Bugzi Posted March 31, 2021 Posted March 31, 2021 Hello, I was wondering how anyone else has solved this please. We currently use SCCM to dish out all of our Windows Updates (Office too, but separate ADRs). Due to Covid, we have several staff that work from home and as such, we are having a bit of an issue in terms of pumping out Windows Updates. We have a VPN system in place, but we had to limit the speed so everyone can use it. I know that with SCCM you can use CMG and Co-Manage Software Updates, but is there a way to get SCCM to dictate which updates the end device downloads but then downloads this from the Internet please? I've had a look around and someone mentioned IBCM, but I'm unsure on that. What we are trying to do is control which updates the end devices can install but then not bombard our VPN. Thanks
computer_expert Posted March 31, 2021 Posted March 31, 2021 Would something like option 3 here do the trick?
Bugzi Posted March 31, 2021 Author Posted March 31, 2021 Thanks. I'll have to ask again, but last time I checked, our network guy was not happy to implement a split VPN. It's a shame with Windows Updates for Business, you can't choose which updates to apply
Steve21 Posted March 31, 2021 Posted March 31, 2021 If you're happy doing it across all of your devices, the easiest way is changing the SCCM ADR to do "Download from Microsoft Updates" and then it'll still restrict what applies, but it does mean all machines would use the internet to download them (not just laptops etc) Steve
Bugzi Posted March 31, 2021 Author Posted March 31, 2021 How do other organisations handle Windows Updates on Laptops / Surfaces if they are mobile and not always on the VPN?
computer_expert Posted March 31, 2021 Posted March 31, 2021 Thinking about it, standalone WSUS can download 'express' updates but you'll need a lot of disk space to store said updates. It looks like SCCM supports this too so maybe worth a try?
DarkenRahl Posted April 1, 2021 Posted April 1, 2021 Intune / SCCM with co-management may do what is required, you could then shift the updates payload for the laptop devices to use Microsoft and leave desktops on SCCM/WSUS.
Bugzi Posted April 12, 2021 Author Posted April 12, 2021 Thanks everyone. If I understand co-management, that requires a server sitting in Azure acting as a Proxy (aka CMG)? Thing with Intune, I'm not sure how we could manage which updates get applied, as we would like to still be in control of what updates can be installed to avoid a possible bad update, like the printing one recently.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now