.

 

We will see [emoji848]

Posted

Updates are annoying, not updating and getting hacked, ransomware everywhere, more annoying. Update a few machines manually, check no problems, then email everyone saying there's a lot of security updates to do to protect the school, and to reboot asap when you're not using the machine for 2 hours.

 

Update problems only affect a very small %age of people, if all 1 billion Windows computers failed, it would be global news

Posted

Or get a maintaince windows working. Wake the PCs at night and trigger updates. I've also encountered the disable windows updates mantra. If you take GDPR and Cyber Essentials seriously you need to keep current. We are no longer in a world with a static IT environment for the academic year.

Windows Updates need a fast ring and a slow ring. Also a medium ring for servers. I recommend going to 1809 not 1903 yet.

Posted

Windows Updates need a fast ring and a slow ring. Also a medium ring for servers. I recommend going to 1809 not 1903 yet.

 

Thanks for the tip. I have fully patched 1709 version which by the looks of it as I check in with the server all is ok. My view is to feature upgrade a couple computers or an ict suite to 1809 see if it breaks anything and then go from there.

 

Thanks all for your valuable input

Posted
It has been pretty stable with 1607, 1703 and 1903 builds at ours, didn’t use 1709 or the 2018 builds. Generally 10 is fine - I always defer updates for a little while after release to catch any recalls/major bugs, but this carries a degree of risk for active exploits. You won’t go far wrong having them auto-approve.
Posted

Sounds to me like this tech had a problem with WSUS and was having problem with updates as a result

 

Maybe updates were disabled as a temporary measure until WSUS could be sorted - then they left before they could finish it????

 

I do remember when I left my last job I spent the last month or more running around trying to tie up things that were not completed fully - but still had a few things left that I had not had time to sort out

  • Thanks 1
Posted (edited)

Another possibility is that he may have had SCCM in at some point and was using that to do updates. Although SCCM uses WSUS to do updating, you still have to disable the built mechanism for it to work.

 

Either that or the guy was either fed up with complaints about updates and disabled them or he was a complete tool.

Edited by Norphy
  • Thanks 1
Posted
Another possibility is that he may have had SCCM in at some point and was using that to do updates. Although SCCM uses WSUS to do updating, you still have to disable the built mechanism for it to work.

 

Either that or the guy was either fed up with complaints about updates and disabled them or he was a complete tool.

 

Yeah don’t get me started on sccm. I found a server with sccm and wsus on as well. Again non functioning services stopped and disabled. This lad must have had a right nightmare.

 

That my intention to rebuild the sccm server then that will take over eventually.

Posted
If your using SCCM to manage software updates WSUS has to be installed on the server
Posted

Wsus is so easy when it is used and maintained properly.

Maintaining wsus always has been regular routine maintenance for me when I was in my own school. Now I work for a private company supporting schools I am going out fixing problems due to technicians lack of routine maintenance.

Posted
Wsus is so easy when it is used and maintained properly.

Maintaining wsus always has been regular routine maintenance for me when I was in my own school. Now I work for a private company supporting schools I am going out fixing problems due to technicians lack of routine maintenance.

 

Was always grinding to a halt, plus taking up 500GBs of storage, causing WU to fail on one site completely, those cleanup scripts helped a bit, but eventually it always died, and then reinstalling it from scratch was another pita. Plus that whole esd debacle, WUfB is much nicer, and obviously how MS wants everyone to head, plus it works when laptops are at home.

 

Not even noticed the bandwidth hit, but I do have 2Mb/client

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...