ITGURU Posted January 12, 2023 Posted January 12, 2023 Hi all, just looking for a bit of advice. Does anyone use software for deploying windows updates on demand ? Currently WSUS works well for clients, i have a group i approve updates for, test on a few workstations before approving for all the clients. As for servers, due to things that get broken, i manually apply to each server one by one, reboot and test services. Is there any good software I can use to manage out Trust bank of servers in each school centrally and push updates and remotely reboot immediately , rather than logging onto each server one by one?WSUS is alright to approve the updates but still have to login to each one to force a download, install and reboot. thanks in advance.
MatthewL Posted January 12, 2023 Posted January 12, 2023 Desktop Central, now Endpoint Central can do this from Manage Engine.
ITGURU Posted January 12, 2023 Author Posted January 12, 2023 Desktop Central, now Endpoint Central can do this from Manage Engine. What kind of pricing are we looking at? Is it per device etc?
FN-GM Posted January 12, 2023 Posted January 12, 2023 (edited) I manage a fleet of 250+ servers. I use WSUS to fully patch them, including installation and reboot. But the reboot is scheduled overnight. It works great. I do have a test group I use first, if all good then deploy to production. I do have production spilt into groups and patch over a 4 day period. I split servers like domain controllers into seperate groups so they aren’t all offline at the same time. To reboot immediately you could use a tool called batch patch. It can download updates from WSUS, install and reboot right away. Edited January 12, 2023 by FN-GM
MatthewL Posted January 13, 2023 Posted January 13, 2023 Not sure on licensing side on that, know its based on technician login's but not sure if there is a device license. My colleagues deal with that I just use it, cannot fault it one of the best packages I've used. Desktop Central does more than just that but they do have a product called Patch Manager Plus. Worth having a look on their site and having a chat with them, they are helpful.
penfold Posted January 13, 2023 Posted January 13, 2023 (edited) I manage a fleet of 250+ servers. I use WSUS to fully patch them, including installation and reboot. But the reboot is scheduled overnight. It works great. I do have a test group I use first, if all good then deploy to production. I do have production spilt into groups and patch over a 4 day period. I split servers like domain controllers into seperate groups so they aren’t all offline at the same time. To reboot immediately you could use a tool called batch patch. It can download updates from WSUS, install and reboot right away. In my last place we did something very similar. We had different waves for servers so updates were deployed to Test servers first. Then if no issues occurred we moved onto next wave. Each server was set to have specific install week/day/time via GPP. Reboot was configured to happen after the install. Install time was generally set during the night. This meant that we could deploy to Test group and group policy was configured so that you could approve the updates to the whole group, but the servers could install the updates over a week. GPP was configured based on Computer AD groups. Edited January 13, 2023 by penfold
FN-GM Posted January 13, 2023 Posted January 13, 2023 It’s worth adding that if you update your ADMX files there are heaps more options in group policy relating to automating patches.
ITGURU Posted January 13, 2023 Author Posted January 13, 2023 I manage a fleet of 250+ servers. I use WSUS to fully patch them, including installation and reboot. But the reboot is scheduled overnight. It works great. I do have a test group I use first, if all good then deploy to production. I do have production spilt into groups and patch over a 4 day period. I split servers like domain controllers into seperate groups so they aren’t all offline at the same time. To reboot immediately you could use a tool called batch patch. It can download updates from WSUS, install and reboot right away. WSUS is alright but its not instant. Yeah i've looked at Batch patch which seems to work and do the job - might purchase this.
penfold Posted January 13, 2023 Posted January 13, 2023 WSUS is alright but its not instant. Yeah i've looked at Batch patch which seems to work and do the job - might purchase this. My question would be, does it need to be instant if these are servers? If you setup the schedule in advance you will have updates being deployed at the same time each month. Just approve from WSUS and systems will download them when available and install at the time you set.
penfold Posted January 13, 2023 Posted January 13, 2023 It’s worth adding that if you update your ADMX files there are heaps more options in group policy relating to automating patches. Good point. Our solution was being used due to legacy servers being in place which couldn't apply all new Windows Update settings. We only needed 1 solution for all servers rather than keeping 2 different methods depending on Server version
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now