Warwick_Tech Posted January 5, 2022 Posted January 5, 2022 So my WSUS server is playing up again, even with the awesome ajtek script - I decided to do a rebuild onto server 2022 but it still crashes with 'Server Node Error' even when thinking about only a few machines at a time. Anyone done the jump to ditching this frankly outdated method of updating? I know SCCM and Azure offer an alternative, but I don't really want to go through the bother of setting up SCCM just for WSUS (Still use WDS for new builds) I assume it's just a case of pointing the GPO to online windows instead of internally, but how to prevent 'windows as a service' updates and stick to the current version? what are peoples thoughts?
tmoon-mint Posted January 5, 2022 Posted January 5, 2022 Switched from WSUS to Windows update for business with update compliance last year. Since changing I havent had a single problem with updates. This is what I used to setup update compliance: Get started with Update Compliance - Windows Deployment | Microsoft Docs Windows update for business: Windows Update for Business - Windows Deployment | Microsoft Docs 2
tmoon-mint Posted January 5, 2022 Posted January 5, 2022 WUFB it works using Azure, is it free? We already use Office 365 but it is free to create one if you dont already. Weirdly enough when setting up update compliance I did need to put in credit card details to set it up in Azure however I have never been charged for anything.
chazzy2501 Posted January 5, 2022 Posted January 5, 2022 yeah, I click to get the app from Azure Marketplace, it makes me login to azure (even though, I'm already logged in) it then takes me to a page to buy a trial of azure OR to view azure. I choose view and it takes me to my azure but nothing happens....?
Warwick_Tech Posted January 5, 2022 Author Posted January 5, 2022 yeah, I click to get the app from Azure Marketplace, it makes me login to azure (even though, I'm already logged in) it then takes me to a page to buy a trial of azure OR to view azure. I choose view and it takes me to my azure but nothing happens....? Same here - Wonder if it's worth opening an azure helpdesk ticket?
robyholmes Posted January 5, 2022 Posted January 5, 2022 Removed WSUS here and went to WUfB and Update Compliance (Which you can still use with WSUS by the way, it's just cloud monitoring). We already had an account with Azure with invoicing setup for backups so that made creating the log workspace or what ever they call it setup. 1
Warwick_Tech Posted January 5, 2022 Author Posted January 5, 2022 Looking at this do you need InTune?
Norphy Posted January 5, 2022 Posted January 5, 2022 No. To use Update Compliance, you need an Azure account and you'll need an Azure subscription to set up a log analytics workspace. That workspace doesn't cost anything once it's in place. However, WUfB and Update Compliance can both be configured with a normal group policy if desired, you don't need Intune for that.
HereIGoAgain2601 Posted January 5, 2022 Posted January 5, 2022 Just to say we went to Windows Update for Business on around 1000 devices over 2 years ago and it’s been fantastic, especially with large numbers of staff devices not returning to school for months of end. Some of our trust staff haven’t been into an office since 2020. It’s fantastic and the update compliance is so much more useful and up to date for monitoring purposes. We also had to put credit card in to setup but have never been charged as it is free.
Warwick_Tech Posted January 7, 2022 Author Posted January 7, 2022 yeah, I click to get the app from Azure Marketplace, it makes me login to azure (even though, I'm already logged in) it then takes me to a page to buy a trial of azure OR to view azure. I choose view and it takes me to my azure but nothing happens....? After contacting support they gave me this link https://azure.microsoft.com/en-us/pricing/purchase-options/pay-as-you-go/ Like others said, had to use a credit card, but decline any payment and you're good to go 1
Guest ZFarnworth Posted January 7, 2022 Posted January 7, 2022 Nope. Not yet it’s not stopped working for us yet so we’ll carry on using it until it stops.
MatthewL Posted January 7, 2022 Posted January 7, 2022 We manage our updates using Desktop Central, also is our remote tools, allows us to copy configs, add on for our MDM links to our service desk, updates work quite well there.
Warwick_Tech Posted May 24, 2022 Author Posted May 24, 2022 Necroing an old thread (gotta save that environment) As WUFB has been working fine for a few months, but now I'm getting some odd errors - First off it works and installs everything, but now it can see 21H2 it keeps trying to install, and failing with 0x80246019 I wondered if it was my GPO settings, but then if I have them hidden it should show the yellow '!' not the red 'X' right? Also some of my GPO settings are not there - I did push out 21H1 for W11 yesterday, but where have they gone all of a sudden?
Warwick_Tech Posted May 24, 2022 Author Posted May 24, 2022 Panic over, reloaded them and there they are Of course, this still doesn't answer the question, and why does it say depreciated when that's not selected (?)
Michael Posted May 24, 2022 Posted May 24, 2022 Yes at every site I support - I've previously discussed it on Edugeek. WUfB is definitely the way to go over WSUS. The biggest advantage of course is clients will continue to update outside the four walls of your school or business.
tmoon-mint Posted May 24, 2022 Posted May 24, 2022 (edited) Panic over, reloaded them and there they are [ATTACH=CONFIG]65555[/ATTACH] Of course, this still doesn't answer the question, and why does it say depreciated when that's not selected (?) [ATTACH=CONFIG]65556[/ATTACH] I set a target feature update version rather than using the deferral method. Seems to work fine for me plus it has the side benefit of supressing any Microsoft nagging users to upgrade to Windows 11. Edited May 24, 2022 by tmoon-mint 1
Warwick_Tech Posted May 24, 2022 Author Posted May 24, 2022 I set a target feature update version rather than using the deferral method. Seems to work fine for me plus it has the side benefit of supressing any Microsoft nagging users to upgrade to Windows 11. [ATTACH=CONFIG]65557[/ATTACH] that did it - Thanks
KK20 Posted June 21, 2022 Posted June 21, 2022 can you set a cache server for WUFB or do you only have the update peer to peer requests? Can you set a time for WUFB to start looking for updates or will they come down at any time? I am looking for WSUS replacement this summer so might start a test policy with a room or two on WUFB.
Warwick_Tech Posted June 22, 2022 Author Posted June 22, 2022 can you set a cache server for WUFB or do you only have the update peer to peer requests? Can you set a time for WUFB to start looking for updates or will they come down at any time? I am looking for WSUS replacement this summer so might start a test policy with a room or two on WUFB. It's pretty customisable to be fair (via GPO that is) but not sure about the cache server - I was worried about it strangling our bandwidth too, but I've noticed no difference since ditching WSUS, in fact It's arguably better.
KK20 Posted June 29, 2022 Posted June 29, 2022 we dont have a 1gb connection and I wasnt keen on client machines collapsing the internet on patch tuesday. However, you can cache on a server https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/microsoft-connected-cache with the GPO living in windows components\delivery optimization -> cache server hostname I have a test ring running which seems to work.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now