Jump to content

Recommended Posts

Posted
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436

 

WUfB then? But you have to pay for Log Monitor to get reporting.

 

Just seems like the need to increase Azure spending to me.

 

A reply in that link:

 

Anyway, the point is that it doesn't have to be a system that you're responsible for to become your problem. The end of WSUS is a gift to attackers.
Posted
It’s still going to be part of Windows and I believe it is in [emoji638][emoji[emoji6[emoji640][emoji638]][emoji640][emoji6[emoji640][emoji638]]][emoji638][emoji6[emoji640][emoji637]]. But no more development. I don’t believe there has been any for a long time anyway!
Posted
I was a hold-on to WSUS for years, but it was becoming such an unreliable dog. I don’t miss it - changing over to WUfB took less time than it would have taken to even start diagnosing the latest reason why clients weren’t getting updates.
Posted
Still use WSUS here - I've set up WuFB reporting so it's just a case of swapping over for me - But I'm wary as WuFB pushes BIOS updates out and the last thing I want is for kids to randomly knock off PCs in the middle of upgrading..
  • Thanks 1
Posted
BIOS should be under drivers - I turned those off (mainly because Synaptics like to deploy drivers that include the hardware ID for ancient kit that then blue screens when you touch the trackpad).
Posted
Still use WSUS here - I've set up WuFB reporting so it's just a case of swapping over for me - But I'm wary as WuFB pushes BIOS updates out and the last thing I want is for kids to randomly knock off PCs in the middle of upgrading..

 

In Group Policy, you can use "Specify source service for specific classes of Windows Updates" to make sure that computers don't get driver updates from WUfB.

 

IME (Dell, mainly) most BIOS upgrades appear under the optional 'Other updates', and are only installed automatically via WUfB if the vendor has marked them as especially urgent. Also, the older the model, the less likely you are to see firmware updates coming through anyway.

Posted
Still use WSUS here - I've set up WuFB reporting so it's just a case of swapping over for me - But I'm wary as WuFB pushes BIOS updates out and the last thing I want is for kids to randomly knock off PCs in the middle of upgrading..
In Group Policy, you can use "Specify source service for specific classes of Windows Updates" to make sure that computers don't get driver updates from WUfB.

 

IME (Dell, mainly) most BIOS upgrades appear under the optional 'Other updates', and are only installed automatically via WUfB if the vendor has marked them as especially urgent. Also, the older the model, the less likely you are to see firmware updates coming through anyway.

Given the number of zero days vulnerabilities and other critical updates, surely you want bios updated asap?

 

With either GPO or Intune policies you can control WUfB to only restart out off hours - that should prevent the risk of students messing with the power mid update.

Posted

Aye aware I can disable Driver updates to stop BIOS updates but I find that such bad design.

 

A BIOS update is a.. BIOS update. It shouldn't be lumped in with Driver updates.

 

I'm fine for PCs to do driver updates - If anything you want them active so during the OOB experience Windows can pull any missing ones. I just don't want them doing BIOS updates

Posted

We've had pretty good experience with WUfB to be fair, along with driver and UEFI updates working well (presumably that's what people mean when they say BIOS because UEFI has now been the standard for over 10 years I think) - the UEFI update process has been quite robust I've found, more than BIOS updates used to be.

 

Took a bit of tweaking to get 'our config our way' in WUfB but we're pleased with it now and it vastly simplifies deployment and updates for us.

Posted

Same here. WUfB has been really smooth and our machines work better for it. We never did driver or firmware updates through WSUS, so we had a spate of firmware ugrades after the initial switch. If you're concerned about firmware upgrades happening in front of students, then I guess you just need a range of models in a test ring so that you can spot them and get into rooms to nurse the computers through those particular updates.

 

I find that Windows is far smarter these days when it comes to scheduling forced restarts, too. Our workstations just have a couple of policy options set now which govern update scheduling, and computers don't suddenly restart on people in the middle of lesson like we've had in years past.

Posted

Ugh. I've been looking at alternatives for WSUS patching for servers again this morning, and thought great - I'll use WUfB for clients and servers. But noooo MS now charge for ARC servers. We've a lot of on-prem servers across our Trust, so it's unaffordable to pay £3.71 a month per server. Thanks MS - perhaps the £80K I give you each year, isn't quite enough.

 

Sticking with WSUS for servers seems to be the only option right now.

Posted
Ugh. I've been looking at alternatives for WSUS patching for servers again this morning, and thought great - I'll use WUfB for clients and servers. But noooo MS now charge for ARC servers. We've a lot of on-prem servers across our Trust, so it's unaffordable to pay £3.71 a month per server. Thanks MS - perhaps the £80K I give you each year, isn't quite enough.

 

Sticking with WSUS for servers seems to be the only option right now.

 

You can use WUfB to update on-prem servers without needing them to be Azure Arc enabled. It's just that the WUfB reports dashboard only includes data for the Windows client SKUs, so you won't see any of your servers listed in there. Our servers are all using the WUfB Group Policy options for deferral periods successfully. You can ignore the target version option on servers - none of our 2019 servers have upgraded themselves to 2022, for instance.

 

Our monitoring platform includes Windows Updates checks for servers (i.e. which updates they have pending), and our inventory system reports the OS build, which shows me which CU a server has got installed (i.e. build 20348.2700 is Server 2022 with the September 2024 update installed).

  • Thanks 1
Posted

We are looking at getting WSUS and it's resources offsite.

 

What would you select in that policy to say:

 

YES for Quality Updates from WUFB

NO for Driver Updates from WUFB

 

How about Security updates that traditionally in WSUS will be set to auto approve? I also read that specific KB updates can not be removed/blocked using WUFB.

 

Maybe things have changed.

Posted (edited)

Thanks @jthompson. Which monitoring are you using for WU checks?

 

Presume you're able to defer 'dodgy' updates etc, as usual?

 

I'm not that fussed about using Azure for monitoring server updates (especially if I can do it on-prem for free), but I do want auto updates in rings on servers (just WUs, not feature updates or drivers etc), with the ability to pause a dodgy one, without having to use WSUS. If I can still achieve that with WUfB without a charge, then great!

 

Out of interest, have you set up a caching server? We've got a couple of sites with over 1000 devices, so would make sense, even with 1GB synchronous bb.

Edited by lewisburgess
Posted

See https://learn.microsoft.com/en-us/windows/deployment/update/waas-configure-wufb

 

For WUfB you can set a standing deferral period for Quality updates of anything up to 30 days (and also a separate deferral period for Feature updates). If you set a deferral period for Quality updates of, say, 7 days, then the computer wouldn't detect an update until 7 days after it was released by MS. You can use that option to set up your different rings of machines that pick up updates at different stages.

 

WUfB doesn't give you granular controls to hold or reject a specific individual update, but you can pause all Quality updates for up to 35 days, after which updates will automatically begin to flow again. https://learn.microsoft.com/en-us/windows/deployment/update/waas-configure-wufb#pause-quality-updates.

 

To have a computer get Quality updates from WUfB but not other categories of update, in Group Policy you can use "Computer Configuration → Policies → Administrative Templates → Windows Components → Windows Update → Specify source service for specific classes of Windows Updates". That allows you to mix WUfB with WSUS as sources of different categories of update. I should imagine that specifying a phantom WSUS server as the source of driver updates would 'work' to stop any driver updates arriving.

 

I don't have a caching server specifically for updates, but instead use Delivery Optimisation so that machines can p2p share update files over the local network rather than everything hitting the WAN/proxy.

 

I use Checkmk for monitoring. The Windows agent includes a plugin for monitoring Windows Update status, and will indicate which updates are pending and whether or not the machine is needing a restart to complete its updates.

I use GLPI for inventory, and the Windows agent for that will report OS details including the build number (approx every 24 hours be default, but that is configurable).

Posted

I don't have a caching server specifically for updates, but instead use Delivery Optimisation so that machines can p2p share update files over the local network rather than everything hitting the WAN/proxy.

 

Cheers. Don't 'spose you're willing/able to share what you've set for DO in GP? Did you bother to create a Group ID or set any min/max values? Assume you've set the Download mode to LAN (1) only?

Posted (edited)
Cheers. Don't 'spose you're willing/able to share what you've set for DO in GP? Did you bother to create a Group ID or set any min/max values? Assume you've set the Download mode to LAN (1) only?

 

My DO configuration is mainly set to Group (2) mode (I have a fallback policy of LAN mode but pretty much everything will be on mode 2), with then a number of groups, which broadly correlate to one group for each of our school buildings. Since our site has a number of different buildings, they're like spurs on the network, so I wanted to keep DO p2p traffic contained within each of those areas of the network as much as possible (they're not on separate VLANs). There are at least a few staff PCs in each of those areas, which I make sure are picking up updates in advance of the main bulk of computers, so that they can then be an initial source for computers to grab update files from. I'm getting around about 50% bandwidth saving overall, according to WUfB reports, which is not as high as I'd like but it's about as high as I've managed to get it.

Edited by jthompson
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...