Skip to content Skip to sidebar Skip to footer

Right Click to Download Collection Will Already Downloaded Updates Download Again Sccm

Introduction

In Part I I took you lot through configuring the required Server Roles & Features, WSUS Installation and Configuration, IIS settings, Folder Permissions and linking it all up into SCCM.

Now, In Part Ii i'll evidence yous how to deploy updates and properly manage the futurity with ADRs, whilst catering for the past with Baselines.

Handling Windows Updates can be tricky at the best of times.  Timing, testing and the sheer resources to complete that can exist a headache.  Nonetheless by utilising SCCM'south ADRs (Automatic Deployment Rule) and ensuring we are testing on Dev machines first can really accept the strain off.

FYI

I'm going to stick to the easiest base to build from in this guide, and go with a once monthly deployment routine.  Sure products like Endpoint Protection don't fit this then I shan't be covering them.  Also for the sake of simplicity and the length of this web log already, this won't encompass Office 365.

Likewise this mail service has been written over a few months, then please excuse a few time differences in screenshots!

Pre-Read Fabric

If you lot're new to the Cumulative model in regards to Windows 7 and eight.1, or but need a refresher on the naming conventions, I'd advise yous read Microsoft's release here.


What we're going to exercise

Equally hinted in the Introduction, we are going to divide our updates into two categories, and its best you sympathize this first:

Baseline

Covering the past.

A Baseline is a group of updates for a Production that have been released since Solar day 1 of its life wheel, to the electric current day.

For example, Windows 7 was released on 22nd July 2009..  The baseline I would create would concur every relevant not superseded update between and then and today.

We volition create a Baseline for each Product.  one for Windows 7, 1 for Windows ten, 1 for Server 2016, 1 for Office 2013 etc.

These Baselines will and then be deployed to collections containing clients of their relevant OS'.

ADR

Covering the futurity.

An Automatic Deployment Rule is there to create a monthly update packet.  Equally per its name, it will run automatically on a schedule we configure, and go off, download the updates nosotros pre-configured it to, and and then deploy them to the clients we tell it to.

The idea hither is every month you lot every bit an administrator should take very little easily on, and fifty-fifty if you decide to take a vacation, it volition still run on a schedule. (Merely remember to let change management know beginning!).

Collections – Prod & Dev

To actually utilize the ADRs in particular, I'll show you how to deploy your monthly updates to Evolution machines firstly, giving you time to test out the updates for any gremlins, prior to the automated deployment to Production, say, a week subsequently.


Setup Collections

First things first, lets setup those collections nosotros spoke about.  Granularity here is key to having full control later.

I've created a Powershell script which tin do the beneath automatically and configure the folder construction, queries and limiting collections automatically.

Create Windows Update Device Collection Download

Only for an overview:

I'd suggest splitting between Servers & Workstations, then a level deeper by Os:

2017-07-27_20-35-10

Create peak level Server Device Collections which contain all Servers.  1 for Production Servers, and 1 for Development or Pre-Product Servers.

A level down, split your Server OS'south into individual folders and Device Collections.  Then a folder for Server 2016 with Dev and Prod collections.  One for Server 2012 etc.

Gear up the limiting collection for these Bone specific Device Collections to the acme level 'All Server' groups.

Exercise the same for Workstations.  All workstations at the top, with Dev & Prod.  Then each individual OS below that you wish to support.

For the OS specific collections, set a query to ensure only that Bone is included, and set an Include Collections from the Top Level.

Baseline'south

With Products like Windows 10 now being fully Cumulative, there is a off-white statement to say a Baseline isn't required for these, however, i'm going to create 1 for the sake of fullness.  Other products that are not or accept not ever been cumulative, certainly need a baseline created.

We demand to create a baseline for each Product you lot demand to update.  Windows 10, Server 2008r2, Office 2013 etc.

To do this, navigate to Software Library>Software Updates>All Software Updates

Correct of the Search Push, selectAdd together Criteria and add together the below, then hit Search;

Product = Windows ten

AND Superseded = NO

ANDUpdate Classification = Critical Updates

ORUpdate Classification = Definition Updates

ORUpdate Classification = Security Updates

ORUpdate Classification = Update Rollups

ORUpdate Classification = Updates

Please exist very careful with the 'Updates' classification – in many cases this will include 'Preview' of updates. i.eastward adjacent months rather untested updates.

VpxClient_2017-03-30_17-41-07

This will now bear witness yous what should be all applicable updates for the selected Product.

Select a unmarried update in the list, and hit Select All –Ctrl+A.

VpxClient_2017-03-30_17-42-09

Right click > Create Software Update Group

VpxClient_2017-03-30_17-42-49

Give it a sensible name;

"Baseline – Windows 10 Updates – DDMMYY"

VpxClient_2017-03-30_17-45-34
Started this web log quite a while ago…

Earlier you shoot off anywhere else, lets save this Criteria Search so yous don't have to enter them all manually again..

VpxClient_2017-03-30_17-46-16 VpxClient_2017-03-30_17-46-36 VpxClient_2017-03-30_17-47-11 VpxClient_2017-03-30_17-47-29

Now change theProduct in the search and repeat the above for all your Products.

VpxClient_2017-03-30_17-50-04

Id suggest in one case you've done your main Products, you also do a unmarried i for the bottom categories such at Silverlight, Visual Studio etc.

Do the same with the baseline creation but add together multiple Production lines.

VpxClient_2017-03-30_22-48-00

Call it'Baseline – Windows Update – Windows General Products'

VpxClient_2017-03-30_22-49-37

In one case you've finished creating, let's become see what we've created..

Software Library>Software Updates>Software Update Groups

VpxClient_2017-07-27_21-07-26

Equally alluded to at the start of this department, cumulative updates don't really fit into what we're trying to achieve with Baselines, so before going any farther.. I'd propose you view the members of each Update Group and remove whatever Cumulative Updates, or other updates you simply don't desire contained.

VpxClient_2017-07-27_22-24-31.png

Untick Membership;

Download the Baseline'due south

Software Library>Software Updates>Software Update Groups

VpxClient_2017-07-27_21-07-26

So there are all our Baseline's.  But all we've done is collect them all together and given them a name.

Lets Download them…

Correct Click > Download

VpxClient_2017-03-30_22-50-54

Create a new Deployment Package

Requite it the same proper name as the Baseline itself

Set up the Package Source location to theSCCMDeploymentPackage location nosotros created in Part I.

Y'all will need to manually create the folder itself within the location.

VpxClient_2017-03-30_22-52-19

ClickNext and select a Distribution Indicate\Group to send them out to

VpxClient_2017-03-30_22-52-35

Select your Distribution Settings

VpxClient_2017-03-30_22-53-09

Download from the Internet

VpxClient_2017-03-30_22-53-23

Your language preference..

VpxClient_2017-03-30_22-53-58

Summary, and Next to terminate

VpxClient_2017-03-30_22-54-11

This part will have a little while every bit information technology runs through and downloads them all..

VpxClient_2017-03-30_22-54-21

In one case Complete. (Cheque the bottom of this folio for any errors, if in that location are any –i'm looking at yous Windows seven-, and then repeat the procedure again until success).

VpxClient_2017-03-30_23-37-39

You can now check the file location, and you lot will see all your downloaded updates.  Inside each binder you lot'll have the individual .cab files.

VpxClient_2017-03-30_23-38-30

Repeat this process for each of your Software Update Groups..

VpxClient_2017-07-27_21-44-32.png
..Here'south 1 I made before

Deploy the Baseline'due south

Nosotros've grouped them, we've downloaded them, we've distributed them…  Now to deploy them..

We're going to make ii deployments of each.  1 to our Dev collection, ane to Prod.

Right Click > Deploy

VpxClient_2017-03-30_23-42-04

Name it the same again.

VpxClient_2017-03-30_23-44-10

Equally this is the Windows 10 Baseline, select the Windows 10 Device Collection – Dev in this instance.

VpxClient_2017-03-30_23-44-45

Side by side

VpxClient_2017-03-30_23-46-26

Required Deployment

Side by side

VpxClient_2017-03-30_23-48-51

Set to ' Every bit soon as possible '

VpxClient_2017-03-30_23-49-03

Display in Software Eye, and only prove notifications for calculator restarts.

This does what it says on the tin, and is my preferred selection.

Deadline Behaviour

This tin exist used to override whatever Maintenance Windows you take set, by default, you wouldn't apply this.

Device Restart Behaviour

Tick if you want to suppress automated restarts after installation.

Write filter treatment

Windows Embedded devices just

Software Updates Deployment re-evaluation behaviour upon restart

TICK It! – This forces the customer to rescan the device after information technology has restarted for updates.  If you don't tick this, you run the risk of SCCM not beingness aware of updates existence installed later a restart, prior to the next scheduled scan.

VpxClient_2017-03-30_23-49-26

Set alerts if you run across fit..

VpxClient_2017-03-30_23-49-42

Download options.  Most environments will want to Download / download and install.

Read the 2nd to bottom tick box carefully and determine.  If software updates have been deployed to your clients\servers but for whatever reason they cannot access the update from a Distribution Betoken, then you tin allow them to download it from Microsoft Update.

VpxClient_2017-03-30_23-49-55

Select an Existing Deployment Packet

VpxClient_2017-03-30_23-50-25

The correct i nosotros created earlier…

VpxClient_2017-03-30_23-50-48

Set to Download (although we've already done this)..

VpxClient_2017-03-30_23-51-00

Set Language..

VpxClient_2017-03-30_23-51-16

Stop!

Before you lot click adjacent again, hitRelieve As Template

VpxClient_2017-03-30_23-51-30

Relieve asBaseline Default

VpxClient_2017-03-30_23-51-54

ClickSide by side to Finish

VpxClient_2017-03-30_23-52-04

VpxClient_2017-03-30_23-52-14 VpxClient_2017-03-30_23-53-28

Repeat the Deployment again, this time to the Production production specific collection.

Select 'Select Deployment Template' and hit theBaseline Default you created.

Run through all the steps ensuring its correct and end.

VpxClient_2017-03-30_23-57-49

Until you have your Baseline deployed to both your Development and Production Device Collection.

VpxClient_2017-03-30_23-58-22
Repeat the in a higher place for all the Baseline groups y'all accept.

For the Not-Os Specific Software Update Groups like Office, and our Windows General Products Baseline, follow the below.

Use the same Template you created, butdeploy them to the elevation level All Windows Clients& if it applies, ALL Servers.

VpxClient_2017-03-31_00-03-31

This way, our Non-Bone Specific products volition get deployed to all Operating Systems which could house them.


Automated Deployment Rules

So onto patching the future.

In the same vein as Baseline's, we are going to create product specific ADRs.  Each ADR volition so be deployed to our Dev and Prod device collections accordingly.Merely the Prod deployment volition have a delayed release time of 7 days.

This ways, when our ADR runs, it volition automatically release the updates to our Dev devices, then vii days after…once you have thoroughly tested…release to our production devices.

Lets get..

Create a new Automated Deployment Rule

VpxClient_2017-03-30_20-47-47

Give it a logical name – ADR – Windows Update – Windows 10

Description – Windows ten Monthly Updates

Select Scan for a collection to target..

VpxClient_2017-03-30_21-31-53

Select the Development – Windows Updates – Windows ten Collection

VpxClient_2017-03-30_21-32-24

Select Create a new Software Update Grouping and click Next.

VpxClient_2017-03-30_21-32-52

Select Automatically deploy all software updates constitute past this dominion, and approve any license agreements.

VpxClient_2017-03-30_21-34-39

At present we demand to set what criteria we want this ADR to match every time it runs.  i.e, what updates do we want this to find?

Engagement Released or Revised =Last 1 Month

Product =Windows 10

Superseded =No

Update Classification =Critical Updates OR Definition Updates ORFeature Packs ORSecurity Updates ORService Packs ORUpdate Rollups

Fairly self explanatory, when this runs, it'll find any updates released or revised in the last one month for Windows 10 that are not superseded, that lucifer any of those classifications.

You lot can hitPreview here, to see, well a preview of what this criteria currently matches in your update database.

VpxClient_2017-03-30_22-12-20

VpxClient_2017-03-30_21-36-55

ClickNext

VpxClient_2017-03-30_22-12-08

Now for the schedule to run this ADR..

Currently, our Software Update Point Synchronisation takes place belatedly on Patch Tuesday, the 2d Tuesday of the month at 23:00.  Now, nosotros want to give it a few hours to complete earlier nosotros run the ADR.. and so that takes usa into the Second Midweek.  05:00am sounds like a reasonable time to me.

Practise Not Gear up 'Run the rule after whatsoever software update point synchronisation'.

If you practise this, you lot are tethering your ADRs to your Sync and I guarantee you one solar day down the road you lot, or someone else, volition go and manually sync your SUP, unknowingly boot off the ADRs, and with them, deployments.

VpxClient_2017-08-03_20-16-09 VpxClient_2017-08-03_20-16-45

As at the start, we selected the Development collection, nosotros desire these clients to update straight abroad one time the updates take been establish, for this reason selectAs shortly as possiblehere to both Available and Deadline.

VpxClient_2017-03-30_21-40-37

A repeat of settings we configured for baselines before..

VpxClient_2017-03-30_21-42-16

I'd advise you set up to Generate an Alarm hither.  Its good to know every calendar month what the compliance of updates are.  Set information technology to 80 per centum later 7 days, and come across if yous can ramp it upwards to xc-95 over the coming months.

VpxClient_2017-03-30_21-42-53

Download Settings for Clients.  You may have specific requirements for boundaries\fallback, just generally most should gear up this every bit per below.

VpxClient_2017-03-30_21-44-06

Select toCreate a new deployment package with the aforementioned name you gave it earlier.

Place its content in its own folder underSCCMDeploymentPackages with the same name.

VpxClient_2017-03-30_21-55-07

VpxClient_2017-03-30_21-55-27

Select the Distribution Points \ Groups to automatically distribute to when the ADR runs.

VpxClient_2017-03-30_21-57-04

Ready toDownload software updates from the net

VpxClient_2017-03-30_21-57-20

Set your required Languages

VpxClient_2017-03-30_21-57-38

Over again, lets save all this as a Template before going any futher..

VpxClient_2017-03-30_21-57-53

ADR Default

VpxClient_2017-03-30_21-58-29

SelectNext and Closeto stop

VpxClient_2017-03-30_21-58-44

VpxClient_2017-03-30_21-58-59

We now have our showtime ADR.  If you lot select theDeployment Settingstab down the lesser..

VpxClient_2017-03-30_21-59-28

Y'all will see it'southward set to deploy to our Development Windows 10 collection.  This will happen automatically on the schedule we configured.

VpxClient_2017-03-30_21-59-48

So at present lets add to this ADR..

Right click the ADR, selectAdd together Deployment

VpxClient_2017-03-30_22-00-17

Scan for and select ourProduction – Windows Update – Windows 10 drove

VpxClient_2017-03-30_22-00-35 VpxClient_2017-03-30_22-01-01

ClickAdjacent

VpxClient_2017-03-30_22-01-13

Next once more

VpxClient_2017-03-30_22-01-26

Now we want to fix a delay.  We desire to say, 7 Days after this ADR runs, these updates will become available to this collection.

Set theSoftware available time toSpecific Time = 7 Days

VpxClient_2017-03-30_22-02-06

Same settings over again..

VpxClient_2017-03-30_22-02-32

Configure Alerting..

VpxClient_2017-03-30_22-02-54

Download Options..

VpxClient_2017-03-30_22-03-15

Next & Close to Cease

VpxClient_2017-03-30_22-03-27 VpxClient_2017-03-30_22-03-38

Now selecting the Deployment Settings tab will evidence both our deployments.

Like shooting fish in a barrel way for a single ADR to manage the release of updates over a period of fourth dimension to dissimilar collections.

VpxClient_2017-03-30_22-04-00

At present echo this process of ADR creation\deployment for each Product category you take..  Selecting the Template you lot created earlier to save a few push button presses, and ensuring you alter\select the correct reference collection each time.

VpxClient_2017-03-30_22-05-24 VpxClient_2017-03-30_22-05-54 VpxClient_2017-03-30_22-11-26

Until you lot have an ADR for each Bone y'all need to back up, each with two (or more!) deployments.

VpxClient_2017-03-30_22-24-26

For Function, yous probable want to deploy to the top level collections..  Later all, different Office versions could exist installed on any OS depending on how you manage it.

VpxClient_2017-03-30_22-25-48 VpxClient_2017-03-30_22-26-21 VpxClient_2017-03-30_22-26-47

Have Office on Servers too?  Ok.. add in more than deployments..

VpxClient_2017-03-30_22-30-54

Now for our Windows Full general Products, which we covered in Baselines.  Create an ADR in the same way, selecting the Top Level collections.

VpxClient_2017-03-30_22-36-09

Only add in the Product categories here that you need to cover..

Silverlight, Visual Studio 2012, Report Vieweretc

VpxClient_2017-03-30_22-37-29

Once complete, you will take a nice selection of ADRs that will practice their business on the schedule y'all configured.

Nevertheless, should you be impatient (winadmins slack members 😉) then y'all can select the ADRs and hitRun Now.

Expect this to take a little fourth dimension whilst they run..

VpxClient_2017-03-31_00-07-27

In one case consummate, underDeployment Packages, you lot volition exist able to encounter your ADRs and Baselines all together.

VpxClient_2017-03-31_00-06-56

UnderSoftware Update Groups you lot can run across the groups, per month in the case of ADR's for what has been created.

VpxClient_2017-08-03_20-00-50

On each Software Update Group, y'all can see their deployments, and the dates for which they will get available to the targeted clients.

Check the 'Deployed On' time here.  My single ADR sent updates to my Development machines on 02/08/2017 (yesterday at time of writing), but the deployment to Production won't happen until 09/08/2017!

VpxClient_2017-08-03_20-03-12

And lastly, for those of yous following forth with my naming conventions, you tin can now easily search the deployments monitoring to run into customer status for Baselines and ADRs akin.

VpxClient_2017-08-03_20-04-14

Conclusion

And so we've patched our products for all updates released and so far with Baseline's and we've covered future releases with ADRs, whilst at the same time giving ourselves flexibility to run granular tests per OS \ Product.

As I continue this series, I'll demonstrate how this granularity and separation can exist your best friend in times when y'all exercise notice problems with updates or you just need slightly more detail in monitoring.

In Function III i'll cover Client Settings, Maintenance Windows, Group Policy configuration and HTTPS.

Thank you for reading, I hope this has helped yous, and a personal thank you to the WinAdmins SCCM Slack group for nagging me enough to consummate this blog! – If you're not a member already, I highly suggest you join!

Rich Mawdsley


walkerclon1975.blogspot.com

Source: https://richmawdsleyblog.wordpress.com/2017/08/04/configuring-wsus-with-sccm-current-branch-server-2016-part-ii-adrs-baselines/

Post a Comment for "Right Click to Download Collection Will Already Downloaded Updates Download Again Sccm"