garethEds Posted November 3, 2021 Posted November 3, 2021 Evening All, I've been reading about WuFB and it's advantages/disadvantages. So I have a few questions before I go any further... 1. Can it be used without inTune or SCCM? Is there a way of configuring it so that clients use it, but I just control it? (crap question really). 2. What is the URL? To set this up? Any pointers? I'm working through the docs at the moment but nothing shows me how to set it up beyond setting the GPOs. Cheers for reading what are simple questions. Gareth 1
Steve21 Posted November 3, 2021 Posted November 3, 2021 WUfB is it's own system in that regards, things like inTune/SCCM just have the pretty wrapper on top, but it's all GPO based underneath it. Generally though it's designed that once the GPOs are setup there is no "controlling it" it just does it as set "URL" wise I'm not sure what you mean, it's GPOs so it's set on your clients. There is a report part in Azure that's got a url etc, but the basic WUfB isn't a website etc Regarding starting out with it I'd be tempted to say wait for 21H2 they're changing the way Windows updates work in regards to being able to set things like drivers to go to one update system, while updates come from another, so you'd be better off starting based on that logic in regards to what you want setup on it Steve
mavhc Posted November 4, 2021 Posted November 4, 2021 1 Yes 2 http://www.edugeek.net/forums/windows-10/207846-update-compliance.html
garethEds Posted November 4, 2021 Author Posted November 4, 2021 1 Yes 2 http://www.edugeek.net/forums/windows-10/207846-update-compliance.html Mind if I send you some DMs about it? Gareth
Michael Posted November 4, 2021 Posted November 4, 2021 I've been using WUfB for sometime, as above it's just GPOs, then Windows Update takes care of everything else. I delay updates by 30 days, (again by GPO) so currently clients are operating on the September 2021 update (at the time of writing). This is entirely your choice, but it still means clients used regularly off site are kept up-to-date. Separately I also looked at the idea of making WSUS accessible over the internet, but it's relatively complicated I thought. Windows Update & GPOs really is seamless and one less VM for me to manage at each site running WSUS.
Koldov Posted November 4, 2021 Posted November 4, 2021 Would appreciate you detailing your experience if and when you take the plunge @garethedmonson for those of us still dealing with WSUS (and its quirks) and sitting on the fence... let us know if the grass is any greener! 1
Smokebomb Posted November 4, 2021 Posted November 4, 2021 (edited) We were using WSUS and ConfigMgr for updates but wanted to use something more agile to help achieve the "patch within 14 days" requirement for Cyber Essentials so moved to WUfB. Taken some tinkering but now works really well! We wake desktop PCs at 10pm to run scans, laptops catchup when they can using Windows 10 maintenance schedules. We have PCs grouped into three rings with different deferral dates for quality updates - test, pilot and deploy. I have put some screenshots of our GPO config in the attached document. Hope this proves useful.WuFB Configuration.docx Edited November 4, 2021 by Smokebomb 1
garethEds Posted November 5, 2021 Author Posted November 5, 2021 Morning all, I'm back. So everything seems to be set up regarding Update Compliance but it's still reporting no devices have registered. Following instructions, I have tried to run the Microsoft Update Compliance Script but it seems to fail when running the census.exe file. Or at least I think it's failing. I got the impression that when the script was successfully run, the test machine would show up on the Azure Dashboard. I've also read it could take up to 72 hours for a machine to appear. What are opinions here? Cheers for all the help so far. Gareth
caffrey Posted November 5, 2021 Posted November 5, 2021 It can take longer, our fleet took more than 72
tmoon-mint Posted November 5, 2021 Posted November 5, 2021 Morning all, I'm back. So everything seems to be set up regarding Update Compliance but it's still reporting no devices have registered. Following instructions, I have tried to run the Microsoft Update Compliance Script but it seems to fail when running the census.exe file. Or at least I think it's failing. I got the impression that when the script was successfully run, the test machine would show up on the Azure Dashboard. I've also read it could take up to 72 hours for a machine to appear. What are opinions here? Cheers for all the help so far. Gareth For some reason I found ours took an absolute age to appear in Update compliance so this seems pretty normal. Now that I have moved completely away from WSUS and switched to WUFB and update compliance I dont really have to worry about updates anymore. It just works. As above I defer the quality updates for 14 days but for feature updates I set a target feature update version and then move to the next one once im happy its not a broken mess (like 1809 for example).
caffrey Posted November 5, 2021 Posted November 5, 2021 Anyone want to share their update ring settings?
Primus Posted November 5, 2021 Posted November 5, 2021 I've been using WUfB for sometime, as above it's just GPOs, then Windows Update takes care of everything else. I delay updates by 30 days, (again by GPO) so currently clients are operating on the September 2021 update (at the time of writing). This is entirely your choice, but it still means clients used regularly off site are kept up-to-date. Separately I also looked at the idea of making WSUS accessible over the internet, but it's relatively complicated I thought. Windows Update & GPOs really is seamless and one less VM for me to manage at each site running WSUS. Is delaying updates by such a long period of time really a good idea - in the current climate you'd surely want updates pushing out ASAP - obviously testing them first but operating a full month behind seems to me to be a really bad idea.
chaplic Posted November 5, 2021 Posted November 5, 2021 Would appreciate you detailing your experience if and when you take the plunge @garethedmonson for those of us still dealing with WSUS (and its quirks) and sitting on the fence... let us know if the grass is any greener! Im using WuFB with Intune Managed/ Azure AD joined devices. My experience has been that machines update flawlessly and reliably, but previously with WSUS some machines simply refuse to update and required a manual kick once in a while. I dont know the reason for that and maybe if I went back to WSUS with modern win10 builds it would be just as reliable.
garethEds Posted November 7, 2021 Author Posted November 7, 2021 Morning All, Checked Azure this morning and my machine has turned up. Hooray. That works. Have now set the policy to look at all machines in our OU. Yeah. Now - to get the updates for the test ring working. Seems easy enough. However - quick question - how to I stop it reporting anything newer that 20H2? That is what we are staying on for a while. I know things are missing after this. Gareth
mavhc Posted November 8, 2021 Posted November 8, 2021 You can make your own search queries, but not sure you can change the defaults, why aren't you moving to 21H1?
garethEds Posted November 8, 2021 Author Posted November 8, 2021 You can make your own search queries, but not sure you can change the defaults, why aren't you moving to 21H1? 21H1 - not sure to be honest. I have a brief recollection that the LEA were not supporting it as it had a shorter support period than 20H2 - but maybe I am wrong. I'm waiting to see if machines update now. Gareth
tmoon-mint Posted November 8, 2021 Posted November 8, 2021 21H1 - not sure to be honest. I have a brief recollection that the LEA were not supporting it as it had a shorter support period than 20H2 - but maybe I am wrong. I'm waiting to see if machines update now. Gareth You're right 21H1 is December 2022 and 20H2 is May 2023. 21H2 will be May 2024. That said it will upgrade from 21H1 to 21H2 using the new method. It installs a cumulative update and then an "enablement package" to turn the 21H2 features on. These usually take minutes if that to install so ive just been rolling out 21H1.
mavhc Posted November 8, 2021 Posted November 8, 2021 They're all pretty much exactly the same these days, over 1 new features! So yeah, only reason to upgrade is to win the WUfB game
garethEds Posted February 10, 2022 Author Posted February 10, 2022 Would appreciate you detailing your experience if and when you take the plunge @garethedmonson for those of us still dealing with WSUS (and its quirks) and sitting on the fence... let us know if the grass is any greener! Hi @Koldov - Apologies for not getting back to you. Just looking back over old posts and saw that I had not replied. Get in touch if you want info. I'm still working on the project as other things took over but we are set up and are now monitoring with the possibility of making minor changes. Gareth
Koldov Posted February 11, 2022 Posted February 11, 2022 Hi @garethedmondson, No worries, I've had a few other things to take my mind off it too. Honestly, for our small network and few devices I actually have no problem with WSUS and it works really well. I'm used to the interface and like the way I can control (hold, deploy or remove) updates and have quite a detailed view of what's happening. I just wondered if it was just going to be a case of configuring a couple of GPOs I might go for it. Just thought it would be good to remove another role from the server and also have updates still delivered when devices are off-site (as we have a couple of teachers off long-term - and what with isolating and such), but still have control over it.
mavhc Posted February 11, 2022 Posted February 11, 2022 The philosophy of WuFB is: "It's WU, but with a tiny bit more control and reporting. Because just install updates as fast as possible you nutters, the world is full of hackers." 3
garethEds Posted February 11, 2022 Author Posted February 11, 2022 Hi @garethedmondson, No worries, I've had a few other things to take my mind off it too. Honestly, for our small network and few devices I actually have no problem with WSUS and it works really well. I'm used to the interface and like the way I can control (hold, deploy or remove) updates and have quite a detailed view of what's happening. I just wondered if it was just going to be a case of configuring a couple of GPOs I might go for it. Just thought it would be good to remove another role from the server and also have updates still delivered when devices are off-site (as we have a couple of teachers off long-term - and what with isolating and such), but still have control over it. Hi @Koldov, Get in touch when you are ready. The process was quite easy, despite taking time. The last reason you give about off-site devices is one of the reasons I have moved as well. 80 staff laptops than need updating. Gareth 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now