Jump to content

Recommended Posts

Posted

Hi All,

 

I was wondering what Patch Management software/systems you all use.

 

We currently have SCCM, but deploying updates aren't instant. In fact, you can't guarantee that it'll be done within a week.

 

So what do you use? How easy/hard is it? What's the performance like? And how much is/was it?

 

Kind Regards

 

-Kitkatninja

Posted
Use SCCM and EndPoint Manager (InTune) coupled with PatchMyPC and Dell Update catalogue which handles all our patching drivers, OS and third-party software updates etc. We aim to get updates done in a two week window which we are about 95% successful in achieving considering a lot of laptops and very sporadic usage patterns.
  • Thanks 1
Posted

I use WSUS together with GPOs to auto patch around 500 servers a month.

 

I've split them into three groups, early adopter which get the updates immediately and the two more group which get the patches 15 days and 30 days later.

  • Thanks 1
Posted (edited)

Still just WSUS here for all the MS stuff. Largely automated and with CAU in place for our clustered servers. Linux servers use APT and are largely automated as well. Applications that don't have automatic updates working out of the box like Chrome or Drive File Stream do will be a matter of doing something manually, even if that's just deploying the latest version of an msi.

 

The number and category of WSUS or APT updates each server has waiting are one of the things we monitor from our monitoring platform, so we can keep half an eye on it from there.

 

Our WSUS clients hardly ever show up as 100%, but I think that's just down to sync frequencies, etc. WSUS syncs nightly, and clients check WSUS daily, with a 7-day deadline applied for completing each update. The missing percentages are therefore usually just made up of updates released in recent days.

 

Would also be interested in what others are doing to manage stuff like drivers and firmware that can't be taken care of using WSUS.

Edited by jthompson
  • Thanks 1
Posted

This thread smells of Cyber Essentials [emoji16].

Patch My PC is the way to go with ADRs.

I would also not be afraid to query if all software is needed to reduce the software you need to patch.

 

Also all the user installed apps probably need reigning into SCCM as machine level.

Posted (edited)

For a cyber essentials project I did recently I went with Patch Manager Plus Cloud Enterprise - covers windows and 3rd party applications, not reliant on PC being connected to the network and can set boundaries up so that if a device is on a certain IP it can use an internal distribution server, if it's on any other IP it will report directly to the cloud.

 

Relatively quick and easy to set up, the only thing I haven't deployed with it was Windows Feature Updates - windows updates and other supported patches have just worked.

Edited by Cache

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...