ITGURU Posted October 28, 2024 Posted October 28, 2024 I read that WSUS will be phasing out. What is everyone using in place of this for local AD connected machines to approve and manage updates? Any associated costs?
mullet_man Posted October 28, 2024 Posted October 28, 2024 I read that WSUS will be phasing out. What is everyone using in place of this for local AD connected machines to approve and manage updates? Any associated costs? We ditched WSUS/SCCM updates a while ago and moved to WUfB via Intune. Not had any issues to be honest and you get bios and driver updates if you want. Plus updates work off site which is good for us as sometimes staff laptops can be at home for long periods so they get updates still. I just update our servers manually each month.
ITGURU Posted October 28, 2024 Author Posted October 28, 2024 We ditched WSUS/SCCM updates a while ago and moved to WUfB via Intune. Not had any issues to be honest and you get bios and driver updates if you want. Plus updates work off site which is good for us as sometimes staff laptops can be at home for long periods so they get updates still. I just update our servers manually each month. Is there a cost for WUFB and how do machines get enrolled when attached to local AD?
3s-gtech Posted October 28, 2024 Posted October 28, 2024 No cost. They don’t enroll. They just check in with Windows Update, using the settings you specify with Intune or GP. Massively simpler. No management or approvals like WSUS.
ITGURU Posted October 28, 2024 Author Posted October 28, 2024 No cost. They don’t enroll. They just check in with Windows Update, using the settings you specify with Intune or GP. Massively simpler. No management or approvals like WSUS. Currently i approve updates to a subset of machines before deploying across 2400 endpoints. can you do that with WUFB or do all machines just check in and download automatically? Seems all the new products are unfinished with lack of the features in the current/legacy applications.
3s-gtech Posted October 28, 2024 Posted October 28, 2024 There are update rings, so you can choose how advanced or held back you choose for those machines. It’s much less feature rich, but also a massively reduced admin burden and far less bloody complex. I kept WSUS for years, but the ******* broke one two many times. 1
jthompson Posted October 28, 2024 Posted October 28, 2024 With WUfB you can use Grou Policy to specify how many days (up to 30) quality updates are deferred by. That allows you to phase your updates. I use WUfB on servers now, too. Windows 10 and 11 clients can be configured with an organisation ID so that you can see reporting of updates in an Azure dash (known as "Windows Update for Business reports"). Servers OS's aren't included in WUfB reports, so you need to find your own way of monitoring updates on servers. There's Azure Update Manager for doing that, but that's not free for on-prem servers any more.
mullet_man Posted October 28, 2024 Posted October 28, 2024 There are update rings, so you can choose how advanced or held back you choose for those machines. It’s much less feature rich, but also a massively reduced admin burden and far less bloody complex. I kept WSUS for years, but the ******* broke one two many times.I had WSUS with SCCM and my update folders would never clean out old updates so every so often it would get full and break the ADRs. Moving to WUfB has been a massive reduction in admin. The one thing I need to maybe get my head around is delivery optimisation and clients sharing the load of downloading updates.
supportman Posted October 29, 2024 Posted October 29, 2024 Ditched it years ago, we just Auto update these days. We have a registry key to stop major updates such as windows 10 to 11 . Having granular control used to great, but over complicates things now I think.
jthompson Posted October 29, 2024 Posted October 29, 2024 The one thing I need to maybe get my head around is delivery optimisation and clients sharing the load of downloading updates. Good point, I would second that too. Windows 11 24H2 now has checkpoint updates, which are meant to serve as differential updates from one monthly update to another, rather than each one being entirely cumulative each time. I'm not sure exactly how that will play out in terms of DO and bandwidth savings, but I would imagine that if the bulk of the fleet keeps pace with updates each month, then there'll be a significantly lower volume of downloads/peering going on.
Jobos Posted October 31, 2024 Posted October 31, 2024 Been looking at this too and would anyone be willing to share their WUfB policies?
User3204 Posted November 12, 2024 Posted November 12, 2024 Does anyone have a guide to WUFB? We're using WSUS, and apart from having to rebuild it every so often, it's been fine. I've tried to get a couple of test machines to connect to WUFB, but I can't see them appearing in any logs on Entra. If I run the PSwindowsUpdate command "get-wuservicemanage", it says I'm using "Microsoft Update", but unmanaged. I've been scrabbling around various web sites, but they all seem to be against older versions of this, as the console on Entra looks different to mine.
jthompson Posted November 12, 2024 Posted November 12, 2024 AFAIK, you'll only see WUfB reporting in the Windows Update for Business reports workbook. portal.azure.com/home -> Monitor -> Workbooks -> Windows update for Business reports (under the Insights group). Or alternatively, http://aka.ms/wufbreports If there's some other console that you're looking at (Azure/Entra is a tangled mess of menus imho), I don't know what that'd be.
Jobos Posted November 12, 2024 Posted November 12, 2024 Does WUfB work with all versions of windows or just the latest versions?
jthompson Posted November 12, 2024 Posted November 12, 2024 I should imagine that it works for all currently supported versions. Certainly working for Win 10 Edu 22H2 as well as Server 2019 and Server 2022. Note that the WUfB reports dashboard doesn't ingest or present any stats from Windows Server OSes, just the client SKUs. You can still use WUfB Group Policy options to set the deferral periods, etc on Windows Servers. On the Windows Server side there is also Azure Update Manager, which offers more control and reporting, but you need to pay to manage on-prem servers with that.
harold_dawg Posted November 14, 2024 Posted November 14, 2024 I use manage engine patch manager plus. It is free for up to 25 devices.
mullet_man Posted November 20, 2024 Posted November 20, 2024 One thing to look out for, I've had a bit of an issue we use Office 365 for staff and 2021 for students and I pushed out a setting which set the channel for updates but if a student device received a channel setting then Office 2021 wouldn't do any updates. Took me a while to work this out and found a post on Reddit with someone having the exact same symptoms as me. Just thought I'd post it in case anyone runs into any issues.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now