Solved

Microsoft Update KB956391 breaks Reporting Services ReportViewer

Posted on 2008-10-27
8
1,372 Views
Last Modified: 2012-06-21
Not that  familiar with GPOs in AD? I need to find away to block the following update from installing on Our City computers. Can you find an answer for this?

Microsoft Update KB956391 breaks Reporting Services ReportViewer
0
Comment
Question by:dharnet
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
8 Comments
 

Author Comment

by:dharnet
ID: 22817240
Can you suggest me how to restrict only one particular microsoft update to be blocked through GPO active directory for all computers.

Microsoft Update KB956391 to be restricted to all computers.
0
 
LVL 8

Accepted Solution

by:
pzozulka earned 300 total points
ID: 22817391
I don't know if blocking an MS update in ADUC or GPO is possible. This sounds like something that can be easily done in WSUS. In your WSUS server locate the MS Update by either searching for it, or locating it through the tree structure of security updates. Open the MS update, and select "Decline" for all computers (Assigned & Unassigned).

I tried searching for KB956391 in WSUS and it found it in our system, however, I could not locate it in the tree structure under updates. Strange. Either way, it was not applied to our SQL reporting server. I will try to Decline it as well.
0
 
LVL 23

Assisted Solution

by:Malli Boppe
Malli Boppe earned 200 total points
ID: 22819364
0
Major Incident Management Communications

Major incidents and IT service outages cost companies millions. Often the solution to minimizing damage is automated communication. Find out more in our Major Incident Management Communications infographic.

 

Author Comment

by:dharnet
ID: 22823467
I installed WSUS on IIS server machine how do we manage WSUS while connecting to server finding problem where port is 80  suggest me ! Through WSUS I need to stop the Microsoft Update KB956391 breaks Reporting Services ReportViewer.
0
 
LVL 8

Assisted Solution

by:pzozulka
pzozulka earned 300 total points
ID: 22824742
Open WSUS. In the left panel, expand Computers. This will list all the computers listed in the Active Directory structure. Find your server in that list.

However, I recommend going directly to the updates by Expanding the Updates, and declining the update directly. Unless mboppe's solution helped. I recommend trying his recommendations first. His solution offers a fix as in my solution offers a work around.
0
 

Author Comment

by:dharnet
ID: 22824805
On WSUS. In the left panel, expand Computers. there is no computers it shows. ?

0
 
LVL 8

Assisted Solution

by:pzozulka
pzozulka earned 300 total points
ID: 22826929
You need to create a GPO for a computer group to point to the WSUS server to retrieve updates:
Computer Configuration > Administrative Templates > Windows Components > Windows Update:
"Specify intranet Microsoft update service location" = Enabled

Specifies an intranet server to host updates from the Microsoft Update Web sites. You can then use this update service to automatically update computers on your network.

This setting lets you specify a server on your network to function as an internal update service. The Automatic Updates client will search this service for updates that apply to the computers on your network.

To use this setting, you must set two servername values: the server from which the Automatic Updates client detects and downloads updates, and the server to which updated workstations upload statistics. You can set both values to be the same server.

If the status is set to Enabled, the Automatic Updates client connects to the specified intranet Microsoft update service, instead of Windows Update, to search for and download updates. Enabling this setting means that end users in your organization don't have to go through a firewall to get updates, and it gives you the opportunity to test updates before deploying them.

If the status is set to Disabled or Not Configured, and if Automatic Updates is not disabled by policy or user preference, the Automatic Updates client connects directly to the Windows Update site on the Internet.

Note: If the "Configure Automatic Updates" policy is disabled, then this policy has no effect.

ALSO:  "Enable client-side targeting" = Enabled
Target Group Name for this Computer = "DomainExample" <-- This is the name that is going to show up under computers when you expand the computer node in WSUS.

Specifies the target group name or names that should be used to receive updates from an intranet Microsoft update service.

If the status is set to Enabled, the specified target group information is sent to the intranet Microsoft update service which uses it to determine which updates should be deployed to this computer.

If the intranet Microsoft update service supports multiple target groups this policy can specify multiple group names separated by semicolons. Otherwise, a single group must be specified.

If the status is set to Disabled or Not Configured, no target group information will be sent to the intranet Microsoft update service.

Note: This policy applies only when the intranet Microsoft update service this computer is directed to is configured to support client-side targeting. If the "Specify intranet Microsoft update service location" policy is disabled or not configured, this policy has no effect.

Create Computer Groups for Computers:
http://technet.microsoft.com/en-us/library/cc708446.aspx

Step-by-Step Guide to Getting Started with WSUS:
http://www.microsoft.com/downloads/details.aspx?FamilyID=28C43D57-2E15-47B2-9A6F-1514AA3ED05F&displaylang=en
0
 
LVL 23

Assisted Solution

by:Malli Boppe
Malli Boppe earned 200 total points
ID: 22827233
Do you really don't want to install KB956391. By not installing it you might get into other problems.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
2008 R2 Domain Controllers Not Connected for a few hours due to move 6 49
Recover from a ISCSI Share In Windows 2 68
Server 2016 FTP 5 23
temp profile 5 21
It’s been over a month into 2017, and there is already a sophisticated Gmail phishing email making it rounds. New techniques and tactics, have given hackers a way to authentically impersonate your contacts.How it Works The attack works by targeti…
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question