WSUS Windows Update Services

Slides:



Advertisements
Similar presentations
WSUS Presented by: Nada Abdullah Ahmed.
Advertisements

WSUS, MU and WU oh my! SMB Technology Network Susan Bradley, Patchaholic.
Installation and Deployment in Microsoft Dynamics CRM 4.0
Configuring Windows Vista Security Chapter 3. IE7 Pop-up Blocker Pop-up Blocker prevents annoying and sometimes unsafe pop-ups from web sites Can block.
11.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 10: Server Administration.
Week 12 - Lesson 19: Configuring and Managing Updates
SWOCA TSS ACADEMY Implementing Patch Management and Systems Monitoring on Windows Server 2012.
Lesson 18: Configuring Application Restriction Policies
Patching MIT SUS Services IS&T Network Infrastructure Services Team.
Maintaining and Updating Windows Server 2008
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
1 Chapter Overview Introduction to Windows XP Professional Printing Setting Up Network Printers Connecting to Network Printers Configuring Network Printers.
VMware vCenter Server Module 4.
Configuring Active Directory Certificate Services Lesson 13.
11 MAINTAINING THE OPERATING SYSTEM Chapter 5. Chapter 5: MAINTAINING THE OPERATING SYSTEM2 CHAPTER OVERVIEW Understand the difference between service.
SUS Services ECE Computer Facilities. SUS Services Software Update Services Microsoft Security And Critical Update Service Microsoft Security And Critical.
Module 16: Software Maintenance Using Windows Server Update Services.
16.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 16: Examining Software Update.
11 MAINTAINING THE OPERATING SYSTEM Chapter 5. Chapter 5: MAINTAINING THE OPERATING SYSTEM2 CHAPTER OVERVIEW  Understand the difference between service.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
Patch Management drill down Steven Hope Lead Technical Security Specialist
Working with Drivers and Printers Lesson 6. Skills Matrix Technology SkillObjective DomainObjective # Understanding Drivers and Devices Install and configure.
Test Review. What is the main advantage to using shadow copies?
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Two Deploying Windows Servers.
IT:Network:Microsoft Server 2 Chapter 27 WINDOWS SERVER UPDATE SERVICES.

Tutorial 11 Installing, Updating, and Configuring Software
Using Windows Firewall and Windows Defender
1 Guide to Novell NetWare 6.0 Network Administration Chapter 11.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
Module 13: Maintaining Software by Using Windows Server Update Services.
Managing and Monitoring Windows 7 Performance Lesson 8.
Network Management Tool Amy Auburger. 2 Product Overview Made by Ipswitch Affordable alternative to expensive & complicated Network Management Systems.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
INSTALLATION HANDS-ON. Page 2 About the Hands-On This hands-on section is structured in a way, that it allows you to work independently, but still giving.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Four Windows Server 2008 Remote Desktop Services,
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
Migration from Software Update Services to Windows Server Update Services Jeff Alexander IT Pro Evangelist Microsoft Australia Scott Korman WSUS MVP SEC316.
1 Chapter Overview Publishing Resources in Active Directory Service Redirecting Folders Using Group Policies Deploying Applications Using Group Policies.
Supporting and Maintaining Desktop Applications Lesson 13.
Updating Windows Vista Lesson 10. Skills Matrix Technology SkillObjective Domain SkillDomain # Understanding UpdatesApply security patches and updates.
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
Module 5: Configuring Internet Explorer and Supporting Applications.
CN2140 Server II Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Troubleshooting Security Issues Lesson 6. Skills Matrix Technology SkillObjective Domain SkillDomain # Monitoring and Troubleshooting with Event Viewer.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Module 8: Managing Software Distribution. Collections Packages Programs Advertisements Collections Packages Programs Advertisements How Software.
Deploying Software with Group Policy Chapter Twelve.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Administering Microsoft Windows Server 2003 Chapter 2.
Optimizing Windows Vista Performance Lesson 10. Skills Matrix Technology SkillObjective DomainObjective # Introducing ReadyBoostTroubleshoot performance.
1 Terminology. 2 Requirements for Network Printing Print server Sufficient RAM to process documents Sufficient disk space on the print server.
…the basics…. Wildland Fire Information and Technology Server Requirements ● Windows 7 Professional or Windows 2003/2008 Server ● Windows 8/10 (discussion)
Internet Explorer 7 Updated Advice for the NHS 04 February 2008 Version 1.3.
Managing Servers Lesson 10. Skills Matrix Technology SkillObjective DomainObjective # Using Remote DesktopPlan server management strategies 2.1 Delegating.
Planning Server Deployments Chapter 1. Server Deployment When planning a server deployment for a large enterprise network, the operating system edition.
ITMT 1371 – Window 7 Configuration 1 ITMT Windows 7 Configuration Chapter 8 – Managing and Monitoring Windows 7 Performance.
CACI Proprietary Information | Date 1 PD² SR13 Client Upgrade Name: Semarria Rosemond Title: Systems Analyst, Lead Date: December 8, 2011.
Maintaining and Updating Windows Server 2008 Lesson 8.
CACI Proprietary Information | Date 1 PD² v4.2 Increment 2 SR13 and FPDS Engine v3.5 Database Upgrade Name: Semarria Rosemond Title: Systems Analyst, Lead.
Fixing Windows 10 Automatic Updates Install Problem
Introduction to Group Policy Lesson 7. Group Policy Group Policy is a method of controlling settings across your network. – Group Policy consists of user.
11 DEPLOYING AN UPDATE MANAGEMENT INFRASTRUCTURE Chapter 6.
Implementing Update Management
Presentation transcript:

WSUS Windows Update Services Robert Cultrara World Health Organization

Purpose of the presentation How to make an assessment of the security on your windows network Get started with Microsoft and Windows update How to install, manage and troubleshoot WSUS How WSUS can be used in a low-bandwidth environment

The problem: Viruses (self inflicted) Worms (network inflicted) *.ware - Malware/Spyware Users countering policy Service and Network Outage (due to saturation and loss)

Microsoft Baseline Security Analyzer (MBSA) MBSA makes an assessment of your windows network security It provides you clear instruction how to make your windows network more secure

Windows and Microsoft updates

WU and MU Windows Update Just patches Windows http://update.microsoft.com/windowsupdate Microsoft update http://update.microsoft.com/microsoftupdate Patches Windows Office Exchange More to come Engine is the same - Troubleshoot the same

MU is optional How to activate Microsoft update

MU steps Accept EULA Need to install software to get it to use it Downloads activeX files \Windows\Downloaded Program Files The following ActiveX controls will be installed: MUWebControl Class WUWebControl Class

Is it safe? If first visit will get ‘authenticode’ prompt

Checking for updates

Two options to install Express Install: This option is recommended and provides the easiest method for installing high priority updates. Custom Install: This option enables a user to select which specific updates are installed.

Better ‘history’ interface

Revert to WU Go back Click on Change settings Check the box

File updated Windows Genuine Advantage control Windows Installer 3.1 Background Intelligent Transfer Service (BITS) update

Auto updates options Download Will allow you to install them at a later time

WSUS How to update an entire network

WSUS installation Install on Windows server As default it goes on port 8530 On standard loads up a MSDE instance Remember …clients may need in registry http://servername:8530, or Group Policy

WSUS: Services √ SUS 1.0 synchronizes with WU Supported Applications Windows Update Microsoft Update Windows (2000 SP3+, XP+, WS2003) √ Office (XP & 2003) SQL Server 2000, MSDE 2000 Exchange 2003 Additional products over time SUS 1.0 synchronizes with WU WSUS synchronizes with MU Both services built on customized version of Windows Update Services

WSUS: How it Works Microsoft Update WUS Server Desktop Clients Target Group 1 Server Clients Target Group 2 WUS Administrator Administrator approves updates Administrator subscribes to update categories Server downloads updates from Microsoft Update Clients register themselves with the server Administrator puts clients in different target groups Clients install administrator approved updates

Update Management Features Target Groups Registry-based policy support for AD environments Server-side lists for non-AD environments Administrator control Initiate scan of machines for patch applicability Approve for install and uninstall (requires update support) Date-based deadlines for approved updates Deploy different updates to target groups Configurable client polling frequency Configurable reboot behavior Port configurability Non-administrators can install updates (like administrators) Install at Shutdown (XP SP2 only)

WSUS issues Clients may not check in Sync process takes a long time Manually put in registry Sync process takes a long time About 24 hours if you pull down all files

Install WSUS… Double-click the installer file WSUSSetup.exe. Note: The latest version of WSUSSetup.exe is available on the Microsoft Web site for Windows Server Update Services at http://go.microsoft.com/fwlink/?LinkId=47374. 2. On the Welcome page of the wizard, click Next. 3. Read the terms of the license agreement carefully, click I accept the terms of the License Agreement, and then click Next. 4. On the Select Update Source page, you can specify where clients get updates. If you select the Store updates locally check box, updates are stored on the WSUS server and you select a location in the file system to store updates. If you do not store updates locally, client computers connect to Microsoft Update to get approved updates. Keep the default options, and click Next. Select Update Source Page

Install Needs a LOT of disk space 6 GB

WMSDE is default On the Database Options page, you select the software used to manage the WSUS database. By default, WSUS Setup offers to install WMSDE if the computer you are installing to runs Windows Server 2003. If you cannot use WMSDE, you must provide a SQL Server instance for WSUS to use, by clicking Use an existing database server on this computer and typing the instance name in the SQL instance name box. For more information about database software options besides WMSDE, see the “Deploying Microsoft Windows Server Update Services” white paper. Keep the default options, and click Next. Database Options Page

WSUS install Now up to 8 gigs

Web admin console WSUS will chose 8530

To get to WSUS Admin tools http://servername:8530/WSUSAdmin/

WSUS sync

WSUS console Missing the computers!

Adding the WUAU template 1. In Group Policy Object Editor, click either of the Administrative Templates nodes. 2. On the Action menu, click Add/Remove Templates. 3. Click Add. 4. In the Policy Templates dialog box, click wuau.adm, and then click Open. 5. In the Add/Remove Templates dialog box, click Close.

Connect the clients In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update. In the details pane, click Specify Intranet Microsoft update service location. Type the HTTP URL of the same WSUS server in both Set the intranet update service for detecting updates and Set the intranet statistics server. For example, type http://servername:8530 in both text boxes, where servername is the name of your WSUS server. Click OK, and then configure the behavior of Automatic Updates

Assigning groups Two methods Group policy Move computers

Group Policy Add a new policy to active directory

Drill down to the setting Computer config Admin Components Windows Update

WU – point it First point your intranet updating Remember 8530

Change the check in interval If you like – change the detection frequency

Adding ZONES Key decision making right here What risk What zone What deployment strategy Who gets what patches when? At least have a Zone for the server[s] One for workstations More zones?

Groups are your Risk areas Create the ‘groups’ to match your risk zones

Approve updates Approval

Approval Approval – be patient

Troubleshooting Main causes of issue are simple configuration errors “http://wsusservernome/” in a GPO Object SelfUpdate tree needs to be on port 80 Tools with the RC Clientdiag.exe – diagnoses some issues Logs %systemroot%\WindowsUpdate.log

Securing WSUS traffic Forcing WSUSAdmin site to use SSL is simple Obtain and install a web certificate Enable SSL on WSUSADMIN directory

Low-bandwidth tips Some initial configuration requires Synchronisation options Schedule What types of updates Proxy server settings Languages (ALL languages is the default) Automatic Approval options Which updates should be automatically approved