Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Strange problem. I've configure WSUS to approve for detection & installation the following categories; Critical, Security, Service Packs, Update Rollups & Updates. All updates are being approved for detect, but not all for install. Anyone had this? How do I fix it?

 

Thanks...

Posted

Are you making sure that in the Approve for Installation section the Computer Groups you want are selected for patches to install, and is not set to unassigned computers for example.

 

I have mine set to approve and detect cirtical and security patches only.

 

Don't know if that helps??

Posted

I think the problem is that the AutoApproval only works when updates are initially synchronised. When the WSUS server finds out about a new update, it applies the AutoApproval rules then and then only.

 

I tried using the Server Debug Tool to do a resetanchor and then did a synchronize. This caused a lot of new updates to be downloaded (which suggests they got approved), but there are still several hundred which are set to detect only.

Posted
@ajbritton: You can at least do a select all and approve them all at once. You'll just have to remember to check once a month.
Posted
@Ric_: I've never been comfortable doing that because of the warnings about superceded updates. I would have assumed that it was OK to approve all superceding updates whilst removing all superceded updates. There are warnings against doing this in WSUS though.
Posted
I've only seen that happen with MS Office updates and XP SP2. For some reason the WSUS server failed to download the EULA associated with the update and would not let me approve it.
Posted
@Ric_: I've never been comfortable doing that because of the warnings about superceded updates. I would have assumed that it was OK to approve all superceding updates whilst removing all superceded updates. There are warnings against doing this in WSUS though.

 

Here's a quick and dirty way of doing what Ric suggested while still not approving superceded updates. Just column sort based on the "Additional Information" column, the one labelled with "!". You will then have all the different types grouped together.

 

I may be being thick but can someone explain why the August cumalitive update for IE doesn't superced all previous ones? Isn't that what cumalative is meant to mean?

 

Also make sure the superceded updates appear at the top. That way below a certain point you should be 'safe'.

Posted
From what I have seen, the superceded updates cannot be installed anyway. These tend to be DELL drivers that have been updated and then removed and replaced by updates to the updates.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...