From a network administrator perspective, can you think of any real logic why an organization may not apply Microsoft security updates to their test servers? I have been doing some analysis of last updates applied to all servers in a domain, and the common theme on those ‘behind’ seem to be they are test environments for some of our line of business applications. I haven’t had chance to query this with the team who look after the servers as yet but I was interested if you had any theories and/or if this is fairly common?
Additional info: I did check the server OS installed on the systems with no recent updates, as my initial thoughts were those without updates may be unsupported Windows versions which no longer receive updates from Microsoft, hence the lack of recent patching activity, but that doesn't seem to be the case (2012 R2, 2016, 2019 - same product installed on other servers in the domain with recent patches applied).
Our community of experts have been thoroughly vetted for their expertise and industry experience.
The Distinguished Expert awards are presented to the top veteran and rookie experts to earn the most points in the top 50 topics.