How to manage Software Updates Using Microsoft System Center 2012 R2 Configuration Manager
Many IT network teams often delay important software updates because they can take up significant time, and may not seem that important. But, consider this is a blunder that may open the door open for hackers to access your private information, putting you at risk for identity theft, loss of money, credit, and more.
Did you hear about Equifax data breach, in which 143 million Americans were potentially affected? There was theft of Social Security numbers, birth dates, and home addresses et etc. A security fix for this was actually available couple of months before the hack, but the company failed to update its software.
Microsoft System Center 2012 R2 Configuration Manager provides a set of tools and resources that can help you to manage software updates enterprise wide. SCCM 2012 R2’s maintenance window; dedicated for software updates installation; lets you configure a general maintenance window and a different maintenance window for software updates. Additionally, you can review the software updates before you create the deployment in the preview window.
This quick guide will help you to deploy software updates using SCCM 2012 R2. As you may know, there are 2 ways to deploy software updates using SCCM 2012 R2, Manual and Automatic. We will focus on manual software updates.
Quick steps for Manual Software updates using MS SCCM. First install the Software Update Point role.
-
Launch the Configuration Manager Console and click on Administration, expand Overview, click Site Configuration.
-
Click on Sites.
-
At the top menu, click on Add Site System Roles.
-
Check Software Update Point and click Next in the next window (From the Add Site System Roles Wizard).
-
It is important to note that WSUS is configured to use ports 8530 and 8531 for client communications. You can specify whether to use the default Internet Information Services (IIS) or create a new custom WSUS website during installation of WSUS. When you use a custom website for WSUS 3.0, WSUS configures port 8530 for HTTP and port 8531 for HTTPS.
-
In next screen, click Use credentials to connect to the WSUS server in WSUS Server Connection Account, click on Set and choose the account.
-
Click Next.
-
In next screen of proxy & account settings, select Synchronize from Microsoft Update and click Next.
-
Select Enable synchronization on a schedule and let the schedule be set to default. You may also click Alert when sync fails on any site in hierarchy.
-
Click Next.
-
In the Supersedence behavior screen, select Immediately expire a superseded software update.
-
Click Next.
-
In classification screen, Select Critical updates, Definition Updates and Security updates.
-
Click Next.
-
In products screen, select all products that you want to sync,
-
Click Next.
-
Select languages,
-
click Next.
-
The Software Update Point role has been installed. Click Close.
-
Click Software Library in the configuration manager console and expand Overview,
-
Click Software Updates in top menu
-
Click All Software Updates
-
Click Synchronize Software Updates at the top menu.
-
Open wsyncmgr.log and WCM.log file to check background processes,
-
When the synchronization is completed, all updates can be seen by clicking All Software Updates option in the Console.
-
You can also add criteria for filtering. Click on Add criteria. Select Expired, Product, Superseded, Bulletin ID.
-
Click Add.
-
Now select all the updates, right click on the updates and click Create Software Update Group.
-
Provide the name to the software update group as desired.
-
Click Create.
-
Click on Software Update Group and you will find the software update group that was created in the previous step. Right click on the created Group and click Deploy.
-
In Deploy Software Updates Wizard, provide a Deployment Name, description and choose the collection for which this software update deployment must be deployed.
-
Click Next.
-
Set the Type of deployment. You can also set detail level to Only success and error messages.
-
Click Next.
-
Configure the schedule for the deployment.
-
Set the local Time.
-
Click Next.
-
On the User Experience page, you can set the restart for Server or Workstations.
-
Click Next.
-
For Deployment options, If the updates are not available with preferred deployment packages then select Download and install software updates from the fallback content source location.
-
Click Next.
-
Create a new deployment package by providing a name, location for the Package source and selecting priority.
-
Click Next.
-
Add the Distribution Point.
-
Click Next.
-
For Download Location choose Download software updates from the Internet.
-
Click Next.
-
Choose the language and click Next. The wizard will now download the updates and deploy them to the collection as per the schedule defined.
-
Click on Close to close the wizard.
-
You can check that the updates are installed on client machines in the collection
-
You may be asked to get system restarted.
-
You may restart the computer by choosing Restart now or you can select to be reminded later.
Source: www.linkedin.com/pulse/quick-enterprises-guide-manage-software-updates-using-ajay-ray/