Jump to content

Recommended Posts

Posted

Hi all,

Looking to manage Windows Updates within an ICT Suite environment.

The IT Teachers do not want Windows Update to disrupt teaching and learning which is a fair point.

 

Currently got an active hours policy set at 8am-5pm. Machines will not auto-restart during these hours, so as long as they're not rebooted, all should be fine.

I have WoL in place booting my machines at 6:57am

Windows Update policy kicks in at 7am and installs/updates and reboots if needs be. All good on this front.

 

The problem I have is during the day, if Class A turns off the devices when finished, then Class B come into the suite, it is going to install updates upon boot because on the previous power cycle an update may of been pending because I cannot find anything to dictate to tell my clients "do not go searching for updates at a certain time". The Microsoft Update guidance only specifies policies I can enforce to prevent auto-restarts, nothing on auto-installs. The solution would be if I could implement a policy which disregarded Windows Updates for my active hours specified, but Microsoft do not offer this as far as I can see.

 

I might look into ActionOne (free for up to 100 devices) hopefully this has better management.

 

Keen to know how this is managed elsewhere.

Reading this back I sound like a mad man!!

 

Thanks in advance

Posted

I thought if you configured active hours WUfB only installed updates outside of that, even if the PC is restarted. Maybe my users are more patient than I thought as no one has complained.

 

As an alternative, you could remove the option for students to restart or shutdown the PC.

Posted

Disable shutdown, only allow sleep.

 

I stopped the power button doing anything, because when told to log off they'd just press the power button

Posted
One approach I've used in the past (and I'm assuming would still work with 10/11) is to set a BITS throttling policy to prevent the clients from downloading the updates during the day.
  • Thanks 1
Posted
With WSUS I set all the disruptive activity overnight for desktops. For laptops that can’t WOL, I drip updates through singly. All of that after having tested the updates on the IT team for a week first.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...