Jump to content

Recommended Posts

Posted
Don't know if im just lucky or... but for the last 5? years i've just done the updates day after patch Tuesday and never had any serious issues!

 

Apart from DCs entering a boot loop and several servers requiring rollback when we came in the following morning (affecting lots of organisations, not just us), no I can't say we've had any issues in 5 years.

 

But i'd rather wait for other people to test them first!

Posted
Don't know if im just lucky or... but for the last 5? years i've just done the updates day after patch Tuesday and never had any serious issues!

 

I think it was on Windows 7 when we had an update go out that gave everyone just a black screen instead of the login screen. Fun times.

Posted
So... i'm just lucky then?

 

Either that or we are just overly keen to be guinea pigs for Microsoft. Who needs a QA department when you have end users am I right?

Posted (edited)
Don't know if im just lucky or... but for the last 5? years i've just done the updates day after patch Tuesday and never had any serious issues!

 

Apart from DCs entering a boot loop and several servers requiring rollback when we came in the following morning (affecting lots of organisations, not just us), no I can't say we've had any issues in 5 years.

 

But i'd rather wait for other people to test them first!

 

Previously I hadn't had any major issues that I can recall, maybe some minor ones that just get forgotten about in the 'mists of time' and general multitude of things that need to be dealt with on a daily basis... and I had even set our WSUS to automatically approve everything, lulled into a false sense of security.

 

Until last October onwards and Print Nightmare (oh and we also caught the boot loop too). If you have been fortunate enough not to have been affected, the I.T. gods have truly been smiling upon you.

 

But since then I have decided to wait a while before deploying any new update...

 

EDIT: I asked something similar:

 

http://www.edugeek.net/forums/windows-server-2012/226748-march-updates.html

 

The only issue is that of the various roles/features each of us is using and possibly the amount of different versions of OS.

 

As it shows in the Mega thread on Reddit, things quickly become lost and the same question is asked/answered multiple times. Sometimes the issue only affects a particular client/server version, or maybe just Office/Exchange/DCs/Print Servers/Hyper Vs... and then it becomes difficult trying to get the information you need quickly (I gave up after the first page on Reddit).

Edited by Koldov
Posted

Last 6 months have been a nightmare, with multiple printer nightmare quirks, the exchange issue, and rebooting dcs…

 

I tend to keep an eye on the Reddit mega thread but also take it as a pinch of salt as loads of people panic over the slightest thing

Posted
As it shows in the Mega thread on Reddit, things quickly become lost and the same question is asked/answered multiple times. Sometimes the issue only affects a particular client/server version, or maybe just Office/Exchange/DCs/Print Servers/Hyper Vs... and then it becomes difficult trying to get the information you need quickly (I gave up after the first page on Reddit).

 

If there is anything major, it will normally get added to the intro blurb of the thread to save you reading loads. I also found it useful to put the thread into newest posts first, so I was only reading the current issues.

Posted

I hadn't had a patch issue for about 10 years, I normally test the patches for a week on my home servers and test devices at work before doing the roll out and even these machines have not had a patch related issue for years.

 

Then we got hit with the DC reboot issue and because I had not rolled back a patch for so long I didn't decline it on the WSUS server and got hit again the next day.

Posted (edited)

Thing is, I'm not sure how thoroughly I can test the devices if I'm honest... recently I'd fired up a couple of VM's, but as I didn't make a full separate network for them (so I could issue the updates to them from our WSUS), they aren't DCs and don't have Hyper V machines running on them (as they're Hyper Vs themselves).

 

So for the last couple of issues... completely pointless going to all that effort...

 

EDIT: I have the same issues with backups, everyone says test your backups fully - but how with one physical DC with a few other roles including SIMS/Print Server/DNS/File Storage etc. (yes, I know it's probably not MS recommended/supported) on site am I supposed to test restore a full DC in a production environment...?

Edited by Koldov
Posted
Thing is, I'm not sure how thoroughly I can test the devices if I'm honest... recently I'd fired up a couple of VM's, but as I didn't make a full separate network for them (so I could issue the updates to them from our WSUS), they aren't DCs and don't have Hyper V machines running on them (as they're Hyper Vs themselves).

 

So for the last couple of issues... completely pointless going to all that effort...

 

EDIT: I have the same issues with backups, everyone says test your backups fully - but how with one physical DC with a few other roles including SIMS/Print Server/DNS/File Storage etc. (yes, I know it's probably not MS recommended/supported) on site am I supposed to test restore a full DC in a production environment...?

That was one of the reasons that I virtualized my single physical server at a previous school. I also split it the roles and ran two DCs. This gave me options to update one at a time and do it in working hours as people didn't lose access to stuff. It also meant I could do a proper DR test; I took one of the backups and ran it in Hyper-V on my laptop. Pretty slow, but it did run.
  • Thanks 1
  • 1 month later...
Posted
everyone says test your backups fully - but how with one physical DC with a few other roles including SIMS/Print Server/DNS/File Storage etc.

For me, when it comes to renewing a server at about 5 years, I keep the old server for these types of things. One of my schools now has a few older server, with one being over 10 years old and their other just over 5 years.

  • Thanks 1
Posted (edited)

Yeah, that's a good shout, but unfortunately I have only one school and one server, that was new about 8 years ago maybe (there is zero budget here unfortunately and looking worse every year)...

 

But the one it replaced could only manage Server 2003 due to hardware limitations, I kept it for a bit but had to scrap it eventually as there really was no point keeping it.

 

EDIT: For a minute I thought this was about patch Tuesday! I hadn't seen anyone ranting on here so did mine last night... I thought just my luck there's an issue been found now!

 

EDIT 2: Still would love a sticky at the top of each OS forum... :getmecoat:

Edited by Koldov
  • 3 weeks later...
Posted

This is why for quite some time now I've implemented WUfB and using GPOs, specify that only updates published for more than 30 days can be installed. This is regardless of location; just anywhere with an internet connection and applies to workstations and servers.

 

It also means you lot are my guinea pigs when it comes to new Microsoft patches :D

Posted
It also means you lot are my guinea pigs when it comes to new Microsoft patches :D

 

Can you still have a central (wsus) server for WuFB?

Posted
Can you still have a central (wsus) server for WuFB?

 

The benefit is you don't need a WSUS server at all - devices communicate with Windows Update directly, but adhere to your set policies.

 

I've had far less issues with WUfB than WSUS to be perfectly honest, plus it's one less VM per site to manage.

 

I did look at making a WSUS server public facing, but there are big question marks over security, you'd need an SSL cert (potentially a small cost), plus you still have to manage that VM.

Posted

Thanks for that.

 

How would i "view" which machines are upto date and ones that aren't. Normally i'd view this in wsus. We're a google school here so use Google workspace not o365. we don't use azure.

 

Cheers

Posted

Have a look here but unfortunately Azure is the most common solution.

 

I guess alternatively you could use a Powershell script to check the Windows version/build.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...