Jump to content

Recommended Posts

Posted

Hi all,

 

Hope you're keeping well - I'm looking for some clarification in clients receiving updates from Microsoft Update, rather than WSUS.

 

Currently I have WSUS setup and publish updates as and when, so I'm in full control what's deployed. The bigger issue in a pandemic scenario, are that clients may not be brought back on site for months and consequently will not connect to WSUS.

 

So hypothetically, if I did away with WSUS in full or part and enabled these policies -

 

Select when Feature Updates are received - Enabled - CBB - 30 Days.

 

For the most part the above wouldn't apply, as I normally deploy LTSB and LTSC versions of Windows 10.

 

Select when Quality Updates are received - Enabled - 30 Days.

 

So hypothetically, if Microsoft release a bad update, the client wouldn't receive the security/quality update for 30 days. Is this the correct assumption, by which time Microsoft may have pulled the update and published another?

 

If so, you can observe that here. Microsoft published two updates for 1809 in January 2021. Presumably only the newer 'fixed' update would get deployed? I've always generally preferred to be a month behind in rolling out updates for this very reason.

 

Do not include drivers with Windows Updates - Enabled

 

Thanks for reading! :)

Posted

There are a few caveats with it depending on how you're currently doing things. Bearing in mind using your 30 days feature upgrades will roll out full upgrades to 20H2 etc if they aren't already rolled out, as you can't pick/choose upgrades it's either on or deferred. (Although you did mention about LTSB etc so maybe not so much of an issue on your end)

 

You also lose any reporting ability unless you're linking them to Azure reports, as they won't return data to WSUS/SCCM etc

 

Do you use anything like VPN with your laptops, as WSUS should still be connecting across that to report back to server and getting downloads etc. We've temporarily just changed our policies so it reports back in, but downloads updates directly to save backwards traffic etc

 

Steve

  • Thanks 1
Posted

Yes - select users use VPN, but more so for legacy applications. The majority of personnel don't, as everything's cloud based.

 

As far as I know, Microsoft don't offer a solution for WSUS and/or MU.

 

I don't dive in too much into WSUS reporting being honest. Definitely more so being able to control and deploy updates, yet more and more devices are now off site.

 

If what I'm proposing isn't a good idea, I'm open to ideas what others are doing!

Posted
You can, if you want, carry on using WSUS to control all of your updates by setting it up with an external FQDN and pointing all of your clients towards that. Bit of a fiddle, but doable and means you can decide when feature updates go out.
  • Thanks 1
Posted (edited)

Odd this, as I was looking to do the same (Windows Update for Business), even started setting up the policies and groups this afternoon.

Just haven't applied them yet.

 

With regards to reporting, you can use Update Compliance in Azure. It's free, but you will need a subscription and therefore have to enter credit card details. But there is no charge for compliance data. You also need to set up some policies for your clients (or run some Microsoft scripts) so that they report into it.

There's some details here:

https://docs.microsoft.com/en-us/windows/deployment/update/update-compliance-using

 

I'm also looking at peer to peer caching type thing called Delivery Optimization for devices on site.

Edited by e-class
  • Thanks 1
Posted

Thanks all. There's a good guide here.

 

In summary you need to setup a downstream replica (not ideal for smaller sites) and place it in in the DMZ, apply an SSL cert and manipulate DNS.

 

I don't know what the risks are exposing ports 8530 and 8531 to the internet, even if it was in the DMZ?

 

The guide also describes to enable 'Do not store updates locally' in WSUS, which leads me to think it's pointless, as all clients internally will download from MU anyway.

 

If I did store updates locally, it would then put a lot more stress on the WAN uplink. I'm a bit stuck on this one.

 

Yesterday I downloaded/imported the latest 20H2 ADMX templates, just to see if there any new enhancements or options.

Posted

I've had a read of these notes and plan on testing on a small site.

 

Other than removing the Intranet location and Client side targeting GPOs, as well as enabling/configuring Feature and Quality GPOs, the policies have remained identical. The Quality updates in particular are deferred for 30 days from the point of release.

 

They'll be using Windows 10 LTSC 1809, patched up to December 2020 as standard.

 

A lot of the services they use are cloud based, rather than legacy, which also influenced my decision on this. I'll report back in a few months (if I remember)! :)

  • 1 month later...
Posted

Just to update this discussion - Windows Update for Business has worked so well, I'll be decommissioning all WSUS servers in the near future. These are the things I've observed -

 

- By far devices obtain fixes quicker and install faster

 

- I think the above is due a combination of devices being able to download update files from any location, as well as peer to peer

 

- Remaining 30 days behind, for both workstations and servers seems to be a working strategy. March 2021 patches have been somewhat a disaster, with Microsoft publishing two updates for Windows 10 1607 and four updates for Windows 10 1809

 

- Currently exploring options such as this whereby I can query the network and get a report back (possibly even emailed), as an easy solution to keep tabs on workstation status

 

Any thoughts or something I've missed? Let me know!

  • Thanks 2
Posted

I've been looking at this recently as we're getting lots of laptops not being brought back in to update etc, but still find it hard addressing some issues with this system on a few test machines I have, and wondered how you're currently working around these (Only doing basic tests so might have overlooked something obvious!):

 

1) Managing feature updates so they won't affect lessons etc (For example, even with a scheduled update times/reboots set if they're turning it off/not restarting it at the right time, it'll start doing a long slow update in the mornings (An example on an old old laptop being like 1709 to 2004 on a non-SSD when turned on at 8:00am and wouldn't be ready for lesson times)

2) Bypassing mini-FeatureUpdates (for example, if we want 1909 to go to 20H2 not 2004), with the set day deferrals if it overlaps it'll still do the 2004 update before the 20H2 which seems silly and annoying to end users doing multiple updates that aren't needed)

3) Blocking single updates from deploying (For example, with the recent printing one, with SCCM/WSUS we just decline that update, with WUfB is there any way apart from pausing all updates?)

4) Complying with things like Cyber Essentials (patching in 14 days), while having the same issues above about not being able to block updates etc

5) More as a query, did you do this for desktops etc too? or just laptops? Just in terms of "cache" devices for Delivery Opt. if they're all laptops there doesnt' seem any point in these

 

Sure I'll find some more as my testing goes, but just curious if you had any of these and any thoughts/solutions?

 

Steve

Posted

Thanks Steve - to go through your points -

 

1, 2 and 3 - LTSB and LTSC versions of Windows 10 do not have Feature updates, only Quality updates. At any point however, you can defer Quality Updates up to 30 days (as I do) and optionally pause. At any point you can also defer Feature Updates up to 365 days and optionally pause. In both cases, to remove the pause, you simply remove the date entered from the GPO.

 

4. In regards to Cyber Essentials, I think a balance needs to be weighed up. As per my example, March 2021 for Windows Updates has been a disaster. I very much doubt any of these organisations have an answer to this kind of scenario. I appreciate this isn't the same every month, yet Microsoft have a reputation for releasing problematic Quality or Feature updates. I would also say that with the WSUS model, you could easily have notebooks which are months out of date if they're not brought back on site (for whatever the reason).

 

5. Yes, notebooks, workstations/desktops and servers.

 

I'd also say I enforce the Windows Firewall when devices are used off site, but disable it when devices are on the LAN (again all by GPO), which offers a degree of protection.

 

By all means, far from perfect, but I still think it's a better set up than WSUS. Alternatively you can make your WSUS public via SSL, but I've no idea what the risks are, even if you VLAN'ed the WSUS off, or placed it in the DMZ.

  • Thanks 1
  • 3 weeks later...
Posted

Interestingly if you have a A3+ subscription it seems MS are releasing new options that will resolve a lot of what I mentioned under a new service addon for WUfB:

 

The deployment service significantly extends the management plane available to devices connecting to Windows Update. It will enable you to:

 

  • Schedule update deployments to begin on a specific date (ex: deploy 20H2 to these devices on March 14, 2021)
  • Stage deployments over a period of days or weeks using rich expressions (ex: deploy 20H2 to 500 devices per day, beginning on March 14, 2021)
  • Bypass pre-configured Windows Update for Business policies to immediately deploy a security update across your organization when emergencies arise
  • Ensure coverage of hardware and software in your organization through deployments that are tailored to your unique device population through automatic piloting
  • Leverage Microsoft ML to automatically identify and pause deployments to devices which are likely to be impacted by a safeguard hold
  • Manage driver and firmware updates just like feature updates and quality updates

 

 

https://techcommunity.microsoft.com/t5/windows-it-pro-blog/announcing-the-windows-update-for-business-deployment-service/ba-p/2178419

 

Steve

  • Thanks 1
Posted

Thanks for the update - users my end received the March 2021 update mainly from home (working on notebooks) over Easter so again WUfB is proving to be robust.

 

I agree that the above updates are more essential for very large environments.

Posted

Microsoft now have a security baseline for Windows Update which is useful to base your policy from, I'm using WUfB and it's been working really well, traditionally I used to delay my updates by a few weeks so little was my confidence in MS updates, that confidence is still just as low but with the push on security first than this is not really feasible any more.

 

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-update-baseline-joins-the-security-compliance-toolkit/ba-p/2098482

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...