Keeping your servers up-to-date with patches


hello all,

please note not wsus question. have installed in our environment , know how use it, or @ least think do. system admin of virtualized environment. our company grows, more , more servers have been built , keeping latest patches has become challenge. looking advice users have more experience here do.

up point, have been updating virtual machines esx(i) hosts. okay when there fewer machines. now, if there 20 or more vms on single host, time consuming. also, add more hosts, fall behind updates. so, thinking can keep on top of better if can separate esx(i) updates windows updates. perhaps can update different group of vms each day. production vms need wait until weekend of course. thinking create new group in wsus has of latest updates approved , move vms group ready each machine. manually approve updates can auto-approve critical updates. 

anyway, of who work in larger environments , keep on top of windows updates servers, how do it? best practices? of our desktop computers automatically install updates in late-night hours cannot servers. let me know if have questions or need more information. help.

-adam

the best way i've found handling spread servers receive updates on days, , servers can allowed automatically install them , reboot, , while need manual intervention.

i assume handle wsus settings via gpo, though if manually via registry still similar, it's more leg work.

rather having single gpo setting when , how install updates, i've split servers across number of ous in ad, , configured gpo each group. each gpo handles day , time updates installed (so there gpo's days throughout week), , whether auto install them (so 2 variations of each day).

then it's matter of deciding servers fit categories. instance redundant servers auto install, configured on different days. likewise servers aren't customer facing, or aren't used @ night can auto install. rest set download , prompt, day they're set download spread out well, they're not doing @ same time.

in case haven't bothered spreading them across multiple time periods throughout night, if have  lot of servers configure option.



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...