WSUS: always ignore superseded ?

Does this sound ok as a way of making administration of WSUS less onerous:

1.      Unless it’s for software we don’t use (e.g. office 2013 since we are office 2007 users): We shall always approve superseding updates.

2.      We shall always disapprove superseded updates.

3.      Two weeks after Microsoft publishes updates, we will approve all updates (unless for products we don’t use).

4.      Even if ALL pc’s on our network are up-to-date for superseding updates, we will keep that update around until it gets superseded in case we spin up a new pc which has not received the updates yet.

We do realize that we disapprove the superseded updates and have not yet approved the superseding update,  there could be two weeks where the PC’s might be vulnerable.  However, in practice, if a user complies and applies updates and reboots as we release updates, chances are, this should not be a big problem.

Any glaring problems with this strategy?

If there’s a better approach to make WSUS less terrible to administer, I’d love to hear any suggestions.  

Sorry for sounded like such a woose but I hate applying these updates!

Thanks,
Mike
mike2401Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Seth SimmonsSr. Systems AdministratorCommented:
Unless it’s for software we don’t use...

then uncheck that category so it won't look for office 2003

We shall always disapprove superseded updates.

agree. decline updates that have been replaced with something else

Two weeks after Microsoft publishes updates, we will approve all updates

that's more of a business decision but if that works for you, then ok

we will keep that update around until it gets superseded

not sure i understand this one correctly
if you bring up a new system, install the superseded update and not the old one first
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
mike2401Author Commented:
I am so sorry for loosing track of this question.

Your answers make sense,
Thank you!

Mike
0
mike2401Author Commented:
Thank you!

(My EE email notice went into my gmail promo folder which I don't check often :-)
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.