Use Configuration Manager to deploy and manage software updates (1)

Source: Internet
Author: User

Today we will demonstrate how to use Configuration Manager to deploy and manage software updates.

I. Technical Overview

1. Software Update Synchronization

Software Updates In Configuration Manager synchronously use Microsoft updates to retrieve software update metadata. A top-level site (administration site or independent master site) is synchronized with Microsoft updates when synchronization is started manually from the Configuration Manager Console as planned or in the enterprise. When Configuration Manager completes Software Update synchronization on the top-level site, the software update synchronization starts at the Child site (if any. When synchronization is completed on each primary site or secondary site, a site range policy is created to provide the client computer with the location of the Software Update point.

By default, software updates are enabled in client settings. But what if I enable software update on the client? If the client is set to "no" to Disable Software Update on the collection or the default settings, the location of the Software Update point is not sent to the associated client. After receiving the policy, the client starts the software update compliance scan and writes the information to Windows Management Instrumentation (Wmi ). Then, the compliance information is sent to the management point, which then sends the information to the Site Server.

2. Software Update conformity assessment

Before deploying software updates to a client computer in Configuration Manager, start the software update compliance scan on the client computer. For each software update, a status message is created, including the update compliance status. Status messages are sent to the management point in batches and then to the Site Server. on the Site Server, the compliance status is inserted into the site database. The compliance status of software updates is displayed on the Configuration Manager Console. You can deploy and install software updates on the computer to be updated. The following sections provide information about the compliance status and describe the process for scanning the software to update compliance.

3. Scan the software update compliance process

After the Software Update point is installed and synchronized, a site-wide computer policy is created, which notifies the client that Configuration Manager software update is enabled for the site. After receiving the computer policy, the client plans to start a compliance evaluation scan randomly within the next two hours. After the scan starts, the Agent process of the Software Update client clears the scan history, submits a request to find the WSUS server applied to the scan, and updates the local group policy using the WSUS server location.

Scan requests are passed to the Windows Update proxy (wua ). Then, wua connects to the WSUS server location listed in the local policy, retrieves the software update metadata synchronized on the wsus server, and scans the updates on the client computer. The agent process of the Software Update client detects that the compliance scan is completed and creates a status message for each software update that changes the compliance status after the last scan. Status messages are sent to the management point every 15 minutes. The management point then forwards the status message to the Site Server. on the Site Server, the status message is inserted into the Site Server database.

After the first scan software updates compliance, the scan starts according to the configured scan plan. However, if the client scans the software update compliance within the time range specified by the TTL value, the client uses the locally stored software to update metadata. When a scan is out of TTL, the client must connect to the WSUS running on the software update point and update the software update metadata stored on the client.

4. Software Update deployment package

The software update deployment package is a carrier used to download software updates to the network shared folder, and copy the software update source file to the content library on the Site Server, and the content library of the distribution point defined in the deployment. By using the download Update Wizard, you can download software updates and add them to the deployment package before deploying them. This wizard allows you to set software updates on the distribution point and verify that the deployment process is successful before deploying software updates to the client.

Before you use the deployment Software Update Wizard to deploy the downloaded software update, the deployment will automatically use the deployment package containing the software update. When you deploy software updates that have not been downloaded, you must specify a new or existing deployment package in the deployment Software Update Wizard. The software updates will be downloaded when the Wizard is complete.

5. Software Update deployment Workflow

There are two main solutions for deploying software updates in your environment: manual deployment and automatic deployment. Generally, you manually deploy software updates to create a baseline for the client computer, and then use the automatic deployment to manage software updates on the client. The following section provides an overview of manual and automatic Deployment workflows for software updates.

1) manual deployment of Software Updates

Manual deployment of software updates is the process of selecting software updates on the Configuration Manager Console and manually starting the deployment process. Before creating an automatic deployment rule that will manage ongoing monthly software updates and deployments, you will usually use this deployment method to keep the client computer up-to-date with the required software updates, deploy out-of-band Software Update Requirements.

2) Automatic deployment of Software Updates

Use automatic deployment rules to configure automatic software update deployment. You usually use this deployment method for monthly software updates (known as Tuesday patch) and Management definition updates. When running the rule, software updates that meet the specified conditions (for example, all Security Software Updates released last week) will be added to the Software Update group, and software update content files will be downloaded and copied to the distribution point, then, deploy the software update to the client computer in the target set.

6. Software Update deployment process

After the software is updated or when the automatic deployment rule runs and the software is updated, the deployment allocation policy is added to the Computer Policy of the site. The system downloads software updates from the download location (Internet or network shared folder) to the package source. The system copies software updates from the package source to the content library on the Site Server, and then to the content library on the distribution point.

When the client computer in the target set of deployment receives the computer policy, the Software Update client agent starts the evaluation scan. After receiving the deployment, the client agent will download the software update content from the distribution point to the local Client Cache. However, the software update will not be installed until the "software availability time" is set. The software updates in the optional deployment (deployment with no installation deadline) are not downloaded until you manually start the installation.

When the client computer in the target set of deployment receives the computer policy, the Software Update client agent starts the evaluation scan. After receiving the deployment, the client agent will download the software update content from the distribution point to the local Client Cache. However, the software update will not be installed until the "software availability time" is set. The software updates in the optional deployment (deployment with no installation deadline) are not downloaded until you manually start the installation.

2. Prerequisites for deploying and managing software updates in Configuration Manager

1. wsus3.0 SP2 or later versions

2. The wsus3.0 console must be installed on the Configuration Manager Site Server.

3. Configuration Manager site system role

1) management point

2) distribution point

3) Software Update point

4) Reporting Services

4. Client Requirements

1) Client settings

2) configure the Windows Update agent on the Configuration Manager Client

3. Configure software update points on the Configuration Manager Site Server

(1) Prerequisites for Site System Configuration

1. log on to the Configuration Manager server, click Server Manager, click Computer Management, click system tools, expand local users and groups, and click groups.

2. Double-click administrators and click Add.

650) This. width = 650; "Height =" 395 "Title =" clip_image002 "style =" margin: 0px; "alt =" clip_image002 "src =" http://img1.51cto.com/attachment/201408/23/8995534_14087873302ZI7.jpg "/>

3. Select User, computer, service account, and group, click object type, and select computer

4. "enter an object name to select", type the WSUS computer name, click check name, and then click OK. In this experiment, WSUS server and Configuration Manager server are integrated. According to Microsoft's best practice, WSUS server and Configuration Manager server are installed separately, but WSUS Management Console must be installed on the Configuration Manager server.

5. Click "Tools" and select "WSUS Update Service" to ensure that the WSUS server or the WSUS console has been installed on the Configuration Manager server.

650) This. width = 650; "Height =" 404 "Title =" clip_image004 "style =" margin: 0px; "alt =" clip_image004 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787331XSeh.jpg "/>

(2) Add a software update point to the Site System

1. log on to the Configuration Manager server and open the Configuration Manager Console.

2. Click Manage to expand site configuration. Click server and site system roles, right-click Site Server name, and select Add site system role.

650) This. width = 650; "Height =" 394 "Title =" clip_image006 "style =" margin: 0px; "alt =" clip_image006 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787331vTsq.jpg "/>

3. On the Add site system role Wizard Page, click Next.

4. Specify the Internet proxy server page and click Next.

5. On the System role selection page, select Add Software Update point and click Next.

650) This. width = 650; "Height =" 414 "Title =" clip_image008 "style =" margin: 0px; "alt =" clip_image008 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787331kX2R.jpg "/>

6. specify the Software Update point settings. Set WSUS to use ports 8530 and 8531 for client communication (the default setting of WSUS on Windows Server 2012). Set the client connection type to allow only Intranet client connections, click Next

650) This. width = 650; "Height =" 364 "Title =" clip_image010 "style =" margin: 0px; "alt =" clip_image010 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787331YXDc.jpg "/>

7. Specify the agent and account settings page for the software update point, and click Next.

8. On the synchronization Source Page, select not to synchronize from Microsoft updates or upstream data sources, and click Next.

650) This. width = 650; "Height =" 411 "Title =" clip_image012 "style =" margin: 0px; "alt =" clip_image012 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787331QCT0.jpg "/>

9. Specify the synchronization plan page, configure the synchronization plan as needed, and click Next.

650) This. width = 650; "Height =" 308 "Title =" clip_image014 "style =" margin: 0px; "alt =" clip_image014 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787331QvJt.jpg "/>

10. Select the replaced Software Update behavior and click Next.

650) This. width = 650; "Height =" 288 "Title =" clip_image016 "style =" margin: 0px; "alt =" clip_image016 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787332YUAl.jpg "/>

11. Select the Software Update category to be synchronized, select the update type based on the actual environment of the enterprise, and click Next.

650) This. width = 650; "Height =" 237 "Title =" clip_image018 "style =" margin: 0px; "alt =" clip_image018 "src =" http://img1.51cto.com/attachment/201408/23/8995534_140878733226a1.jpg "/>

12. Select the desired synchronization product and click Next.

650) This. width = 650; "Height =" 410 "Title =" clip_image020 "style =" margin: 0px; "alt =" clip_image020 "src =" http://img1.51cto.com/attachment/201408/23/8995534_14087873323kcn.jpg "/>

13. Select the language you want to synchronize and click Next.

650) This. width = 650; "Height =" 414 "Title =" clip_image022 "style =" margin: 0px; "alt =" clip_image022 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787332LOpi.jpg "/>

14. Confirm the summary page and click Next. Wait until the configuration is complete.

15. On the completion page, click Finish.

650) This. width = 650; "Height =" 412 "Title =" clip_image024 "style =" margin: 0px; "alt =" clip_image024 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787332E8Zd.jpg "/>

16. Click monitoring, expand system status, click component Status, right-clickSms_wsus_control_managerSelect Display message and click all

650) This. width = 650; "Height =" 393 "Title =" clip_image026 "style =" margin: 0px; "alt =" clip_image026 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787333gEia.jpg "/>

17. In the Configuration Manager status message viewer, find the Message ID: 1015 to verify whether the component is successfully installed.

650) This. width = 650; "Height =" 115 "Title =" clip_image028 "style =" margin: 0px; "alt =" clip_image028 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787333bx6S.jpg "/>

(3) configure the Software Update Point Component

1. Click the software library, expand software updates, right-click all software updates, and select synchronize software updates.

650) This. width = 650; "Height =" 393 "Title =" clip_image030 "style =" margin: 0px; "alt =" clip_image030 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787334Cmuf.jpg "/>

2. In the synchronization software update dialog box, click "yes"

650) This. width = 650; "Height =" 254 "Title =" clip_image031 "style =" margin: 0px; "alt =" clip_image031 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787334GnbE.png "/>

3. Click "manage" to expand site configuration. Right-click the site, right-click the site name, select "Configure site components", and click "Software Update point ".

650) This. width = 650; "Height =" 395 "Title =" clip_image033 "style =" margin: 0px; "alt =" clip_image033 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787335tkyi.jpg "/>

4. On the Software Update Point Component properties page, configure relevant settings as needed. On the synchronization settings page, confirm that you choose not to synchronize data from Microsoft updates or upstream data sources.

650) This. width = 650; "Height =" 414 "Title =" clip_image035 "style =" margin: 0px; "alt =" clip_image035 "src =" http://img1.51cto.com/attachment/201408/23/8995534_140878733516Mb.jpg "/>

5. Click products, select office2013, Windows 8.1, and Windows Server 2012r2, select products based on the actual products deployed by the enterprise, and click OK.

650) This. width = 650; "Height =" 414 "Title =" clip_image037 "style =" margin: 0px; "alt =" clip_image037 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787336783j.jpg "/>

(4) synchronization software update points

1. Click the software library, expand software updates, right-click all software updates, and wait for the software updates to be synchronized.

2. Click monitoring and synchronization status of the Software Update point to view the synchronization status.

650) This. width = 650; "Height =" 392 "Title =" clip_image039 "style =" margin: 0px; "alt =" clip_image039 "src =" http://img1.51cto.com/attachment/201408/23/8995534_14087873360YLI.jpg "/>

3. Open the cmtrace log analysis tool and openWsyncmgr. LogView synchronization status

650) This. width = 650; "Height =" 337 "Title =" clip_image041 "style =" margin: 0px; "alt =" clip_image041 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787337y125.jpg "/>

4. Wait for a moment, click the software library, expand the Software Update, and click the Software Update to view the synchronized update list.

650) This. width = 650; "Height =" 393 "Title =" clip_image043 "style =" margin: 0px; "alt =" clip_image043 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787338RzTI.jpg "/>

(5) configure the software to update the client settings

1. Click "software library", "client Settings", right-click "Default Client Settings", and select "properties ".

650) This. width = 650; "Height =" 393 "Title =" clip_image045 "style =" margin: 0px; "alt =" clip_image045 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787338IlDa.jpg "/>

2. on the default settings property page, click "Software Update ".

650) This. width = 650; "Height =" 309 "Title =" clip_image047 "style =" margin: 0px; "alt =" clip_image047 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787339BZVV.jpg "/>

3. Click the status message to configure the status message report period.

650) This. width = 650; "Height =" 305 "Title =" clip_image049 "style =" margin: 0px; "alt =" clip_image049 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787339FwnB.jpg "/>

(6) execute software updates on the client

1. log onto the client machine BJ-CLI-04, open the control panel, click Configuration Manager

650) This. width = 650; "Height =" 243 "Title =" clip_image051 "style =" margin: 0px; "alt =" clip_image051 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787339tXER.jpg "/>

2. On the Configuration Manager properties page, click operations, select a computer policy retrieval and evaluation cycle, and click run now.

650) This. width = 650; "Height =" 414 "Title =" clip_image052 "style =" margin: 0px; "alt =" clip_image052 "src =" http://img1.51cto.com/attachment/201408/23/8995534_1408787339GR13.png "/>

3. Select the Software Update scan cycle and click run now.

650) This. width = 650; "Title =" software .png "src =" http://s3.51cto.com/wyfs02/M01/47/53/wKiom1P4aOGg4af9AAGLF4VpBHE062.jpg "alt =" wkiom1p4aogg4af9aaglf4vpbhe062.jpg "/>


This article is from "Xu Ting's blog", please be sure to keep this source http://ericxuting.blog.51cto.com/8995534/1543835

Use Configuration Manager to deploy and manage software updates (1)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.