Update bug fixes for distributed environments via SYSTEM UPDATE SERVICES (SUS)
Perhaps everyone has suffered from computer problems that resulted in virus, hacker data loss and system vulnerabilities. So, since 1998 Microsoft has released a method to update patches when use Windows operating system through the websitewww.windowsupdate.com.When using Win XP or Win 2K SP3 or later, we have a new feature called A utomatic updates that can automatically connect to the windows update site to download the system patch files.
Automatic Updates program automatically updates the patch
However, in a distributed environment, the single update of patches for the system is often not highly effective due to many reasons such as sugar. transmission, difficult to manage due to the carelessness of users. So in the role of IT Supervisor or Network Administrator, we probably want a more efficient method of processing.And fortunately, SUS can solve that problem for us, with SUS we can manage the update of system patches for users through one or more susserver intermediary servers.And the A utomatic updates program on users' computers will be configured to connect to the server to download updates instead of from the Microsoft website. This will help us manage the process of updating the system more effectively with mechanisms such as scheduling updates to clients or specifying files to be installed. based on domain policy.
In this article, I will present the method of installing, configuring sus server and setting up domain policies on a real model of a customer company with more than 50 users to be able to manage and deploy counter. Update the system more effectively.
The TestLab model needs the following machines:
Step 1: Install and Configure Software Update Services
Software Update Services (SUS) is a completely free, downloadable product from http://www.microsft.com/downloads and proceed to install on susserver.mcsesecurity.com.The installation process is relatively simple, we only need to specify the location to store the necessary files of the program and follow some instructions given as shown below.
After the installation process is complete, the next step is to log into the admin websitehttp://susserver.mcsesecurity.com conduct data synchronization with Microsoft server update and perform some necessary configuration operations.
Administration website of Software Update Service server
Click Synchronize to download the fixes from Microsoft servers, because the volume of updates is quite large, it takes a long time for the data synchronization process. Therefore, in order to limit bandwidth usage, we should set a schedule for this process to take place outside the working time by selecting Synchronizer Scheduler and setting the following parameters:
When the synchronization process finishes, depending on your system, you can select the necessary hotfixes to let the clients update through the A utomatic updates utility by selecting Approve updates and checking the files to patch for the machines. Online:
List of patches and options
So we have installed and configured the sus server. Next, we just need to configure the auomatic update program on the clients connected to this machine to download the patches to install again.If the client computers on the network do not have the Automatic updates utility, they can be downloaded from the Microsoft download website and distributed to the member machines through Group Policy or instructing the user to install them from a shared folder. Check the Cntrol Panel again when the installation is complete to ensure that Automatic Updates is available on your system.
Step 2: Configure Group Policy on the domain controller
We manage the patch update process for the client through Group Policy on the domain admin machine through the following actions:
1. Select Start -> Program-> Admnistrati Tools-> Active Directory User and Computer
2. Click the right mouse on the domain and select Properties, then select Group Policy, select Default Domain Security Policy and click Edit to open the domain's policy editor and select Add / Remove Templates as shown below:
3. Select the ADM (administrative template) named wuad.adm and click Open
4. Then we edit the policy by clicking Automatic Update in the right pane of the WUAU-ADM template and selecting Auto download and scheduler the install and determining the date and time for the client to download the system update files. About as shown below:
5. Next, click on the Specific intranet Microsoft Update server location and select enable then enter the name of the sus server and select OK:
So we have completed the SUS server system and created the necessary policies so that the agents can download patches from the grave. specific servers in the domain system.Following this, we run hGPupdate.exe from the Run command and ask users to restart the system when possible.
Note: For computers in a Workgroup environment we can still deploy this model by changing the local policy of each machine.
To ensure the safety of the system when a problem occurs, we should make backup of necessary data of the sus server .To backup your content, the website of administration and iis metabase, you can see more about this issue at microsoft site or contact the email address at the end of the post to get more information.
However, some patches may cause older applications on the system to become unstable, so for systems that are critical we should thoroughly check patch files on test machines and refer to Carefully review the production information about their side effects.And in order to know which computers on the system have not updated in time for this vulnerability, we should use automatic scanning programs provided by Micorosoft. Offer like Hfnetchk or MBSA, these are The program can be downloaded for free through the Microsoft download website.
References - You can download books, demo video files and programs at the following address:
http://www.security365.org/downloads/books
http://www.security365.org/downloads/demo
http://www.security365.org/downloads/software/
Nguyen Tran Duy Vinh, NetManager - MCP
An Security Solution Company
www.security365.org
consultant@security365.org
You should read it
- How to disable Lock Screen lock screen on Windows 10 Anniversary Update
- Fix Error not downloading or installing updates from Windows Update
- Instructions on how to turn off Self-Update notifications when you shutdown on Windows 10
- The trick prevents Windows from automatically updating specific drivers
- How to set Windows Updates download bandwidth limit in Windows 10
- Steps to turn off Windows 11 Update, How to stop updating Windows 11
- How to join Windows Insider to download and experience the latest Builds?
- Notable new features on the Windows 10 April update 2018 Update
May be interested
- Apple fixes the overheating MacBook Airapple on tuesday released an update that fixes problems in the macbook air's radiator fan system after a series of reflections on how this laptop has often become too hot.
- Windows 11 receives important update, fixes system 'crash' error when launching gamesmicrosoft is rolling out an out-of-band update for windows 11 version 24h2.
- How are Linux kernel updates distributed on Windows Update?users will be allowed to download linux kernel updates in wsl2 from windows update.
- Apple fixes many important bugs on MacOS Xyesterday, apple released a new patch for its mac os x operating system. there were 13 errors corrected during this update.
- How to update iPad to the latest version of iPadOSfree ipados updates from apple bring your ipad the latest features, security patches and bug fixes. therefore, it is extremely important to regularly check and update system software.
- Included iOS 12.1.3 with some improvements and bug fixes for iPhone and iPadapple has just officially released the ios 12.1.3 update with some improvements and bug fixes to provide a better experience for users on the iphone and ipad.
- How to fix Windows Update errorregular windows updates will help keep your system running smoothly and with the latest bug fixes. however, the update process sometimes happens not smoothly and you don't know how to fix it?
- Steps to turn off Windows 11 Update, How to stop updating Windows 11microsoft regularly releases updates to patch bugs for its operating system as well as its products and services. windows 11 is also not an exception to this policy, so it will be regularly updated with patches.
- The new update fixes many bugs on Windows 10 April 2018 Update but causes a more serious erroralthough kb4103721 fixes a lot of errors, many hardware models run windows 10 april 2018 update (version 1803) after the cumulative update has a black screen error, a much more serious error than the error. cause hang up when opening google chrome or cortana.
- Apple officially released iOS 8.1.1apple has just officially updated ios 8.1.1 to all ios users. this new update is quite heavy with bug fixes and performance improvements on older devices.