Installation, Configuration and Deployment of Software Updates – SCCM 2007 -Part3

Installation, Configuration and Deployment of Software Updates – SCCM 2007
Configuring Software Update & Deployment Procedure - Part 3


Quick review interms of configuration & installation of SUP:

  • Installed SQL with sp2
  • Installed WSUS 3.1
  • Installed SCCM
  • Installed SUP
  • Configured SUP
  • Synched WSUS with Ms Updates
  • Downloaded all the critical & security updates for Windows XP

Now it’s a time to push the updates to the client. The major requirement for client machine – it should have internet connectivity to download the updates or atleast source path from where it should download those updates and other thing Configuration Manager Software needs to be installed. One of the major reason why we need configuration manager interms of Software updates is Windows Update Agent (WUA) 3.0 is required on client machine to retrieve the list of software updates that need to be need to scanned for compliance from WSUS. At the time of installation of Configuration Manager, the latest version of WUA is downloaded and if required configuration manager will upgrade the version.

Software Deployment Procedure:
Create Search Folder:
Assume a scenario where your client requested you to do Windows XP operating system deployment for some of the users. You would have Images in places which you will advertise and then your client will get standard base OS as per their requirement. But that image will be pretty older and till the time you deploy the OS, I am sure MS release lots of updates for respective operating system. Generally what we will do – simply assigning those patches and installing them one by one (if administrator doesn’t know the concept of categorization and templates).

By mode of search folder we can create search criteria to see all the packages with a specific set of rules like released\revised\MS Bulletin ID etc. This search folder will only help us to categorize the required data which can be associated in the form of one single template that means it won’t store any data in search folder but it will create a virtual folder.

Here in my case I want to install all the patches which is being released last 3 months, so inorder to achieve this we need to create search folder by following the below steps:

  • Open the SCCM Console => Site Database => Site Management => Computer Management
  • Expand Software updates => Update Repository => Right click Search Folder and click on “New Search Folder

Figure 1:

 

  • Once you configure the search folder you will see the list of updates in the search folder

Figure 2:
 

Even you can customize the Search folder as per your requirement like bulletin ID MS08 (MS08 indicate MS updates for the year 2008)

Create Software Update List:
The software update list will allow you to add or modify existing update list with new updates. This will make your manual task much simple otherwise you need to create a deployment for each and every updates.

Inorder to create update list:

  • Open the SCCM console
  • Navigate to new created search folder (in my case “Last 3 Months updates) : select all the updates under that search folder, right click and click on update list

Figure 3:

 

  • It will open a wizard, select “Create a new update list” and give a friendly for your update list

Figure 4:

 

  • Then it will give security rights details, simply click on NEXT
  • Summary updates about the patch details and update list information – Click on NEXT
  • Then it will display the progress of the update list

Figure 5:
 

  • Finally it will show the wizard completion status with green tick mark status as successful, click on close

Figure 5: 



Deploy Software Updates:
Note: Before creating deployment template for the update list, create one test collection for test computer to test or make sure your have the collection details on which you are going to push the updates. In my case I created one collection called as “Updates XP”

Deploy software updates  allows to create the deployment method to install the updates to the client machine on the target collection. Inorder to do this..

  • Go to Update list => right click on the update template and select “Deploy Software Updates”

Figure 6:

 

  • It will open Deploy Software update Wizard – in the General give a friendly name for your deployment template

Figure 7:

 

  • In Deployment Template select “ Create a new deployment definition”

Figure 8:
 

  • In the collection : select the target collection where you want to push this updates – I have selected “Update XP”
  • Display/Time Setting : Select “Allow display notifications on client” & “Client Local Time” to push the updates

Figure 9:

 

  • Restart Setting : You can set option “not to restart” for servers, as my update is only for client I am going to go with default setting
  • Event Generation : Default Setting
  • Download Setting : Set as per your requirement

Figure 10:


 

  • Create Template : Give a friendly name for your template

Figure 11:

 

  • Deployment Package : Create a new deployment package

Figure 12:

 

  • Configure the distribution point by select the DP server

Figure 13:

 

  • Download location : select the mode of download

Figure 14:
 

  • Language Selection : English (as a default one)
  • Schedule : customize as per your need
  • Summary : Summary about the setting which has been chosen
  • Progress : it will create and download the updates

Figure 15:
 

  • Confirmation : it will display the status of the template which is created

Figure 16:
 

Client End Configuration :
On the client end we require Windows Update Agent (WUA) 3.0 which is already installed and configured at the time of configuration manager software installation. And another thing is client computer should be have internet connection because we did the setup having the patch to download from Microsoft updates website
If everything is configured properly you should see Software Update Management Pop-Up
Figure 17:
 

If the update expired the time period what we had set for software updates – it will do a mandatory installation.

Troubleshooting Software Updates

  • Ensure that all the policy are applied on the client computer (Note : by default it should have all the policies running) Inorder to verify
  • Login to client computer => Control Panel => Double click Configuration Manager => Click on Actions Tab

Figure 18:
 

  • Check WindowsUpdate.log (Location C:\windows)
  • Check LocationServices.log
  • Check WUAHandler.log
  • Check UpdatesDeployment.log
  • Check CAS.log

Software Update Report:
Software Updates - A. Compliance

The reports in the Software Updates - A. Compliance category provide the scan results for software update compliance on client computers. More specifically, these reports provide information about what software updates are required, installed, or not required on clients. The following software updates reports are in this category:
• Compliance 1 - Overall Compliance
This report returns the overall compliance for the set of software updates in a specific update list and collection.
• Compliance 2 - Specific software update
This report returns the overall compliance data for a specified software update.
• Compliance 3 - Update list (per update)
This report returns the overall compliance data for software updates defined in an Update List.
• Compliance 4 - Deployment (per update)
This report returns the overall compliance data for software updates defined in a deployment.
• Compliance 5 -Updates by vendor/month/year
This report returns the compliance data for software updates released by a vendor during a specific month and year.
• Compliance 6 - Specific computer
This report returns the software update compliance data for a specific computer.
• Compliance 7 - Specific software update states <secondary>
This report returns the count and percentage of computers in each compliance state for the specified software update.
• Compliance 8 - Computers in a specific compliance state for an update list <secondary>
This report returns all computers that have a specific compliance state for the set of software updates in an update list.
• Compliance 9 - Computers in a specific compliance state for an update
This report returns all computers in a specific compliance state for a software update
Source : Microsoft Technet

Related Article:
Overview of Software Updates & Installation of WSUS 3.0 - Part 1
Installation of SUP and Software Update Synchronization - Part 2
Configuring Software Update & Deployment Procedure - Part 3

Reference Link:
http://technet.microsoft.com/en-us/library/bb680701.aspx

 

 del.icio.us  Stumbleupon  Technorati  Digg 

 

What did you think of this article?




Trackbacks
  • Trackbacks are closed for this entry.
Comments

Leave a comment

Submitted comments will be subject to moderation before being displayed.

 Enter the above security code (required)

 Name (required)

 Email (will not be published) (required)

 Website

Your comment is 0 characters limited to 3000 characters.