Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Microsoft Support > Windows NT/2000/2003 Server/2008 Server
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Windows NT/2000/2003 Server/2008 Server Find support for Windows NT/2000/2003 Server/2008 Server editions.

Reply
 
LinkBack Thread Tools
Old 05-09-2007, 02:07 PM   #1 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


WSUS 3.0 Best Practices

In WSUS 3.0 I do not have the same features at my disposal as I did in previous versions (or maybe I don't realize it). I can see all the machines and that they need to have 5 updates installed but I cannot see what updates are required by an individual client.

I also noticed there is not "Detect Only" option, is there an equivalent in WSUS 3.0?

How can you prepare for this senario: A new PC had been added to the domain and successfully connected to the WSUS server, however you don't know what updates are needed that you may have previously declined because all the computers in the domain before this new one did not need the update. I would always use the "Detect Only" option left for every update and if a new machine was connected I could approve the updates that were needed.

What is the best way? Approve every update?
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 05-09-2007, 02:19 PM   #2 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


Re: WSUS 3.0 Best Practices

If an update is declined will there be somewhere that tells you that the declined update is needed?
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-10-2007, 01:04 AM   #3 (permalink)
Registered User
 
MAQ_FR's Avatar
 
Join Date: Mar 2005
Location: Switzerland (origin: Scotland)
Posts: 134
OS: WinXP pro: 2003 Server: 2008 Server: RHES 4


Re: WSUS 3.0 Best Practices

Hi Newhouse

One of our people had an issue similar to this just before Xmas, and I don't know if they actualy sussed it out (or if it was identical).

I did a bit of digging and i found this in Technet:

"Q. What do the different update approval options mean, such as Detect Only, Not Approved, Install, Declined, and Remove?

A.

Only updates that have the approval status Install will be downloaded to computers served by WSUS. By default, Critical and Security updates are already approved for detection (Detect Only), which means WSUS will determine if these updates are needed by any of your computers. These updates will still need to be approved for Install before WSUS downloads them to your computers.

All other new updates will show up as Not Approved until you decide to approve them for Install or decline them with the Declined approval. (You can also approve them for Detect Only or Remove). If you decline an update, it will no longer appear in your list of updates unless you filter by All updates or Declined updates. Remove will remove updates from computers that already have the update installed, providing that the update is compatible with this feature. For details, see the Installation Information on the Details tab of the update. "

Its all here :

http://www.microsoft.com/technet/win...uate/faqs.mspx

but you've probably seen this.
__________________
regardz à tous

Maq
MAQ_FR is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-10-2007, 04:46 PM   #4 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


Re: WSUS 3.0 Best Practices

What is required to run WSUS 3.0? All downloads on this months secuirty updates list did not download to the clients successfully. Is there a client install required?
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-10-2007, 05:15 PM   #5 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


Re: WSUS 3.0 Best Practices

Communication error was due to the SSL configuration, since we are downloading the updates internally this should not be an immediate problem. But I will look at why this failed.

How would you configure the update server to ensure that all machines are scanned and all applicable updates are approved, even ones that are behind on the image. Leave them all un-approved?

Take this for example, right now all PC's have SP2 insalled, but so the SP2 update is declined, if I bring a new machine in and SP2 is not installed, I want WSUS to tell me that and deploy that update or go to the machine and install it myself.

I could run MBSA scans and verify the updates against MS servers, but I would expect WSUS to tell me this.

There is no Detect Only feature in WSUS 3.0!!
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-11-2007, 01:04 AM   #6 (permalink)
Registered User
 
MAQ_FR's Avatar
 
Join Date: Mar 2005
Location: Switzerland (origin: Scotland)
Posts: 134
OS: WinXP pro: 2003 Server: 2008 Server: RHES 4


Re: WSUS 3.0 Best Practices

Hi Newhouse, I'm sorry, but as I said, I don't use WSUS enough to know much more about it, and our guy is working in the far east at the moment.
But hey I found this........

http://www.microsoft.com/technet/pro....mspx?mfr=true

for the client: WUA 3.0 Is Required

The WUA 3.0 client is required on clients to connect to the WSUS 3.0 server and retrieve the list of software updates that need to be scanned for compliance assessment. During initial setup for Configuration Manager client computers, WUA 3.0 is installed, if not already present. WUA 3.0 is available on the Configuration Manager 2007 CD at \SMSSETUP\CLIENT\<platform>. For information about how to verify the WUA version on client computers, see How to Check the Windows Update Agent Version on Clients.

I also found this interesting, I think you need SMS2003..........

No Microsoft Office updates are displayed when you use Microsoft Update or Windows Server Update Services

Basically, for all updates installed from a patched admin install point, you will not be able to use the ITMU to detect and deploy patches to that product. "Patched admin install point" means an admin install point that you have updated (e.g. with a service pack or hotfix using a .msp file).

From Microsoft KB article:
This behavior occurs if a client computer uses an update from an administrative installation point as the installation source. Updates can only be correctly detected by Microsoft Update or by WSUS if the updated were applied directly to a client computer and not to an administrative installation point.

Microsoft Update or WSUS can be used to update a client computer only if the installation source has not been updated.

The workaround for this issue is to:
1) Revert the updated admin install point to an unaltered installation source, or
2) Continue to detect and deploy updates to Office using the Microsoft Office Inventory Tool for Updates

here: http://www.microsoft.com/downloads/d...DisplayLang=en

It seems to me from your info and what I've found that:
There is no Detect Only feature - so you need SMS2003.

For the clients, see also here:
http://technet2.microsoft.com/window....mspx?mfr=true

hope it helps
__________________
regardz à tous

Maq
MAQ_FR is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-11-2007, 07:21 AM   #7 (permalink)
Member, Networking Team
 
Join Date: Jan 2005
Location: Ohio
Posts: 1,040
OS: Windows Server 2003


Re: WSUS 3.0 Best Practices

I will see what leaving the updates un-approved will do. I think if I can get to a point where all updates are unapproved, I can eventually get to the point where updates that have not been downloaded are still utilizing the "detect only" feature and the others will have been downloaded and approved for install already.
__________________
Because you can read this thank a teacher, because it's English thank a soldier.
newhouse1390 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 06:02 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85