Solved

security patch approval for windows servers

Posted on 2015-02-20
6
87 Views
Last Modified: 2015-03-11
I have no experience with WSUS, but ran some baseline security analyser reports the other week. It lists a number of updates missing, that are confirmed as missing, and also have not been approved by the systems admin.

What does this actually mean, is this some form of approval on the server itself, or is this a stage within WSUS? I didnt realise the software was checking WSUS, I thought it was just scanning the server itself, so I was unsure where the "approval" thing comes in.
0
Comment
Question by:pma111
6 Comments
 
LVL 1

Accepted Solution

by:
LukeMo earned 167 total points
ID: 40620728
Yes, even with automatic approvals, some updates require you to accept licensing terms.   You'll find those in the WSUS control panel.    
Once approved for install, do a manual sync and then you'll see those start to download.    Once downloaded the clients can then take their updates.
0
 
LVL 3

Author Comment

by:pma111
ID: 40620778
so the approval happens in WSUS, and not on each individual server by a systems admin? Until approved in WSUS they wont be deployed to the Server's?
0
 
LVL 9

Assisted Solution

by:Muhammad Mulla
Muhammad Mulla earned 167 total points
ID: 40620930
That's correct. The reason is that the approval is required for the download from  Microsoft. The WSUS server acts as a proxy (not in the technical/network sense) for updates.
0
Free book by J.Peter Bruzzese, Microsoft MVP

Are you using Office 365? Trying to set up email signatures but you’re struggling with transport rules and connectors? Let renowned Microsoft MVP J.Peter Bruzzese show you how in this exclusive e-book on Office 365 email signatures. Better yet, it’s free!

 
LVL 11

Assisted Solution

by:Manjunath Sullad
Manjunath Sullad earned 166 total points
ID: 40621025
As suggest by extpert, First you need to approve the security patches from WSUS server, then it will sync with Microsoft server.

After approving, Clients will be able to discover these patches.
0
 
LVL 3

Author Comment

by:pma111
ID: 40624099
Where exactly does wsus download the patches from?
0
 
LVL 1

Expert Comment

by:LukeMo
ID: 40624120
By default it gets them from Microsoft's servers.   You can also configure it to download from another WSUS server that you specify.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

A brand new malware strain was recently discovered by security researchers at Palo Alto Networks dubbed “AceDeceiver.” This new strain of iOS malware can successfully infect non-jailbroken devices and jailbroken devices alike.
This story has been written with permission from the scammed victim, a valued client of mine – identity protected by request.
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now