SWOCA TSS ACADEMY Implementing Patch Management and Systems Monitoring on Windows Server 2012.

Slides:



Advertisements
Similar presentations
This course is designed for system managers/administrators to better understand the SAAZ Desktop and Server Management components Students will learn.
Advertisements

Auditing Microsoft Active Directory
ESafe Reporter V3.0 eSafe Learning and Certification Program February 2007.
Guide to MCSE , Enhanced 1 Activity 14-1: Browsing Security Templates Objective: To become familiar with built-in security templates Start  Run.
WSUS Presented by: Nada Abdullah Ahmed.
Optimizing Windows Vista Performance Lesson 10. Skills Matrix Technology SkillObjective DomainObjective # Introducing ReadyBoostTroubleshoot performance.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 14: Windows Server 2003 Security Features.
14.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 14: Windows Server 2003 Security Features.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 10: Server Administration.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Week 12 - Lesson 19: Configuring and Managing Updates
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
Maintaining and Updating Windows Server 2008
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
Using the Windows Event Viewer and Task Scheduler Chapter 5.
Guide to MCSE , Enhanced 1 Activity 9-1: Creating a Group Policy Object Using the MMC Objective: To create a GPO using the Group Policy Object Editor.
11 MAINTAINING THE OPERATING SYSTEM Chapter 5. Chapter 5: MAINTAINING THE OPERATING SYSTEM2 CHAPTER OVERVIEW Understand the difference between service.
Module 16: Software Maintenance Using Windows Server Update Services.
16.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 16: Examining Software Update.
11 MAINTAINING THE OPERATING SYSTEM Chapter 5. Chapter 5: MAINTAINING THE OPERATING SYSTEM2 CHAPTER OVERVIEW  Understand the difference between service.
1 Objectives Discuss the Windows Printer Model and how it is implemented in Windows Server 2008 Install the Print Services components of Windows Server.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
Guide to MCSE , Second Edition, Enhanced 1 Objectives Understand and use the Control Panel applets Describe the versatility of the Microsoft Management.
Working with Drivers and Printers Lesson 6. Skills Matrix Technology SkillObjective DomainObjective # Understanding Drivers and Devices Install and configure.
1 Chapter Overview Monitoring Server Performance Monitoring Shared Resources Microsoft Windows 2000 Auditing.
Ch 11 Managing System Reliability and Availability 1.
Microsoft Windows 2003 Server. Client/Server Environment Many client computers connect to a server.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
September 18, 2002 Introduction to Windows 2000 Server Components Ryan Larson David Greer.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
Module 13: Maintaining Software by Using Windows Server Update Services.
Section 2: Using Group Policy Management Tools Local vs. Domain Policies Editing Local Policies Managing Domain Policies Understanding Group Policy Refresh.
Implementing Update Management
Managing and Monitoring Windows 7 Performance Lesson 8.
Module 14: Configuring Server Security Compliance
Module 7: Fundamentals of Administering Windows Server 2008.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
Windows Vista Inside Out Chapter 22 - Monitoring System Activities with Event Viewer Last modified am.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
Supporting and Maintaining Desktop Applications Lesson 13.
Module 7 Configure User and Computer Environments By Using Group Policy.
Maintaining and Updating Windows Server Monitoring Windows Server It is important to monitor your Server system to make sure it is running smoothly.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 11: Monitoring Server Performance.
CN2140 Server II Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Troubleshooting Security Issues Lesson 6. Skills Matrix Technology SkillObjective Domain SkillDomain # Monitoring and Troubleshooting with Event Viewer.
THIS PRESENTATION: WINDOWS UPDATES VIA AUTOMATIC DEPLOYMENT RULES BEST PRACTICES SYSTEM CENTER CONFIGURATION MANAGER 2012 R2 Jodie Gaver Jodie Gaver Working.
Module 8: Managing Software Distribution. Collections Packages Programs Advertisements Collections Packages Programs Advertisements How Software.
Deploying Software with Group Policy Chapter Twelve.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Administering Microsoft Windows Server 2003 Chapter 2.
Optimizing Windows Vista Performance Lesson 10. Skills Matrix Technology SkillObjective DomainObjective # Introducing ReadyBoostTroubleshoot performance.
11 IMPLEMENTING AND MANAGING SOFTWARE UPDATE SERVICES Chapter 7.
Hands-On Microsoft Windows Server 2008 Chapter 5 Configuring Windows Server 2008 Printing.
GROUP POLICY. Group Policy is a hierarchical infrastructure which allows systems administrators to configure computer and user settings from a central.
Managing Servers Lesson 10. Skills Matrix Technology SkillObjective DomainObjective # Using Remote DesktopPlan server management strategies 2.1 Delegating.
Planning Server Deployments Chapter 1. Server Deployment When planning a server deployment for a large enterprise network, the operating system edition.
ITMT 1371 – Window 7 Configuration 1 ITMT Windows 7 Configuration Chapter 8 – Managing and Monitoring Windows 7 Performance.
CACI Proprietary Information | Date 1 PD² SR13 Client Upgrade Name: Semarria Rosemond Title: Systems Analyst, Lead Date: December 8, 2011.
Maintaining and Updating Windows Server 2008 Lesson 8.
CACI Proprietary Information | Date 1 PD² v4.2 Increment 2 SR13 and FPDS Engine v3.5 Database Upgrade Name: Semarria Rosemond Title: Systems Analyst, Lead.
Windows Vista Configuration MCTS : Internet Explorer 7.0.
Lesson 19: Configuring and Managing Updates
Implementing Update Management
Planning a Group Policy Management and Implementation Strategy
Presentation transcript:

SWOCA TSS ACADEMY Implementing Patch Management and Systems Monitoring on Windows Server 2012

UPDATE MANAGEMENT Install and Configure Windows Server Update Services on Windows 2012

TYPES OF UPDATES - HOTFIX  A single update that fixes a single issue.  Normally generally released in Microsoft’s monthly update cycle. Some critical and security updates are released out of band of the schedule if needed.  Some hotfixes are not generally released. Microsoft may require that a support call be initiated to verify your issue or a web form be filled out before it can be downloaded. After verification, MS sends an with a link to the specific hotfix.  Hotfixes can be combined for a product like Internet Explorer or the.NET Framework. These are cumulative updates.

TYPES OF UPDATES – SERVICE PACKS  Service Packs (SP) is an update that combines all previous updates.  It will include security and performance improvements  Support for new hardware  New software features  A version demarcation point for the software. Windows Server 2008 R2 is considered different than Windows Server 2008 R1 SP1.  A Service Pack installation can be required for other software and feature installations.

CLASSIFICATION OF MICROSOFT UPDATES  Important Updates: Improved security, privacy, reliability. Should be installed as soon as they become available and would be installed automatically if the computer is set to Install Updates Automatically.  Recommended Updates: Address non-critical problems or enhance computer experience.  Optional Updates: updates, newer hardware drivers and new software from Microsoft.  Security Updates: Addresses an identified security vulnerability. Rated for severity, and are described in detail via Microsoft’s monthly security bulletin.  Critical Updates: Addresses critical but non-security related bugs in the operating system.

MICROSOFT UPDATE CYCLE  Microsoft releases monthly updates for all of their software.  Security Bulletins and descriptions of each hotfix are provided on the Microsoft Security TechCenter. and RSS alerts are available.  In North America, the update release is scheduled on the second Tuesday, known as, ‘Patch Tuesday’.  Patches can be added to Microsoft’s Update servers on any day.

MICROSOFT SECURITY ADVISORIES AND BULLETINS

MICROSOFT SECURITY BULLETIN  Released monthly – describes each hotfix that will be released for the month.  History of all Security Advisories  Sign up for Microsoft Technical Security Notifications   Options:  WWW, , RSS  Basic, Comprehensive, Advisories  Microsoft Security Response Center Blog   WWW, RSS

PATCH INSTALLATION OPTIONS  Windows / Automatic Updates  Windows updates are set for manual or scheduled installation of updates.  Updates are pulled down per machine, directly from the MS update servers.  Changing from ‘Windows Update’ to ‘Microsoft Update’ allows other Microsoft applications to be patched through the service.  Ideal for many small organizations. Each machine must have internet access.  Windows Server Update Services (WSUS)  Centrally manage updates. Choose which to install for which groups of servers.  Free - Runs as a Server Role  Can download updates directly from the Internet or from another WSUS server.  Microsoft Systems Center Configuration Manager (SCCM)  Not Free – Fully featured Microsoft operating system management platform

WINDOWS UPDATE – GROUP POLICY  Group Policy is a feature within the Microsoft Windows Server products that allow administrators to centrally manage and configure the operating systems, applications and, user settings in an Active Directory (AD) environment.  Group Policy Objects (GPO), linked to Organizational Units (OU) can be set to control the behavior of Windows / Automatic Update on target systems.  Through GPO, administrators can configure different update settings for different types of machines.

WINDOWS & AUTOMATIC UPDATE  Windows XP / Windows Server 2003  Windows Update Website – Use Internet Explorer to manually scan, choose and install updates adhoc.  Automatic Updates – In the Control Panel, schedulable options exist for:  Download and install updates automatically  Download but do not install updates automatically  Notify, but do not download or install updates  Turn off Automatic Updates all together

WINDOWS & AUTOMATIC UPDATE  Windows Server 2008 – 2012 R2, Windows  Windows Update can be found in two places:  Control Panel \ System and Security \ Windows Update  Administrative Tools \ Server Manger \Windows Update

WINDOWS UPDATE – CHANGE SETTINGS

WINDOWS UPDATE - VIEW UPDATE HISTORY

PROGRAMS & FEATURES – INSTALLED UPDATES

CONFIGURE UPDATES VIA GROUP POLICY  Reference: Configure Automatic Updates via Group Polices:  Open Server Manager. Tools > Group Policy Management  In Group Policy Management console, right click on Group Policy Objects > New  Title the New GPO, choose (none) in Source Starter GPO  In the Group Policy Management Editor window that opens, expand Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update.  Configure the options desired, close the Group Policy Management Editor  Link the created Group Policy Object.  In Group Policy Management Console,  Select an OU, right click, Link an Existing GPO.  Choose your GPO and click OK

VERIFYING GPO WINDOWS UPDATE SETTINGS  GPResult /R  Displays the Group Policy Objects that are configured for the target computer and logged in user account.   GPUpdate /force  Refreshes Group Policy Objects for the logged in user account and computer.  Processes new, removed and edited Group Policy Objects 

WINDOWS SERVER UPDATE SERVICES

INSTALLING WSUS - REQUIREMENTS  Windows Server  Internet Information Services (IIS)  Microsoft.NET Framework  Microsoft Management Console (MMC) 3.0  Microsoft Report Viewer Redistributable  SQL Server 2005 SP2 Express +, Windows Internal Database  100 GB of disk space for WSUS, database and, updates.  Internet access for Autonomous WSUS servers

INSTALLING WINDOWS SERVER UPDATE SERVICES  Create a folder to house the downloaded updates. This disk should have plenty of free space on it. It can be a remote share.  Open Server Manager. Manage > Add Roles and Features. Before you Begin page – Next.  Role-based or feature-based installation  Select a server from the server pool.  Select, Windows Server Update Services from the server roles.  Add Features that are required for the WSUS role  In Select Role Services, choose WSUS Server.  Select WID Database if you will use the Windows Internal Database option or,  Select Database if you will use a version of SQL Server.  Choose the location to store the updates.  Next through the IIS pages, Install.

CONFIGURE WSUS – POST INSTALLATION  Open Server Manager > Tools > Windows Server Update Services  Complete WSUS Installation dialog appears. Choose the folder created earlier to store your updates. This process creates your configuration database and folders. Close the dialog when complete.  The Windows Server Update Services Configuration Wizard begins.

WSUS CONFIGURATION WIZARD BEFORE YOU BEGIN

WSUS CONFIGURATION WIZARD MICROSOFT IMPROVEMENT PROGRAM

WSUS CONFIGURATION WIZARD CHOOSE UPSTREAM SERVER

WSUS CONFIGURATION WIZARD SPECIFY PROXY SERVER

WSUS CONFIGURATION WIZARD CONNECT TO UPSTREAM SERVER

WSUS CONFIGURATION WIZARD CHOOSE LANGUAGES

WSUS CONFIGURATION WIZARD CHOOSE PRODUCTS

WSUS CONFIGURATION WIZARD CHOOSE CLASSIFICATIONS

WSUS CONFIGURATION WIZARD SET SYNC SCHEDULE

WSUS CONFIGURATION WIZARD FINISHED INITIAL CONFIGURATION OF YOUR SERVER

WSUS CONFIGURATION WIZARD WHAT’S NEXT

CONFIGURING WSUS COMPUTERS

WSUS COMPUTER GROUPS  Computer groups are created to organize your computers in a way to determine which computers get which updates at what time.  Computers are typically organized by the way you want updates to be installed. i.e.: Test, production, clustered or, manual updates only.  Two methods exist for populating Computer Groups within WSUS:  Server-side targeting – the administrator manually moves computers from group to group.  Client-side targeting – the administrator assigns computers to their groups via Group Policy which modifies the registry of the target machine.

CLIENT-SIDE TARGETING  Client side targeting allows for the most flexibility in automating the configuration of WSUS clients. It is the preferred method for computers that are a member of a Windows Active Directory domain.  To enable client side targeting within WSUS, open the WSUS MMC console. Choose Options > Computers and choose Use Group Policy or registry settings on computers.  To enable client side targeting on clients:  Open Server Manager on a computer with Group Policy Management installed. Tools > Group Policy Management > ‘Your Domain’ > Group Policy Objects > New.. Type in a name to create the new GPO. Find that GPO, right-click and choose Edit.  Computer configuration > Policies > Administrative Templates > Windows Components > Windows Update.  Enable Client-side Extensions, Enable Specify intranet Microsoft update services location.  Choose other options as desired.

APPROVING UPDATES  Besides the actions configured within Group Policy, all updates must be approved by an administrator. Approving the updates make them available to clients when they check in with WSUS.  Open the WSUS Console. Expand Updates > All Updates. In middle pane, Approval: Unapproved. Status: Any.  Releases can be sorted through the field headers.  Select Updates you wish to Approve. Right-click on the selection, choose Approve. Updates that you do not want to ever be installed, choose Decline.  Right click on the Computer Group(s) you wish to Approve the Updates. Inheritance can be by choosing Apply to children. Deadline (for installation) can also be set. This will force the installation before the Deadline date.  Approving the Updates for Install, Removal or Not Approved for a set of computers within a Computer Group.

VIEWING REPORTS  To view reports, Microsoft.Net Framework 2.0 and the Microsoft Report Viewer 2008 Redistributable packages must installed on the computer running the WSUS MMC.  To view Reports, open the WSUS MMC, Expand Reports. Reports are available by Updates and by Computer Groups.  Reports can be saved as in Excel and PDF formats and printed.

TROUBLESHOOTING  Application Event Log – Includes Update Synchronization, WSUS (general), WSUS database errors.  C:\Program Files\Update Services\LogFiles\Change.txt – Records every update installation, synchronization, and WSUS configuration change  C:\Program Files\Update Services\LogFiles\softwareDistribution.txt – detailed log used by MS support if they need to see debug information.

MONITORING SERVERS Finding ways within the native operating system to let you know what is going on and correct them.

SERVICES CONSOLE  Most Windows Server programs are installed as Services. Services are executables launched when the operating system starts or when another program needs it to function. Some services require other services to operate and visa-versa.  Because these Services are critical to your normal operating state, it would be nice to know when they are having an issue.  The Recovery tab of the Service has options to alert and correct a service when it fails.  Run Program allows for custom programs, PowerShell scripts to run if a service fails

EVENT VIEWER  The Event Viewer MMC snap-in enables you to browse and manage the Event Logs created by the OS and programs installed on the computer.  Event Viewer assembles the OS’ System, Security, Application and Setup logs as well as application or Role specific logs in one location.  Because so much information is collected, it is sometimes useful to Filter the data and create Custom Views.  Event Viewer enables you to:  View events from multiple event logs  Save useful event filters  Schedule a task to be run in response to an event  Create and manage event subscriptions

EVENT VIEWER – FILTER EVENTS Each Event Log can contain 1000’s of entries. Events can be sorted by the column headers but when that fails or takes too long, Right click on an Event Log and choose Filter Current Log Logs can be filtered by Event Level, Time it was logged, Event Sources, Keywords, Task Category, User and Computer that was related to the Event.

EVENT VIEWER - CUSTOM VIEWS Some Custom Views are created when Server Roles and applications are installed. They read and filter the Event Logs and gather Events that pertain to the Role or application. The Administrative Events View contains Critical, Error and Warnings from all logs. Administrators can create their own Custom Views (Custom Views > Right-click > New Custom View Custom Views can be further modified by adjusting their filters. Custom Views can be saved for viewing, exported and imported to other computers.

EVENT VIEWER – EVENT SUBSCRIPTIONS  Event Subscriptions allow an administrator to gather relevant events from multiple computers to a central location.  Event Subscriptions require that Windows Remote Management (Server Manager > Windows Remote Management > Enabled) be enabled and the Windows Event Collector Service to be running and configured to automatically start with the computer.  Events can be filtered.  There are two ways to gather Subscribed events:  Collector Initiated:  The Collector computer polls the target computers’ Event Logs for information and gathers the events.  Only works for Domain joined computers, which are selected individually.  Source Computer Initiated:  The forwarding computer contacts the collection computer.  Works for domain and non-domain computers. Non-domain joined computers require certificate authentication.  Events are gathered in Forwarded Events.

EVENT VIEWER – ATTACHING TASKS Sometimes an administrator would like to be notified or have an action taken (or both) when an event is generated. If so, Attach a Task to an event. Attaching a Task uses the Scheduled Tasks wizard using the Event generation as the Trigger The Wizard will ask you for a Name for the Task, populate the Trigger with the Event being generated and give the options for Actions. Start a program, preferably a PowerShell script, is the preferred Action to take. Send an and Display a Message (pop-up on the server console) is being depreciated.