Jump to content

Recommended Posts

Posted

Hi all, just looking for a bit of advice.

Does anyone use software for deploying windows updates on demand ?

Currently WSUS works well for clients, i have a group i approve updates for, test on a few workstations before approving for all the clients.

As for servers, due to things that get broken, i manually apply to each server one by one, reboot and test services.

Is there any good software I can use to manage out Trust bank of servers in each school centrally and push updates and remotely reboot immediately , rather than logging onto each server one by one?WSUS is alright to approve the updates but still have to login to each one to force a download, install and reboot.

thanks in advance.

Posted
Desktop Central, now Endpoint Central can do this from Manage Engine.

What kind of pricing are we looking at? Is it per device etc?

Posted (edited)

I manage a fleet of 250+ servers. I use WSUS to fully patch them, including installation and reboot. But the reboot is scheduled overnight. It works great.

 

I do have a test group I use first, if all good then deploy to production. I do have production spilt into groups and patch over a 4 day period. I split servers like domain controllers into seperate groups so they aren’t all offline at the same time.

 

To reboot immediately you could use a tool called batch patch. It can download updates from WSUS, install and reboot right away.

Edited by FN-GM
Posted

Not sure on licensing side on that, know its based on technician login's but not sure if there is a device license. My colleagues deal with that I just use it, cannot fault it one of the best packages I've used. Desktop Central does more than just that but they do have a product called Patch Manager Plus.

 

Worth having a look on their site and having a chat with them, they are helpful.

Posted (edited)
I manage a fleet of 250+ servers. I use WSUS to fully patch them, including installation and reboot. But the reboot is scheduled overnight. It works great.

 

I do have a test group I use first, if all good then deploy to production. I do have production spilt into groups and patch over a 4 day period. I split servers like domain controllers into seperate groups so they aren’t all offline at the same time.

 

To reboot immediately you could use a tool called batch patch. It can download updates from WSUS, install and reboot right away.

 

In my last place we did something very similar. We had different waves for servers so updates were deployed to Test servers first. Then if no issues occurred we moved onto next wave. Each server was set to have specific install week/day/time via GPP. Reboot was configured to happen after the install. Install time was generally set during the night. This meant that we could deploy to Test group and group policy was configured so that you could approve the updates to the whole group, but the servers could install the updates over a week. GPP was configured based on Computer AD groups.

Edited by penfold
Posted
It’s worth adding that if you update your ADMX files there are heaps more options in group policy relating to automating patches.
Posted
I manage a fleet of 250+ servers. I use WSUS to fully patch them, including installation and reboot. But the reboot is scheduled overnight. It works great.

 

I do have a test group I use first, if all good then deploy to production. I do have production spilt into groups and patch over a 4 day period. I split servers like domain controllers into seperate groups so they aren’t all offline at the same time.

 

To reboot immediately you could use a tool called batch patch. It can download updates from WSUS, install and reboot right away.

 

WSUS is alright but its not instant. Yeah i've looked at Batch patch which seems to work and do the job - might purchase this.

Posted
WSUS is alright but its not instant. Yeah i've looked at Batch patch which seems to work and do the job - might purchase this.

 

My question would be, does it need to be instant if these are servers? If you setup the schedule in advance you will have updates being deployed at the same time each month. Just approve from WSUS and systems will download them when available and install at the time you set.

Posted
It’s worth adding that if you update your ADMX files there are heaps more options in group policy relating to automating patches.

 

Good point. Our solution was being used due to legacy servers being in place which couldn't apply all new Windows Update settings. We only needed 1 solution for all servers rather than keeping 2 different methods depending on Server version

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...