garethEds Posted September 16, 2010 Posted September 16, 2010 Our WSUS server died the other day and because it wasn't really an important server we didn't bother backing up (wish I had). So I've now rebuilt it - it's downloaded a load of updates that need Allowing but can anyone tell me if I need to go through them all one by one and deny the ones we don't need? As in a virgin install? Our machines all have SP3 and have a good few updates post SP3 so if I do have to Allow them then will the machines know what the need and what they don't? Many thanks Gareth
SYNACK Posted September 16, 2010 Posted September 16, 2010 The machines will just grab what they need of the WSUS server but the WSUS server will grab whatever you tell it to. Given the bandwidth constraints in this counrty I click on the "Updates needed by computers" link in the WSUS summary page which brings up all of the updates that are actually required by the current systems tied to WSUS. Filter it to show only the unapproved ones and then select them all with Ctrl+A, right click and allow those updates for each group of PCs that need them. This way it only downloads and stores what is needed at this time but the clients get all the updates that they need. 1
garethEds Posted September 17, 2010 Author Posted September 17, 2010 The machines will just grab what they need of the WSUS server but the WSUS server will grab whatever you tell it to. Given the bandwidth constraints in this counrty I click on the "Updates needed by computers" link in the WSUS summary page which brings up all of the updates that are actually required by the current systems tied to WSUS. Filter it to show only the unapproved ones and then select them all with Ctrl+A, right click and allow those updates for each group of PCs that need them. This way it only downloads and stores what is needed at this time but the clients get all the updates that they need. Just a quick one in relation to this. All of our machines have turned up in WSUS and I have looked at what updates are needed and Approved them. I now have the following at the top of the Main View window: 1678 security updates are waiting to be approved 247 security updates are waiting to be approved Can all of these be declined as the machines did not need them? Or am I going to have to keep them there just in case we build a machine that will eventually need them? Gareth
sted Posted September 17, 2010 Posted September 17, 2010 have you turned on the default approval rule (or written one) if not nothing will get approved unless you manually aprove it
garethEds Posted September 17, 2010 Author Posted September 17, 2010 have you turned on the default approval rule (or written one) if not nothing will get approved unless you manually aprove it I don't tend to auto-approve anything. I check it once a month (as Microsoft launch their monthlies) or if a security bulletin comes out. I don't want things like the EU Browser thing coming through automatically. Although I may set the auto-approve for the critical things. Does anyone sort their machines into groups or do they have one big network or approval? Gareth
timzim Posted September 17, 2010 Posted September 17, 2010 Can all of these be declined as the machines did not need them? Or am I going to have to keep them there just in case we build a machine that will eventually need them? I wouldn't decline them just in case you need them, as you say. As long as you always filter by Unapproved & Needed they won't show up anyway. If you do add an old machine to your domain which needs a load of old updates they'll suddenly show up as Needed and you can then approve them. 1
pete Posted September 17, 2010 Posted September 17, 2010 In WSUS I have: Guinea Pigs (Get patches first - collection of test XP, 7, 2003 and 2008 vms, plus any workstation numbered *-06 in classrooms) Curriculum Machines Curriculum Laptops Admin Machines Staff Laptops Servers This is mainly testing and when I'm forcing deadlines on patches that fix stuff that's being actively exploited. That way, setting a deadline on curriculum machines (for example) won't affect servers (which download updates, but don't automatically apply).
maxepotter Posted October 14, 2010 Posted October 14, 2010 I have (tried to) run through to uninstall the application, but it still appears. When I try to open the WSUS snap-in from the Start Menu (as shown) I get an error message (also shown). Vlc Player Download
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now