Using WSUS

Posted on 2012-03-22
Last Modified: 2016-02-21
I've completed setting up, configuring and testing my GPO and WSUS installation.  I have approx. 3500 updates that need attention.  Several of them say that they've been superseded.  Is there a cheat sheet somewhere that I can use to approve the updates that have been confirmed safe so I can pare that number down?  

Thank you
Question by:Cloud9RealTime
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
LVL 13

Expert Comment

ID: 37753872
You probably don't need to spend a lot of time trying to figure out what and what not to approve, based on whether a given update has been superceded.  WSUS will figure that out for you.  Approve everything by major category (Windows 7 x64, Office 2010, etc, whatever you're actually running there) and let WSUS do the heavy lifting.  I used to obsess over this and spent hours trying to wade through thousands of updates one by one, then I figured out I really didn't need to worry about it.  As long as you have adequate storage space for all the updates you'll be fine.
LVL 17

Assisted Solution

pjam earned 75 total points
ID: 37753883
Try running the "Server cleanup Wizard" in WSUS.  It will remove superceeded etc, see jpeg
server cleanup wizard

Author Comment

ID: 37757492
Dave: We're a TS environment with 4000+ users on 200+ servers....I'm just concerned about pushing one update out that breaks something and then having to figure out which update caused it to break.  

pjam:  I ran that cleared off about 80 updates :)
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 17

Expert Comment

ID: 37757538
Sorry should have mentioned earlier, have you removed any OS or products you do not need such as Itanium etc in "Products and Calssifications"?
also have you selected Languages in "Update files and Languages"?
LVL 13

Accepted Solution

IT-Monkey-Dave earned 75 total points
ID: 37757652
I get what you're saying. For a while I used my system to test new updates for a week prior to releasing to the general population.  For example you could create a WSUS category of systems "Test", populate it with a few representative test machines, and release to them first.  Then later release to the general population.  I stopped doing that because it just wasn't necessary for us.  We have several different major disciplines like art, programming, design.  The pre-testing never once turned up any issues.  In fact I can't recall a single update that has caused us any problems since we started using WSUS a few years ago.  I do wait about 1 week after the updates are released by Microsoft before I approve them.  That way everyone else on the planet is testing them for us and if something is horribly wrong with a particular update, it will have been outed by then and fixed or recalled by MS.  We review and approve updates on Mondays.
LVL 17

Expert Comment

ID: 37757723
We do not make those decisions locally anymore, as we are now a downstream WSUS.  However I have been a subscriber to Windows Secrets and Langa List before that.
That said, Susan Bradley always has a "Patch Watch" on MS update week recommending updates and recommending which to skip.  Not much help for the bulk you at looking at, but going forward it would be useful.

Author Comment

ID: 37758871
pjam - Yeah, I only have the products that I know for a fact are on our network, but with 3 different server OS's and 2 different MS Office versions, it didn't take long to add up.  Thank you for the Susan Bradley ref....that's added to the bookmarks as we move forward.

Dave - That's pretty much the plan I had come up with...different OU's with different GPO's and drop the computers into the appropriate OU.  Release the updates to a few test servers that run most of the applications on our system and then release them a week later to everyone else.  It looks like doing it with OU's and GPO's is going to be an easier way to manage the groups than anything else.  

Having said all of that, I'm dropping those guinea pigs into an OU today to deploy the updates tomorrow night and I'm going to push everything out and see what happens.  There's too much here to go through them and be selective.  I host over 200 different applications and it's impossible to see how a patch will affect all of them, much less 3500.

Author Closing Comment

ID: 37777529
Appreciate the help from pjam and IT-Monkey-Dave.  I ran the cleanup wizard and am just going to push out all the updates to my farm.  Thanks guys!

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Windows Server Update Service (WSUS) is free for everyone, but it lacks of some desirable features like send an e-mail to the administrator with the status of all computers on the WSUS server. This article is based on my PowerShell script …
What to do when Windows Update is not working correctly? What tools can I use to detect the cause of the malfunction problem? What does this numeric error code mean? These and other questions that you have been asking in the past are answered here (…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question