Jump to content

Recommended Posts

Posted

Evening All,

 

I've been reading about WuFB and it's advantages/disadvantages. So I have a few questions before I go any further...

 

1. Can it be used without inTune or SCCM? Is there a way of configuring it so that clients use it, but I just control it? (crap question really).

2. What is the URL? To set this up?

 

Any pointers? I'm working through the docs at the moment but nothing shows me how to set it up beyond setting the GPOs.

 

Cheers for reading what are simple questions.

 

Gareth

  • Thanks 1
Posted

WUfB is it's own system in that regards, things like inTune/SCCM just have the pretty wrapper on top, but it's all GPO based underneath it. Generally though it's designed that once the GPOs are setup there is no "controlling it" it just does it as set

 

"URL" wise I'm not sure what you mean, it's GPOs so it's set on your clients. There is a report part in Azure that's got a url etc, but the basic WUfB isn't a website etc

 

Regarding starting out with it I'd be tempted to say wait for 21H2 they're changing the way Windows updates work in regards to being able to set things like drivers to go to one update system, while updates come from another, so you'd be better off starting based on that logic in regards to what you want setup on it

 

Steve

Posted

I've been using WUfB for sometime, as above it's just GPOs, then Windows Update takes care of everything else.

 

I delay updates by 30 days, (again by GPO) so currently clients are operating on the September 2021 update (at the time of writing). This is entirely your choice, but it still means clients used regularly off site are kept up-to-date.

 

Separately I also looked at the idea of making WSUS accessible over the internet, but it's relatively complicated I thought. Windows Update & GPOs really is seamless and one less VM for me to manage at each site running WSUS.

Posted
Would appreciate you detailing your experience if and when you take the plunge @garethedmonson for those of us still dealing with WSUS (and its quirks) and sitting on the fence... let us know if the grass is any greener!
  • Thanks 1
Posted (edited)
We were using WSUS and ConfigMgr for updates but wanted to use something more agile to help achieve the "patch within 14 days" requirement for Cyber Essentials so moved to WUfB. Taken some tinkering but now works really well! We wake desktop PCs at 10pm to run scans, laptops catchup when they can using Windows 10 maintenance schedules. We have PCs grouped into three rings with different deferral dates for quality updates - test, pilot and deploy. I have put some screenshots of our GPO config in the attached document. Hope this proves useful.

WuFB Configuration.docx

Edited by Smokebomb
  • Thanks 1
Posted

Morning all,

 

I'm back. So everything seems to be set up regarding Update Compliance but it's still reporting no devices have registered. Following instructions, I have tried to run the Microsoft Update Compliance Script but it seems to fail when running the census.exe file. Or at least I think it's failing. I got the impression that when the script was successfully run, the test machine would show up on the Azure Dashboard.

 

I've also read it could take up to 72 hours for a machine to appear.

 

What are opinions here?

 

Cheers for all the help so far.

 

Gareth

Posted
Morning all,

 

I'm back. So everything seems to be set up regarding Update Compliance but it's still reporting no devices have registered. Following instructions, I have tried to run the Microsoft Update Compliance Script but it seems to fail when running the census.exe file. Or at least I think it's failing. I got the impression that when the script was successfully run, the test machine would show up on the Azure Dashboard.

 

I've also read it could take up to 72 hours for a machine to appear.

 

What are opinions here?

 

Cheers for all the help so far.

 

Gareth

 

For some reason I found ours took an absolute age to appear in Update compliance so this seems pretty normal. Now that I have moved completely away from WSUS and switched to WUFB and update compliance I dont really have to worry about updates anymore. It just works. As above I defer the quality updates for 14 days but for feature updates I set a target feature update version and then move to the next one once im happy its not a broken mess (like 1809 for example).

Posted
I've been using WUfB for sometime, as above it's just GPOs, then Windows Update takes care of everything else.

 

I delay updates by 30 days, (again by GPO) so currently clients are operating on the September 2021 update (at the time of writing). This is entirely your choice, but it still means clients used regularly off site are kept up-to-date.

 

Separately I also looked at the idea of making WSUS accessible over the internet, but it's relatively complicated I thought. Windows Update & GPOs really is seamless and one less VM for me to manage at each site running WSUS.

 

Is delaying updates by such a long period of time really a good idea - in the current climate you'd surely want updates pushing out ASAP - obviously testing them first but operating a full month behind seems to me to be a really bad idea.

Posted
Would appreciate you detailing your experience if and when you take the plunge @garethedmonson for those of us still dealing with WSUS (and its quirks) and sitting on the fence... let us know if the grass is any greener!

 

Im using WuFB with Intune Managed/ Azure AD joined devices. My experience has been that machines update flawlessly and reliably, but previously with WSUS some machines simply refuse to update and required a manual kick once in a while. I dont know the reason for that and maybe if I went back to WSUS with modern win10 builds it would be just as reliable.

Posted

Morning All,

 

Checked Azure this morning and my machine has turned up. Hooray. That works. Have now set the policy to look at all machines in our OU. Yeah.

 

Now - to get the updates for the test ring working. Seems easy enough.

 

However - quick question - how to I stop it reporting anything newer that 20H2? That is what we are staying on for a while. I know things are missing after this.

 

Gareth

Posted
You can make your own search queries, but not sure you can change the defaults, why aren't you moving to 21H1?

 

21H1 - not sure to be honest. I have a brief recollection that the LEA were not supporting it as it had a shorter support period than 20H2 - but maybe I am wrong.

 

I'm waiting to see if machines update now.

 

Gareth

Posted
21H1 - not sure to be honest. I have a brief recollection that the LEA were not supporting it as it had a shorter support period than 20H2 - but maybe I am wrong.

 

I'm waiting to see if machines update now.

 

Gareth

 

You're right 21H1 is December 2022 and 20H2 is May 2023. 21H2 will be May 2024.

 

That said it will upgrade from 21H1 to 21H2 using the new method. It installs a cumulative update and then an "enablement package" to turn the 21H2 features on. These usually take minutes if that to install so ive just been rolling out 21H1.

  • 3 months later...
Posted
Would appreciate you detailing your experience if and when you take the plunge @garethedmonson for those of us still dealing with WSUS (and its quirks) and sitting on the fence... let us know if the grass is any greener!

 

Hi @Koldov - Apologies for not getting back to you. Just looking back over old posts and saw that I had not replied. Get in touch if you want info. I'm still working on the project as other things took over but we are set up and are now monitoring with the possibility of making minor changes.

 

Gareth

Posted

Hi @garethedmondson,

 

No worries, I've had a few other things to take my mind off it too.

 

Honestly, for our small network and few devices I actually have no problem with WSUS and it works really well. I'm used to the interface and like the way I can control (hold, deploy or remove) updates and have quite a detailed view of what's happening. I just wondered if it was just going to be a case of configuring a couple of GPOs I might go for it.

 

Just thought it would be good to remove another role from the server and also have updates still delivered when devices are off-site (as we have a couple of teachers off long-term - and what with isolating and such), but still have control over it.

Posted
The philosophy of WuFB is: "It's WU, but with a tiny bit more control and reporting. Because just install updates as fast as possible you nutters, the world is full of hackers."
  • Thanks 3
Posted
Hi @garethedmondson,

 

No worries, I've had a few other things to take my mind off it too.

 

Honestly, for our small network and few devices I actually have no problem with WSUS and it works really well. I'm used to the interface and like the way I can control (hold, deploy or remove) updates and have quite a detailed view of what's happening. I just wondered if it was just going to be a case of configuring a couple of GPOs I might go for it.

 

Just thought it would be good to remove another role from the server and also have updates still delivered when devices are off-site (as we have a couple of teachers off long-term - and what with isolating and such), but still have control over it.

 

Hi @Koldov,

 

Get in touch when you are ready. The process was quite easy, despite taking time. The last reason you give about off-site devices is one of the reasons I have moved as well. 80 staff laptops than need updating.

 

Gareth

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...