Jump to content

Recommended Posts

Posted

Good Morning everyone,

 

I am currently doing some research into WSUS and best practice for our Multi Academy Trust and figured i'd reach out to Edugeek to see how other Academy Trusts manage it across their sites. I have some questions that i've put together and wondered if you could share your thoughts?

 

Do you have a central WSUS server that deploys to your sites and have you considered it?

Do you just have a WSUS server per site?

Do you cache the updates to your local server or do you pull them directly from the internet?

How do you have your automatic-approval rules configured, Do you have a test classroom / machine that runs the updates first?

Do you have a specific person who regularly checks to ensure it's working and managed properly and consistent?

 

Any other insights or ideas about best practice would be welcomed.

 

Kind regards,

 

Jonny

Posted

Our situation is similar but not totally comparable, may be useful though.

 

Central WSUS server

Yes, running as a node

Cached

No automatic approvals other than Defender and Malicious Software Tool

I check it regularly as I manually approve

 

Waiting for @mavhc to come in and tell you that WSUS is dead, peer caching is the future with direct updates. He may be right, but I don't think so yet.

  • Thanks 1
Posted
Good Morning everyone,

Do you have a central WSUS server that deploys to your sites and have you considered it?

Do you just have a WSUS server per site?

Do you cache the updates to your local server or do you pull them directly from the internet?

How do you have your automatic-approval rules configured, Do you have a test classroom / machine that runs the updates first?

Do you have a specific person who regularly checks to ensure it's working and managed properly and consistent?

 

Any other insights or ideas about best practice would be welcomed.

 

Kind regards,

 

Jonny

 

I run one WSUS instance that caches updates for about 1500 workstations across seven sites. The sites are connected via Gig private fiber, so no worries about having a downstream WSUS install on each site. Security updates are set for auto approval as I don't have time to do testing of any sort (one man shop).

 

I haven't seen a WSUS install out of the box that hasn't needed tweaks done to it's application pool in IIS. The application pool process will keep crashing until raise the limits on resources it's allowed to consume. Been an issue in Server 2016 and Server 2019, might even go back farther to be honest. Can't remember which settings, but can look it up on my install if you need.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...