Jump to content

Recommended Posts

Posted

This thread is directed particularly to Primary Schools.

 

Visiting a few primary schools who have their systems looked after by outside contractors I have been surprised to see that many XP computers are not patched up to date - most still seem to be on SP2.

 

As this seems to add to the case for in house IT Support I'm trying to get my LEA to do something about this. Any suggestions on a way forward onn this what I suspect is a national situation would be handy please.

 

There just doesen't seem to be any system in place toward ensuring that system security is universally up to date.

Posted

Thanks Sysman-mk,

 

I'm in a fairly unique position being a Tech in a Primary, I do a day a week in another school; but with school budgets under scrutiny nowadays I'm trying to build a case for them keeping me when the axe inevitably hovers!

 

So, I'm not quite sure where I'm going with this. That said I have been surprised when visiting a few other schools in the County to find that their systems are not up to date.

 

Obviously I think ther is a case to say that in house is better able to keep things up to date.

 

 

 

What sort of thing are you looking for?
Posted

I would have thought there's a good case for setting the machines to download and automatically install all critical updates. That way, it doesn't matter how good or bad the support company is; the updates will just be installed.

 

Of course, this might lead to the odd machine failing due to a faulty update but the risk of that is massively less than the risk of an unpatched machine being let loose on the internet!

  • Thanks 1
Posted

@speckytecky: Obviously keeping your machines patched is pretty important but you could argue that, if the machines are working well, it isn't essential.

 

Of course, if you keep a log of all your jobs and can show that installing patches has improved uptime and efficiency, that will help your cause.

 

I think the best angle to take when justifying your job is to show how much work you do and the best way to do this is via a helpdesk system which will also show turnaround times. These times can then be compared to the SLA that a third party company could provide and that would allow an informed decision to be made.

  • Thanks 1
Posted

In my old job I used to hate going into primaries. Even as late as last summer before I left, I would encounter entire suites still on XP SP1. When asked about who provides the tech support they ould often tell me it was a 'local company', which means soemone doing very little and still getting paid, or worse still, no one at all!

What did anger me though was that some had contracts with a well known provider of school IT support in Lancashire, and their machines would still be unpatched 2 years after the 'company' was supposed to be maintaining them.

  • Thanks 1
Posted
I would have thought there's a good case for setting the machines to download and automatically install all critical updates. That way, it doesn't matter how good or bad the support company is; the updates will just be installed.

 

Of course, this might lead to the odd machine failing due to a faulty update but the risk of that is massively less than the risk of an unpatched machine being let loose on the internet!

 

We were effectively doing this with MS updates installed via WSUS. I stupidly presumed all critical updates were fine to install without testing and let IE8 auto-install, which then promptly broke the entire network. Logging on for all staff post-update caused the BSOD and endless restarts; removing IE8 manually fixed the problem.

 

This was a fairly major incident for us and might not have happened had I tested the update first. :(

  • Thanks 1
Posted
You are not alone! I look after 4 primaries and decided to do something about our PC's being out of date, so just set up WSUS at one school and sorted out what was needed (with help for EduGeek) and now I have all four with their own WSUS setup merrily keeping everything up to date. Its fairly easy to set up and only had a few minor niggles so far, pc's reporting they have not contacted the server for x days but know full well they have at some point, but as I say only minor niggles and far out weighs the fact that they were out of date before.
  • Thanks 1
Posted

If you're using WSUS 3.0 then the following script should resolve any of those "workstation has not reported in...." issues.

 

\\\\windowsupdateagent30-x86.exe /quiet /norestart

 

Download the agent here (see More Information for links to download for your environment) and dump it in a share of your choosing.

 

I run it as a startup script. Installs Windows Update Agent which enables the workstation to talk to WSUS.

 

In theory the Update Agent should be installed on the workstation automatically reading from a public area on the WSUS server but I have yet to see a site where this was happening consistently.

 

Depending on your imaging technique you may need to run something like NewSID although the debate rages on whether this actually does anything useful.

  • Thanks 2
Posted
Depending on your imaging technique you may need to run something like NewSID although the debate rages on whether this actually does anything useful.

 

 

Running Newsid does not reset the required information in the registry for WSUS to work. As I found out to my cost. It can be reset by modifying the registry but I now always use sysprep.

 

Chilbs

  • Thanks 1
Posted

One reason for machines not being up to date on service packs is that they may be a laptop, SP3 will not install even if WSUS delivers it, as it will not run without an external power supply.

 

This does not excuse the fact however.

 

BoX

  • Thanks 1
Posted
Running Newsid does not reset the required information in the registry for WSUS to work. As I found out to my cost. It can be reset by modifying the registry but I now always use sysprep.

 

You're right about newsid not changing the necessary info, but whether or not the WSUS SID is set shouldn't affect getting updates. What it does affect is the reporting - basically, it will look as if only one machine has got the updates but in reality they may all have updated.

 

This is because WSUS is not a push system - Windows Updates are always pulled down by the client. This means that if your WSUS server publishes updates then your clients will pull them down - it's just that you won't know it's worked.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...