Solved

security patch approval for windows servers

Posted on 2015-02-20
6
99 Views
Last Modified: 2015-03-11
I have no experience with WSUS, but ran some baseline security analyser reports the other week. It lists a number of updates missing, that are confirmed as missing, and also have not been approved by the systems admin.

What does this actually mean, is this some form of approval on the server itself, or is this a stage within WSUS? I didnt realise the software was checking WSUS, I thought it was just scanning the server itself, so I was unsure where the "approval" thing comes in.
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 1

Accepted Solution

by:
LukeMo earned 167 total points
ID: 40620728
Yes, even with automatic approvals, some updates require you to accept licensing terms.   You'll find those in the WSUS control panel.    
Once approved for install, do a manual sync and then you'll see those start to download.    Once downloaded the clients can then take their updates.
0
 
LVL 3

Author Comment

by:pma111
ID: 40620778
so the approval happens in WSUS, and not on each individual server by a systems admin? Until approved in WSUS they wont be deployed to the Server's?
0
 
LVL 10

Assisted Solution

by:Muhammad Mulla
Muhammad Mulla earned 167 total points
ID: 40620930
That's correct. The reason is that the approval is required for the download from  Microsoft. The WSUS server acts as a proxy (not in the technical/network sense) for updates.
0
Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

 
LVL 11

Assisted Solution

by:Manjunath Sullad
Manjunath Sullad earned 166 total points
ID: 40621025
As suggest by extpert, First you need to approve the security patches from WSUS server, then it will sync with Microsoft server.

After approving, Clients will be able to discover these patches.
0
 
LVL 3

Author Comment

by:pma111
ID: 40624099
Where exactly does wsus download the patches from?
0
 
LVL 1

Expert Comment

by:LukeMo
ID: 40624120
By default it gets them from Microsoft's servers.   You can also configure it to download from another WSUS server that you specify.
0

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
Read about achieving the basic levels of HRIS security in the workplace.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question