Link to home
Start Free TrialLog in
Avatar of Abdallla
Abdallla

asked on

Windows Server 2016 - 2019-08 Updates

We configure our SCCM/WSUS to automatically approve the security and critical updates only every month and deploy at maintenance windows managed by SCCM.

this month (08-2019), noticed something strange, as  Microsoft released two security updates first of August,
2019-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4512517)
2019-08 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4512501)

But when checked today for pending updates, I didn't find these updates waiting to install, and I noticed that Microsoft releases new updates superseded the above ones and classified as Update not under security and critical, and for sure it will not download by SCCM as per our configuration, the new updates are
2019-08 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4512509)
2019-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4512495)

More details:
https://www.catalog.update.microsoft.com/Search.aspx?q=2019-08%20update%2Bwindows%20Server%202016

Can anyone helps me/ Explain why this could happen?
Can we consider these updates like security updates and approve it
Avatar of Abdul Jalil Abou Alzahab
Abdul Jalil Abou Alzahab
Flag of Canada image

In my case I configured ADR to exclude superseded update and I add "update" classification to ADR, at the end KB4512509 was available and the superseded updates were removed
Avatar of Abdallla
Abdallla

ASKER

Yes, Abdul Jalil.
we already configure the ADR to exclude superseded update,  this is why its disappeared once new updates release.
but why Microsoft change the classification.
ASKER CERTIFIED SOLUTION
Avatar of masnrock
masnrock
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
thanks masnrock,


we configure SCCM it to install only security and critical updates,  hence when checking for the missing update on the server, it's empty because critical and security updates marked as superseded and we exclude superseded updates from the download.

I want to say that they should have one update for Security and/or critical updates and anther one for all updates.

the security update should be superseded by another security update. ( from the same classification)

but like that, they force me to install non-critical and non-security updates.

hope you got my point
No comment has been added to this question in more than 21 days, so it is now classified as abandoned.

I have recommended this question be closed as follows:

Accept: 'masnrock' (https:#a42935568)

If you feel this question should be closed differently, post an objection and the moderators will review all objections and close it as they feel fit. If no one objects, this question will be closed automatically the way described above.

seth2740
Experts-Exchange Cleanup Volunteer