Whether you are managing a single Windows 10 PC or thousands, the challenges of managing updates remain the same. Your goal is to quickly install security-related updates, manage component updates intelligently, and prevent productivity loss due to unexpected reboots.
Does your organization have a comprehensive Windows 10 update management plan? There's a temptation to view these downloads as periodic nuisances to be dealt with as soon as they appear. However, a reactive approach to updates is a recipe for frustration and reduced productivity.
Instead, you can develop a management strategy for testing and implementing updates so that this process becomes as routine as sending invoices or monthly accounting close.
This article provides all the information you need to understand how Microsoft sends updates to devices running Windows 10 and details on the tools and techniques that can be used to smartly manage these updates on Windows 10 devices running Pro, Enterprise, or Education versions. (Windows 10 Home only supports the most basic update management capabilities and is not suitable for business environments.)
But before diving into any of these tools, you'll need a plan.
What do your update policies say?
The purpose of update policies is to make the update process predictable, establish procedures for notifying users so they can plan their work accordingly and avoid unexpected downtime. Policies also include protocols for handling unforeseen issues, including rolling back failed updates.
Smart update policies allocate specific times for dealing with updates each month. In a small organization, this goal can be achieved with a dedicated time slot in each PC's maintenance schedule. In larger organizations, one-size-fits-all solutions are unlikely to work, and you'll need to segment the entire population of PCs into update groups (Microsoft refers to them as 'rings'), each with its own update strategy.
The rules should describe several different types of updates. The most straightforward type is the monthly cumulative security and reliability updates that are released on the second Tuesday of each month (known as 'Patch Tuesday'). This release typically includes the Windows Malicious Software Removal Tool, as well as potentially any of the following types of updates:
- Security updates for .NET Framework
- Security updates for Adobe Flash Player
- Servicing stack updates (which need to be installed from the start).
Installation of any of these updates can be deferred for up to 30 days.
Depending on the PC manufacturer, hardware drivers and firmware can also be distributed through Windows Update. You can opt out of this or manage them in the same manner as other updates.
Finally, component updates [feature updates] are also distributed through Windows Update. These major packages upgrade Windows 10 to the latest version and are released every six months for all editions of Windows 10, except the Long Term Servicing Channel (LTSC). Installation of component updates can be deferred using Windows Update for Business for up to 365 days; for Enterprise and Education editions, further deferral for up to 30 months is possible.
Considering all of this, you can start to formulate update rules, which should include the following elements for each managed PC:
- The installation period for monthly updates. By default, in Windows 10, monthly updates are downloaded and installed within 24 hours after their release on 'Patch Tuesday.' You can delay the downloading of these updates for some or all PCs in the company to give you time to test them for compatibility; this delay also helps you avoid issues in case Microsoft discovers a problem with the update after its release, as has happened multiple times with Windows 10.
- The timeframe for installing semi-annual component updates. By default, component updates are downloaded and installed when Microsoft deems them ready. On devices that Microsoft considers suitable for updates, component updates may appear within a few days after release. On other devices, component updates may take several months to appear, or they might be blocked altogether due to compatibility issues. You can set a delay for some or all PCs in your organization to allow time for testing the new release. Starting with version 1903, PC users will be offered component updates; however, the commands to download and install them will only be initiated by the users themselves.
- When to allow PCs to restart to complete the installation of updates: the majority of updates require a restart to finish installation. This restart occurs outside the 'active hours' period from 8 AM to 5 PM; this setting can be changed if desired, extending the duration of the interval to 6 PM. Management tools allow you to schedule a specific time for downloading and installing updates.
- How to notify users about available updates and restarts: to avoid unpleasant surprises, Windows 10 notifies users about available updates. The management of these notifications in Windows 10 settings is limited. Much more configuration options are available in 'Group Policies.'
- Sometimes Microsoft releases critical security updates outside the normal 'Patch Tuesday' schedule. This is typically necessary to address security flaws that are being actively exploited by malicious parties. Should you expedite the deployment of such updates or wait for the next scheduled window?
- What to do with failed updates: if an update fails to install correctly or causes issues, what will you do in that case?
Having identified these elements, it’s time to choose tools for managing updates.
Manual update management
For very small businesses, including stores with a single employee, it is quite easy to manually configure Windows updates. Navigate to > Update & Security > Windows Update. There you can adjust two sets of settings.
First, select 'Change active hours' and adjust the settings to match your working habits. If you typically work in the evenings, you can avoid downtime by setting these values from 6 PM to midnight, resulting in scheduled restarts occurring in the morning.
Then, select 'Advanced options' and configure 'Choose when updates are installed' according to your rules:
- Select how many days to defer the installation of feature updates. The maximum value is 365.
- Select how many days to defer the installation of quality updates, including cumulative security updates released on 'Patch Tuesdays'. The maximum value is 30 days.
Other settings on this page manage the display of restart notifications (enabled by default) and allow downloading updates over metered connections (disabled by default).
Before Windows 10 version 1903, there was also a setting to choose the channel – semi-annual, or semi-annual targeted. This was removed in version 1903, and in older versions, it simply doesn't work.
Of course, the purpose of deferring updates is not to avoid the process entirely and then surprise users later. For example, if you set a 15-day deferment for quality updates, you need to use that time to check for compatibility and schedule maintenance at a convenient time before this period ends.
Managing updates through Group Policies
All mentioned manual settings can also be applied through group policies, and there are far more update-related policies available in Windows 10 than those present in standard manual settings.
They can be applied to individual PCs using the Local Group Policy Editor Gpedit.msc, or through scripts. However, they are most commonly used in a Windows domain with Active Directory, where policy combinations can be managed across groups of PCs.
A significant number of policies are used exclusively in Windows 10. The most important ones are related to 'Windows Updates for Business', located in Computer Configuration > Administrative Templates > Windows Components > Windows Update > Windows Update for Business.
- Choose when to receive preview builds – the channel and delays for component updates.
- Choose when to receive quality updates – delays for monthly cumulative updates and other security-related updates.
- Manage preview builds: when users can connect their machines to the Windows Insider program and define the Insider ring.
An additional group of policies can be found in Computer Configuration > Administrative Templates > Windows Components > Windows Update, where you can:
- Remove access to the pause updates feature, preventing users from interfering with installations by delaying them for up to 35 days.
- Remove access to all update settings.
- Allow automatic downloading of updates on metered connections.
- Do not download drivers along with updates.
The following settings are only available in Windows 10 and relate to restarts and notifications:
- Disable automatic restarts for updates during the active hours.
- Specify a range for active hours to control automatic restarts.
- Specify a deadline for automatic restarts to install updates (between 2 and 14 days).
- Configure notifications with reminders about automatic restarts: increase the time users are warned about it (from 15 to 240 minutes).
- Disable notifications about automatic restarts for installing updates.
- Configure the notification for automatic restarts so that it does not disappear automatically after 25 seconds.
- Do not allow the policies delaying update retrieval to initiate scans in Windows Update: this policy prevents PCs from checking for updates if a delay is assigned.
- Allow users to manage restart timing and postpone notifications.
- Configure update notifications (notification appearance, from 4 to 24 hours), and warnings about impending restarts (from 15 to 60 minutes).
- Update power management policy for the restart basket (configuration for educational systems allowing updates even on battery power).
- Display update notification settings: allows prohibiting update notifications.
The following policies exist in both Windows 10 and some older versions of Windows:
- Configure automatic updates: this group of settings allows choosing a weekly, biweekly, or monthly update schedule, including the day of the week and time for automatic download and installation of updates.
- Specify the location of the Microsoft update service in the intranet: configure the Windows Server Update Services (WSUS) server in the domain.
- Allow the client to join the target group: administrators can use Active Directory security groups to define WSUS deployment rings.
- Do not connect to Windows Update locations on the internet: prohibit PCs running local updates from connecting to external update servers. proxy server Allow Windows Update power management to wake the system from sleep mode for installing scheduled updates.
- Always automatically restart the system at the scheduled time.
- Do not perform automatic reboots while users are logged into the system.
- Enterprise-level tools
Large organizations with a Windows network infrastructure can circumvent
Microsoft updates and deploy updates from a local server. This requires increased attention from the corporate IT department but adds flexibility to the company. The two most popular options are Windows Server Update Services (WSUS) and System Center Configuration Manager (SCCM). server обновления Microsoft и развёртывать обновления с местного сервера. Это требует повышенного внимания со стороны корпоративного IT-отдела, но добавляет компании гибкости. Два самых популярных варианта – это Windows Server Update Services (WSUS) и System Center Configuration Manager (SCCM).
The WSUS server is simpler to set up. It acts as a Windows Server and provides centralized storage for Windows updates within the organization. Using Group Policies, an administrator directs Windows 10 PCs to the WSUS server, which serves as the sole source of files for the entire organization. From its administration console, updates can be approved, and the timing of their application on individual PCs or groups of PCs can be selected. PCs can be manually assigned to different groups, or client-side targeting can be used to deploy updates based on existing Active Directory security groups.
As the cumulative updates for Windows 10 grow larger with each new release, they can consume a significant portion of bandwidth. WSUS servers save traffic by using Express Installation Files – this requires more free space on the server but significantly reduces the size of the update files sent to client PCs.
On WSUS servers version 4.0 and later, it is also possible to manage updates for Windows 10 components.
The second option, System Center Configuration Manager, utilizes the feature-rich Configuration Manager for Windows alongside WSUS to deploy quality updates and component updates. The dashboard allows network administrators to monitor Windows 10 usage across the network and create maintenance plans based on groups that include information on all PCs nearing the end of their support lifecycle.
If your organization already has Configuration Manager set up for earlier versions of Windows, adding support for Windows 10 will be relatively straightforward.
Source: habr.com
