Re: Patch Management GPO Question

Tech-Archive recommends: Speed Up your PC by fixing your registry



Lesa H. wrote:

I want to implement a patch management scheme where most of the workstations download and install patches automatically. There may be a few workstations that we shouldn't allow to restart automatically so I need to have those download and notify. Finally, I want the servers to download and notify. I know with SBS if I wanted all the workstations to install and reboot, I could apply a GPO to the SBSComputers under MyBusiness\Computers, but in my scenario this wouldn't work. I plan to link a WSUS GPO for servers to the MyBusiness\Computers\SBSServers since all the servers in the network will have the same setting.

What is the best way to use a group policy to get this setup properly? Is group policy the way to go for this or is there a better way?

SBS2003 R2 and SBS2008 have WSUS3 included, and should have appropriate GPOs in place. If you're running SBS2003 SP1, you would need to install WSUS3 for yourself, and create appropriate GPOs.

You have a couple of ways to implement finer control over the process to deal with a small number of "special cases":

* create a separate group for them within WSUS (keeps the GPO simple), or
* create separate GPOs for them, and use GPO security to restrict which GPO applies to each machine.

--
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.
.



Relevant Pages

  • Re: Downloading critical updates.
    ... install', that would be fine but as there is not, I was hoping for a patch I ... find a definitive list that I could pick the KB fixes and download them. ... workstations but I'm assuming the requirements for server will be different. ... Perhaps the most simple is to use MBSA on a reference ...
    (microsoft.public.security)
  • Re: Patch Management GPO Question
    ... I use a GPO for servers with auto download and notify, ... Then for client PCs, I do auto download and install, but I choose the option to not force a reboot. ... For those who shut down before leaving, rather than just logging out, they get the "Install updates and shut down" option. ...
    (microsoft.public.windows.server.sbs)
  • Re: Patch Deployment
    ... I installed SUS, and configured a GPO. ... person can install program except patch. ... > workstations pull their updates from the SUS server instead of Windows ...
    (microsoft.public.win2000.group_policy)
  • Re: Windows Update Administration
    ... >Our small business has three XP workstations and one 2003 Server joined in a ... Is there a way I can bring the Windows Update under one umbrella - ... >just download once and install on all at once instead of downloading and ...
    (microsoft.public.windowsxp.network_web)
  • Slow GPO Software Install
    ... I am deploying Microsoft .NET 1.1 using GPO. ... it is taking up to an hour to install. ... The workstations are at 10 ...
    (microsoft.public.win2000.group_policy)